Artifact GuideUSSensitive Personal Information Limits

US CPRA Sensitive Personal Information Limits

A business must offer the right to limit when it uses or discloses sensitive personal information beyond the permitted purposes in Civil Code section 1798.121 and regulation section 7027.

Apply the cited California statute and regulations to the actual entity, data flow, system, and recipient role; escalate unresolved legal interpretation.

Author
Sorena AI
Published
May 9, 2026
Updated
Jul 24, 2026
Questions
3

Structured answer sets in this page tree.

Primary sources
4

Cited legal and guidance references.

Publication metadata
Sorena AI
Published May 9, 2026
Updated Jul 24, 2026
Overview

The California Consumer Privacy Act (CCPA), as amended by the California Privacy Rights Act (CPRA), lets consumers limit a covered business's use and disclosure of when the business goes beyond specified permitted purposes. This page explains the category, purpose test, request methods, 15-business-day outside deadline, downstream action, consent rules, and evidence to retain.

Search this module

Find a question or answer quickly

3 of 3 questions
Question 1

What should teams do about Sensitive Personal Information Limits under the US CPRA?

includes specified government and account credentials; precise geolocation; racial or ethnic origin, citizenship or immigration status, religious or philosophical beliefs, union membership, genetic data, and neural data; private communications when the business is not the intended recipient; biometric information processed to identify a consumer; analyzed health, sex-life, or sexual-orientation information; and personal information of a consumer the business actually knows is under 16. Publicly available information is excluded from the category.

The applies when a covered business uses or discloses for purposes beyond those listed in regulation section 7027(m). Those permitted purposes include providing goods or services an average consumer reasonably expects, specified security and safety activities, short-term transient use that does not build a consumer profile, and performing services on the business's behalf. Every permitted use must still be reasonably necessary and proportionate. For example, a directions app may use precise geolocation to route the consumer, while a gaming app cannot rely on that expectation if location is unnecessary. A health-article search box may use a query to return results without inferring a characteristic; using the query to profile the consumer changes the analysis.

A business subject to the right must provide at least two request methods, including an online form reached through the "Limit the Use of My " link or a permitted Alternative Opt-out Link when it collects sensitive personal information online. It cannot require an account or a verifiable consumer request. It must stop non-permitted uses and disclosures as soon as feasibly possible and no later than 15 business days after receipt, instruct affected service providers and contractors within the same period, and notify relevant third parties for disclosures made during the processing window.

After honoring a request, the business generally must wait at least 12 months before asking the consumer to consent to a use or disclosure outside section 7027(m). If the consumer initiates a transaction or tries to use a product that requires an additional sensitive-data use, the business may explain the requirement and ask for consent through the section 7004 process. Record the data category, whether the business infers characteristics, each purpose and recipient, the request date, the date restrictions took effect, downstream instructions, and any exception or later consent.

  • Map each sensitive-data use to a specific section 7027(m) purpose; do not label an entire product or system exempt.
  • Test the request method without login and confirm that all affected downstream uses and disclosures stop within 15 business days.
  • Escalate disputes about inference, reasonable consumer expectations, proportionality, or consent before relying on an exception.
Citations
Question 2

What evidence should teams keep for Sensitive Personal Information Limits under the US CPRA?

Keep the sensitive-data inventory, inference analysis, section 7027(m) purpose mapping, recipients, notice and choice-link screenshots, request and consent logs, downstream instructions, and dated tests. The evidence should show both the request date and when every restricted use or disclosure stopped.

  • Scope record: each sensitive-information category, source, system, inference purpose, section 7027(m) purpose if claimed, necessity and proportionality analysis, recipient, and owner.
  • Choice record: notice and link screenshots, methods offered, request timestamp, confirmation state, restricted-use effective time, third-party notices, service-provider and contractor instructions, and the 15-business-day outside deadline.
  • Consent record: prior request date, 12-month timer, consumer-initiated transaction if applicable, two-step opt-in evidence, purpose authorized, withdrawal path, exception note, implementation ticket, and dated retest.
Citations
Question 3

Which mistakes create risk when handling Sensitive Personal Information Limits under the US CPRA?

