Artifact GuideUSSensitive Personal Information

US CPRA Sensitive Personal Information

Sensitive personal information is a defined California category; classification can trigger notices, security, and risk-assessment duties even when the right to limit does not apply.

Classify the exact field or inference, record the purpose and recipients, then apply the separate right-to-limit and section 7150 tests.

Author
Sorena AI
Published
May 9, 2026
Updated
Jul 25, 2026
Sections
4

Structured answer sets in this page tree.

Primary sources
5

Cited legal and guidance references.

Publication metadata
Sorena AI
Published May 9, 2026
Updated Jul 25, 2026
Overview

is a defined subset of personal information. Classify the data first, then decide which duties follow from the actual use: notice at collection, reasonable security, a risk assessment, request handling, vendor controls, or the . The right to limit applies only when a covered business uses or discloses sensitive personal information beyond the purposes allowed by the regulations.

Section 1

What should teams decide about Sensitive Personal Information under the US CPRA?

The current definition covers Social Security, driver's license, state identification card, and passport numbers; account log-in and financial account, debit card, or credit card numbers when combined with credentials that allow account access; ; racial or ethnic origin; citizenship or immigration status; religious or philosophical beliefs; union membership; mail, email, and text-message contents when the business is not the intended recipient; genetic data; and neural data. It also covers biometric information processed to uniquely identify a consumer, information collected and analyzed concerning health, sex life, or sexual orientation, and personal information of consumers the business actually knows are under 16. Willful disregard of age counts as actual knowledge. Publicly available information is excluded.

Each condition matters. A photograph is not automatically biometric information processed to identify a consumer; an approximate city is not ; a card number without the credentials needed to access the account does not meet that specific financial-credential category; and message content is treated differently when the business is the intended recipient. Record the exact field or inference, how it is produced, the consumer and age-knowledge basis, whether it reveals or is analyzed for a listed characteristic, purpose, recipient, and retention.

  • Map each sensitive category to its source, system, purpose, recipient, retention period, access control, and consumer-facing notice.
  • Separate raw data from inferences: coordinates, visits to a sensitive location, and a health inference derived from those visits require distinct classification and risk records.
  • Treat a use that infers a characteristic as a separate processing purpose, even when the underlying field was collected for an allowed operational purpose.
  • Apply contracts, access restrictions, deletion and correction handling, incident controls, and downstream instructions to the live data flow, including derived fields and model features.
Section 2

When does the right to limit apply, and how should a business respond?

The applies when a business uses or discloses for a purpose outside section 7027(m). A business that stays only within those purposes need not provide the limit notice or request method if each use or disclosure is reasonably necessary and proportionate. Sensitive personal information collected or processed without the purpose of inferring characteristics is also outside requests to limit, but the business should document that factual conclusion rather than treating it as a blanket exemption.

When the right applies, the business must provide at least two request methods, including one that reflects how it primarily interacts with consumers. An online collector must at least provide an interactive form through the "Limit the Use of My " link or Alternative Opt-out Link. The methods must be easy to use, require minimal steps, and cannot require an account or a verifiable consumer request.

After a valid request, the business must stop non-permitted uses and disclosures as soon as feasibly possible and no later than 15 business days, instruct affected service providers and contractors within the same period, and send required directions to third parties that received the information between the request and implementation. It must let the consumer confirm that the request was processed and generally wait 12 months before asking for consent to the additional uses again.

  • Test each purpose against all section 7027(m) conditions, including reasonable necessity and proportionality; a broad internal label such as security, analytics, or service delivery is not enough.
  • Permitted purposes include expected goods or services, security-incident work, resistance to malicious or illegal conduct, physical safety, qualifying short-term transient use, specified services for the business, quality or safety verification and improvement, and processing that does not infer characteristics.
  • Make the full limit option available even if the interface also offers narrower choices for particular uses.
  • Use the two-step process in section 7028 if the consumer later chooses to consent to a use or disclosure outside the permitted purposes.
Section 3

Which California CPRA edge cases should teams check before relying on a Sensitive Personal Information decision?

Do not equate with all confidential or high-risk business data. The statutory and regulatory list controls this classification, while other California security, breach, employment, health, financial, or sector rules may still protect data outside the list. Likewise, classification alone does not prove that the applies.

Processing generally requires a risk assessment before the processing starts, even if the use stays within a permitted right-to-limit purpose. Section 7150 provides a narrow exception when employee or independent-contractor sensitive information is processed solely and specifically for listed compensation, work-authorization, benefits, reasonable-accommodation, or wage-reporting purposes. It is not a general employment-data exemption.

Reassess when the business begins inferring characteristics, increases geolocation precision, introduces identity matching, learns that a consumer is under 16, changes who receives message content, trains a model on the data, or adds a recipient or purpose.

