Consumer rights under the California Consumer Privacy Act (CCPA), as amended by the California Privacy Rights Act (CPRA), give California residents specific legal powers over how businesses handle personal information. These rights trigger concrete obligations for businesses, including intake, identity verification, response timelines, opt-out mechanisms, and recordkeeping. This article explains the full list of CCPA and CPRA consumer rights, how consumers exercise them, what businesses must do when those rights are exercised, and how consumer rights handling fits into broader CCPA obligations and enforcement expectations.
Consumer Rights Under the CCPA and CPRA: How Businesses Must Respond
The California Consumer Privacy Act (CCPA), as amended by the California Privacy Rights Act (CPRA), gives California residents a defined set of consumer rights over how their personal information is collected, used, disclosed, and retained. These rights are not abstract principles. Each right creates operational requirements that affect how businesses receive, verify, fulfill, deny, and document consumer requests.
What are consumer rights under the CCPA?
Consumer rights under the CCPA are legal entitlements that allow California residents to understand, influence, and limit how businesses process their personal information. These rights apply when a business falls within the scope of the CCPA and collects personal information from or about California residents.
At a high level, CCPA and CPRA consumer rights allow individuals to:
- Know what personal information is collected and how it is used
- Access copies of personal information held by a business
- Request deletion of personal information, subject to exceptions
- Correct inaccurate personal information
- Opt out of the sale or sharing of personal information
- Limit certain uses of sensitive personal information
- Avoid retaliation or discrimination for exercising privacy rights
While the rights belong to consumers, the law focuses heavily on how businesses must respond once a request is received.
List of rights under the CCPA and CPRA
The CCPA originally introduced a core set of consumer rights. The CPRA expanded and refined those rights. Together, they form the current framework that applies in 2026.
Right to know (access)
Consumers may request disclosure of:
- Categories of personal information collected
- Sources of that information
- Business or commercial purposes for collection or disclosure
- Categories of third parties receiving the information
- Specific pieces of personal information held about the consumer
As part of access rights, consumers may also receive their personal information in a portable, readily usable format that allows transmission to another entity where technically feasible.
Right to delete
Consumers may request deletion of personal information collected from them, subject to statutory exceptions such as security, legal obligations, and internal uses aligned with the original purpose.
Right to correct
Added by the CPRA, this right allows consumers to request correction of inaccurate personal information maintained by a business.
Right to opt out of sale or sharing
Consumers may direct a business to stop selling or sharing their personal information, including sharing for cross‑context behavioral advertising.
Right to limit use of sensitive personal information
Consumers may restrict certain uses and disclosures of sensitive personal information to limited, permitted purposes.
Right to non‑discrimination
Businesses may not deny services, charge different prices, or provide a different level or quality of service solely because a consumer exercised CCPA rights, except in narrowly defined circumstances.
Consumers may also exercise certain rights through an authorized agent, subject to reasonable verification of the agent’s authority.
Summary of CCPA and CPRA consumer rights and business response obligations
Consumer right | How the right is exercised | Identity verification required | Typical response time | Where the obligation applies |
|---|---|---|---|---|
Right to know (access) | Consumer request (DSAR) | Yes | Up to 45 days | Request handling workflow |
Right to delete | Consumer request (DSAR) | Yes | Up to 45 days | Request handling workflow |
Right to correct | Consumer request (DSAR) | Yes | Up to 45 days | Request handling workflow |
Opt-out of sale or sharing | Website link or preference signal | Usually no | As soon as practicable | Website controls |
Limit use of sensitive personal information | Website link (if applicable) | Usually no | As soon as practicable | Website controls |
Non-discrimination | Automatic protection | No | Ongoing | Business practices |
Rights under CCPA and CPRA: what changed
The CPRA did not replace the CCPA. It amended and expanded it. Key changes relevant to consumer rights include:
- Introduction of the right to correct
- Introduction of limits on sensitive personal information
- Expanded disclosure expectations in responses
- Greater emphasis on proportional data use and retention
- Increased enforcement authority for the California Privacy Protection Agency
These amendments are codified in the official statutory text of the California Consumer Privacy Act and the California Privacy Rights Act amendments.
