What California's data minimization requirement actually means
California's CPRA gives residents six major rights to control their personal information, from deletion to correction.

California's Privacy Rights Act (CPRA), which took effect January 1, 2023, gives residents a set of defined rights over personal data that companies collect. Unlike federal privacy law, which largely allows businesses to do what they want with consumer data, California gives individuals the power to know what's collected, demand its deletion, correct it, and restrict how companies use it. The law's most significant addition to California's earlier privacy rules is a data minimization requirement that restricts what companies can collect in the first place.
Understanding what these rights actually mean matters because the CPRA only gives consumers the standing to sue in data breach cases. Most enforcement falls to the California Attorney General and the California Privacy Protection Agency, a new state agency created specifically to oversee privacy law. But knowing what you can demand forces companies to build systems to handle requests, and creates the regulatory pressure that shapes what California businesses do with personal data.
The six consumer rights: Know, delete, correct, opt-out, limit, and non-discrimination
The CPRA gives California residents six core rights. The right to know lets you request disclosure of the categories and specific pieces of personal information a company has collected about you, how it was used, and who it was shared with. The right to delete lets you request that a business delete personal information it collected and direct its service providers and contractors to delete it as well, though legal or regulatory requirements may force a company to keep records.
The right to correct lets you ask a business to correct inaccurate information it holds about you. The right to opt-out lets you stop a company from selling or sharing your personal information. California law defines sharing specifically as cross-context behavioral advertising—the targeting of advertising to a consumer based on their personal information obtained from their online activity across numerous websites. Consumers can opt out through a privacy request, or via a "global privacy control" signal sent through their browser or device.
The right to limit sensitive information restricts how companies use certain kinds of personal data—more on those categories below. Finally, the right to non-discrimination means businesses cannot discriminate against you for exercising these rights, such as by raising prices, lowering service quality, or denying service. Businesses can offer financial incentives for data collection, but those incentives cannot be so large or valuable that refusing them becomes impractical.
Sensitive data gets special protection
The CPRA defines sensitive personal information as a narrower category that gets stronger protections than regular personal data. Sensitive categories include social security numbers and other government identifiers, financial account credentials, precise geolocation, biometric information processed to identify you, genetic data, health information, sexual orientation and sex life, racial or ethnic origin, religious or philosophical beliefs, and union membership. A newer category—neural data, information generated from measuring nervous system activity—joined the list January 1, 2025.
For sensitive data, the law's default position is opt-in: a business must generally ask permission before using sensitive information for any purpose other than providing the services you requested. This is stricter than regular data, where the default is opt-out. Consumers also have the right to direct businesses to limit sensitive information use to what's necessary to provide requested services, even if the company has other legal basis to collect it.
How to submit a request and what happens next
When you make a request—to know, delete, or correct—the business has 45 days to respond and must verify your identity appropriately before granting the request. A company can extend the deadline by another 45 days if it notifies you and explains the reason. Businesses must also offer multiple ways to submit requests: a toll-free phone number, email, web portal, or a combination of these.
There are exceptions: a company can refuse to delete if the information is needed to fulfill a transaction, detect fraud, comply with law or regulations, defend against legal claims, or enable internal uses reasonably aligned with consumer expectations. Sensitive data has an additional safeguard—companies need affirmative consent before using it for new purposes, and consumers can revoke that consent at any time.
The DELETE Act and a state-wide deletion platform
The California Delete Act, separate legislation signed in 2023, created the Delete Request and Opt-out Platform (DROP), a state-hosted website where consumers can submit a single deletion request to all registered data brokers at once. The platform launched in January 2026. Data brokers are required to access the DROP platform at least every 45 days, starting August 1, 2026, and process deletion requests found there.
Data brokers—companies whose primary business is collecting and selling consumer personal information—have been a privacy gap under California law because there are hundreds of them and consumers generally don't know they exist or how to find them. The DROP tool attempts to solve that problem by creating a single submission point. The system has the potential to delete consumer data across the entire data broker industry with minimal effort from consumers, though success depends on data brokers complying with the requirement to check the platform regularly.
“”
Data minimization: what companies can collect in the first place
A distinction of the CPRA is that it includes the first data minimization requirement of any U.S. state privacy law. This means companies must limit collection, use, sharing, and retention of personal information to what is reasonably necessary and proportionate to achieve their intended purpose.
Data minimization operates upstream of the consumer rights described above: it restricts what companies can collect to begin with, rather than just letting consumers request deletion later. Violations can result in penalties up to $2,663 for non-intentional violations and $7,988 for intentional violations. This standard puts a burden on companies to justify why they need specific data, rather than the earlier approach of collect-first-and-sort-it-out-later.
Who the law covers and what it doesn't protect
The CPRA applies to for-profit businesses that collect California residents' personal information and meet at least one of three thresholds: revenue exceeding $26.625 million, or deriving 50 percent or more of revenue from selling or sharing California residents' personal information.
The law does not give consumers a private right of action for most violations—only the California Attorney General and the Privacy Protection Agency can sue for most violations. The exception is data breaches of unencrypted personal information; consumers can sue directly if a breach exposes their data due to a business's failure to maintain reasonable security. This limitation means that enforcement depends largely on regulatory action rather than individual lawsuits.



