Artifact GuideUSRetention

US CPRA Retention

A business must disclose how long it intends to retain each category of personal information, or the criteria used to set that period, and must not keep the category longer than reasonably necessary for its disclosed purpose.

Use this guide to build a category-by-purpose schedule, align the notice with system behavior, and document exceptions without allowing indefinite retention.

Author
Sorena AI
Published
May 9, 2026
Updated
Jul 25, 2026
Sections
4

Structured answer sets in this page tree.

Primary sources
7

Cited legal and guidance references.

Publication metadata
Sorena AI
Published May 9, 2026
Updated Jul 25, 2026
Overview

The California Consumer Privacy Act (CCPA), as amended by the California Privacy Rights Act (CPRA), does not impose one for all personal information. A covered business must state, at or before collection, how long it intends to retain each category of personal information, including sensitive personal information. If a period cannot be stated, the business must disclose the criteria used to determine it. For each disclosed purpose, retention must be no longer than reasonably necessary, and the overall processing must be reasonably necessary and proportionate.

Section 1

What does CPRA retention require?

Civil Code section 1798.100 requires a category-level disclosure. A single statement such as "we keep information as long as necessary" does not identify a period and may not give a consumer meaningful criteria for determining one. Criteria should tell the reader what event starts or ends retention and what obligation can extend it.

Personal information includes information that identifies, relates to, describes, or could reasonably be linked with a consumer or household, not only direct identifiers. A category can have more than one purpose and therefore more than one justified period. For example, contact details used to deliver an order may also appear in a transaction record kept for a separately identified accounting or dispute purpose. Map the category, purpose, system, start event, normal end event, and supported extension instead of assigning one unexplained period to the whole database.

  • State a fixed period when the business can determine one.
  • When a fixed period is not possible, state usable criteria, such as account closure plus a defined dispute period or the end of a documented legal obligation.
  • Include sensitive personal information in the same category-by-purpose analysis.
  • At the approved endpoint, delete the personal information or convert it to that cannot reasonably be linked to a consumer, backed by the required anti-reidentification measures, public commitment, and recipient contracts.
Section 2

How should a business pick a reasonable retention period?

Start with the specific purpose disclosed when the information was collected. Identify the minimum information and time needed to achieve that purpose, the possible negative effects on consumers, and safeguards that address those effects. Storage cost, possible future usefulness, or the absence of deletion tooling does not establish that retention is reasonably necessary and proportionate.

Then test each proposed extension separately. A statute, court order, contract, active dispute, fraud investigation, or legal hold may support longer retention for particular records, but the facts and applicable rule determine its scope. Record the authority, affected categories, start and end conditions, and permitted use during the extension. Do not let a narrow exception pause deletion for unrelated copies or uses.

  • Use separate periods when one category serves different disclosed purposes.
  • Test whether aggregation or CCPA-compliant deidentification can meet a continuing analytical need without retaining personal information.
  • Define when the clock starts: collection, last interaction, transaction completion, account closure, or another objective event.
  • Give every exception an owner, authority, scope, review date, and release condition.
Section 3

Who should own the retention decision and what evidence should support it?

Privacy or data governance should maintain the retention schedule and notice mapping. The team responsible for each system should implement the end-of-period action. Legal should approve claimed legal obligations and holds, procurement should carry the schedule into service-provider and contractor controls, and security or internal audit should test whether deletion and deidentification run as designed.

The evidence record should connect the public disclosure to actual data. For each category and purpose, retain the approved period or criteria, governing authority, systems and vendors, clock-start event, deletion or deidentification action, exception logic, owner, approval date, and last test result.

  • Reconcile the data inventory, retention schedule, Notice at Collection, privacy policy, contracts, and production configuration.
  • Test primary stores, archives, logs, exports, data lakes, employee tools, and vendor copies rather than checking only the system of record.
  • Record counts or sampled records before and after a deletion or deidentification job so the result can be reviewed.
  • Review failed jobs, restored backups, and released holds to prevent expired information from returning to active use.
Section 4

What should teams check before they publish or update a retention notice?

