Artifact GuideUSCorrection Rights

US CPRA Correction Rights

A California consumer may ask a covered business to correct inaccurate personal information; the business must verify, assess, respond, and keep corrected data from being overwritten.

Apply the cited California statute and regulations to the actual entity, data flow, system, and recipient role; escalate unresolved legal interpretation.

Author
Sorena AI
Published
May 9, 2026
Updated
Jul 24, 2026
Questions
3

Structured answer sets in this page tree.

Primary sources
5

Cited legal and guidance references.

Publication metadata
Sorena AI
Published May 9, 2026
Updated Jul 24, 2026
Overview

This page explains how a covered business should receive, verify, decide, and implement a California , including the 10-business-day confirmation, 45-calendar-day response period, denial grounds, downstream corrections, and backup-system rule.

Search this module

Find a question or answer quickly

3 of 3 questions
Question 1

How should a business handle a correction request under the US CPRA?

A California consumer may ask a covered business to correct inaccurate personal information that the business maintains. The business must use , taking into account the nature of the information and the purposes for which it is processed. It must confirm receipt within 10 business days and respond within 45 calendar days of receipt. If necessary, it may extend once for up to 45 additional calendar days, but it must notify the consumer and explain the delay.

Verify the consumer with information other than the field being disputed. The business may deny the request if it cannot verify the consumer or if, after considering the totality of the circumstances, the contested information is more likely than not accurate. The assessment should consider whether the information is objective or subjective, how it was obtained, why the business uses it, its effect on the consumer, and documentation from the consumer, the business, or another source. If the business is not the source and has no supporting documentation, the consumer's assertion may be enough to establish inaccuracy.

When granting the request, correct active systems, prevent later data imports from restoring the error, and instruct service providers and contractors that maintain the information to correct it and keep it corrected. A correction in an archived or backup system may wait until that system is restored, accessed, or used. A denial response should explain the basis and tell the consumer that they may submit a complaint to the CPPA or California Attorney General.

Other denial grounds require their own records. A business may deny the same alleged inaccuracy after a denial within the previous six months, or deny a request it reasonably and in good faith believes is fraudulent or abusive, but it must explain the decision. A claim of impossibility or needs enough facts for the consumer to understand why compliance is not possible; a bare label is insufficient.

The business may delete instead of correct only if deletion will not harm the consumer or the consumer consents. If the business is not the source, it must either name the source to the consumer or tell the source to correct the information. A consumer can ask to confirm the correction; for sensitive identifiers such as account credentials, government identifiers, financial account numbers, health identifiers, and unique biometric data, provide a secure confirmation method rather than disclosing the value.

A denial involving personal information collected and analyzed about the consumer's health has an additional branch. The response must explain that the consumer may submit a written statement, limited to 250 words for each alleged inaccuracy, and ask for it to be added to the record. On request, the business must make that statement available to a person to whom it discloses, shares, or sells the disputed information.

  • Confirm the disputed record and requested correction without collecting more verification data than necessary.
  • Track the 10-business-day confirmation and the 45-calendar-day response period from the date of receipt, not the verification date.
  • Test whether source feeds, service providers, contractors, and restored backups preserve the corrected value.
  • Use correction documentation only for the correction and required recordkeeping, protect it with reasonable security, and retain the request-and-response record for at least 24 months.
Citations
Question 2

What evidence should teams keep for Correction Rights under the US CPRA?

Keep the request, receipt confirmation, verification steps, disputed field and proposed correction, accuracy evidence considered, decision, systems and recipients updated, response date, extension notice if any, and denial explanation. Minimize retained identity evidence and record how the business prevents an inaccurate source feed from overwriting the correction.

The request log should show the request date and method, request type, response date and type, and any denial basis for at least 24 months. If the business relies on a repeat-request, fraud, abuse, impossibility, disproportionate-effort, deletion, source-notification, or health-statement branch, retain the facts, notice, approval, and completed follow-up for that branch.

