If you want to see what a California business has collected about you, submit a California Consumer Privacy Act (CCPA) right-to-know request to that business. Use the privacy form, email address, phone number, or dashboard listed in its current privacy policy. You can ask for the categories of information it collected and, when you need a closer look, the specific pieces linked to you.
A covered business generally must confirm receipt within 10 business days and respond within 45 calendar days. When reasonably necessary, it can extend the response period by up to 45 more days, but it must tell you about the extension. Keep the request, verification messages, and response so you can establish when the process began.
The CCPA doesn't cover every company. A request sent to one business also doesn't automatically reach its advertising partners, data brokers, payment processors, or other organizations.
What a California data access request can provide
California law commonly calls this the right to know. Depending on the request and the verification process, you can ask a covered business for:
- The categories of personal information it collected about you
- The specific pieces of personal information it collected about you, subject to verification and legal exceptions
- The categories of sources from which it obtained the information
- The business or commercial purposes for collecting, using, selling, or sharing it
- The categories of third parties to which it disclosed, sold, or shared the information
- Whether it sold or shared your personal information and, where applicable, the categories involved
Personal information can include identifiers, account details, purchase records, browsing or device information, location information, and inferences. What applies depends on what the business collects and whether the CCPA covers that information.
An account download may help, but it isn't always the same as a formal privacy response. If you want information from a retailer, social network, data broker, and financial app, you'll generally need to contact each organization separately.
The California Privacy Protection Agency consumer FAQ describes the right to know and related California privacy rights.
Who can use the CCPA request process?
The CCPA applies only when the consumer, business, and information fall within the law's scope. Coverage can depend on a business's legal status, revenue, business model, or the amount and type of personal information it processes. Some organizations and types of information are exempt.
In practice:
- A website serving California isn't automatically covered just because it has California visitors.
- A company outside the CCPA's scope may still accept a privacy request as a matter of policy.
- A multinational company's GDPR form doesn't automatically give a California consumer a one-month response deadline.
- The CCPA rules here aren't universal rules for every U.S. state.
If you don't live in California, check your state's privacy law and the company's policy before relying on the 45-day timeline.
How to submit a right-to-know request
1. Identify the business that holds the information
Send the request to the company that operates the account, service, or transaction. Use the legal or brand name shown in the privacy policy, account settings, receipts, or customer-support records.
Don't send it to a search engine, app store, or regulator simply because that organization hosts or lists the service. The request should go to the business that collects the information.
2. Find the company's privacy-request channel
Check the current privacy policy for headings such as:
- California privacy rights
- Do not sell or share my personal information
- Submit a privacy request
- Privacy choices
- Consumer requests
- Contact the privacy team
A business may provide a web form, email address, toll-free phone number, or privacy dashboard. The California official privacy-request guidance describes these options and notes that data brokers can collect information even when you haven't dealt with them directly.
Use the company's current official channel, not an address copied from an old article. A large platform may offer both an account download and a separate form for privacy-rights requests.
3. State what you want
Before submitting the form, decide whether you want categories, specific pieces, or both. Include enough information to help the business locate the right account:
- The account email, phone number, username, or customer number connected with you
- The products or services involved
- A time period, if you want information tied to a particular account or activity
- Whether you're asking for categories, specific pieces, or both
A right-to-know request doesn't delete information or stop future collection. If you want to stop the sale or sharing of personal information, make an opt-out request. If you want eligible information erased, submit a deletion request instead.
4. Provide only reasonable verification information
The business can take reasonable steps to confirm that you are the person connected with the information. The method may differ depending on whether you have an account and how sensitive the requested information is.
A full government ID isn't automatically required. Start with the account or contact details the business already has and ask how it wants any additional verification submitted. If an ID is genuinely needed, use a secure upload portal where possible. Never include a password, full payment-card number, or unnecessary Social Security number in an email.
If the business asks for more information than seems necessary, ask what it is verifying and whether a less sensitive alternative is available. Keep a copy of that exchange.
Right-to-know request template
Adapt this message to the company's form or email channel:
Subject: California CCPA Right-to-Know Request
I am a California resident and am requesting to know what personal information [Business name] has collected about me.
Please provide:
- The categories of personal information collected
- The specific pieces of personal information associated with my account or identifiers
- The categories of sources
- The business or commercial purposes for collecting, using, selling, or sharing the information
- The categories of third parties to which my information was disclosed, sold, or shared
My identifying details are:
- Name: [name]
- Account email or username: [details]
- Phone number or customer number: [details]
Please confirm receipt and tell me what information you reasonably need to verify my identity. If you withhold any portion of the requested information, please identify the portion withheld and the general reason.
Please send the response through [secure portal or preferred method].
Sincerely,
[name]
[date]
Don't claim California residency if it isn't true. When using a form, fill in only the fields needed to match the account.
