Glossary of Compliance

Compliance Glossary

Our list of curated compliance glossary offers everything you to know about compliance in one place.

Glossary » CCPA » CCPA Data Subject Rights

CCPA Data Subject Rights

The California Consumer Privacy Act establishes a set of fundamental rights for the residents of California, known as data subjects concerning their personal information. These rights empower consumers with greater control over their data and increase transparency in how businesses handle their personal information. 

The key Data Subject Rights under the CCPA are:

Right to know: Consumers have the right to request that businesses disclose the categories and specific pieces of personal information collected about them, the sources of that information, the purpose for collecting or selling the information, and the categories of third parties with whom the information is shared. 

Right to delete: Consumers can request the deletion of their personal information collected by businesses, subject to certain exceptions such as completing transactions, detecting security incidents, or complying with legal obligations. 

Right to opt-out: Consumers have the right to direct businesses not to sell their personal information to third parties. Businesses must provide a clear and conspicuous “Do Not Sell My Personal Information” link on their website homepage to facilitate this right.

Right to non-discrimination: Businesses are prohibited from discriminating against consumers who exercise their CCPA rights. This includes denying goods or services, charging different prices, or providing a different quality of goods or services.

Right to access: Consumers can request access to their personal information free of charge, delivered by mail or electronically in a readily usable format that allows the consumer to transmit this information to another entity without hindrance.

Right to correct: Consumers have the right to correct inaccurate personal information that a business has about them.

Right to limit use:  Consumers have the right to limit the use and disclosure of sensitive personal information collected about them.

These Data Subject rights form the core of the CCPA’s consumer protection and aims to promote transparency, control, and accountability in the handling of personal information by businesses.

Additional reading

Cloud Data Loss Prevention: Challenges & Best Practices

TL,DR: Cloud DLP is a cybersecurity strategy protecting sensitive data from malicious attacks, accidental disclosure, or unauthorized transfer by detecting, classifying, and applying protection controls across cloud repositories DLP uses data transformation techniques including masking, encryption, and tokenization to reduce exposure risks while maintaining usability for authorized users Gartner forecast cloud spending to increase 20.7%…

Tugboat vs Secureframe: Features, Pricing, and the Better Fit for Your Business 2026

Compliance tools aren’t created equal. Tugboat Logic and Secureframe both promise faster audits and smoother certification, but that’s where the similarities end. Tugboat Logic favors a guided, step-by-step approach ideal for managing multiple frameworks. Secureframe is all about speed, using automation and real-time monitoring to get you audit-ready fast. In this comparison, we break down…

ISO 27001 Audit Checklist: 5 Steps to Certification

TL,DR: An ISO 27001 audit checklist verifies whether your ISMS meets certification requirements. Preparation includes risk assessment, control mapping, evidence collection, policy review, and management review. The article covers internal audits, certification audits, surveillance audits, and five checklist steps. Preparing for an ISO 27001 audit can feel chaotic. You’re left rushing through control tests, patching…

Sprinto: Your growth superpower

Use Sprinto to centralize security compliance management – so nothing
gets in the way of your moving up and winning big.