Privacy & Data · United States · California

Practical CCPA/CPRA Guide: How to Make a Covered California Business Reveal, Delete and Limit Your Personal Information

California consumers have powerful privacy rights, but they do not apply to every company and they do not require every request to be granted. Here is how to make a request that is complete, verifiable and trackable.

Start With the Right Company

The CCPA does not apply to every organization. It generally covers for-profit businesses doing business in California that meet one of the statutory thresholds, subject to exemptions. Government agencies and many nonprofits are outside the CCPA's ordinary scope.

That distinction matters. A privacy request sent to a business that is not covered by the CCPA does not become enforceable merely because the request cites "CCPA/CPRA."

What You Can Ask For

Depending on the business and the circumstances, California consumers can exercise rights that include:

The 45-Day Response Period Is Real — But It Can Become 90 Days

Under the current California regulations, a business must respond to requests to know and delete no later than 45 calendar days after receipt. Where necessary, it can take up to one additional 45-day period — a maximum of 90 calendar days — if it gives the required notice and explanation.

Current regulations also require a business to confirm receipt of a request within 10 business days and explain, in general terms, how it will process the request and when the consumer should expect a response.

The 45-day period starts when the business receives the request, regardless of how long identity verification takes.

Write the Request So Verification Does Not Become the Whole Dispute

  1. Use the business's designated privacy-request method.
  2. Identify the account or information category involved.
  3. State exactly which right you are exercising.
  4. Provide only the information reasonably needed for verification.
  5. Save the submission date and confirmation.

A business can deny or limit a request where verification fails or where a statutory exception applies. A deletion request is not a guaranteed command to erase every record in every system.

Authorized Agents Can Submit Requests — But They Do Not Eliminate Verification

California allows consumers to use an authorized agent. A business may require evidence that the agent was authorized, and it may require the consumer to verify identity directly or confirm the authorization.

This makes authorized-agent workflows useful for structured or repeated requests, but it is inaccurate to promise that an agent can automatically force any company to delete a person's data without verification or without regard to statutory exceptions.

Precise Geolocation Is Sensitive Personal Information

California treats precise geolocation as sensitive personal information. For covered businesses using or disclosing sensitive personal information for purposes outside the statutory exceptions, the consumer can have a right to limit those uses and disclosures.

Do not confuse that right with the separate right to opt out of sale or sharing. The two rights address different processing activities and can have different compliance requirements.

What if the Business Refuses?

Read the business's response and identify the stated exception or verification problem. If the business is covered and you believe it is not honoring the CCPA, the California Privacy Protection Agency accepts consumer complaints.

Keep the original request, the acknowledgement, the substantive response and the dates. Your evidence should show exactly what was requested and how the business responded.

What This Means Practically

Sources