What should teams do about Sensitive Personal Information Limits under the US CPRA?
includes specified government and account credentials; precise geolocation; racial or ethnic origin, citizenship or immigration status, religious or philosophical beliefs, union membership, genetic data, and neural data; private communications when the business is not the intended recipient; biometric information processed to identify a consumer; analyzed health, sex-life, or sexual-orientation information; and personal information of a consumer the business actually knows is under 16. Publicly available information is excluded from the category.
The applies when a covered business uses or discloses for purposes beyond those listed in regulation section 7027(m). Those permitted purposes include providing goods or services an average consumer reasonably expects, specified security and safety activities, short-term transient use that does not build a consumer profile, and performing services on the business's behalf. Every permitted use must still be reasonably necessary and proportionate. For example, a directions app may use precise geolocation to route the consumer, while a gaming app cannot rely on that expectation if location is unnecessary. A health-article search box may use a query to return results without inferring a characteristic; using the query to profile the consumer changes the analysis.
A business subject to the right must provide at least two request methods, including an online form reached through the "Limit the Use of My " link or a permitted Alternative Opt-out Link when it collects sensitive personal information online. It cannot require an account or a verifiable consumer request. It must stop non-permitted uses and disclosures as soon as feasibly possible and no later than 15 business days after receipt, instruct affected service providers and contractors within the same period, and notify relevant third parties for disclosures made during the processing window.
After honoring a request, the business generally must wait at least 12 months before asking the consumer to consent to a use or disclosure outside section 7027(m). If the consumer initiates a transaction or tries to use a product that requires an additional sensitive-data use, the business may explain the requirement and ask for consent through the section 7004 process. Record the data category, whether the business infers characteristics, each purpose and recipient, the request date, the date restrictions took effect, downstream instructions, and any exception or later consent.
- Map each sensitive-data use to a specific section 7027(m) purpose; do not label an entire product or system exempt.
- Test the request method without login and confirm that all affected downstream uses and disclosures stop within 15 business days.
- Escalate disputes about inference, reasonable consumer expectations, proportionality, or consent before relying on an exception.
Official statutory text for the consumer's right to limit qualifying use and disclosure of sensitive personal information.
Effective regulations defining permitted purposes and the no-inference boundary for requests to limit in section 7027.
Current regulations effective January 1, 2026, including request methods, the 15-business-day response rule, downstream instructions, the 12-month consent rule, and permitted purposes.