If you want to see what a California business has collected about you, submit a California Consumer Privacy Act (CCPA) right-to-know request to that business. Use the privacy form, email address, phone number, or dashboard listed in its current privacy policy. You can ask for the categories of information it collected and, when you need a closer look, the specific pieces linked to you.

A covered business generally must confirm receipt within 10 business days and respond within 45 calendar days. When reasonably necessary, it can extend the response period by up to 45 more days, but it must tell you about the extension. Keep the request, verification messages, and response so you can establish when the process began.

The CCPA doesn't cover every company. A request sent to one business also doesn't automatically reach its advertising partners, data brokers, payment processors, or other organizations.

What a California data access request can provide

California law commonly calls this the right to know. Depending on the request and the verification process, you can ask a covered business for:

Personal information can include identifiers, account details, purchase records, browsing or device information, location information, and inferences. What applies depends on what the business collects and whether the CCPA covers that information.

An account download may help, but it isn't always the same as a formal privacy response. If you want information from a retailer, social network, data broker, and financial app, you'll generally need to contact each organization separately.

The California Privacy Protection Agency consumer FAQ describes the right to know and related California privacy rights.

Who can use the CCPA request process?

The CCPA applies only when the consumer, business, and information fall within the law's scope. Coverage can depend on a business's legal status, revenue, business model, or the amount and type of personal information it processes. Some organizations and types of information are exempt.

In practice:

If you don't live in California, check your state's privacy law and the company's policy before relying on the 45-day timeline.

How to submit a right-to-know request

1. Identify the business that holds the information

Send the request to the company that operates the account, service, or transaction. Use the legal or brand name shown in the privacy policy, account settings, receipts, or customer-support records.

Don't send it to a search engine, app store, or regulator simply because that organization hosts or lists the service. The request should go to the business that collects the information.

2. Find the company's privacy-request channel

Check the current privacy policy for headings such as:

A business may provide a web form, email address, toll-free phone number, or privacy dashboard. The California official privacy-request guidance describes these options and notes that data brokers can collect information even when you haven't dealt with them directly.

Use the company's current official channel, not an address copied from an old article. A large platform may offer both an account download and a separate form for privacy-rights requests.

3. State what you want

Before submitting the form, decide whether you want categories, specific pieces, or both. Include enough information to help the business locate the right account:

A right-to-know request doesn't delete information or stop future collection. If you want to stop the sale or sharing of personal information, make an opt-out request. If you want eligible information erased, submit a deletion request instead.

4. Provide only reasonable verification information

The business can take reasonable steps to confirm that you are the person connected with the information. The method may differ depending on whether you have an account and how sensitive the requested information is.

A full government ID isn't automatically required. Start with the account or contact details the business already has and ask how it wants any additional verification submitted. If an ID is genuinely needed, use a secure upload portal where possible. Never include a password, full payment-card number, or unnecessary Social Security number in an email.

If the business asks for more information than seems necessary, ask what it is verifying and whether a less sensitive alternative is available. Keep a copy of that exchange.

Right-to-know request template

Adapt this message to the company's form or email channel:

Subject: California CCPA Right-to-Know Request

I am a California resident and am requesting to know what personal information [Business name] has collected about me.

Please provide:

  • The categories of personal information collected
  • The specific pieces of personal information associated with my account or identifiers
  • The categories of sources
  • The business or commercial purposes for collecting, using, selling, or sharing the information
  • The categories of third parties to which my information was disclosed, sold, or shared

My identifying details are:

  • Name: [name]
  • Account email or username: [details]
  • Phone number or customer number: [details]

Please confirm receipt and tell me what information you reasonably need to verify my identity. If you withhold any portion of the requested information, please identify the portion withheld and the general reason.

Please send the response through [secure portal or preferred method].

Sincerely,
[name]
[date]

Don't claim California residency if it isn't true. When using a form, fill in only the fields needed to match the account.

CCPA response deadlines and costs

Stage General expectation
Receipt confirmation Within 10 business days
Substantive response Within 45 calendar days
Possible extension Up to 45 additional calendar days when reasonably necessary, with notice
Ordinary request fee Generally free

An acknowledgment email isn't the final response unless it provides the requested information or explains a lawful limitation.

