Artifact GuideUSSensitive Personal Information Limits

US CPRA Sensitive Personal Information Limits

The right to limit applies when a covered business uses or discloses sensitive personal information beyond the purposes permitted by section 7027(m).

Classify each category and purpose, provide the required request method, stop restricted uses within 15 business days, instruct recipients, and retain evidence.

Author
Sorena AI
Published
May 9, 2026
Updated
Jul 25, 2026
Sections
4

Structured answer sets in this page tree.

Primary sources
5

Cited legal and guidance references.

Publication metadata
Sorena AI
Published May 9, 2026
Updated Jul 25, 2026
Overview

The is not a blanket ban on processing every category of . A covered business must determine whether it uses or discloses a consumer's sensitive personal information beyond the permitted purposes in the regulations; if it does, it must provide the required limit notice or link, honor limitation requests, and propagate the instruction to relevant recipients.

Section 1

What should teams decide about Sensitive Personal Information Limits under the US CPRA?

Classify the data under Civil Code section 1798.140 and regulation section 7001, then map each use and disclosure to a permitted purpose in (m). The permitted-purpose analysis turns on what the business does with the information, not only on the category name. Account credentials used to authenticate a consumer may fit a permitted service purpose, while using the same information for an unrelated inference or advertising purpose may trigger the right.

The lets a consumer restrict use and disclosure to the permitted purposes; it is not a deletion request or a blanket opt-out from all processing. If the business uses or discloses the information beyond those purposes, it must provide the required limit method and honor a request without identity verification. It must stop the restricted use or disclosure as soon as feasibly possible and no later than 15 business days, notify applicable service providers, contractors, and third parties, and wait at least 12 months before asking the consumer to consent to the previously restricted use or disclosure.

  • Inventory each sensitive category, whether it is collected or processed to infer characteristics, its purpose, recipient, retention, and sale or sharing status.
  • Classify each purpose against (m); do not treat a security or service-delivery purpose as permission for unrelated profiling or advertising.
  • Provide a Notice of that explains the right and request method, or use the permitted Alternative Opt-out Link to combine access to limit and sale-or-sharing choices.
  • Propagate the restriction to relevant recipients and retain the request time, implementation time, instruction, confirmation, exception, and reviewer.
Section 2

Who should own Sensitive Personal Information Limits, and what evidence should prove the decision?

Privacy should own the category and purpose classification and the consumer response. Product and engineering should own the public interface and system restriction. Procurement or vendor management should own downstream instructions, and legal should review disputed classifications or exceptions. Assign one case owner to track the 15-business-day implementation deadline across those teams.

The evidence record should connect the consumer's choice to the systems and recipients affected by it. Keep the category-and-purpose map, notice version, request timestamp, system change, recipient instruction, confirmation, exception rationale, reviewer, and dated test together.

  • Name one accountable owner and one reviewer for the Limits workflow.
  • Keep source screenshots or source links, decision notes, implementation tickets, and approval records together.
  • Use dated evidence for deadlines, notices, risk assessments, contracts, user journeys, and regulator-facing records.
  • Review the evidence after product changes, new markets, new vendors, enforcement updates, or material changes in the source text.
Section 3

Which edge cases should teams check before relying on a Sensitive Personal Information Limits decision?

The is separate from deletion and from the opt-out of sale or sharing. It does not require a business to stop uses within (m), and a service provider's involvement does not authorize a purpose outside that list. Publicly available information and information outside the statutory sensitive categories do not become merely because a business regards them as confidential.

Check the definition carefully at its boundaries. Message contents count only when the business is not the intended recipient, and precise geolocation has a statutory meaning. Biometric information is sensitive only when processed to identify a consumer uniquely; the separate right-to-limit test also asks whether the business processes information to infer characteristics. Reassess when a purpose, inference, recipient, advertising use, retention period, interface, or contract changes.

A right-to-limit exception does not remove the separate risk-assessment duty. Under the regulations effective January 1, 2026, a business generally must assess processing of before it begins. A narrow exception covers employee or independent-contractor information processed solely and specifically for listed compensation, work-authorization, benefits, reasonable-accommodation, or wage-reporting purposes. Covered processing already underway before January 1, 2026, must be assessed by December 31, 2027; assessments must be reviewed at least every three years and updated within 45 calendar days after a material change.