The Notice at Collection must be available at or before collection and must include the or criteria for every listed category. An online notice may link directly to the specific privacy-policy section containing the required information; sending the consumer to the start of a long policy does not meet the regulation's direct-link standard.

Before publication, compare the words with system rules. Criteria should be understandable without internal knowledge, and any broad phrase should be followed by the event or obligation that determines the endpoint. If a purpose, category, or period materially changes, assess whether the business must update the notice before collecting or using information under the new practice.

  • Check every personal-information and sensitive-personal-information category against the schedule.
  • State periods consistently across the Notice at Collection, privacy policy, product notices, and internal rules.
  • Verify that stated criteria produce a determinable endpoint and do not amount to indefinite retention.
  • Re-run the review when purposes, categories, systems, vendors, legal obligations, or deletion methods change.
Primary sources

References and citations

leginfo.legislature.ca.gov
Referenced sections
  • Requires notice before collection and new notice before collecting additional categories or using information for additional purposes incompatible with the disclosed purpose.
leginfo.legislature.ca.gov
Referenced sections
  • Defines deidentified information and the measures, public commitment, and recipient contract needed for information to qualify.
leginfo.legislature.ca.gov
Referenced sections
  • Provides the retention limitation and identifies circumstances in which CCPA obligations do not restrict a business's ability to comply with law, legal process, or specified investigations.
cppa.ca.gov
Referenced sections
  • Official CPPA source for current regulations on proportionality, the Notice at Collection, privacy policies, and service-provider and contractor restrictions.
Related guides

