HomeBlog › CCPA/CPRA redaction guide

CCPA/CPRA Redaction Guide: Personal Information Requests

The California Consumer Privacy Act (CCPA), as amended by the California Privacy Rights Act (CPRA), gives California residents rights over the personal information businesses hold about them — and it comes with a redaction problem most guides skip. When a business fulfills a "right to know" request by compiling a record of what it holds, that record often contains other people's data, and specific fields the law says should never appear in the response at all. Here's what counts as personal information under the CCPA, what has to stay out of a disclosure, and how to build a workflow around it.

Key takeaways

  • The CCPA is codified at Cal. Civ. Code § 1798.100 et seq., effective January 1, 2020, and was substantially amended by the CPRA (Proposition 24), with most CPRA provisions effective January 1, 2023.
  • "Personal information" (§ 1798.140) is defined broadly — far wider than a name and email — and the CPRA added a narrower "sensitive personal information" category with extra protection.
  • CCPA regulations tell businesses not to include a consumer's SSN, driver's license number, financial account number, health/medical ID number, or account password in a right-to-know response — those fields get redacted, not disclosed.
  • The CPRA created the California Privacy Protection Agency (CPPA), the first U.S. state agency dedicated to privacy enforcement and rulemaking, alongside continued Attorney General enforcement.
  • The CCPA's private right of action is narrow: it covers certain data breaches under § 1798.150, not general violations.
  • Redacting the response file locally, in your browser, keeps a consumer's personal-information report from ever passing through a third-party server before it reaches them.

What is the CCPA/CPRA and who must comply?

The CCPA is a California statute, codified at Cal. Civ. Code § 1798.100 et seq., that took effect January 1, 2020. In November 2020, California voters approved Proposition 24 — the California Privacy Rights Act (CPRA) — which amended and expanded the CCPA; most of its provisions took effect January 1, 2023. The CPRA also created the California Privacy Protection Agency (CPPA), the first dedicated state-level privacy regulator in the United States, with rulemaking and enforcement authority alongside the state Attorney General.

The law generally applies to a for-profit business doing business in California that meets at least one of three thresholds: annual gross revenue above $25 million, buying, selling or sharing the personal information of 100,000 or more California consumers or households in a year, or deriving 50% or more of annual revenue from selling or sharing consumers' personal information. A notable CPRA change: the temporary exemptions that had let businesses treat employee and B2B-contact data more loosely expired on January 1, 2023, so most employee and business-contact personal information now falls under the same general obligations as customer data.

Since January 1, 2023, job applicants, employees and B2B contacts are covered by the CCPA/CPRA on largely the same footing as consumers — the earlier employee/B2B carve-outs were temporary and were not renewed.

What counts as personal information?

Cal. Civ. Code § 1798.140 defines "personal information" broadly: information that identifies, relates to, describes, is reasonably capable of being associated with, or could reasonably be linked, directly or indirectly, with a particular consumer or household. The statute lists example categories rather than a short fixed list, including:

Publicly available government records and de-identified or aggregate information are excluded from the definition. Everything else is broad enough that most documents a business assembles about a specific person — support tickets, order history exports, HR files, marketing profiles — will contain personal information under this definition, even without an obvious identifier like a Social Security number on the page.

Sensitive personal information: the CPRA's stricter category

The CPRA introduced a narrower, higher-risk subset called "sensitive personal information" (also defined at § 1798.140), which consumers can specifically direct a business to limit the use of. It includes:

Sensitive personal information isn't just "extra confidential" — several categories in this list are exactly the fields CCPA regulations say a business must not disclose in a right-to-know response at all. They get redacted, not delivered.

The consumer rights the law creates

The CCPA/CPRA gives California consumers several distinct rights, and a redaction workflow needs to know which one it's supporting:

Redaction work concentrates almost entirely around the right-to-know request: a business has to assemble a response document — often a PDF or export — and that document is exactly where over-disclosure risk lives.

What has to be redacted from a right-to-know response

Two separate redaction problems show up in a right-to-know response, and it's easy to only catch one of them.

First: specific fields the regulations say never to disclose. CCPA regulations direct businesses responding to a request for specific pieces of personal information not to disclose a consumer's Social Security number, driver's license number or other government-issued identification number, financial account number, health insurance or medical identification number, account password, or security questions and answers. These fields should be redacted or omitted, with the response describing the category of information held (e.g., "financial account number") instead of showing the value.

Second: other people's personal information that ends up in the same record. A support ticket, an email thread, or a shared document frequently contains a second person's name, contact details, or account information alongside the requesting consumer's own data. Disclosing that second person's personal information to someone else's right-to-know request creates its own exposure — the fix is the same discipline used for GDPR data-subject access requests: redact everyone in the record except the person who has the right to see it.