Common failures include treating every sensitive-data use as limitable, claiming the no-inference boundary while using the data to profile a consumer, treating one permitted purpose as an entity-wide exemption, relying on a cookie banner that does not address the , or changing a preference display while downstream use and disclosure continue.

  • Claiming a permitted purpose without showing that the use is reasonably necessary and proportionate.
  • Requiring account creation or identity verification for a request that does not require either.
  • Recording the preference in one interface while vendors or other recipients continue a restricted use.
Citations
Primary sources

References and citations

leginfo.legislature.ca.gov
Referenced sections
  • Official statutory text for the consumer's right to limit qualifying use and disclosure of sensitive personal information.
"limit its use of the consumer’s sensitive personal information"
cppa.ca.gov
Referenced sections
  • Effective regulations defining permitted purposes and the no-inference boundary for requests to limit in section 7027.
"without the purpose of inferring characteristics about a consumer"
Related guides

Explore more topics

California CCPA and CPRA Applicability Test
Decide whether the CCPA as amended by the CPRA applies, using California nexus, current business thresholds, related-entity rules, and data-specific exemptions.
California CCPA and CPRA Compliance Checklist
A California CCPA/CPRA implementation checklist covering scope, notices, rights, opt-outs, vendor contracts, retention, security, and 2026 regulations.
California CCPA/CPRA Deadlines and Compliance Calendar
Track California CCPA and CPRA request clocks, phased 2026 regulation deadlines, recurring metrics, and separate Delete Act dates.
California CCPA/CPRA Penalties, Fines, and Private Damages
Understand current California CCPA and CPRA fine caps, who enforces them, the limited private action for security breaches, and the evidence to preserve.
California CPRA FAQ
Practical California CPRA FAQ guidance with implementation decisions, evidence, edge cases, and official California source citations.
California CPRA Requirements Guide
California CCPA/CPRA requirements for covered businesses: notices, rights, opt-outs, data-use limits, contracts, security, and phased 2026 rules.
California CPRA Risk Assessments, Cybersecurity Audits, and ADMT Guide
Apply the separate California trigger tests, duties, phase-in dates, evidence, and consumer rights for risk assessments, cybersecurity audits, and ADMT.
California Data Broker Deletion Workflow Guide
California Delete Act and CPRA-adjacent guidance for data broker deletion workflows, with practical decisions, evidence, edge cases, and official citations.
California Data Broker Registry and DROP Guide
California Delete Act guide to data-broker scope, annual registration, DROP processing from August 1, 2026, deletion, opt-out fallback, metrics, and audits.
California Delete Act data broker registry and DROP guide
California Delete Act guidance for the data broker registry and Delete Request and Opt-Out Platform (DROP), with owners, evidence, and official sources.
CCPA vs CPRA: What Changed in California Privacy Law
Compare the original CCPA with the CPRA amendments, including scope thresholds, new rights, contracts, retention, enforcement, and implementation steps.
CPPA Regulations Tracker | CCPA and CPRA
Track the in-force 2023 and 2026 CCPA regulations, their legal status, affected processing, and phased risk, audit, and ADMT deadlines.
CPRA enforcement advisories: CPPA investigations, fines, and risk mitigation
US CPRA guidance for Enforcement Advisories, with practical decisions, evidence, edge cases, and external source citations.
CPRA Global Privacy Control (GPC): opt-out requirements and enforcement FAQ
US CPRA guidance for GPC, with practical decisions, evidence, edge cases, and external source citations.
CPRA vs Colorado Privacy Act: Practical Comparison
Compare California and Colorado privacy law on scope, consumer rights, opt-outs, sensitive data, contracts, assessments, and enforcement.
CPRA vs Virginia VCDPA: Practical Comparison
Compare California and Virginia privacy law on scope, rights, sale, advertising, sensitive data, contracts, assessments, and enforcement.
US CPRA Compliance Guide