  • Assess whether an applicable CCPA exemption or sector-specific rule changes the treatment of the information or entity.
  • Test the separately from deletion, sale-or-sharing opt-out, correction, and retention duties.
  • Do not carry forward a previous classification after the data, purpose, inference, interface, recipient role, or contractual flow changes.
  • Record unresolved category or purpose questions and route them for legal review before relying on an exception.
Section 4

How should teams operationalize Sensitive Personal Information Limits with proportionate controls?

Build the control at the purpose and recipient level. A data field may remain available for a permitted account-security use while being blocked from cross-context behavioral advertising, profiling, or another non-permitted purpose. The implementation should prevent the restricted use without disabling a permitted use the consumer still expects.

Test the public request method, the 15-business-day system change, profile and device behavior, downstream instructions, the 12-month consent rule, and the privacy-policy explanation. A closed support ticket does not prove that the system and recipients stopped the restricted use.

  • Route both the dedicated limit link and any Alternative Opt-out Link to the same controlled request workflow.
  • Map each request to the affected purposes, systems, recipients, owner, deadline, reviewer, and evidence fields.
  • Test that the restriction persists across sign-in states, profiles, devices, restored data, and downstream recipient updates where applicable.
  • Re-run the classification and control tests when official rules, data flows, products, or recipient roles change.
Primary sources

References and citations

leginfo.legislature.ca.gov
Referenced sections
  • Direct statutory authority for the consumer's right to limit use and disclosure of sensitive personal information.
leginfo.legislature.ca.gov
Referenced sections
  • Binding source for the right to limit, business response, recipient instructions, and related statutory duties.
nist.gov
Referenced sections
  • Nonbinding privacy-governance background; use the California statute and regulations for the legal category and purpose analysis.
Related guides