Treat a right-to-know response like a subject access request: redact regulator-designated high-risk fields (SSN, driver's license, financial account, health ID, password) unconditionally, and redact every other person's personal information that isn't the requester's own.

Enforcement, penalties and the limited right to sue

The CPPA and the California Attorney General share enforcement authority; the CPPA took on primary rulemaking and enforcement responsibility beginning in mid-2023. Civil penalties under § 1798.155 can reach up to $2,500 per violation, or up to $7,500 per intentional violation and for violations involving a consumer known to be under 16. The CPRA removed the mandatory 30-day cure period that businesses previously had before enforcement, though regulators retain discretion in how they proceed.

Consumers themselves cannot sue over most CCPA violations. Cal. Civ. Code § 1798.150 creates a private right of action limited to specific data breaches — where nonencrypted, nonredacted personal information is exfiltrated, stolen or disclosed because a business failed to implement and maintain reasonable security procedures — with statutory damages of $100 to $750 per consumer per incident (or actual damages, if higher). Outside that breach scenario, enforcement runs through the CPPA and Attorney General, not individual lawsuits.

A practical CCPA redaction workflow

A defensible way to prepare a right-to-know response, or any document a California business shares that contains personal information, without any of it touching a third-party server:

  1. Identify which right is being exercised. A right-to-know response has different redaction rules than an internal record being shared with a vendor or produced in litigation.
  2. Redact the regulator-designated fields unconditionally. Social Security number, driver's license number, financial account number, health/medical ID number, account passwords and security answers do not belong in a right-to-know disclosure.
  3. Scan for other consumers' data in the same record. Shared inboxes, support tickets and multi-party documents often carry a second person's personal information that the requester has no right to see.
  4. Redact with a method that removes data, not one that covers it. A rectangle drawn over text in a PDF leaves the underlying text layer intact and often still selectable — the same failure pattern behind many public redaction failures.
  5. Strip metadata on export. Author fields, prior revisions and embedded file properties can carry identifiers that never appear on the visible page.
  6. Verify before sending. Select all, copy, and search the exported file for the redacted values. If they surface, the redaction did not work.

You can run this entire workflow in SladdPDF, a free browser-based redaction tool. It processes files locally with JavaScript and WebAssembly — a consumer's personal-information report never leaves your device, and the tool works offline once loaded. Secure mode rasterizes each page on export, destroying the underlying text layer, and metadata can be stripped in the same pass. The free version redacts documents with no page limit; a Pro license unlocks high-resolution 300 DPI export.

This article is general guidance, not legal advice. Whether a specific field must be withheld, and how the CCPA/CPRA applies to a particular business, depends on facts that should be checked with counsel or a privacy officer.

Redact personal-information responses without uploading anything

SladdPDF runs entirely in your browser — files are never uploaded to a server. Free with no page limit; Pro unlocks high-resolution 300 DPI export.

Redact a PDF now

Frequently asked questions

What counts as personal information under the CCPA?

Cal. Civ. Code § 1798.140 defines personal information broadly: information that identifies, relates to, describes, is reasonably capable of being associated with, or could reasonably be linked, directly or indirectly, with a particular consumer or household. That includes identifiers like name, address, email and IP address, plus commercial, biometric, internet-activity, geolocation, employment and inference-based data.

What is "sensitive personal information" under the CPRA?

The CPRA added a narrower category defined at Cal. Civ. Code § 1798.140: Social Security, driver's license, state ID and passport numbers; account log-in credentials; precise geolocation; racial or ethnic origin, religious beliefs and union membership; the contents of private mail, email and text messages; genetic data; biometric data used for identification; health data; and data about sex life or sexual orientation.

Does a business have to disclose someone's Social Security number in a right-to-know response?

No. CCPA regulations direct businesses not to disclose a consumer's Social Security number, driver's license number, financial account number, health insurance or medical identification number, or account password in response to a right-to-know request. Those fields should be redacted or withheld, with the response describing the category instead of showing the value.

Can a consumer sue a business under the CCPA?

Only in a narrow circumstance. Cal. Civ. Code § 1798.150 gives consumers a private right of action limited to certain data breaches caused by a business's failure to implement reasonable security, with statutory damages of $100 to $750 per consumer per incident. Most other CCPA violations are enforced by the California Privacy Protection Agency and the state Attorney General, not by consumer lawsuits.

Sources
  1. California Legislative Information — Civil Code § 1798.100 et seq. (CCPA)
  2. California Privacy Protection Agency — CCPA Regulations
  3. California Privacy Protection Agency — About the CPPA
  4. California Attorney General — California Consumer Privacy Act (CCPA)
  5. Cal. Civ. Code § 1798.140 — Definitions (Justia)