Back to the hub

How long can a business keep personal information under the CCPA?

Under California Civil Code section 1798.100(a)(3), a business must tell consumers at or before collection how long it intends to retain each category of personal information, or the criteria it uses to set that period. It may not keep the data longer than is reasonably necessary for the disclosed purpose it was collected for.

Applies to: For-profit businesses covered by the CCPA that collect California consumers' personal information and must publish retention periods alongside their notice at collection.

Find out what applies to you

Run the free 2-minute Obligation Scan and get a plain-language list of what your business has to do, and by when.

Run the free 2-minute Obligation Scan

Founding 30% off with code FOUNDING until 15 August 2026

Most privacy programs treat retention as a filing question. Under the CCPA it is a disclosure obligation with a hard limit attached, and it sits in the same subdivision as the notice you already give at the point of collection. If your privacy policy says "we retain data as long as necessary" and stops there, it does not meet the standard.

What Section 1798.100(a)(3) requires

A business that controls the collection of a consumer's personal information must, at or before the point of collection, inform consumers of the length of time it intends to retain each category of personal information, including sensitive personal information. Where stating that length is not possible, it must instead give the criteria used to determine the period.

Then comes the limit. The same paragraph provides that a business shall not retain a consumer's personal information or sensitive personal information, for each disclosed purpose for which it was collected, for longer than is reasonably necessary for that disclosed purpose.

Two obligations, one sentence: say how long, and do not exceed it.

Per category, not per business

The wording is "each category." A single global retention line does not satisfy it. Account records, support transcripts, payment history, marketing engagement data, and any sensitive personal information you hold are separate categories with separate justifications, and the statute expects a period or a criterion for each.

Sensitive personal information gets called out explicitly, which matters because it is also the category consumers can ask you to limit the use of. The category list you already built for your notice at collection is the right starting point.

When you cannot name a number

Some data genuinely has no fixed end date at collection time. The statute allows criteria in that case, but criteria still have to do real work. "As long as necessary" restates the legal standard without disclosing anything. "For the life of the account, plus the period of the applicable statute of limitations" tells a consumer something they can hold you to.

How retention interacts with deletion

Retention and deletion are separate duties that meet in practice. Section 1798.105 gives consumers the right to ask you to delete personal information you collected from them, subject to the exceptions the section lists. A retention schedule does not override that right, and a deletion request does not excuse an over-long schedule. A business that quietly holds five years of data it disclosed a one-year period for has a problem in both directions.

The proportionality rule alongside it

Section 1798.100(c) frames the whole thing. A business's collection, use, retention, and sharing of personal information must be reasonably necessary and proportionate to achieve the purposes it was collected or processed for, or another disclosed and compatible purpose, and it must not be further processed in a manner incompatible with those purposes. Retention is one of the four verbs in that sentence, which is why an unjustified schedule is a substantive violation rather than only a disclosure gap.

Next step

If you are not sure whether the CCPA applies to you or what your retention disclosure has to say, the free 2-minute Obligation Scan checks which privacy laws reach your business and lists the notices you owe. The California privacy overview covers the thresholds, and the US state privacy laws hub compares retention and minimization duties across states.

Compliance checklist

  • Inventory your personal information by category, and separately identify sensitive personal information, because Section 1798.100(a)(3) covers both.
  • Set a retention period for each category, or write down the criteria you use where a fixed period is not possible.
  • Publish those periods or criteria at or before the point of collection, alongside the other Section 1798.100(a) disclosures.
  • Check no category is held longer than reasonably necessary for the disclosed purpose it was collected for, which is the substantive limit in the statute.
  • Confirm your collection, use, retention, and sharing stay reasonably necessary and proportionate under Section 1798.100(c), and are not further processed incompatibly.

Sources

Last verified: 2026-08-14

Informational, not legal advice.