CCPA response deadlines and costs
| Stage | General expectation |
|---|---|
| Receipt confirmation | Within 10 business days |
| Substantive response | Within 45 calendar days |
| Possible extension | Up to 45 additional calendar days when reasonably necessary, with notice |
| Ordinary request fee | Generally free |
An acknowledgment email isn't the final response unless it provides the requested information or explains a lawful limitation.
Record the date and time you submit the request. For a web form, save the confirmation screen. For email, retain the sent message and any automated reply. For postal mail, keep delivery tracking.
If the company asks for verification, respond promptly and preserve the exchange. If it says more time is needed, check whether it gives a reason and a revised response date.
How to review the company's response
Compare the response with the request you sent, not just with the company's general privacy policy. Look for:
- The categories of personal information requested
- The sources and purposes
- The relevant categories of recipients
- Specific pieces of information, if you requested them and completed verification
- A clear explanation for anything the business did not provide
A partial response isn't automatically improper. A business may redact or withhold information when disclosure would reveal another person's private information, create a security risk, or fall within another legal exception. It may also be unable to provide information if it can't reasonably verify your identity or doesn't hold the information.
If something is missing, write back with a specific question rather than sending the entire request again. For example:
I received your response dated [date], but it does not address the categories of sources or third parties requested on [submission date]. Please confirm whether those categories were searched and, if not provided, explain the applicable reason.
Don't ask one company to produce data held solely by another. Send a separate request to the organization that controls the relevant account, transaction, or service.
Why a business may deny or redact information
Common explanations include:
- The business couldn't reasonably verify the request
- The information isn't held by that business
- A legal exception protects another person's information
- Disclosure could create a security, fraud, or legal-privilege problem
- The organization or information is outside the CCPA's scope
Ask whether the business can provide non-exempt portions and request the general basis for its decision. Keep the response in case you later contact a regulator.
Businesses should also protect information belonging to other people. For example, a response might remove another person's contact details from a message thread rather than disclose the entire record.
What to do if the business misses the deadline
An unanswered request isn't automatically a denial. Follow up in writing:
- State the submission date, account identifier, and original 45-day deadline. Note any extension notice the company sent.
- Ask whether the request is awaiting verification, has been extended, or has been closed.
- Request the missing information or a written explanation for any denial.
- Save the privacy policy in effect when you submitted the request, along with emails, screenshots, and attachments.
- If the issue remains unresolved, review the current complaint instructions from the California Privacy Protection Agency.
A regulatory complaint may help bring the issue to the agency's attention, but it isn't an instant data-delivery service and doesn't guarantee individual compensation.
If the company made a specific privacy promise and appears not to have honored it, the FTC's privacy and security guidance says that a participating company's failure to comply with the Principles may violate Section 5 of the FTC Act's prohibition on unfair or deceptive acts. That's a separate consumer-protection issue, not a replacement for sending the CCPA request.
Right to know, deletion, correction, and opt-out are different
Choose the request that matches your goal:
- Right to know: Find out what personal information a business collected, where it came from, why it is used, and which categories of organizations received it.
- Right to delete: Ask the business to erase eligible personal information, subject to exceptions.
- Right to correct: Ask the business to correct inaccurate information.
- Right to opt out: Tell the business not to sell or share personal information where the law gives you that choice.
California's Global Privacy Control can communicate certain opt-out choices through a user-enabled browser or device signal. It isn't a substitute for a right-to-know request.
The state's CCPA guidance from the Attorney General covers these rights and the Global Privacy Control. Read the company's instructions carefully before selecting a request type.
Data brokers and California's DROP tool
Data brokers may hold information about you even if you never knowingly opened an account with them. California's official privacy guidance describes DROP as a way to submit a deletion request to registered data brokers.
DROP isn't an access report for every company. It doesn't replace a right-to-know request to a retailer, app, employer, or platform where you have an account. If you want to see what a particular business has about you, contact that business directly. You may also need a separate request for each organization whose records you want to access.
Common questions
Can I submit a request by email?
Yes, if the business lists email as an available privacy-request method. A web form, phone number, or privacy dashboard may also be appropriate. Keep proof of submission and don't use an unverified address from a third-party website.
Do I have to send a government ID?
Not automatically. The business may request information reasonably needed to verify your identity, but the appropriate method depends on the account and the sensitivity of the information. Ask for a secure upload method and provide the minimum necessary information.
Does a data request make the company delete my information?
No. Access, deletion, correction, and opt-out requests are separate. State the action you want and submit the corresponding request.
What if I live outside California?
Don't assume the CCPA applies or that the 45-day deadline controls. Check your state's privacy rules and the company's privacy policy. A company may offer a voluntary request channel even when a particular law doesn't require it.
Is this legal advice?
No. This is general consumer information. For a dispute involving sensitive information, employment, identity theft, or significant financial harm, consider obtaining advice from a qualified professional.
Before you submit the request, open the company's current privacy policy, screenshot the privacy-request instructions, and note the date and channel you use. Send only the account details needed for verification.