For businesses, these changes mean that rights-handling workflows must be more precise and better documented than under the original CCPA.
How consumers exercise their rights under the CCPA and CPRA
Understanding consumer rights under the CCPA also requires understanding how those rights are exercised in practice. Not all rights follow the same path, and businesses are expected to support multiple mechanisms depending on the right involved.
Broadly, CCPA and CPRA rights fall into two categories:
- Request‑based rights, which are exercised through consumer requests
- Preference‑ and link‑based rights, which must be available directly on a business’s website or interface
This distinction affects verification, response timing, and how businesses design their compliance workflows.
Request‑based rights and DSR workflows
Several consumer rights are exercised by submitting a data subject request to a business. These requests typically require intake, verification, and a documented response.
Request‑based rights include:
These are commonly referred to as CCPA requests or data subject requests (DSRs).
For these rights, businesses are expected to:
- Provide clear request submission channels
- Verify the identity of the requester where required
- Respond within statutory timelines
- Explain any applicable legal exceptions
- Keep records of how the request was handled
Link‑based and preference‑based consumer rights
Other consumer rights must be available without requiring a traditional request workflow. These rights are typically exercised through clearly labeled website links or recognized preference signals.
Do Not Sell or Share My Personal Information
Businesses that sell or share personal information must provide a clearly labeled “Do Not Sell or Share My Personal Information” link. This right allows consumers to opt out of certain disclosures of their personal information.
Key characteristics of this right include:
- It must be available directly on the website or interface
- It may be exercised without identity verification in many cases
- It may be triggered through recognized opt‑out preference signals
- It requires businesses to stop applicable sale or sharing activities once exercised
Limit the Use of My Sensitive Personal Information
When a business uses sensitive personal information beyond limited, permitted purposes, consumers must be able to restrict those uses through a “Limit the Use of My Sensitive Personal Information” link or an equivalent combined mechanism.
This right:
- Applies only when sensitive personal information is used beyond allowed purposes
- Often overlaps with notice, purpose limitation, and data minimization obligations
- Requires businesses to adjust downstream processing once the limitation is exercised
Opt‑out preference signals
Under the CPRA framework, certain consumer choices may be expressed through browser or device‑based opt‑out preference signals. When recognized, these signals may require businesses to honor opt‑out rights automatically, without requiring the consumer to submit a separate request.
Businesses must account for these signals when designing their consumer rights handling processes and ensure they are applied consistently across applicable data uses.
Business obligations when consumer rights are exercised
When a consumer submits a request, the CCPA and CPRA shift focus from policy language to execution. Across all consumer rights, businesses are expected to address several common operational requirements.
Intake and request channels
Businesses must provide designated methods for submitting requests, such as web forms, toll‑free numbers, or other appropriate channels depending on how the business interacts with consumers.
Identity verification
Before fulfilling certain requests, businesses must verify the identity of the requester using methods appropriate to the sensitivity of the data involved. Verification requirements vary by request type.
Acknowledgment and response timelines
Businesses are expected to confirm receipt of a consumer request within a reasonable timeframe, typically within 10 business days.
In most cases, businesses have 45 days to respond to a verified request, with a possible extension when reasonably necessary. Silence or delayed responses can increase enforcement risk.
Response content
Responses must be complete, understandable, and consistent with disclosures made elsewhere, such as privacy policies and notices at collection.
Recordkeeping
Businesses are expected to document how requests are handled, including verification steps, response timing, decisions, and outcomes. Records should be retained for a defined period consistent with regulatory guidance and enforcement expectations.
Handling consumer rights in practice
Although each consumer right is distinct, most organizations manage them through a shared request workflow. That workflow typically includes:
- Request receipt and categorization
- Identity verification
- Internal data mapping and retrieval
- Evaluation of legal exceptions
- Consumer response and confirmation
- Internal documentation
Each step introduces practical challenges, especially for organizations with multiple systems, vendors, or data flows.
Use case: handling a CCPA access request
To illustrate how these obligations come together, consider the following common scenario.
A California resident submits a request to know through a company’s online privacy request form, asking for access to the personal information the business holds about them. The business reviews the submission within a few days, categorizes it as a CCPA access request, and sends an acknowledgment of receipt to the requester, typically within 10 business days.
