Privacy Rights & Law
The rights and rules that decide what happens to your data, from GDPR to CCPA.
- CCPA (California Consumer Privacy Act)
-
California's baseline privacy law, in force since 2020, giving residents the right to know, delete, correct, and opt out of the sale or sharing of their personal information. The text is Civil Code Title 1.81.5.
It binds only businesses over a threshold: $25 million in gross revenue, or handling the personal information of 100,000 consumers or households, or drawing half their revenue from selling it. Most data brokers clear the last two comfortably. Enforcement is public, though. You can sue on your own behalf only over a breach caused by unreasonable security, at $100 to $750 per incident.
Full explainer: Why Is There No Federal Privacy Law in the US? The Two Disputes That Kill Every Bill, and the Money Behind Them →
- CPRA (California Privacy Rights Act)
-
The ballot measure that rewrote the CCPA rather than replacing it. Voters approved Proposition 24 on 3 November 2020, and its changes became operative on 1 January 2023.
It introduced the sensitive personal information category and the right to correct, and it built an enforcer: the California Privacy Protection Agency, a five-member board that writes the regulations and brings its own actions instead of leaving everything to the Attorney General. That agency now also runs the Delete Act's broker registry and the deletion portal behind it.
- Data Controller
-
The party that determines the purposes and means of processing personal data, in the language of GDPR Article 4(7). Two organisations can hold the role jointly.
Control follows decisions rather than contract wording, which is why the ICO asks who actually chose the purpose. A people search site that picks what to scrape, how to merge it and who may buy the result is a controller in its own right, not a processor working for its sources. Your deletion request goes to that site, not up its supply chain.
- Data Processor
-
A person or body that processes personal data on behalf of a controller, under GDPR Article 4(8), without deciding why the processing happens.
The arrangement has to be written down. Article 28 requires a binding contract covering the subject matter, duration and purpose of the work, and a processor that starts choosing purposes for itself becomes a controller for that activity whatever the paperwork says. Brokers sometimes claim processor status to send removal requests elsewhere; the question to ask is who decided what to collect.
- Data Subject
-
The identified or identifiable living person that personal data is about. GDPR Article 4(1) counts anyone who can be picked out directly or indirectly.
American law does not use the phrase. California's nearest equivalent, the consumer of Civil Code § 1798.140(i), is narrower in one respect and wider in another: it reaches only California residents, while its personal information covers households as well as individuals. Which word a broker's privacy policy reaches for is a fair hint at the regime it thinks applies to you.
- Data Subject Access Request (DSAR / DSR)
-
A formal request asking an organisation to confirm what personal data it holds about you and hand over a copy, usually made under GDPR Article 15. DSAR and SAR mean the same thing, and a request need not use either label to count.
The clock is the part worth knowing. Article 12(3) gives a controller one month to act, extendable by two further months where the request is complex, and California runs its own 45-day timetable. Brokers commonly answer with a verification demand instead of data, which in practice restarts the wait.
- De-identified / Anonymized Data
-
Data altered so it cannot reasonably be used to infer anything about, or be linked to, a particular person. California sets the standard at Civil Code § 1798.140(m).
De-identified and anonymous are not synonyms, and which one applies decides whether any law still does. Under GDPR Recital 26 genuinely anonymous data falls outside the regulation altogether. California keeps de-identified data in scope and attaches three continuing duties: reasonable measures against re-association, a public commitment never to re-identify, and contracts binding every recipient to the same terms.
- GDPR (General Data Protection Regulation)
-
Europe's data protection regulation, applicable since May 2018 and kept in British law after Brexit, where the ICO enforces it. It grants rights of access, correction, erasure and portability over your personal data.
Its reach is what makes it matter beyond Europe, because the rules follow the person: a company targeting or monitoring people in the EU is covered wherever it sits. Article 83 caps fines at 20 million euro or 4 percent of worldwide annual turnover, whichever is higher. A US resident writing to a US broker has no standing under it; the CCPA is the lever that works.
- Opt-In
-
A consent model that requires you to agree before processing starts. GDPR Article 4(11) sets the bar: freely given, specific, informed, and unambiguous.
Silence does not qualify, and neither does a pre-ticked box, because the article wants a statement or clear affirmative action. Article 7 adds that withdrawing consent must be as easy as giving it. American privacy law mostly runs the other way round, on opt-out, which is why a broker can list you without ever having asked, and why the work of finding the listing falls to you.
- Opt-Out
-
Telling a business to stop a data practice it has already started. The Californian version, Civil Code § 1798.120, covers the sale or sharing of your personal information.
