- Civil Code section 1798.121 is the statutory basis for the right to limit use and disclosure of sensitive personal information.
"consumers have the right to limit the use or disclosure of their sensitive personal information"
Sensitive personal information is a defined California category; classification can trigger notices, security, and risk-assessment duties even when the right to limit does not apply.
Classify the exact field or inference, record the purpose and recipients, then apply the separate right-to-limit and section 7150 tests.
Structured answer sets in this page tree.
Cited legal and guidance references.
is a defined subset of personal information. Classify the data first, then decide which duties follow from the actual use: notice at collection, reasonable security, a risk assessment, request handling, vendor controls, or the . The right to limit applies only when a covered business uses or discloses sensitive personal information beyond the purposes allowed by the regulations.
The current definition covers Social Security, driver's license, state identification card, and passport numbers; account log-in and financial account, debit card, or credit card numbers when combined with credentials that allow account access; ; racial or ethnic origin; citizenship or immigration status; religious or philosophical beliefs; union membership; mail, email, and text-message contents when the business is not the intended recipient; genetic data; and neural data. It also covers biometric information processed to uniquely identify a consumer, information collected and analyzed concerning health, sex life, or sexual orientation, and personal information of consumers the business actually knows are under 16. Willful disregard of age counts as actual knowledge. Publicly available information is excluded.
Each condition matters. A photograph is not automatically biometric information processed to identify a consumer; an approximate city is not ; a card number without the credentials needed to access the account does not meet that specific financial-credential category; and message content is treated differently when the business is the intended recipient. Record the exact field or inference, how it is produced, the consumer and age-knowledge basis, whether it reveals or is analyzed for a listed characteristic, purpose, recipient, and retention.
The applies when a business uses or discloses for a purpose outside section 7027(m). A business that stays only within those purposes need not provide the limit notice or request method if each use or disclosure is reasonably necessary and proportionate. Sensitive personal information collected or processed without the purpose of inferring characteristics is also outside requests to limit, but the business should document that factual conclusion rather than treating it as a blanket exemption.
When the right applies, the business must provide at least two request methods, including one that reflects how it primarily interacts with consumers. An online collector must at least provide an interactive form through the "Limit the Use of My " link or Alternative Opt-out Link. The methods must be easy to use, require minimal steps, and cannot require an account or a verifiable consumer request.
After a valid request, the business must stop non-permitted uses and disclosures as soon as feasibly possible and no later than 15 business days, instruct affected service providers and contractors within the same period, and send required directions to third parties that received the information between the request and implementation. It must let the consumer confirm that the request was processed and generally wait 12 months before asking for consent to the additional uses again.
Do not equate with all confidential or high-risk business data. The statutory and regulatory list controls this classification, while other California security, breach, employment, health, financial, or sector rules may still protect data outside the list. Likewise, classification alone does not prove that the applies.
Processing generally requires a risk assessment before the processing starts, even if the use stays within a permitted right-to-limit purpose. Section 7150 provides a narrow exception when employee or independent-contractor sensitive information is processed solely and specifically for listed compensation, work-authorization, benefits, reasonable-accommodation, or wage-reporting purposes. It is not a general employment-data exemption.
Reassess when the business begins inferring characteristics, increases geolocation precision, introduces identity matching, learns that a consumer is under 16, changes who receives message content, trains a model on the data, or adds a recipient or purpose.
The data owner should classify each field and purpose; privacy should decide the CCPA consequences and request design; security should set controls appropriate to the data; engineering should enforce purpose, access, retention, and preference rules; and procurement should bind service providers, contractors, and third parties to the approved use. Legal should review unclear conditions and exemptions.
Keep one data-category register with the defined category and condition, source and derivation, age-knowledge basis, inference purpose, system, recipient role, notice, retention, security control, right-to-limit decision, risk-assessment record, owner, reviewer, and review date. Reconcile the register with deployed code, configurations, logs, exports, and vendor behavior rather than relying only on questionnaires.
Use Sorena to assign classification and control owners, request evidence, track assessments and requests, and maintain the category register.
Create scoped classification questions, evidence fields, owners, and review tasks.
Use Research Copilot to answer follow-up questions with cited source material.
Review scope, evidence, owners, and the next compliance actions with Sorena.
"consumers have the right to limit the use or disclosure of their sensitive personal information"
"“Sensitive personal information” means:"
"The CPRA amended the CCPA by adding additional consumer privacy rights and obligations for businesses"
"Organizations should not assume implementation of these Privacy Framework activities or outcomes means that they have met the"