Skip to main content
Dark green background, "Weak Application Security Can Cost You Millions," 3 slanted images of fingers pointing to digital locks, and a "Learn the Basics" button
Category: Consumer Privacy Rights

Right to Limit Sensitive Personal Information

Also known as: Right to Limit Use and Disclosure of Sensitive Personal Information, Limit the Use of My Sensitive Personal Information, Right to Limit SPI
Simply put

Under California's privacy law, this is a consumer right that lets California residents tell a business to limit how it uses and shares certain particularly sensitive categories of their personal information. It is one of several consumer rights created by California's privacy framework and applies specifically to information classified as 'sensitive personal information.' Businesses subject to the law are generally expected to inform consumers of this right and provide a way to exercise it.

Formal definition

The Right to Limit Sensitive Personal Information is a consumer right under California's privacy regime (introduced through amendments associated with the CPRA and operationalized in the CCPA framework) that allows consumers to direct a business to limit its use and disclosure of their sensitive personal information. Under the implementing regulations, businesses are required to provide a Notice of Right to Limit informing consumers of this right and the means of exercising it (see Cal. Code Regs. Tit. 11, § 7014). This right reflects California's opt-out model, contrasting with the opt-in consent approach used in the EU; the precise scope of what counts as 'sensitive personal information,' the exemptions that apply, and the specific business obligations depend on the statutory and regulatory text and are not fully detailed in this entry. This right is a US-state-specific mechanism and should not be assumed to apply in other jurisdictions or to satisfy consent requirements under the EU GDPR or ePrivacy rules.

Why it matters

The Right to Limit Sensitive Personal Information reflects a distinctive feature of California's privacy framework: rather than requiring opt-in consent before certain data is processed, it gives consumers the ability to restrict how a business uses and discloses information that has already been classified as sensitive. For organizations that collect categories of data such as precise geolocation, government identifiers, or other information treated as sensitive under California law, this right creates operational obligations that sit alongside, but are distinct from, the more familiar right to opt out of the sale or sharing of personal information.

For compliance teams, the practical significance lies in the requirement to surface this right to consumers and to honor requests to limit. Under the implementing regulations, businesses are generally expected to provide a Notice of Right to Limit informing consumers of the right and the means to exercise it. Failing to provide a clear mechanism, or failing to act on a consumer's request, can expose an organization to enforcement risk under California's privacy regime.

It is important not to overstate the reach of this right. It is a California-specific mechanism and should not be assumed to apply in other US states or jurisdictions, nor does it satisfy the opt-in consent standards that generally apply under the EU GDPR and ePrivacy rules. The precise scope of what qualifies as sensitive personal information, the exemptions that may apply, and the exact obligations depend on the statutory and regulatory text, which is not fully reproduced here.

Who it's relevant to

Privacy and compliance officers
Teams responsible for California privacy compliance need to determine whether the business handles sensitive personal information and, if so, ensure that a Notice of Right to Limit and a working request mechanism are in place. They should also confirm that requests are actioned in line with the statutory and regulatory requirements, which are not fully detailed here.
Legal counsel and data protection professionals
Counsel advising on multi-jurisdictional compliance should treat this right as California-specific. It should not be assumed to apply in other US states or to satisfy EU GDPR or ePrivacy consent obligations. The precise scope of sensitive personal information and applicable exemptions depends on the underlying statutory and regulatory text.
Web developers and CMP implementers
Those building consent and preference interfaces may need to implement a 'Limit the Use of My Sensitive Personal Information' link or equivalent request path and ensure that limit requests are captured and propagated. Tooling supports these obligations but does not by itself guarantee compliance with California law.
Marketing and analytics compliance teams
Teams that rely on sensitive personal information for targeting or measurement should understand that consumers may direct the business to limit its use and disclosure of that data, which can affect downstream processing under California's opt-out model. Permitted uses after a request depend on the applicable regulatory text.

Inside Right to Limit Sensitive Personal Information

Statutory Basis (CPRA)
The right to limit the use and disclosure of sensitive personal information (SPI) is a consumer right introduced by the California Privacy Rights Act (CPRA), which amended the CCPA. It applies to businesses subject to California law and is not a universal requirement across all US states or other jurisdictions.
Defined Categories of Sensitive Personal Information
California law defines SPI to include categories such as precise geolocation, government identifiers, racial or ethnic origin, religious or philosophical beliefs, contents of certain communications, genetic and biometric data, and health, sex life, or sexual orientation information. Practitioners should consult the current statutory definition, as the exact scope is set by law and may be subject to regulatory interpretation.
Limitation to Specified Purposes
When a consumer exercises this right, the business is generally directed to use SPI only for purposes permitted under the statute, such as providing the requested goods or services and other narrowly defined operational purposes. Uses beyond those permitted purposes are what the consumer can restrict.
Opt-Out Rather Than Opt-In Model
This right operates on an opt-out basis, meaning the business may process SPI until the consumer requests limitation. This differs materially from the EU/EEA approach, where processing of special category data and non-essential cookies generally requires prior affirmative consent (opt-in).
Mechanisms for Exercising the Right
Businesses are typically expected to provide a means to exercise the right, which may include a designated link (commonly associated with the 'Limit the Use of My Sensitive Personal Information' notice) and recognition of opt-out preference signals such as Global Privacy Control, where applicable under California requirements.
Relationship to Cookies and Tracking Technologies
Where cookies, pixels, SDKs, local storage, or similar technologies collect data that meets the definition of SPI (for example precise geolocation), a limitation request may affect how that data is used and disclosed. The right addresses use and disclosure, not solely the initial placement of a technology on a device.