Opting out is not the same as deletion. The business keeps what it holds and simply stops passing it on, so a people search site profile can stay up after a successful opt-out unless you also ask for removal. Both requests are worth making, and on broker sites the opt-out request is usually the one with a working form behind it.
- Personal Data / Personal Information
-
Any information that identifies, relates to, or could reasonably be linked to a particular consumer or household, in the words of Civil Code § 1798.140(v)(1). Names, addresses, device identifiers and location history all count.
That last word, household, is what makes the California definition wider than Europe's, since GDPR Article 4(1) reaches an identified or identifiable natural person and stops there. The gap matters when you file removals: a people search site profile listing your relatives and former addresses is personal information about you in California even when no single field on it names you.
- Personally Identifiable Information (PII)
-
Information that distinguishes or traces an individual's identity, either on its own or combined with other data. The most-cited American definition, NIST SP 800-122, was written as guidance for federal agencies.
No single US law owns the term. GLBA, HIPAA, FERPA and fifty state breach statutes each draw the boundary somewhere different, so PII and personal information are not interchangeable even though people swap them freely. California avoids "PII" for exactly that reason. The narrow reading is the one brokers reach for, arguing that an address with no name attached identifies nobody.
- Right to Access / Right to Know
-
The right to make an organisation tell you what personal information it holds about you. California sets it out at Civil Code § 1798.110, and Europe at GDPR Article 15.
What comes back differs. Article 15 entitles you to a copy of the data itself, while section 1798.110 entitles you to the categories collected, the sources they came from, the purpose, and the third parties they went to, with the specific pieces available on request. For a removal the categories-and-sources answer is usually worth more, because it names the aggregator upstream that will refill the listing.
- Right to Be Forgotten
-
The popular name for the erasure right at GDPR Article 17, which applies when data is no longer needed, consent is withdrawn, or it was processed unlawfully.
The phrase is not really statutory. It appears in that article's heading, in brackets, and nowhere in its text. What most people mean by it is the search-engine delisting the Court of Justice recognised in its 2014 Google Spain judgment, which is narrower again: it hides results for a name without touching the page behind them. American law has no counterpart, so the right to delete is the nearest thing on offer.
Full explainer: Why Is There No Federal Privacy Law in the US? The Two Disputes That Kill Every Bill, and the Money Behind Them →
- Right to Correct (Rectify)
-
A right to have inaccurate personal information about you fixed. California added it at Civil Code § 1798.106; Europe has carried the equivalent at GDPR Article 16 from the start.
On broker sites this right has more to do than anywhere else, since wrong ages, addresses you never lived at and relatives who are not yours are routine. There is a catch worth weighing first: correcting a listing confirms that the rest of it describes you. Where the aim is removal rather than accuracy, opt out first and correct only what survives.
- Right to Delete (Erasure)
-
California's version of erasure, at Civil Code § 1798.105: a business must delete personal information it holds about you on request, subject to exceptions for security, legal obligations and finishing a transaction you asked for.
Read the first line closely. The section reaches information the business collected from the consumer, which is an awkward fit for a broker that assembled a profile about you out of public records and purchases from other brokers. That gap is part of why California built a separate deletion route for registered brokers. Re-listing is the other reason one deletion rarely settles anything.
- Sale of Personal Information
-
Handing a consumer's personal information to a third party for money or, in the words of Civil Code § 1798.140(ad), for other valuable consideration.
Those last three words do the work. A company that swaps data for analytics credit or ad placement rather than cash has still sold it, which is how so many "we do not sell your data" claims fall apart on inspection. California fined Sephora $1.2 million in 2022 for exactly that mismatch. A sale is what turns on your opt-out right, so the definition decides whether you have one.
- Sensitive Personal Information / Special Category Data
-
The higher-risk subset of personal information listed at Civil Code § 1798.140(ae): Social Security and passport numbers, account credentials, precise geolocation, racial or ethnic origin, genetic data, message contents, and health or sex life.
California added neural data to that list in 2024. Europe treats the same categories more strictly: GDPR Article 9 prohibits processing special-category data unless a listed exemption applies, where California grants only a right to limit its use. Precise geolocation is the entry that matters most for removals, because it is the field data brokers resell most readily.
- Sharing (Cross-Context Behavioral Advertising)
-
Passing personal information to a third party for advertising targeted at you using your activity across other sites, defined at Civil Code § 1798.140(ah) and (k).
The category exists because of an argument companies kept winning. Handing data to an ad network brought no money in, so they said no sale had happened. Sharing closes that off: it counts whether or not anything of value changes hands. One opt-out link covers both, which is why the required wording is "Do Not Sell or Share My Personal Information" rather than the shorter phrase people still use.
Where to go next