Cybersecurity, explained for the rest of us.

General

California Privacy Rights: How to Use CCPA to Control Your Data

Margot 'Magic' Thorne@magicthorneJuly 25, 202612 min read
Person reviewing privacy settings on laptop with California state outline in background

The California Consumer Privacy Act gives you three core rights: the right to know what data companies collect about you, the right to delete that data, and the right to opt out of its sale to third parties. Those rights exist on paper. Making them work in practice requires understanding the exact mechanism, knowing where companies hide the request forms, and following through when they don't respond.

CCPA applies to California residents interacting with businesses that meet specific thresholds: annual gross revenues exceeding $25 million, buying or selling the personal information of 50,000 or more consumers annually, or deriving 50% or more of annual revenues from selling personal information. If a company meets any one of those criteria and does business in California, CCPA applies.

The law defines personal information broadly: anything that identifies, relates to, or could reasonably be linked to you or your household. That includes obvious identifiers like name, email, and Social Security number, but it also covers IP addresses, browsing history, geolocation data, biometric information, purchase records, and inferences drawn from your behavior. The scope is wider than most people expect.

Here's how to use those rights, what happens when you submit requests, and what companies can still do with your data even after you've exercised every option CCPA provides.

The Right to Know What Data Companies Hold

CCPA gives you the right to request disclosure of what personal information a company has collected about you over the past 12 months, the categories of sources from which it was collected, the business purpose for collection, the categories of third parties with whom the company shares that information, and the specific pieces of personal information the company holds about you.

Companies must provide this information free of charge within 45 days of receiving a verifiable request. They can extend that deadline by another 45 days if the request is complex, but they must notify you of the extension and explain why it's necessary.

The FTC's privacy enforcement work includes monitoring how companies handle these disclosure requests, but enforcement is reactive. If a company ignores your request or provides incomplete information, you file a complaint. The FTC investigates. The company might face penalties. That process takes months or years. Your leverage is limited.

Most companies provide a CCPA request form somewhere in their privacy policy or website footer. The link often says "Do Not Sell My Personal Information" or "Your Privacy Choices." Some companies make you email their privacy contact directly. Some require you to log into your account. Some ask you to fill out a web form with no authentication at all.

The verification process varies. Companies can ask for information that matches what they have on file: your name, email address, phone number, account number, or recent transaction details. They're trying to confirm you're actually the person whose data you're requesting. If you can't verify your identity, they can deny the request.

When you submit a right-to-know request, you're asking the company to compile a report. That report should list the categories of personal information collected, the sources, the purposes, and the third parties who received it. Some companies provide detailed spreadsheets. Some provide vague summaries. CCPA requires disclosure, but it doesn't specify the format or level of detail.

What you get back depends on the company's interpretation of the law and their willingness to be transparent. Large tech companies with dedicated privacy teams tend to provide more detail. Smaller companies or those without strong compliance infrastructure provide less.

The Right to Delete Your Data

CCPA gives you the right to request deletion of personal information a company has collected from you. The company must delete your information from its records and direct any service providers to delete it as well. There are exceptions: companies can keep data needed for completing transactions, detecting security incidents, complying with legal obligations, or exercising free speech rights.

The deletion process is not instantaneous. Companies have 45 days to respond, with a possible 45-day extension. They must confirm receipt of your request and verify your identity before processing it. Once verified, they delete what CCPA requires them to delete and inform you that the deletion is complete.

But deletion doesn't mean erasure from every system. Companies can retain data in backup systems if those backups are not actively accessed or used. They can keep transaction records required for tax compliance. They can retain information necessary to maintain security or prevent fraud. They can keep aggregated or de-identified data that no longer identifies you personally.

The practical result: deletion removes your data from active databases and customer-facing systems, but traces persist in backups, logs, and archived records. If you're trying to disappear completely, CCPA deletion won't get you there.

