Artifact GuideUSSensitive Personal Information Limits
US CPRA Sensitive Personal Information Limits
The right to limit applies when a covered business uses or discloses sensitive personal information beyond the purposes permitted by section 7027(m).
Classify each category and purpose, provide the required request method, stop restricted uses within 15 business days, instruct recipients, and retain evidence.
The is not a blanket ban on processing every category of . A covered business must determine whether it uses or discloses a consumer's sensitive personal information beyond the permitted purposes in the regulations; if it does, it must provide the required limit notice or link, honor limitation requests, and propagate the instruction to relevant recipients.
1
Section 1
What should teams decide about Sensitive Personal Information Limits under the US CPRA?
Classify the data under Civil Code section 1798.140 and regulation section 7001, then map each use and disclosure to a permitted purpose in (m). The permitted-purpose analysis turns on what the business does with the information, not only on the category name. Account credentials used to authenticate a consumer may fit a permitted service purpose, while using the same information for an unrelated inference or advertising purpose may trigger the right.
The lets a consumer restrict use and disclosure to the permitted purposes; it is not a deletion request or a blanket opt-out from all processing. If the business uses or discloses the information beyond those purposes, it must provide the required limit method and honor a request without identity verification. It must stop the restricted use or disclosure as soon as feasibly possible and no later than 15 business days, notify applicable service providers, contractors, and third parties, and wait at least 12 months before asking the consumer to consent to the previously restricted use or disclosure.
Inventory each sensitive category, whether it is collected or processed to infer characteristics, its purpose, recipient, retention, and sale or sharing status.
Classify each purpose against (m); do not treat a security or service-delivery purpose as permission for unrelated profiling or advertising.
Provide a Notice of that explains the right and request method, or use the permitted Alternative Opt-out Link to combine access to limit and sale-or-sharing choices.
Propagate the restriction to relevant recipients and retain the request time, implementation time, instruction, confirmation, exception, and reviewer.
Who should own Sensitive Personal Information Limits, and what evidence should prove the decision?
Privacy should own the category and purpose classification and the consumer response. Product and engineering should own the public interface and system restriction. Procurement or vendor management should own downstream instructions, and legal should review disputed classifications or exceptions. Assign one case owner to track the 15-business-day implementation deadline across those teams.
The evidence record should connect the consumer's choice to the systems and recipients affected by it. Keep the category-and-purpose map, notice version, request timestamp, system change, recipient instruction, confirmation, exception rationale, reviewer, and dated test together.
Name one accountable owner and one reviewer for the Limits workflow.
Keep source screenshots or source links, decision notes, implementation tickets, and approval records together.
Use dated evidence for deadlines, notices, risk assessments, contracts, user journeys, and regulator-facing records.
Review the evidence after product changes, new markets, new vendors, enforcement updates, or material changes in the source text.
Which edge cases should teams check before relying on a Sensitive Personal Information Limits decision?
The is separate from deletion and from the opt-out of sale or sharing. It does not require a business to stop uses within (m), and a service provider's involvement does not authorize a purpose outside that list. Publicly available information and information outside the statutory sensitive categories do not become merely because a business regards them as confidential.
Check the definition carefully at its boundaries. Message contents count only when the business is not the intended recipient, and precise geolocation has a statutory meaning. Biometric information is sensitive only when processed to identify a consumer uniquely; the separate right-to-limit test also asks whether the business processes information to infer characteristics. Reassess when a purpose, inference, recipient, advertising use, retention period, interface, or contract changes.
A right-to-limit exception does not remove the separate risk-assessment duty. Under the regulations effective January 1, 2026, a business generally must assess processing of before it begins. A narrow exception covers employee or independent-contractor information processed solely and specifically for listed compensation, work-authorization, benefits, reasonable-accommodation, or wage-reporting purposes. Covered processing already underway before January 1, 2026, must be assessed by December 31, 2027; assessments must be reviewed at least every three years and updated within 45 calendar days after a material change.
Assess whether an applicable CCPA exemption or sector-specific rule changes the treatment of the information or entity.
Test the separately from deletion, sale-or-sharing opt-out, correction, and retention duties.
Do not carry forward a previous classification after the data, purpose, inference, interface, recipient role, or contractual flow changes.
Record unresolved category or purpose questions and route them for legal review before relying on an exception.
How should teams operationalize Sensitive Personal Information Limits with proportionate controls?
Build the control at the purpose and recipient level. A data field may remain available for a permitted account-security use while being blocked from cross-context behavioral advertising, profiling, or another non-permitted purpose. The implementation should prevent the restricted use without disabling a permitted use the consumer still expects.
Test the public request method, the 15-business-day system change, profile and device behavior, downstream instructions, the 12-month consent rule, and the privacy-policy explanation. A closed support ticket does not prove that the system and recipients stopped the restricted use.
Route both the dedicated limit link and any Alternative Opt-out Link to the same controlled request workflow.
Map each request to the affected purposes, systems, recipients, owner, deadline, reviewer, and evidence fields.
Test that the restriction persists across sign-in states, profiles, devices, restored data, and downstream recipient updates where applicable.
Re-run the classification and control tests when official rules, data flows, products, or recipient roles change.
Sections 7014, 7015, and 7027 support the dedicated and alternative links, request workflow, implementation deadline, recipient instructions, and confirmation control.