US State Law California, USA

CCPA Sensitive Personal Information: Categories and Duties

What counts as sensitive personal information under the CPRA, when the 'Limit' right applies, permitted uses, and how SPI differs from GDPR special categories.

Regulation

Cal. Civ. Code 1798.121 and 1798.140(ae) (CPRA sensitive personal information)

Max Penalty

$2,500 per violation; $7,500 per intentional violation or violation involving minors

Enforcing Authority

California Privacy Protection Agency (CPPA) and California Attorney General

Official Source

cppa.ca.gov

Executive Summary

  • The CPRA created a defined 'sensitive personal information' class: SSN and government identifiers, financial account credentials, precise geolocation (within ~1,850 feet), race/ethnicity, religion, union membership, mail/email/text contents, genetic data, biometric identifiers, health data, and sex life or sexual orientation.
  • SPI used to infer characteristics beyond enumerated business purposes triggers the 'Limit the Use of My Sensitive Personal Information' right and link.
  • California's model is limit-on-use, not consent: businesses may collect SPI without opt-in (except minors), but consumers can restrict use to what is necessary to provide the service.
  • Most other state laws (Colorado, Connecticut, Texas, Oregon and the Virginia lineage) instead require opt-in consent for sensitive data, so multistate programs usually build to consent and inherit California compliance.
  • Enforcement is converging on inference: the Healthline settlement treated article titles implying health conditions as sensitive-adjacent data flowing to ad networks without adequate disclosure.

California added a sensitive-data tier in 2023, but with an American twist: instead of forbidding processing without consent, it gives consumers a brake pedal. The practical consequence is that SPI compliance is mostly an advertising question, whether identifiers, location, health-adjacent browsing, or inferred characteristics leak into the ad stack beyond what the permitted-purpose safe harbor covers, and the first enforcement actions confirm that reading.

ProvisionsCiv. Code 1798.121, 1798.140(ae)
Mechanism”Limit the Use of My SPI” right + link
Consent needed?No (California); yes in most other states
RegulatorCPPA

Operating rules

Classify first. Tag SPI fields in your data map, including derived and inferred values: a health-condition inference from content consumption is SPI even if no explicit health field exists. Precise geolocation deserves its own audit given SDK sprawl.

Check the safe harbor honestly. If every SPI use fits the permitted purposes (service delivery, security, transient use, quality), you need no link and limit machinery. The moment SPI feeds behavioral advertising, lookalike modeling, or characteristic inference, the safe harbor is gone. Most companies fail here through their tag manager, not their databases.

Honor limits like opt-outs. Same 15-business-day propagation, same GPC-adjacent automation expectations, same symmetry rules against dark patterns. Requests restrict use to permitted purposes; they do not require deletion.

Build to consent for multistate reach. Colorado, Connecticut, Texas, Oregon, and the Virginia-lineage states require opt-in consent for sensitive data, and their category lists differ at the edges (Oregon adds status as a victim of crime; New Jersey adds financial data). One consent-gated pipeline for the union of categories, documented in your state sensitive-data comparison, beats fifty conditional flows.

Minors are a separate track. Under-16 sale/sharing needs opt-in; under-13 needs parental consent, and COPPA plus the state children’s laws layer on top.

Find out whether your site is already transmitting SPI-adjacent signals, location, health-implying URLs, identifiers, to third parties: run a free scan.

Frequently Asked Questions

What exactly is in the SPI list?

Cal. Civ. Code 1798.140(ae): SSN, driver's license, state ID, or passport numbers; account log-in or financial account with credentials; precise geolocation; racial or ethnic origin, religious or philosophical beliefs, or union membership; contents of mail, email, and text messages (unless the business is the intended recipient); genetic data; biometric information processed to identify; health data; and sex life or sexual orientation data. Neurodata joined via 2024's SB 1223, which added neural data to the definition.

When do we need the 'Limit' link?

When you collect or process SPI for purposes beyond the regulation's permitted list: providing the requested service, security and integrity, short-term transient use (including non-personalized advertising), order fulfillment, and service quality. Using SPI for cross-context behavioral advertising or to infer characteristics takes you outside the safe harbor and requires the link plus honoring limit requests.

Is precise geolocation really sensitive?

Yes, defined as location within a radius of 1,850 feet, which captures most mobile SDK location collection. Ad-tech and retail apps deriving store-visit attribution from device location are processing SPI; if that feeds advertising, the limit right applies. The FTC's parallel enforcement against location brokers (Kochava, X-Mode, InMarket) shows both regulators treating location as the highest-risk category.

How does SPI differ from GDPR special-category data?

Three ways: California includes financial credentials, precise geolocation, and message contents (GDPR does not); GDPR includes some California omits from heightened treatment; and the legal mechanics invert, GDPR Article 9 prohibits processing without an exception (consent being the usual one), while California allows processing but grants a use-limitation right. A GDPR-compliant consent flow generally over-complies with California.

What about inferences drawn from SPI?

Inferences are personal information under the CCPA, and the CPPA/AG treat inferring characteristics (health conditions from browsing, ethnicity from names or location) as SPI processing. Healthline's $1.55M settlement is the template: sending URLs whose titles implied medical diagnoses to advertisers was charged as a disclosure practice violating the statute's purpose-limitation expectations. Model your inference pipelines as SPI, not metadata.

Regulatory Crosswalk

CPRAGDPR Art. 9State sensitive-data laws

Organizations subject to this regulation often operate under these overlapping frameworks. BD Emerson maps controls across frameworks to reduce duplicated compliance effort.

Evaluate your compliance posture now

BD Emerson's automated scanner audits your public-facing properties against your applicable regulations in minutes, not weeks.