To submit a deletion request, follow the same process as a right-to-know request. Find the company's CCPA request form, verify your identity, and specify that you want your data deleted. Some companies require you to confirm the request a second time to prevent accidental deletion.

After submission, you wait. If the company doesn't respond within 45 days, you can follow up. If they refuse to delete without a valid exception, you can file a complaint with the California Attorney General's office or the FTC. Enforcement takes time, but repeated complaints create pressure.

The Right to Opt Out of Data Sales

CCPA defines "sale" as selling, renting, releasing, disclosing, disseminating, making available, transferring, or otherwise communicating personal information to another business or third party for monetary or other valuable consideration. That definition is broader than most people expect. It includes data sharing arrangements where no money changes hands but both parties benefit from the exchange.

Advertising networks, data brokers, analytics providers, and marketing platforms all receive data under arrangements that CCPA classifies as sales. When you opt out, companies must stop selling your data going forward. They don't have to recall data already sold. They don't have to delete data held by third parties who received it before you opted out.

The opt-out mechanism is usually a link in the website footer: "Do Not Sell My Personal Information" or "Your Privacy Choices." Clicking that link should take you to a form or toggle that stops future sales. Some companies process the opt-out immediately. Some take days or weeks. CCPA requires compliance, but it doesn't mandate speed.

The Electronic Frontier Foundation's Privacy Badger can help block some third-party trackers automatically, but it doesn't replace CCPA opt-outs. Privacy Badger stops tracking in your browser. CCPA opt-outs stop sales at the company level. Both tools serve different functions.

After opting out, companies must honor your choice for at least 12 months before asking you to opt back in. They cannot charge you for opting out, deny you service, or provide a different level of service because you exercised your rights. Discrimination is explicitly prohibited.

In practice, some companies make opting out inconvenient. They bury the link. They require multiple clicks. They ask you to opt out separately for each brand they own. They reset your preference after updates or account changes. These friction tactics are common, and CCPA enforcement hasn't eliminated them.

How to Submit a CCPA Request Step by Step

Start by identifying which companies hold your data. Your email provider, your bank, your phone carrier, the retailers you shop with, the apps you use, the websites you visit regularly. Make a list. Prioritize the companies that hold the most sensitive information or the largest volume of data.

Visit each company's website and look for their privacy policy. Most privacy policies include a section on CCPA rights and a link to submit requests. If you don't see a link, search the site for "CCPA," "Do Not Sell," or "Your Privacy Choices." If that fails, email the privacy contact listed in the policy.

When you find the request form, decide which right you want to exercise. Right to know, right to delete, or right to opt out. Some forms let you select multiple options. Some require separate submissions for each right.

Fill out the form with the information the company requests. This usually includes your name, email address, and sometimes your phone number or account number. If you're logged into your account, the company may pre-fill some fields or skip verification entirely.

Submit the request. You should receive an automated confirmation email immediately. That email confirms receipt but doesn't confirm processing. The company has 45 days to respond with the requested information, confirm deletion, or process your opt-out.

If 45 days pass without a response, send a follow-up email. Reference your original request and ask for a status update. If the company still doesn't respond, file a complaint with the California Attorney General or the FTC. Document everything: request dates, confirmation emails, follow-ups, and non-responses.

What Companies Can Still Do After You Opt Out

Opting out of data sales doesn't stop all data collection. Companies can still collect information necessary to provide their services. They can still use your data for internal purposes like improving their products, detecting fraud, or complying with legal obligations. They can still share data with service providers who perform functions on their behalf, as long as those providers don't use the data for their own purposes.

CCPA distinguishes between selling data and sharing data with service providers. Service providers process data on behalf of the company under contractual restrictions. They can't sell that data or use it for their own benefit. Sales involve transferring data to third parties who use it for their own purposes, often for advertising or analytics.

After you opt out, companies must stop selling your data to third parties, but they can continue sharing it with service providers. That distinction matters. Your data still flows to payment processors, cloud storage providers, customer support platforms, and email marketing tools. Those are service providers, not third-party buyers.