  • Source URL and quote used for the decision.
  • Scope notes, disputed field, source system, downstream recipients, backup behavior, and verification method.
  • Implementation ticket, decision and approval, consumer response, exception evidence, overwrite test, and review date.
Citations
Question 3

Which mistakes create risk when handling Correction Rights under the US CPRA?

Common failures include starting the 45-day clock after verification, correcting only the customer-facing profile, allowing a later import to restore the error, demanding disproportionate verification, treating a disputed opinion as an objectively false fact without considering its nature, or denying a request without a factual explanation.

  • Starting the response clock after verification instead of on the day the request arrives.
  • Rejecting the consumer's evidence without considering the source, nature, and existing documentation for the disputed field.
  • Correcting an active record without preventing an old source or restored backup from reintroducing the error.
Citations
Primary sources

References and citations

leginfo.legislature.ca.gov
Referenced sections
  • Official source for risk and boundary analysis of confirming the correction right comes from California statute, not a dark-pattern or data-broker provision.
"taking into account the nature of the personal information"
cppa.ca.gov
Referenced sections
  • Official consumer background on the right to correct; the detailed denial rules come from the regulations cited with this section.
"You may ask businesses to correct inaccurate information they have about you."
Related guides

Explore more topics

California CCPA and CPRA Applicability Test
Decide whether the CCPA as amended by the CPRA applies, using California nexus, current business thresholds, related-entity rules, and data-specific exemptions.
California CCPA and CPRA Compliance Checklist
A California CCPA/CPRA implementation checklist covering scope, notices, rights, opt-outs, vendor contracts, retention, security, and 2026 regulations.
California CCPA/CPRA Deadlines and Compliance Calendar
Track California CCPA and CPRA request clocks, phased 2026 regulation deadlines, recurring metrics, and separate Delete Act dates.
California CCPA/CPRA Penalties, Fines, and Private Damages
Understand current California CCPA and CPRA fine caps, who enforces them, the limited private action for security breaches, and the evidence to preserve.
California CPRA FAQ
Practical California CPRA FAQ guidance with implementation decisions, evidence, edge cases, and official California source citations.
California CPRA Requirements Guide
California CCPA/CPRA requirements for covered businesses: notices, rights, opt-outs, data-use limits, contracts, security, and phased 2026 rules.
California CPRA Risk Assessments, Cybersecurity Audits, and ADMT Guide
Apply the separate California trigger tests, duties, phase-in dates, evidence, and consumer rights for risk assessments, cybersecurity audits, and ADMT.
California Data Broker Deletion Workflow Guide
California Delete Act and CPRA-adjacent guidance for data broker deletion workflows, with practical decisions, evidence, edge cases, and official citations.
California Data Broker Registry and DROP Guide
California Delete Act guide to data-broker scope, annual registration, DROP processing from August 1, 2026, deletion, opt-out fallback, metrics, and audits.
California Delete Act data broker registry and DROP guide
California Delete Act guidance for the data broker registry and Delete Request and Opt-Out Platform (DROP), with owners, evidence, and official sources.
CCPA vs CPRA: What Changed in California Privacy Law
Compare the original CCPA with the CPRA amendments, including scope thresholds, new rights, contracts, retention, enforcement, and implementation steps.
CPPA Regulations Tracker | CCPA and CPRA
Track the in-force 2023 and 2026 CCPA regulations, their legal status, affected processing, and phased risk, audit, and ADMT deadlines.
CPRA enforcement advisories: CPPA investigations, fines, and risk mitigation
US CPRA guidance for Enforcement Advisories, with practical decisions, evidence, edge cases, and external source citations.
CPRA Global Privacy Control (GPC): opt-out requirements and enforcement FAQ
US CPRA guidance for GPC, with practical decisions, evidence, edge cases, and external source citations.
CPRA vs Colorado Privacy Act: Practical Comparison
Compare California and Colorado privacy law on scope, consumer rights, opt-outs, sensitive data, contracts, assessments, and enforcement.