Explore more topics

California CCPA and CPRA Applicability Test
Decide whether the CCPA as amended by the CPRA applies, using California nexus, current business thresholds, related-entity rules, and data-specific exemptions.
California CCPA and CPRA Compliance Checklist
A California CCPA/CPRA implementation checklist covering scope, notices, rights, opt-outs, vendor contracts, retention, security, and 2026 regulations.
California CCPA/CPRA Deadlines and Compliance Calendar
Track California CCPA and CPRA request clocks, phased 2026 regulation deadlines, recurring metrics, and separate Delete Act dates.
California CCPA/CPRA Penalties, Fines, and Private Damages
Understand current California CCPA and CPRA fine caps, who enforces them, the limited private action for security breaches, and the evidence to preserve.
California CPRA FAQ
Practical California CPRA FAQ guidance with implementation decisions, evidence, edge cases, and official California source citations.
California CPRA Requirements Guide
California CCPA/CPRA requirements for covered businesses: notices, rights, opt-outs, data-use limits, contracts, security, and phased 2026 rules.
California CPRA Risk Assessments, Cybersecurity Audits, and ADMT Guide
Apply the separate California trigger tests, duties, phase-in dates, evidence, and consumer rights for risk assessments, cybersecurity audits, and ADMT.
California Data Broker Deletion Workflow Guide
California Delete Act and CPRA-adjacent guidance for data broker deletion workflows, with practical decisions, evidence, edge cases, and official citations.
California Data Broker Registry and DROP Guide
California Delete Act guide to data-broker scope, annual registration, DROP processing from August 1, 2026, deletion, opt-out fallback, metrics, and audits.
California Delete Act data broker registry and DROP guide
California Delete Act guidance for the data broker registry and Delete Request and Opt-Out Platform (DROP), with owners, evidence, and official sources.
CCPA vs CPRA: What Changed in California Privacy Law
Compare the original CCPA with the CPRA amendments, including scope thresholds, new rights, contracts, retention, enforcement, and implementation steps.
CPPA Regulations Tracker | CCPA and CPRA
Track the in-force 2023 and 2026 CCPA regulations, their legal status, affected processing, and phased risk, audit, and ADMT deadlines.
CPRA enforcement advisories: CPPA investigations, fines, and risk mitigation
US CPRA guidance for Enforcement Advisories, with practical decisions, evidence, edge cases, and external source citations.
CPRA Global Privacy Control (GPC): opt-out requirements and enforcement FAQ
US CPRA guidance for GPC, with practical decisions, evidence, edge cases, and external source citations.
CPRA vs Colorado Privacy Act: Practical Comparison
Compare California and Colorado privacy law on scope, consumer rights, opt-outs, sensitive data, contracts, assessments, and enforcement.
CPRA vs Virginia VCDPA: Practical Comparison
Compare California and Virginia privacy law on scope, rights, sale, advertising, sensitive data, contracts, assessments, and enforcement.
US CPRA Compliance Guide
Build a CCPA/CPRA compliance program for scope, notices, consumer rights, opt-outs, vendor contracts, retention, security, and phased 2026 duties.
US CPRA Consumer Rights Workflow Guide
Run California CCPA and CPRA requests to know, delete, correct, opt out, limit, and access or opt out of covered ADMT, with deadlines, verification, exceptions, and evidence.
US CPRA Contract Terms Guide
Required CCPA/CPRA contract terms for service providers, contractors, and third parties, with role tests, clause checks, and evidence.
US CPRA Contracts Contractors and Service Providers Guide
Classify CCPA recipients as service providers, contractors, or third parties and apply the correct purpose limits, contracts, and consumer instructions.
US CPRA Correction Rights Guide
Handle CCPA correction requests: verification, accuracy review, documentation, system and vendor updates, response timing, denials, and records.
US CPRA Cyber Audit Readiness Workflow Guide
US CPRA guidance for Cyber Audit Readiness Workflow, with practical decisions, evidence, edge cases, and external source citations.
US CPRA DSAR and Correction Workflow Guide
US CPRA guidance for DSAR and Correction Workflow, with practical decisions, evidence, edge cases, and external source citations.
US CPRA GPC Handling Guide
How businesses subject to the CCPA must detect, apply, test, and document Global Privacy Control opt-out signals.
US CPRA GPC Handling Workflow Guide
A California GPC workflow for signal detection, browser and profile scope, conflicts, downstream suppression, 15-business-day completion, and test evidence.
US CPRA Retention Guide
How to set, disclose, implement, and review personal-information retention periods under the California CCPA and CPRA.
US CPRA Risk Assessment Intake Workflow Guide
Screen the six CPPA risk-assessment triggers, record exceptions and evidence, hold covered launches for approval, and track review and submission dates.
US CPRA Risk Assessment Template Guide
US CPRA guidance for CPRA Risk Assessment Template, with practical decisions, evidence, edge cases, and external source citations.
US CPRA Risk Assessments and Cybersecurity Audits Guide
Apply the separate CPPA trigger tests for processing-level risk assessments and entity-level annual cybersecurity audits, with phase-in dates and evidence.
US CPRA Sensitive Personal Information Guide
Classify California sensitive personal information, distinguish category status from the right to limit, and apply notices, assessments, controls, and deadlines.
US CPRA Sharing and Cross-Context Behavioral Advertising Guide
How to classify advertising data flows as sharing for cross-context behavioral advertising under the California CCPA and CPRA.
What counts as sharing under the California CPRA?
How to identify sharing for cross-context behavioral advertising and implement California notice, opt-out, preference-signal, contract, and recordkeeping duties.
What should teams do about ADMT under the US CPRA?
Decide whether California's ADMT rules cover an automated decision, then apply the 2027 notice, access, opt-out, appeal, and evidence requirements.
What should teams do about Contract Terms under the US CPRA?
Classify California data recipients and check the required service-provider, contractor, third-party, subcontractor, monitoring, and remediation terms.
What should teams do about Correction Rights under the US CPRA?
Handle a California request to correct with the right verification, 10-day confirmation, 45-day response, accuracy test, denial rules, and downstream evidence.
What should teams do about Cybersecurity Audits under the US CPRA?
US CPRA guidance for Cybersecurity Audits, with practical decisions, evidence, edge cases, and external source citations.
What should teams do about retention under the California CPRA?
California CPRA guidance for retention, including data minimization, privacy policy disclosures, evidence records, and official source citations.
What should teams do about Sensitive Personal Information Limits under the US CPRA?
US CPRA guidance for Sensitive Personal Information Limits, with practical decisions, evidence, edge cases, and external source citations.
When is a CPRA risk assessment required?
When California businesses must conduct CPRA risk assessments, what each report must contain, and the review, retention, and filing deadlines.