Build a CCPA/CPRA compliance program for scope, notices, consumer rights, opt-outs, vendor contracts, retention, security, and phased 2026 duties.
US CPRA Consumer Rights Workflow Guide
Run California CCPA and CPRA requests to know, delete, correct, opt out, limit, and access or opt out of covered ADMT, with deadlines, verification, exceptions, and evidence.
US CPRA Contract Terms Guide
Required CCPA/CPRA contract terms for service providers, contractors, and third parties, with role tests, clause checks, and evidence.
US CPRA Contracts Contractors and Service Providers Guide
Classify CCPA recipients as service providers, contractors, or third parties and apply the correct purpose limits, contracts, and consumer instructions.
US CPRA Correction Rights Guide
Handle CCPA correction requests: verification, accuracy review, documentation, system and vendor updates, response timing, denials, and records.
US CPRA Cyber Audit Readiness Workflow Guide
US CPRA guidance for Cyber Audit Readiness Workflow, with practical decisions, evidence, edge cases, and external source citations.
US CPRA DSAR and Correction Workflow Guide
US CPRA guidance for DSAR and Correction Workflow, with practical decisions, evidence, edge cases, and external source citations.
US CPRA GPC Handling Guide
How businesses subject to the CCPA must detect, apply, test, and document Global Privacy Control opt-out signals.
US CPRA GPC Handling Workflow Guide
A California GPC workflow for signal detection, browser and profile scope, conflicts, downstream suppression, 15-business-day completion, and test evidence.
US CPRA Retention Guide
How to set, disclose, implement, and review personal-information retention periods under the California CCPA and CPRA.
US CPRA Risk Assessment Intake Workflow Guide
Screen the six CPPA risk-assessment triggers, record exceptions and evidence, hold covered launches for approval, and track review and submission dates.
US CPRA Risk Assessment Template Guide
US CPRA guidance for CPRA Risk Assessment Template, with practical decisions, evidence, edge cases, and external source citations.
US CPRA Risk Assessments and Cybersecurity Audits Guide
Apply the separate CPPA trigger tests for processing-level risk assessments and entity-level annual cybersecurity audits, with phase-in dates and evidence.
US CPRA Sensitive Personal Information Guide
Classify California sensitive personal information, distinguish category status from the right to limit, and apply notices, assessments, controls, and deadlines.
US CPRA Sensitive Personal Information Limits Guide
Decide when California's right to limit applies, map uses to section 7027(m), implement the 15-business-day restriction, and preserve evidence.
US CPRA Sharing and Cross-Context Behavioral Advertising Guide
How to classify advertising data flows as sharing for cross-context behavioral advertising under the California CCPA and CPRA.
What counts as sharing under the California CPRA?
How to identify sharing for cross-context behavioral advertising and implement California notice, opt-out, preference-signal, contract, and recordkeeping duties.
What should teams do about ADMT under the US CPRA?
Decide whether California's ADMT rules cover an automated decision, then apply the 2027 notice, access, opt-out, appeal, and evidence requirements.
What should teams do about Contract Terms under the US CPRA?
Classify California data recipients and check the required service-provider, contractor, third-party, subcontractor, monitoring, and remediation terms.
What should teams do about Correction Rights under the US CPRA?
Handle a California request to correct with the right verification, 10-day confirmation, 45-day response, accuracy test, denial rules, and downstream evidence.
What should teams do about Cybersecurity Audits under the US CPRA?
US CPRA guidance for Cybersecurity Audits, with practical decisions, evidence, edge cases, and external source citations.
What should teams do about retention under the California CPRA?
California CPRA guidance for retention, including data minimization, privacy policy disclosures, evidence records, and official source citations.
When is a CPRA risk assessment required?
When California businesses must conduct CPRA risk assessments, what each report must contain, and the review, retention, and filing deadlines.