CCPA Sensitive Personal Information: Compliance Steps for Businesses
CCPA/CPRA sensitive personal information: Civil Code definition, right to limit under 1798.121, homepage link rules, and a practical compliance checklist for businesses.
- SPI list: Government IDs, credentials with access codes, precise geolocation, health, biometrics for unique ID, genetic/neural data, and related categories.
- Right to limit: Consumers can restrict SPI to expected services and listed business purposes unless they later consent to more.
- UX: “Limit the Use of My Sensitive Personal Information” link (or allowed alternative) plus interactive form under 11 CCR 7014.
- Backend: Propagate limit flags to CRM, CDP, and ad platforms; bind service providers by contract.
- Not GDPR: SPI and Article 9 lists overlap but are not identical; map each regime separately.
What CCPA calls sensitive personal information
California’s Consumer Privacy Act (CCPA), as amended by the California Privacy Rights Act (CPRA), gives “sensitive personal information” its own definition and a consumer right to limit how businesses use and disclose it. The definition sits in Civil Code section 1798.140. The right to limit sits in section 1798.121, with homepage link and notice rules in section 1798.135 and California Code of Regulations, title 11, section 7014.
This guide is for businesses that meet the CCPA “business” thresholds and collect California consumer data through websites, apps, or offline channels. It summarises public statute and regulation text. It is not legal advice.
For how other regimes treat high-harm data, see our notes on India’s DPDP Act (no statutory sensitive tier) and GDPR Article 9 special category data.
Who must comply
Section 1798.140 defines a “business” that does business in California, determines purposes and means of processing, and meets at least one threshold (dollar revenue, volume of buying/selling/sharing, or revenue share from selling or sharing), plus certain affiliates, joint ventures, and voluntary certifiers. Confirm current dollar thresholds and facts with counsel. If you are not a CCPA business, the SPI limit right still does not apply to you as a covered business, but other California or sector rules might.
The statutory SPI list (Civil Code section 1798.140)
Under section 1798.140, “sensitive personal information” includes:
- Personal information that reveals a consumer’s Social Security, driver’s license, state identification card, or passport number.
- Account log-in, financial account, debit card, or credit card number in combination with any required security or access code, password, or credentials allowing access to an account.
- Precise geolocation (defined in the same section as device-derived location used or intended to locate a consumer within a circle of radius 1,850 feet, except as regulations provide).
- Racial or ethnic origin, citizenship or immigration status, religious or philosophical beliefs, or union membership.
- Contents of mail, email, and text messages, unless the business is the intended recipient.
- Genetic data.
- Neural data (information generated by measuring activity of the central or peripheral nervous system that is not inferred from nonneural information).
- Processing of biometric information for the purpose of uniquely identifying a consumer.
- Personal information collected and analyzed concerning a consumer’s health.
- Personal information collected and analyzed concerning a consumer’s sex life or sexual orientation.
SPI that is “publicly available” under section 1798.140 is excluded from the SPI (and personal information) definitions. Deidentified and aggregate consumer information are also outside personal information.
Read the current LegInfo text before you freeze an inventory. The Assembly has amended these definitions more than once; neural data is one recent addition.
The consumer right to limit (section 1798.121)
A consumer may direct a business that collects their SPI to limit use of that SPI to:
- Uses necessary to perform the services or provide the goods reasonably expected by an average consumer who requests those goods or services.
- Certain business purposes listed in section 1798.140, subdivision (e), paragraphs (2), (4), (5), and (8) (security and integrity; short-term transient use with the limits in that paragraph; performing services on behalf of the business; quality and safety activities).
- Additional purposes authorised by regulations under section 1798.185.
If you use or disclose SPI for purposes beyond those limits, you must give notice that SPI may be used or disclosed for additional specified purposes and that consumers have the right to limit. After a consumer directs a limit, you may not use or disclose their SPI for other purposes unless the consumer later consents.
Section 1798.121 also states that SPI collected or processed without the purpose of inferring characteristics about a consumer is not subject to that section (as further defined in regulations) and is treated as ordinary personal information for other CCPA sections.
Homepage link and Notice of Right to Limit
When you must offer the right to limit, Civil Code section 1798.135 requires a clear and conspicuous homepage link titled “Limit the Use of My Sensitive Personal Information,” unless you use an allowed alternative (for example a combined “Your Privacy Choices” style link under the regulations, or frictionless opt-out preference signals where the statute and regs permit).