Companies can also continue collecting data from you directly. When you visit their website, make a purchase, or use their app, they collect information about that interaction. CCPA doesn't require them to stop collecting data. It only requires them to stop selling it after you opt out.

If you want to stop collection entirely, you need to stop using the service. CCPA gives you control over sales, not collection. That's a narrower right than most people expect.

CCPA vs. GDPR: What's Different

CCPA protects California residents. GDPR protects residents of the European Union. Both laws give you rights over your personal data, but the mechanisms differ.

GDPR requires companies to obtain explicit consent before collecting most personal data. CCPA does not. CCPA allows companies to collect data by default and gives you the right to opt out of sales after the fact. That's an opt-out model, not an opt-in model.

GDPR gives you the right to data portability: the right to receive your data in a structured, commonly used format and transfer it to another service. CCPA does not include portability. You can request a copy of your data, but companies don't have to provide it in a transferable format.

GDPR enforcement is stricter. The European Data Protection Board issues fines that reach hundreds of millions of euros for serious violations. CCPA enforcement is newer and less aggressive. The California Attorney General can fine companies up to $7,500 per intentional violation, but enforcement actions are less frequent.

Some companies extend GDPR-style rights to all users globally for operational simplicity. Others apply CCPA only to California residents and GDPR only to EU residents. The company's privacy policy should specify which rights apply to you.

If you're not in California or the EU, you might still be able to request data access or deletion, but you're relying on the company's goodwill, not legal obligation. Some companies honor requests from all users. Some don't.

Using CCPA Rights for Data Brokers

Data brokers collect, aggregate, and sell personal information about millions of people. They scrape public records, purchase data from other companies, and infer details about your behavior from indirect sources. Most people have never heard of the companies that hold dossiers on them.

CCPA applies to data brokers operating in California. If a broker meets the revenue or data thresholds, California residents can submit requests to know, delete, or opt out. The challenge is identifying which brokers hold your data.

EPIC's consumer privacy resources provide guidance on finding and contacting data brokers, but the process is manual. You search for broker sites, find their CCPA request forms, submit requests, and wait for responses. There's no centralized registry. There's no one-click opt-out.

Services like Incogni and DeleteMe automate this process by submitting removal requests to dozens of brokers on your behalf. They charge a monthly or annual fee. They handle follow-ups. They monitor for re-listing. The tradeoff is cost versus time. You can do it yourself for free, but it takes hours spread over weeks.

After opting out or requesting deletion from a data broker, your information should disappear from their active databases. But brokers re-scrape public records and re-purchase data from other sources. Opting out once doesn't guarantee permanent removal. You need to monitor and re-submit requests periodically.

When Companies Deny Your Request

Companies can deny CCPA requests under specific circumstances. If they can't verify your identity, they can refuse to process the request. If the request is manifestly unfounded or excessive, they can refuse or charge a reasonable fee. If an exception applies, like retaining data for legal compliance or security, they can deny deletion.

When a company denies your request, they must explain why. CCPA requires them to provide a reason. If the reason seems invalid or pretextual, you can challenge it.

Start by responding to the denial email. Ask for clarification. Request specific details about which exception applies and why. Some companies provide vague explanations initially and offer more detail when pressed.

If the company still refuses, file a complaint with the California Attorney General or the FTC. Include your original request, the denial, and any follow-up correspondence. Enforcement agencies use complaint data to identify patterns of non-compliance.

In The Office, Dwight Schrute maintains elaborate files on his coworkers: their habits, their weaknesses, their secrets. When someone asks to see their file, Dwight refuses. He controls the information, and he's not giving it up without a fight. CCPA is the mechanism that forces Dwight to hand over the file. But Dwight still writes the rules about what stays in the file and what exceptions apply. Your leverage is limited to what the law explicitly requires, and companies interpret those requirements narrowly.

