What is the CCPA right to limit use of sensitive personal information?
Under Cal. Civ. Code section 1798.121(a) a consumer may at any time direct a business to limit use of their sensitive personal information to what is necessary to perform the goods or services an average consumer would reasonably expect, plus the specific service purposes listed in section 1798.140(e).
Applies to: For-profit businesses covered by the CCPA that use or disclose California residents' sensitive personal information for purposes beyond those permitted in Civil Code section 1798.121(a) and 11 CCR section 7027(m).
Find out what applies to you
Run the free 2-minute Obligation Scan and get a plain-language list of what your business has to do, and by when.
Run the free 2-minute Obligation ScanThe right to limit is the CCPA right businesses most often miss, because it does not work like the others. It is not a deletion right and not a straightforward opt-out. It is a right to cap what a business may do with a narrow class of data, and whether you owe it at all depends on what you use that data for.
What the statute says
Section 1798.121(a) gives a consumer the right, at any time, to direct a business that collects sensitive personal information about them to limit its use of that information to the use which is necessary to perform the services or provide the goods reasonably expected by an average consumer who requests those goods or services, to perform the services set out in paragraphs (2), (4), (5) and (8) of section 1798.140(e), and as authorized by regulations adopted under section 1798.185(a)(18)(C).
The same subdivision adds a notice duty. A business that uses or discloses sensitive personal information for purposes other than those specified must tell consumers, under section 1798.135(a), that the information may be used or disclosed to a service provider or contractor for additional specified purposes, and that consumers have the right to limit.
Section 1798.121(b) is the effect of the direction. Once a business has received it, section 1798.135(c)(4) prohibits the business from using or disclosing that sensitive personal information for any other purpose after receipt, unless the consumer subsequently consents.
Section 1798.121(c) carries the instruction down the chain. A service provider or contractor assisting a business with the permitted purposes may not use the sensitive personal information for any other purpose once it has received instructions from the business and has actual knowledge that the information is sensitive. The obligation is scoped to its relationship with that business and to information received under a written contract.
Section 1798.121(d) is the boundary. Sensitive personal information collected or processed without the purpose of inferring characteristics about a consumer is not subject to this section, and is treated as ordinary personal information for all other purposes of the Act. The section as it currently stands was amended by Stats. 2024, Ch. 121, Sec. 2 (AB 3286), effective January 1, 2025.
When you do not owe a Limit link at all
This is the part that decides the question for most businesses. 11 CCR section 7027(m) sets out the purposes from section 1798.121(a) for which a business may use or disclose sensitive personal information without offering a right to limit, and then states the consequence directly: a business that only uses or discloses sensitive personal information for those purposes, where the use or disclosure is reasonably necessary and proportionate, is not required to post a Notice of Right to Limit or provide a method for submitting a request to limit.
The first permitted purpose, at 7027(m)(1), is performing the services or providing the goods reasonably expected by an average consumer who requests them. The regulation illustrates it with precise geolocation: a mapping application may use it to give directions, while a gaming application may not, because the average consumer would not expect a game to need it.
The rest cover security and safety. Section 7027(m)(2) permits preventing, detecting and investigating security incidents that compromise the availability, authenticity, integrity or confidentiality of stored or transmitted personal information. Section 7027(m)(3) permits resisting malicious, deceptive, fraudulent or illegal actions directed at the business or at consumers and prosecuting those responsible. Section 7027(m)(4) permits ensuring the physical safety of natural persons. Further paragraphs cover short-term transient use and related service purposes.
The regulation's own examples show how tightly these are read. A business may use biometric information to authenticate employees into secured areas under 7027(m)(3), but may not retain it indefinitely or reuse it to develop commercial products. A business may scan outgoing employee email to stop leaks of sensitive personal information, but scanning for other purposes falls outside the exception.
What compliance looks like if you do owe it
If any use falls outside that list, three things follow.
First, notice and a link. 11 CCR section 7014 requires a Notice of Right to Limit, and a conspicuous "Limit the Use of My Sensitive Personal Information" link located at the header or footer of your homepage. Clicking it must either immediately limit use and disclosure, or take the consumer to a page where they can learn about and make that choice. Under 7014(d), a business may post the Alternative Opt-out Link instead of the separate Limit link, but still has to post the Notice of Right to Limit.
Second, request methods. Section 7027(b) requires two or more designated methods, with at least one reflecting how the business primarily interacts with consumers. A business collecting sensitive personal information online must at minimum offer an interactive form reached from the Limit link or the Alternative Opt-out Link. Section 7027(b)(4) rules out treating a cookie banner as a method, because cookies concern collection rather than use and disclosure.
Third, low friction. Section 7027(c) requires methods that are easy to execute and require minimal steps. Section 7027(d) bars requiring an account or information beyond what is needed to direct the business to limit. Section 7027(e) bars requiring a verifiable consumer request.
Which data this attaches to
The right only reaches the categories listed in section 1798.140(ae): government identifiers, account log-in and financial account credentials, precise geolocation, racial or ethnic origin, citizenship or immigration status, religious or philosophical beliefs, union membership, the contents of mail, email and text messages where the business is not the intended recipient, genetic data and neural data, plus biometric processing for unique identification and information collected and analyzed concerning health or sex life and sexual orientation.
Start there. Map which of those you use rather than which you hold, then run each use through 7027(m). Most businesses find the answer is narrower than they feared, and the ones that do owe the link usually owe it because of a single analytics or advertising flow.
Next step
If you handle any of the sensitive categories and are unsure whether you owe a Limit link, the free 2-minute Obligation Scan works out which California duties apply and what each requires. The US state privacy law hub sets the rest of the CCPA picture in order.
Compliance checklist
- Inventory which of the 1798.140(ae) sensitive categories you actually use, not just which you collect.
- Test each use against the 11 CCR 7027(m) list; if every use fits, you owe no Limit link and no request method.
- If any use falls outside, post a Notice of Right to Limit and a conspicuous 'Limit the Use of My Sensitive Personal Information' link in your homepage header or footer, under 11 CCR 7014(c).
- Offer two or more designated methods for submitting requests to limit, under 11 CCR 7027(b), including an interactive form if you collect online.
- Do not require an account or a verifiable consumer request, under 11 CCR 7027(d) and (e).
- Flow the instruction through to service providers and contractors, which section 1798.121(c) binds once they receive it.
Sources
- Cal. Civ. Code Section 1798.121 (consumers' right to limit use and disclosure of sensitive personal information), California Legislative Information
- California Code of Regulations, Title 11, Division 6, sections 7014 and 7027 (Notice of Right to Limit; requests to limit), CPPA approved text of regulations
- Cal. Civ. Code Section 1798.140 (definitions, including sensitive personal information at subdivision (ae)), California Legislative Information
Last verified: 2026-09-15
Informational, not legal advice.