What your California privacy rights actually let you do
You can ask a business what it holds about you, tell it to delete that, correct it, and stop it being sold or shared. The limits are as important as the rights.

California's privacy law gives residents a defined set of rights against businesses that collect their personal information. Knowing precisely what those rights are is what makes them usable.
Who is covered
The law applies to for-profit businesses doing business in California that meet at least one threshold: annual revenue above a set figure, handling personal information about a large number of consumers or households, or deriving a substantial share of revenue from selling or sharing personal information.
A small local business below all three thresholds is generally not covered. Non-profits and government agencies sit largely outside it.
What you can ask for
**Access.** What categories of personal information a business collected, where it came from, why it was collected, and to whom it was disclosed — plus the specific pieces of information it holds.
**Deletion.** That the business delete personal information it collected from you, and pass the request to its service providers.
**Correction.** That inaccurate personal information be corrected.
**Opt out of sale or sharing.** Including sharing for cross-context behavioural advertising, which is the mechanism behind most targeted advertising.
**Limit use of sensitive information.** Restricting use of defined sensitive categories to what is necessary to provide the service.
The exceptions
Deletion is where expectations diverge most from reality. A business may retain information needed to complete a transaction, provide a requested service, detect security incidents, comply with a legal obligation, or for internal uses reasonably aligned with your expectations.
So a bank will not delete your transaction history on request, and it is not being obstructive.
“The right to delete is a right to have unnecessary data removed, not a right to be forgotten.”
How to exercise them
Businesses must provide at least two methods, typically a web form and a toll-free number, and must respond within a defined period after verifying your identity.
Verification is a legitimate step. A business that handed over a data file to anyone who asked would be creating a far worse problem.
Browsers and extensions can send a universal opt-out signal that covered businesses must honour as an opt-out request, which is considerably more practical than clicking a link per site.
Retaliation
A business may not discriminate against you for exercising these rights — denying service, charging different prices, or degrading quality — subject to permitted financial incentive programmes that must be disclosed.
Practical points
- Send an access request first; it tells you what a deletion request should target.
- Enable a universal opt-out signal rather than opting out site by site.
- Keep the dates, since response deadlines are defined.
- Expect partial deletion, and ask which exception is being relied on.



