Skip to main content

What your California privacy rights actually let you do

You can ask a business what it holds about you, tell it to delete that, correct it, and stop it being sold or shared. The limits are as important as the rights.

Technology Editor

· 2 min read

A data centre interior.
A data centre interior.Wikideas1 · CC0 · via Wikimedia Commons

California's privacy law gives residents a defined set of rights against businesses that collect their personal information. Knowing precisely what those rights are is what makes them usable.

Who is covered

The law applies to for-profit businesses doing business in California that meet at least one threshold: annual revenue above a set figure, handling personal information about a large number of consumers or households, or deriving a substantial share of revenue from selling or sharing personal information.

A small local business below all three thresholds is generally not covered. Non-profits and government agencies sit largely outside it.

What you can ask for

**Access.** What categories of personal information a business collected, where it came from, why it was collected, and to whom it was disclosed — plus the specific pieces of information it holds.

**Deletion.** That the business delete personal information it collected from you, and pass the request to its service providers.

**Correction.** That inaccurate personal information be corrected.

**Opt out of sale or sharing.** Including sharing for cross-context behavioural advertising, which is the mechanism behind most targeted advertising.

**Limit use of sensitive information.** Restricting use of defined sensitive categories to what is necessary to provide the service.

The exceptions

Deletion is where expectations diverge most from reality. A business may retain information needed to complete a transaction, provide a requested service, detect security incidents, comply with a legal obligation, or for internal uses reasonably aligned with your expectations.

So a bank will not delete your transaction history on request, and it is not being obstructive.

The right to delete is a right to have unnecessary data removed, not a right to be forgotten.

How to exercise them

Businesses must provide at least two methods, typically a web form and a toll-free number, and must respond within a defined period after verifying your identity.

Verification is a legitimate step. A business that handed over a data file to anyone who asked would be creating a far worse problem.

Browsers and extensions can send a universal opt-out signal that covered businesses must honour as an opt-out request, which is considerably more practical than clicking a link per site.

Retaliation

A business may not discriminate against you for exercising these rights — denying service, charging different prices, or degrading quality — subject to permitted financial incentive programmes that must be disclosed.

Practical points

  • Send an access request first; it tells you what a deletion request should target.
  • Enable a universal opt-out signal rather than opting out site by site.
  • Keep the dates, since response deadlines are defined.
  • Expect partial deletion, and ask which exception is being relied on.

Related