California Code of Regulations, title 11, section 7014 adds operational detail:
- The link must sit in the header or footer of the internet homepage(s), or you may use the Alternative Opt-out Link under section 7015 while still posting a Notice of Right to Limit.
- Clicking the link must either apply the limit immediately or take the consumer to a page where they can learn and choose.
- The Notice of Right to Limit must describe the right and how to submit a request, including an interactive online form when you collect online.
- You do not need the notice or link if you only use and disclose SPI for purposes in section 7027(m) and say so in the privacy policy, or if you only collect or process SPI without inferring characteristics and say so in the privacy policy.
- If you collect SPI while the notice is missing, you generally may not later use it outside 7027(m) purposes without consumer consent.
Compliance steps for businesses
1. Confirm you are a covered business
- Map California residents in your customer, prospect, employee, and B2B contact bases as relevant to CCPA scope.
- Check revenue, buy/sell/share volume, and revenue-from-sale/share tests against current section 1798.140 thresholds.
2. Inventory SPI collection and use
- Tag every field, file, SDK, and vendor against the section 1798.140 SPI list.
- Record purpose, whether you infer characteristics, retention, and recipients (service providers, contractors, third parties).
- Flag precise geolocation, payment credentials with access codes, government IDs, health, biometrics used for unique ID, and message contents stored when you are not the intended recipient.
3. Decide whether the limit right applies
- If every SPI use fits section 1798.121 / 11 CCR 7027(m) and you state that in the privacy policy, you may not need the SPI limit link.
- If you use SPI for advertising profiles, analytics that infer traits, or other secondary purposes, plan for the link, notice, and enforcement path.
4. Ship notice and choice UX
- Add the statutory or alternative opt-out link on homepage header or footer.
- Build an interactive request-to-limit form (section 7027 / 7014).
- Honour Global Privacy Control or other opt-out preference signals where required for sale/share and, where your design maps them, for limit requests.
- Update the privacy policy: SPI categories collected, purposes, whether you sell or share, and how to limit.
5. Wire the backend
- Propagate limit flags to CRM, CDP, ad platforms, and warehouses within required timelines.
- Contractually bind service providers and contractors; section 1798.121(c) restricts their use after they receive instructions and know the data is SPI.
- Keep proof of requests, responses, and preference signals.
6. Security and minimisation
- Encrypt SPI at rest and in transit; restrict admin access; shorten retention for credentials and government IDs.
- Stop collecting SPI you do not need. Prefer tokenization for payment and account credentials.
7. Align with other CCPA rights
- Know / access, delete, correct, opt out of sale or sharing, and non-discrimination still apply to personal information, including SPI treated as PI.
- Train support so free-text tickets do not recreate health or orientation data outside approved systems.
Common failure modes
- Treating “we do not sell data” as enough while still using health or precise location for profiling.
- Missing the SPI limit link because marketing owns the footer and legal owns the privacy policy.
- Assuming GDPR Article 9 mapping equals CCPA SPI. The lists overlap but are not identical (for example CCPA’s credential-plus-password and precise geolocation rules).
- Assuming India’s DPDP Act copies CCPA SPI. It does not; see the DPDP sensitive data guide.
Practical rollout order
- SPI inventory and purpose matrix.
- Counsel review of 7027(m) vs secondary uses.
- Privacy policy and Notice of Right to Limit copy.
- Homepage link and interactive form.
- Vendor and ad-tech suppression.
- Audit logs and quarterly re-scan of new product fields.
Sources
- California Civil Code section 1798.140 (definitions, including sensitive personal information, precise geolocation, business, business purpose): California Legislative Information.
- California Civil Code section 1798.121 (right to limit use and disclosure of SPI).
- California Civil Code section 1798.135 (methods for limiting sale, sharing, and SPI use; homepage links).
- Cal. Code Regs. tit. 11, section 7014 (Notice of Right to Limit and “Limit the Use of My Sensitive Personal Information” link).
- Cal. Code Regs. tit. 11, section 7027 (requests to limit; permitted purposes in subsection (m)).
- California Privacy Protection Agency FAQ pages summarizing the right to limit (plain-language overview).
Disclaimer
This article was prepared by Imran using publicly available information. It is for general education only and is not legal advice. Do not rely on it alone when implementing cookie compliance, DSAR handling, consent flows, sensitive-data controls, breach response, or other privacy and data-protection measures. Consult your own legal counsel for advice that fits your business, jurisdictions, and systems.
Last updated on 28 September 2026