Record the date and time you submit the request. For a web form, save the confirmation screen. For email, retain the sent message and any automated reply. For postal mail, keep delivery tracking.

If the company asks for verification, respond promptly and preserve the exchange. If it says more time is needed, check whether it gives a reason and a revised response date.

How to review the company's response

Compare the response with the request you sent, not just with the company's general privacy policy. Look for:

A partial response isn't automatically improper. A business may redact or withhold information when disclosure would reveal another person's private information, create a security risk, or fall within another legal exception. It may also be unable to provide information if it can't reasonably verify your identity or doesn't hold the information.

If something is missing, write back with a specific question rather than sending the entire request again. For example:

I received your response dated [date], but it does not address the categories of sources or third parties requested on [submission date]. Please confirm whether those categories were searched and, if not provided, explain the applicable reason.

Don't ask one company to produce data held solely by another. Send a separate request to the organization that controls the relevant account, transaction, or service.

Why a business may deny or redact information

Common explanations include:

Ask whether the business can provide non-exempt portions and request the general basis for its decision. Keep the response in case you later contact a regulator.

Businesses should also protect information belonging to other people. For example, a response might remove another person's contact details from a message thread rather than disclose the entire record.

What to do if the business misses the deadline

An unanswered request isn't automatically a denial. Follow up in writing:

  1. State the submission date, account identifier, and original 45-day deadline. Note any extension notice the company sent.
  2. Ask whether the request is awaiting verification, has been extended, or has been closed.
  3. Request the missing information or a written explanation for any denial.
  4. Save the privacy policy in effect when you submitted the request, along with emails, screenshots, and attachments.
  5. If the issue remains unresolved, review the current complaint instructions from the California Privacy Protection Agency.

A regulatory complaint may help bring the issue to the agency's attention, but it isn't an instant data-delivery service and doesn't guarantee individual compensation.

If the company made a specific privacy promise and appears not to have honored it, the FTC's privacy and security guidance says that a participating company's failure to comply with the Principles may violate Section 5 of the FTC Act's prohibition on unfair or deceptive acts. That's a separate consumer-protection issue, not a replacement for sending the CCPA request.

Right to know, deletion, correction, and opt-out are different

Choose the request that matches your goal:

California's Global Privacy Control can communicate certain opt-out choices through a user-enabled browser or device signal. It isn't a substitute for a right-to-know request.

The state's CCPA guidance from the Attorney General covers these rights and the Global Privacy Control. Read the company's instructions carefully before selecting a request type.

Data brokers and California's DROP tool

Data brokers may hold information about you even if you never knowingly opened an account with them. California's official privacy guidance describes DROP as a way to submit a deletion request to registered data brokers.

DROP isn't an access report for every company. It doesn't replace a right-to-know request to a retailer, app, employer, or platform where you have an account. If you want to see what a particular business has about you, contact that business directly. You may also need a separate request for each organization whose records you want to access.

Common questions

Can I submit a request by email?

Yes, if the business lists email as an available privacy-request method. A web form, phone number, or privacy dashboard may also be appropriate. Keep proof of submission and don't use an unverified address from a third-party website.

Do I have to send a government ID?

Not automatically. The business may request information reasonably needed to verify your identity, but the appropriate method depends on the account and the sensitivity of the information. Ask for a secure upload method and provide the minimum necessary information.

Does a data request make the company delete my information?

No. Access, deletion, correction, and opt-out requests are separate. State the action you want and submit the corresponding request.

What if I live outside California?

Don't assume the CCPA applies or that the 45-day deadline controls. Check your state's privacy rules and the company's privacy policy. A company may offer a voluntary request channel even when a particular law doesn't require it.

Is this legal advice?

No. This is general consumer information. For a dispute involving sensitive information, employment, identity theft, or significant financial harm, consider obtaining advice from a qualified professional.

Before you submit the request, open the company's current privacy policy, screenshot the privacy-request instructions, and note the date and channel you use. Send only the account details needed for verification.