- Official California statutory source for opt-out preference signals, sale or sharing opt-outs, and cross-context behavioral advertising rulemaking authority.
"Global opt out from sale and sharing of personal information"
Use this hub to decide whether the CCPA applies, which consumer right or processing rule is triggered, what deadline controls, and which detailed FAQ to open next.
Apply the cited California statute and regulations to the actual entity, data flow, system, and recipient role; escalate unresolved legal interpretation.
Structured answer sets in this page tree.
Cited legal and guidance references.
The CPRA amended California's CCPA; it is not a separate parallel privacy statute. This FAQ hub orients businesses to coverage, consumer rights, sale and sharing choices, sensitive personal information, vendor roles, retention, and the newer cybersecurity, risk-assessment, and regulations.
These focused FAQ modules break this artifact into narrower answer sets so teams can move straight to the right source-backed guidance.
California Delete Act guidance for the data broker registry and Delete Request and Opt-Out Platform (DROP), with owners, evidence, and official sources.
US CPRA guidance for Enforcement Advisories, with practical decisions, evidence, edge cases, and external source citations.
US CPRA guidance for GPC, with practical decisions, evidence, edge cases, and external source citations.
How to identify sharing for cross-context behavioral advertising and implement California notice, opt-out, preference-signal, contract, and recordkeeping duties.
Decide whether California's ADMT rules cover an automated decision, then apply the 2027 notice, access, opt-out, appeal, and evidence requirements.
Classify California data recipients and check the required service-provider, contractor, third-party, subcontractor, monitoring, and remediation terms.
Handle a California request to correct with the right verification, 10-day confirmation, 45-day response, accuracy test, denial rules, and downstream evidence.
US CPRA guidance for Cybersecurity Audits, with practical decisions, evidence, edge cases, and external source citations.
California CPRA guidance for retention, including data minimization, privacy policy disclosures, evidence records, and official source citations.
US CPRA guidance for Sensitive Personal Information Limits, with practical decisions, evidence, edge cases, and external source citations.
When California businesses must conduct CPRA risk assessments, what each report must contain, and the review, retention, and filing deadlines.
Start with entity coverage. A for-profit entity doing business in California is a if it determines the purposes and means of processing and meets at least one statutory test: the current adjusted gross-revenue threshold, buying, selling, or sharing the personal information of at least 100,000 consumers or households in a year, or deriving at least 50% of annual revenue from selling or sharing consumers' personal information. Parent, subsidiary, joint-control, nonprofit, sectoral, and data-specific rules can change the result, so document the legal entity and data flow before applying a control.
Next identify the action: notice at collection; a request to know, delete, or correct; an opt-out of sale or sharing; a signal; a request to limit sensitive personal information; a vendor-role contract; retention; or a newer cybersecurity audit, risk assessment, or duty. For ADMT used to make a significant decision, identify the separate pre-use notice, opt-out, access, and any human-appeal path. The CPRA is an amendment to the CCPA, while the Delete Act's data-broker registry and DROP duties come from a separate California title.
Name the exact trigger, consumer or data category, responsible business process, deadline, owner, downstream recipients, evidence, and escalation point. Use the detailed FAQ for the selected issue rather than applying one answer across unrelated rights.
Assign operational ownership to the team that can change the relevant system: privacy operations for request intake, product and engineering for interfaces and preference signals, procurement and legal for recipient contracts, data owners for retention, and security leadership for audits. Privacy counsel should review coverage, exemptions, denials, and other legal interpretations.
Consumer requests to delete, correct, know, access , or appeal ADMT generally require confirmation within 10 business days and a response within 45 calendar days, with one explained extension of up to 45 additional days when allowed. The response period starts when the business receives the request, regardless of verification time. Sale-or-sharing opt-outs, ADMT opt-outs, and sensitive-information limitation requests follow different rules, including a 15-business-day outer limit for stopping the covered processing and sending required downstream instructions. Keep each clock tied to the correct request type.
Evidence should show the coverage analysis, collection notices, request handling, GPC processing, sensitive-information purpose mapping, recipient contracts, retention controls, and any risk-assessment, cybersecurity-audit, or readiness work that the actual processing triggers.
Do not treat a sectoral or data-specific exemption as an entity-wide exclusion unless the statute says it is one. Publicly available information, deidentified information, employee records, business contacts, regulated financial or health data, and data handled by government bodies each require the exact statutory definition and facts. The temporary employee and business-contact exemptions expired after 2022, so current employment and business-contact processing cannot be excluded on that historical basis.
Reassess before a material change to the data, purpose, interface, vendor, recipient role, system logic, or law. In particular, distinguish selling from sharing for cross-context behavioral advertising, a service provider from a third party, and a sensitive-data use that is limitable from one allowed by section 7027(m). A signal applies at least to the browser or device that sends it and must also reach a known account when the business can associate the signal with that consumer.
Use one intake that captures entity coverage, data categories and purposes, consumer right, opt-out signal, recipient role, retention logic, cybersecurity-audit, risk-assessment and triggers, owner, deadline, and review date.
The result should be a specific record: a coverage memo, notice update, consumer-request workflow, opt-out and GPC test record, sensitive-information purpose map, vendor clause map, retention schedule, risk assessment, rights package, or cybersecurity-audit evidence pack.
This California CPRA guide turns FAQ answers into owners, evidence requests, review checkpoints, and reusable operating records in Sorena.
Turn FAQ into scoped questions, evidence fields, and review tasks.
Use Research Copilot to answer follow-up questions with cited source material.
Review scope, evidence, owners, and the next compliance actions with Sorena.
"Global opt out from sale and sharing of personal information"
"The previous data broker registries can be accessed at the Office of the Attorney General's Data Broker webpage."
"The CPRA amended the CCPA by adding additional consumer privacy rights and obligations for businesses"