  • Under-16 information is now its own sensitive category when the business has actual knowledge of age; separately assess the affirmative-authorization rules for selling or sharing that information.
  • Separate binding law, regulator guidance, consultation material, standards, and enforcement commentary in the evidence record.
  • Apply sector, information, entity, and activity exemptions to the exact processing facts instead of marking an entire organization or dataset exempt.
  • Track unresolved assumptions about data derivation, age knowledge, inference, expected use, proportionality, recipient role, and exemption scope for legal review.
Section 4

What evidence and controls should support the decision?

The data owner should classify each field and purpose; privacy should decide the CCPA consequences and request design; security should set controls appropriate to the data; engineering should enforce purpose, access, retention, and preference rules; and procurement should bind service providers, contractors, and third parties to the approved use. Legal should review unclear conditions and exemptions.

Keep one data-category register with the defined category and condition, source and derivation, age-knowledge basis, inference purpose, system, recipient role, notice, retention, security control, right-to-limit decision, risk-assessment record, owner, reviewer, and review date. Reconcile the register with deployed code, configurations, logs, exports, and vendor behavior rather than relying only on questionnaires.

  • Link every category and purpose to the notice at collection, privacy-policy disclosure, rights-search logic, access control, retention rule, and vendor instruction that implements the decision.
  • Keep dated screenshots and tests for the limit notice, link or alternative link, request methods, confirmation state, authorized-agent path, 15-business-day propagation, and two-step opt-in.
  • Retain the risk-assessment record beside the data-flow decision, including the narrow employment-purpose exception when the business relies on it.
  • Reopen the decision after a product, model, data-source, precision, purpose, recipient, contract, age-signal, or official-source change.
Primary sources

References and citations

leginfo.legislature.ca.gov
Referenced sections
  • Civil Code section 1798.121 is the statutory basis for the right to limit use and disclosure of sensitive personal information.
"consumers have the right to limit the use or disclosure of their sensitive personal information"
leginfo.legislature.ca.gov
Referenced sections
  • California Civil Code provisions are the binding source for sensitive personal information, service-provider terms, and consumer-right obligations.
"“Sensitive personal information” means:"
cppa.ca.gov
Referenced sections
  • CPPA FAQ explains that CPRA amended the CCPA with additional consumer rights and business obligations, which frames sensitive-personal-information handling.
"The CPRA amended the CCPA by adding additional consumer privacy rights and obligations for businesses"
nist.gov
Referenced sections
  • Nonbinding NIST crosswalk material; it does not establish CCPA compliance.
"Organizations should not assume implementation of these Privacy Framework activities or outcomes means that they have met the"
Related guides