Explore more topics

California CCPA and CPRA Applicability Test
Decide whether the CCPA as amended by the CPRA applies, using California nexus, current business thresholds, related-entity rules, and data-specific exemptions.
California CCPA and CPRA Compliance Checklist
A California CCPA/CPRA implementation checklist covering scope, notices, rights, opt-outs, vendor contracts, retention, security, and 2026 regulations.
California CCPA/CPRA Deadlines and Compliance Calendar
Track California CCPA and CPRA request clocks, phased 2026 regulation deadlines, recurring metrics, and separate Delete Act dates.
California CCPA/CPRA Penalties, Fines, and Private Damages
Understand current California CCPA and CPRA fine caps, who enforces them, the limited private action for security breaches, and the evidence to preserve.
California CPRA FAQ
Practical California CPRA FAQ guidance with implementation decisions, evidence, edge cases, and official California source citations.
California CPRA Requirements Guide
California CCPA/CPRA requirements for covered businesses: notices, rights, opt-outs, data-use limits, contracts, security, and phased 2026 rules.
California CPRA Risk Assessments, Cybersecurity Audits, and ADMT Guide
Apply the separate California trigger tests, duties, phase-in dates, evidence, and consumer rights for risk assessments, cybersecurity audits, and ADMT.
California Data Broker Deletion Workflow Guide
California Delete Act and CPRA-adjacent guidance for data broker deletion workflows, with practical decisions, evidence, edge cases, and official citations.
California Data Broker Registry and DROP Guide
California Delete Act guide to data-broker scope, annual registration, DROP processing from August 1, 2026, deletion, opt-out fallback, metrics, and audits.
California Delete Act data broker registry and DROP guide
California Delete Act guidance for the data broker registry and Delete Request and Opt-Out Platform (DROP), with owners, evidence, and official sources.
CCPA vs CPRA: What Changed in California Privacy Law
Compare the original CCPA with the CPRA amendments, including scope thresholds, new rights, contracts, retention, enforcement, and implementation steps.
CPPA Regulations Tracker | CCPA and CPRA
Track the in-force 2023 and 2026 CCPA regulations, their legal status, affected processing, and phased risk, audit, and ADMT deadlines.
CPRA enforcement advisories: CPPA investigations, fines, and risk mitigation
US CPRA guidance for Enforcement Advisories, with practical decisions, evidence, edge cases, and external source citations.
CPRA Global Privacy Control (GPC): opt-out requirements and enforcement FAQ
US CPRA guidance for GPC, with practical decisions, evidence, edge cases, and external source citations.
CPRA vs Colorado Privacy Act: Practical Comparison
Compare California and Colorado privacy law on scope, consumer rights, opt-outs, sensitive data, contracts, assessments, and enforcement.
CPRA vs Virginia VCDPA: Practical Comparison
Compare California and Virginia privacy law on scope, rights, sale, advertising, sensitive data, contracts, assessments, and enforcement.
US CPRA Compliance Guide
Build a CCPA/CPRA compliance program for scope, notices, consumer rights, opt-outs, vendor contracts, retention, security, and phased 2026 duties.
US CPRA Consumer Rights Workflow Guide
Run California CCPA and CPRA requests to know, delete, correct, opt out, limit, and access or opt out of covered ADMT, with deadlines, verification, exceptions, and evidence.
US CPRA Contract Terms Guide
Required CCPA/CPRA contract terms for service providers, contractors, and third parties, with role tests, clause checks, and evidence.
US CPRA Contracts Contractors and Service Providers Guide
Classify CCPA recipients as service providers, contractors, or third parties and apply the correct purpose limits, contracts, and consumer instructions.
US CPRA Correction Rights Guide
Handle CCPA correction requests: verification, accuracy review, documentation, system and vendor updates, response timing, denials, and records.
US CPRA Cyber Audit Readiness Workflow Guide
US CPRA guidance for Cyber Audit Readiness Workflow, with practical decisions, evidence, edge cases, and external source citations.
US CPRA DSAR and Correction Workflow Guide
US CPRA guidance for DSAR and Correction Workflow, with practical decisions, evidence, edge cases, and external source citations.
US CPRA GPC Handling Guide
How businesses subject to the CCPA must detect, apply, test, and document Global Privacy Control opt-out signals.
US CPRA GPC Handling Workflow Guide
A California GPC workflow for signal detection, browser and profile scope, conflicts, downstream suppression, 15-business-day completion, and test evidence.
US CPRA Risk Assessment Intake Workflow Guide
Screen the six CPPA risk-assessment triggers, record exceptions and evidence, hold covered launches for approval, and track review and submission dates.
US CPRA Risk Assessment Template Guide
US CPRA guidance for CPRA Risk Assessment Template, with practical decisions, evidence, edge cases, and external source citations.
US CPRA Risk Assessments and Cybersecurity Audits Guide
Apply the separate CPPA trigger tests for processing-level risk assessments and entity-level annual cybersecurity audits, with phase-in dates and evidence.
US CPRA Sensitive Personal Information Guide
Classify California sensitive personal information, distinguish category status from the right to limit, and apply notices, assessments, controls, and deadlines.
US CPRA Sensitive Personal Information Limits Guide
Decide when California's right to limit applies, map uses to section 7027(m), implement the 15-business-day restriction, and preserve evidence.
US CPRA Sharing and Cross-Context Behavioral Advertising Guide
How to classify advertising data flows as sharing for cross-context behavioral advertising under the California CCPA and CPRA.
What counts as sharing under the California CPRA?
How to identify sharing for cross-context behavioral advertising and implement California notice, opt-out, preference-signal, contract, and recordkeeping duties.
What should teams do about ADMT under the US CPRA?
Decide whether California's ADMT rules cover an automated decision, then apply the 2027 notice, access, opt-out, appeal, and evidence requirements.
What should teams do about Contract Terms under the US CPRA?
Classify California data recipients and check the required service-provider, contractor, third-party, subcontractor, monitoring, and remediation terms.
What should teams do about Correction Rights under the US CPRA?
Handle a California request to correct with the right verification, 10-day confirmation, 45-day response, accuracy test, denial rules, and downstream evidence.
What should teams do about Cybersecurity Audits under the US CPRA?
US CPRA guidance for Cybersecurity Audits, with practical decisions, evidence, edge cases, and external source citations.
What should teams do about retention under the California CPRA?
California CPRA guidance for retention, including data minimization, privacy policy disclosures, evidence records, and official source citations.
What should teams do about Sensitive Personal Information Limits under the US CPRA?
US CPRA guidance for Sensitive Personal Information Limits, with practical decisions, evidence, edge cases, and external source citations.
When is a CPRA risk assessment required?
When California businesses must conduct CPRA risk assessments, what each report must contain, and the review, retention, and filing deadlines.