You can also pursue a private right of action if the company experiences a data breach caused by failure to implement reasonable security measures and that breach results in unauthorized access to your unencrypted personal information. CCPA allows you to sue for statutory damages of $100 to $750 per incident. That's a narrow pathway, and it requires proving the company's negligence, but it exists.

What Happens After You Submit Multiple Requests

CCPA doesn't limit the number of requests you can submit, but companies can refuse requests that are excessive or repetitive. If you submit the same request every week, they can deny subsequent requests as manifestly unfounded.

What counts as excessive depends on context. Requesting data from ten different companies once each is reasonable. Requesting the same data from the same company ten times in a month is excessive.

After you've submitted initial requests to your priority companies, wait for responses. Review what you receive. If the disclosure is incomplete or vague, follow up with specific questions. If deletion isn't confirmed, ask for verification. If the opt-out doesn't seem to take effect, check whether third-party trackers are still active.

CCPA rights are ongoing. You can submit new requests as circumstances change: when you start using a new service, when a company updates its privacy policy, when you learn about a data sharing arrangement you didn't know existed. The law gives you tools. Using them effectively requires persistence.

CCPA Rights for Non-Californians

CCPA only applies to California residents, but some companies extend the same rights to all U.S. users. They do this for operational simplicity: maintaining separate processes for California and non-California users creates complexity. Offering the same rights to everyone is easier.

If you're not in California, check the company's privacy policy. Look for language about CCPA rights or "Your Privacy Choices." If the policy says CCPA rights are available to all users, you can submit requests using the same process California residents use.

If the policy limits CCPA rights to California residents, you can still try submitting a request. Some companies process requests from non-Californians anyway. Some don't. The worst outcome is a denial email.

Other states have passed privacy laws similar to CCPA: Virginia, Colorado, Connecticut, and Utah all have consumer data protection statutes with overlapping rights. If you live in one of those states, you may have similar rights under your state's law. Check your state attorney general's website for guidance.

Federal privacy legislation has been proposed repeatedly but hasn't passed. Until Congress acts, privacy rights remain patchwork: strong in California and a few other states, weak or nonexistent elsewhere.

Monitoring Whether Companies Honor Your Requests

After you opt out of data sales, you want to verify that companies actually stopped selling your data. CCPA doesn't provide a mechanism for real-time monitoring. You can't see inside the company's data sharing agreements. You can't audit their third-party transfers.

What you can do: use browser tools like Privacy Badger to track which third-party domains are loading when you visit a site. If you opted out but the same ad networks and analytics trackers are still firing, the opt-out might not be working.

You can also submit a second right-to-know request months after opting out. Ask the company to disclose which third parties received your data in the past 12 months. If the list includes parties you opted out of, the company violated CCPA.

If you find evidence of non-compliance, document it. Take screenshots. Save emails. File a complaint with the California Attorney General or the FTC. Enforcement depends on people reporting violations.

Checklist showing completed CCPA privacy requests across multiple companies
→ Filed under
privacyccpadata rightsconsumer protectioncalifornia lawdata deletion
ShareXLinkedInFacebook

Frequently asked questions

The California Consumer Privacy Act (CCPA) is a state law that gives California residents the right to know what personal data companies collect, request deletion of that data, and opt out of its sale. It applies to businesses that meet specific revenue or data thresholds.
Most companies provide a 'Do Not Sell My Personal Information' link in their website footer or privacy policy. You can also email their privacy contact directly. They must respond within 45 days and verify your identity before processing the request.
No. CCPA prohibits companies from charging fees, providing different service levels, or discriminating against you for exercising your privacy rights. The process must be free and accessible.
Opting out stops future sales of your data to third parties but doesn't remove what's already been collected. Deletion requests require the company to erase your personal information from their systems, with some exceptions for legal compliance and security.
CCPA only protects California residents, but some companies extend the same rights to all U.S. users for operational simplicity. Check the company's privacy policy or submit a request to find out.

You might also like