Common questions

Answers to the questions practitioners most commonly ask about Right to Limit Sensitive Personal Information.

Does the right to limit sensitive personal information mean businesses cannot collect it at all?
No. This right, which arises under the California Privacy Rights Act (CPRA) amendments to the CCPA, does not prohibit collection of sensitive personal information. Instead, it generally allows a consumer to direct a business to limit its use and disclosure of that information to purposes necessary to provide the goods or services reasonably expected, plus certain other permitted purposes. It is a limitation on use and disclosure, not an outright collection ban, and its exact scope depends on the statutory and regulatory text and how it is interpreted in California.
Is this California-style right the same as consent for special category data under the GDPR?
No, and treating them as equivalent can lead to compliance gaps. The California right to limit is generally an opt-out mechanism: a consumer acts to restrict use of sensitive personal information that a business may otherwise process. Under the GDPR, processing of special category data typically requires a valid legal basis and often relies on an opt-in model such as explicit consent, subject to Article 9 conditions. The two frameworks use different categories, different triggers, and different default positions, so satisfying one does not automatically satisfy the other.
How does this right typically relate to cookies and tracking technologies on a website?
Where cookies, pixels, SDKs, local storage, or similar technologies are used to collect or infer information that falls within the sensitive category under the applicable California definition, the right to limit may apply to how that information is used and disclosed. Because these technologies are treated similarly to cookies for consent and disclosure purposes, teams should map which trackers touch sensitive data. Whether a given cookie triggers the right depends on the specific data involved and the applicable definitions, which is a fact-specific analysis rather than a blanket rule.
What mechanism is generally expected for consumers to exercise this right?
In practice, businesses subject to the California framework often provide a clear method for consumers to submit a limitation request, which may include a designated link or a preference control, and may honor recognized opt-out signals where applicable. The precise mechanisms, wording, and placement are governed by California statute and implementing regulations, which can evolve. A consent management platform can support surfacing and recording these choices, but a tool supports compliance and does not replace legal review of your specific obligations.
How should limitation requests be logged and honored operationally?
Organizations generally need to record that a request was received, when it was made, and how it was actioned, and then propagate the limitation to downstream systems, vendors, and tag configurations so that use and disclosure are actually restricted. This can involve suppressing certain uses of sensitive data collected via tags or SDKs. The specific record-keeping and timing expectations flow from the applicable California requirements; because these can change, confirm current obligations with counsel and document your process rather than relying on a fixed rule.
Does honoring this right in California cover obligations in other jurisdictions?
Not necessarily. This right derives from California law, and other US state privacy laws, the EU, and the UK address sensitive or special category data differently, sometimes through opt-in consent, distinct categories, or separate legal bases. A control built for the California right to limit may not satisfy requirements elsewhere. Scope each obligation to its jurisdiction and avoid assuming that one implementation is sufficient across all regimes.

Common misconceptions

The right to limit sensitive personal information is the same as the EU requirement to obtain consent for special category data.
These are distinct regimes. California's right generally operates as an opt-out that a consumer must invoke, while EU law typically requires prior affirmative consent before processing special category data or setting non-essential cookies. Complying with one does not automatically satisfy the other, and the definitions of sensitive/special data are not identical.
Any use of sensitive personal information stops entirely once a consumer exercises this right.
The right limits use and disclosure to purposes permitted by the statute, such as providing requested services and certain operational uses. It does not necessarily prohibit all processing; the precise permitted uses are defined by California law and may be subject to regulatory interpretation.
This right applies to businesses everywhere and covers all tracking technologies by default.
The right derives from California law and applies to businesses within its scope. Other US states and jurisdictions may address sensitive data differently or not through an equivalent limitation right. It reaches cookies and similar technologies only where the data collected meets the statutory definition of sensitive personal information.

Best practices

Map where your organization collects, uses, and discloses data that may meet California's definition of sensitive personal information, including data gathered through cookies, pixels, SDKs, local storage, and similar technologies.
Provide a clear and accessible mechanism for consumers to exercise the right, and evaluate whether you are required to honor opt-out preference signals such as Global Privacy Control under applicable California requirements.
Document the specific purposes for which sensitive personal information is used so that, upon a limitation request, processing can be confined to purposes permitted under the statute.
Do not assume California's opt-out approach satisfies EU or UK requirements; maintain separate handling for jurisdictions that require prior consent for special category data or non-essential cookies, and scope each control to its applicable geography.
Maintain records of limitation requests and how they were actioned to support accountability and demonstrate responsiveness, recognizing that record-keeping supports but does not by itself guarantee compliance.
Consult current statutory text and evolving regulatory guidance, and obtain legal advice for contested or fact-specific questions, since definitions and enforcement positions may change over time.
Promotional banner for the Penetration Report Template Kit