Explore more topics

California CCPA and CPRA Applicability Test
Decide whether the CCPA as amended by the CPRA applies, using California nexus, current business thresholds, related-entity rules, and data-specific exemptions.
California CCPA and CPRA Compliance Checklist
A California CCPA/CPRA implementation checklist covering scope, notices, rights, opt-outs, vendor contracts, retention, security, and 2026 regulations.
California CCPA/CPRA Deadlines and Compliance Calendar
Track California CCPA and CPRA request clocks, phased 2026 regulation deadlines, recurring metrics, and separate Delete Act dates.
California CCPA/CPRA Penalties, Fines, and Private Damages
Understand current California CCPA and CPRA fine caps, who enforces them, the limited private action for security breaches, and the evidence to preserve.
California CPRA FAQ
Practical California CPRA FAQ guidance with implementation decisions, evidence, edge cases, and official California source citations.
California CPRA Requirements Guide
California CCPA/CPRA requirements for covered businesses: notices, rights, opt-outs, data-use limits, contracts, security, and phased 2026 rules.
California CPRA Risk Assessments, Cybersecurity Audits, and ADMT Guide
Apply the separate California trigger tests, duties, phase-in dates, evidence, and consumer rights for risk assessments, cybersecurity audits, and ADMT.
California Data Broker Deletion Workflow Guide
California Delete Act and CPRA-adjacent guidance for data broker deletion workflows, with practical decisions, evidence, edge cases, and official citations.
California Data Broker Registry and DROP Guide
California Delete Act guide to data-broker scope, annual registration, DROP processing from August 1, 2026, deletion, opt-out fallback, metrics, and audits.
California Delete Act data broker registry and DROP guide
California Delete Act guidance for the data broker registry and Delete Request and Opt-Out Platform (DROP), with owners, evidence, and official sources.
CCPA vs CPRA: What Changed in California Privacy Law
Compare the original CCPA with the CPRA amendments, including scope thresholds, new rights, contracts, retention, enforcement, and implementation steps.
CPPA Regulations Tracker | CCPA and CPRA
Track the in-force 2023 and 2026 CCPA regulations, their legal status, affected processing, and phased risk, audit, and ADMT deadlines.
CPRA enforcement advisories: CPPA investigations, fines, and risk mitigation
US CPRA guidance for Enforcement Advisories, with practical decisions, evidence, edge cases, and external source citations.
CPRA Global Privacy Control (GPC): opt-out requirements and enforcement FAQ
US CPRA guidance for GPC, with practical decisions, evidence, edge cases, and external source citations.
CPRA vs Colorado Privacy Act: Practical Comparison
Compare California and Colorado privacy law on scope, consumer rights, opt-outs, sensitive data, contracts, assessments, and enforcement.
CPRA vs Virginia VCDPA: Practical Comparison
Compare California and Virginia privacy law on scope, rights, sale, advertising, sensitive data, contracts, assessments, and enforcement.
US CPRA Compliance Guide
Build a CCPA/CPRA compliance program for scope, notices, consumer rights, opt-outs, vendor contracts, retention, security, and phased 2026 duties.
US CPRA Consumer Rights Workflow Guide
Run California CCPA and CPRA requests to know, delete, correct, opt out, limit, and access or opt out of covered ADMT, with deadlines, verification, exceptions, and evidence.
US CPRA Contract Terms Guide
Required CCPA/CPRA contract terms for service providers, contractors, and third parties, with role tests, clause checks, and evidence.
US CPRA Contracts Contractors and Service Providers Guide
Classify CCPA recipients as service providers, contractors, or third parties and apply the correct purpose limits, contracts, and consumer instructions.
US CPRA Correction Rights Guide
Handle CCPA correction requests: verification, accuracy review, documentation, system and vendor updates, response timing, denials, and records.
US CPRA Cyber Audit Readiness Workflow Guide
US CPRA guidance for Cyber Audit Readiness Workflow, with practical decisions, evidence, edge cases, and external source citations.
US CPRA DSAR and Correction Workflow Guide
US CPRA guidance for DSAR and Correction Workflow, with practical decisions, evidence, edge cases, and external source citations.
US CPRA GPC Handling Guide
How businesses subject to the CCPA must detect, apply, test, and document Global Privacy Control opt-out signals.
US CPRA GPC Handling Workflow Guide
A California GPC workflow for signal detection, browser and profile scope, conflicts, downstream suppression, 15-business-day completion, and test evidence.
US CPRA Retention Guide
How to set, disclose, implement, and review personal-information retention periods under the California CCPA and CPRA.
US CPRA Risk Assessment Intake Workflow Guide
Screen the six CPPA risk-assessment triggers, record exceptions and evidence, hold covered launches for approval, and track review and submission dates.
US CPRA Risk Assessment Template Guide
US CPRA guidance for CPRA Risk Assessment Template, with practical decisions, evidence, edge cases, and external source citations.
US CPRA Risk Assessments and Cybersecurity Audits Guide
Apply the separate CPPA trigger tests for processing-level risk assessments and entity-level annual cybersecurity audits, with phase-in dates and evidence.
US CPRA Sensitive Personal Information Limits Guide
Decide when California's right to limit applies, map uses to section 7027(m), implement the 15-business-day restriction, and preserve evidence.
US CPRA Sharing and Cross-Context Behavioral Advertising Guide
How to classify advertising data flows as sharing for cross-context behavioral advertising under the California CCPA and CPRA.
What counts as sharing under the California CPRA?
How to identify sharing for cross-context behavioral advertising and implement California notice, opt-out, preference-signal, contract, and recordkeeping duties.
What should teams do about ADMT under the US CPRA?
Decide whether California's ADMT rules cover an automated decision, then apply the 2027 notice, access, opt-out, appeal, and evidence requirements.
What should teams do about Contract Terms under the US CPRA?
Classify California data recipients and check the required service-provider, contractor, third-party, subcontractor, monitoring, and remediation terms.
What should teams do about Correction Rights under the US CPRA?
Handle a California request to correct with the right verification, 10-day confirmation, 45-day response, accuracy test, denial rules, and downstream evidence.
What should teams do about Cybersecurity Audits under the US CPRA?
US CPRA guidance for Cybersecurity Audits, with practical decisions, evidence, edge cases, and external source citations.
What should teams do about retention under the California CPRA?
California CPRA guidance for retention, including data minimization, privacy policy disclosures, evidence records, and official source citations.
What should teams do about Sensitive Personal Information Limits under the US CPRA?
US CPRA guidance for Sensitive Personal Information Limits, with practical decisions, evidence, edge cases, and external source citations.
When is a CPRA risk assessment required?
When California businesses must conduct CPRA risk assessments, what each report must contain, and the review, retention, and filing deadlines.