CPRA vs Virginia VCDPA: Practical Comparison
Compare California and Virginia privacy law on scope, rights, sale, advertising, sensitive data, contracts, assessments, and enforcement.
US CPRA Compliance Guide
Build a CCPA/CPRA compliance program for scope, notices, consumer rights, opt-outs, vendor contracts, retention, security, and phased 2026 duties.
US CPRA Consumer Rights Workflow Guide
Run California CCPA and CPRA requests to know, delete, correct, opt out, limit, and access or opt out of covered ADMT, with deadlines, verification, exceptions, and evidence.
US CPRA Contract Terms Guide
Required CCPA/CPRA contract terms for service providers, contractors, and third parties, with role tests, clause checks, and evidence.
US CPRA Contracts Contractors and Service Providers Guide
Classify CCPA recipients as service providers, contractors, or third parties and apply the correct purpose limits, contracts, and consumer instructions.
US CPRA Correction Rights Guide
Handle CCPA correction requests: verification, accuracy review, documentation, system and vendor updates, response timing, denials, and records.
US CPRA Cyber Audit Readiness Workflow Guide
US CPRA guidance for Cyber Audit Readiness Workflow, with practical decisions, evidence, edge cases, and external source citations.
US CPRA DSAR and Correction Workflow Guide
US CPRA guidance for DSAR and Correction Workflow, with practical decisions, evidence, edge cases, and external source citations.
US CPRA GPC Handling Guide
How businesses subject to the CCPA must detect, apply, test, and document Global Privacy Control opt-out signals.
US CPRA GPC Handling Workflow Guide
A California GPC workflow for signal detection, browser and profile scope, conflicts, downstream suppression, 15-business-day completion, and test evidence.
US CPRA Retention Guide
How to set, disclose, implement, and review personal-information retention periods under the California CCPA and CPRA.
US CPRA Risk Assessment Intake Workflow Guide
Screen the six CPPA risk-assessment triggers, record exceptions and evidence, hold covered launches for approval, and track review and submission dates.
US CPRA Risk Assessment Template Guide
US CPRA guidance for CPRA Risk Assessment Template, with practical decisions, evidence, edge cases, and external source citations.
US CPRA Risk Assessments and Cybersecurity Audits Guide
Apply the separate CPPA trigger tests for processing-level risk assessments and entity-level annual cybersecurity audits, with phase-in dates and evidence.
US CPRA Sensitive Personal Information Guide
Classify California sensitive personal information, distinguish category status from the right to limit, and apply notices, assessments, controls, and deadlines.
US CPRA Sensitive Personal Information Limits Guide
Decide when California's right to limit applies, map uses to section 7027(m), implement the 15-business-day restriction, and preserve evidence.
US CPRA Sharing and Cross-Context Behavioral Advertising Guide
How to classify advertising data flows as sharing for cross-context behavioral advertising under the California CCPA and CPRA.
What counts as sharing under the California CPRA?
How to identify sharing for cross-context behavioral advertising and implement California notice, opt-out, preference-signal, contract, and recordkeeping duties.
What should teams do about ADMT under the US CPRA?
Decide whether California's ADMT rules cover an automated decision, then apply the 2027 notice, access, opt-out, appeal, and evidence requirements.
What should teams do about Contract Terms under the US CPRA?
Classify California data recipients and check the required service-provider, contractor, third-party, subcontractor, monitoring, and remediation terms.
What should teams do about Cybersecurity Audits under the US CPRA?
US CPRA guidance for Cybersecurity Audits, with practical decisions, evidence, edge cases, and external source citations.
What should teams do about retention under the California CPRA?
California CPRA guidance for retention, including data minimization, privacy policy disclosures, evidence records, and official source citations.
What should teams do about Sensitive Personal Information Limits under the US CPRA?
US CPRA guidance for Sensitive Personal Information Limits, with practical decisions, evidence, edge cases, and external source citations.
When is a CPRA risk assessment required?
When California businesses must conduct CPRA risk assessments, what each report must contain, and the review, retention, and filing deadlines.