Because the request involves disclosure of personal information, the business initiates identity verification. In practice, this often involves sending a verification link to the email address associated with the request or the consumer’s existing account. The requester must click the link or provide additional confirming information before the request is treated as verified.
Once identity verification is completed, the 45-day response period begins. During this time, the business identifies relevant personal information across customer account systems, marketing platforms, and customer support tools. Certain data elements are excluded from disclosure where statutory exceptions apply, such as information needed for security or legal obligations.
Before the response deadline, the business provides the required disclosures to the consumer in a readable format and explains any limitations or exclusions in clear, plain language. Finally, the business documents the request, verification method, response timing, and outcome as part of its internal recordkeeping, supporting accountability and potential regulatory review.
How this fits into overall CCPA obligations
Consumer rights are one part of the CCPA and CPRA framework. They interact with notice obligations, data minimization principles, vendor contracts, and enforcement expectations.
For a broader view of how consumer rights connect with other legal duties, see our CCPA compliance guide for businesses, which explains applicability thresholds, notice requirements, enforcement risks, and operational obligations in one place.
How Clym helps businesses manage CCPA consumer rights obligations
Managing CCPA and CPRA consumer rights requires coordination across websites, internal systems, vendors, and documentation processes. Clym provides tools that help businesses organize and manage these obligations in a structured, scalable way.
With Clym, businesses can:
- Publish consumer-facing controls, including privacy preference links and information panels, through Clym’s Control Center, making opt-out and limitation rights accessible from the website interface.
- Support intake and management of consumer rights requests through data subject request management workflows that track request status, response timelines, and outcomes.
- Monitor and organize access, deletion, correction, and opt-out requests in one place, helping teams coordinate responses across systems and vendors.
- Maintain records that support internal reviews, audits, and regulatory inquiries, aligned with evolving enforcement expectations.
- Align consumer rights handling with related obligations such as notices, policies, and data mapping by displaying consumer-facing information through a centralized governance portal.
Key takeaway
CCPA and CPRA consumer rights require more than disclosures. Businesses must support different ways for consumers to exercise their rights, distinguish between request-based and link-based obligations, and operate repeatable workflows for intake, verification, response timing, opt-out and limitation controls, and documentation. Understanding the rights is only the starting point. How those rights are handled in practice is where compliance risk and enforcement attention concentrate.
Frequently asked questions about CCPA consumer rights
Consumer rights under the CCPA give California residents the ability to access, delete, correct, and limit the use of their personal information, as well as opt out of certain data disclosures. These rights require businesses to respond within defined timelines and follow specific verification and documentation rules.
There is no single official number used consistently across all sources. The CCPA and CPRA establish a set of core consumer rights, but they are often grouped differently. Some sources refer to six rights by combining related concepts, others list seven by separating data portability, and others refer to nine by splitting the right to know into multiple disclosure elements or treating agent-related rights separately. These are different ways of describing the same underlying CCPA and CPRA rights framework, not different legal obligations.
No. Some rights, such as access, deletion, and correction, are exercised through consumer requests and typically involve identity verification and response timelines. Other rights, such as opting out of sale or sharing or limiting the use of sensitive personal information, must be available through website links or preference signals and do not always require a traditional request workflow.
Identity verification is generally required for requests to access, delete, or correct personal information, where disclosure or modification of data could pose a risk to the consumer. Verification requirements vary depending on the nature of the request and the sensitivity of the information involved. Opt-out and limitation rights often do not require verification.
In most cases, businesses should acknowledge receipt of a request within a reasonable timeframe and provide a substantive response within 45 days of verifying the request. Limited extensions may be available when reasonably necessary, provided the consumer is informed.
The CCPA and CPRA allow businesses to deny or limit requests in specific circumstances, such as when statutory exceptions apply or when verification cannot be completed. In these cases, businesses are expected to explain the reason for the denial or limitation in their response and document the decision.
Businesses must provide intake channels, acknowledge receipt of requests, verify the requester’s identity where required, respond within defined timelines, explain any applicable limitations or denials, and document how each request is handled. Consistency across systems, vendors, and consumer-facing disclosures is a key expectation.