Under the CCPA as amended by the CPRA, an analytics team wants to keep raw clickstream forever — what do the data minimisation and retention rules require?
answer
- purpose first, then data
- reasonably necessary and proportionate
- the consumer's reasonable expectations
- a disclosed period per category
- 1798.100(c) and 11 CCR 7002
basics
~20 sUnder the CCPA as amended by the CPRA, collecting, using and keeping data must be reasonably necessary and proportionate to a disclosed or compatible purpose (Civil Code 1798.100(c)), with each category's retention disclosed and no longer than that purpose needs (1798.100(a)(3)).
solid answer
~40 sCivil Code 1798.100(c) requires a business's collection, use, retention and sharing to be **reasonably necessary and proportionate** to the purpose it was collected for, or another **disclosed purpose compatible with the context**. 11 CCR 7002 makes that testable: the purpose must match the consumer's **reasonable expectations**, and necessity weighs the **minimum data needed**, the **possible negative impacts** and the **safeguards** in place. Retention is a disclosed commitment: the notice at collection states a period per category, or the criteria, and the business may not keep data **longer than reasonably necessary** for each disclosed purpose (1798.100(a)(3)). "Forever" is neither a period nor a criterion. The answer is to name the purposes, set a retention per purpose, and aggregate or deidentify beyond it. A purpose that fails 7002(a) needs consent (7002(e)).
go deeper
Recall that the CPRA added a necessity and proportionality rule for collection, use, retention and sharing, and that retention per category must be disclosed.
Explain the 7002 factors: reasonable expectations, compatibility of a new purpose, minimum data, negative impacts and safeguards.
Turn 'keep it forever' into purposes with retention windows, aggregation and deletion, and show how you would evidence each decision.
Set the retention and deidentification standard as a platform default, so individual teams cannot quietly accumulate data with no purpose.
## The rule in the statute The CPRA wrote a **data minimisation and purpose limitation** principle into the CCPA. Civil Code **1798.100(c)** says a business's collection, use, retention and sharing of a consumer's personal information *shall be reasonably necessary and proportionate* to achieve either: - the purposes for which it was collected or processed, or - another **disclosed purpose** that is **compatible with the context** in which it was collected, and it may not be further processed in a way incompatible with those purposes. Retention is tied to the same idea from the notice side: **1798.100(a)(3)** requires the notice at collection to state how long each category will be kept, or the criteria used, and forbids keeping personal information for each disclosed purpose **longer than is reasonably necessary** for that purpose. ## How the regulations make it testable 11 CCR **7002** breaks the statute into three questions. | Question | What decides it | Source | |---|---|---| | Is the purpose legitimate for this data? | the consumer's **reasonable expectations**: the relationship, the type and amount of data, the source and method of collection, how clearly the purpose was disclosed, and how visible any service providers or third parties are | 7002(b) | | Is another purpose compatible? | those expectations at the time of collection, the new purpose (including whether it is a statutory business purpose), and the **strength of the link** between them | 7002(c) | | Is the processing necessary and proportionate? | the **minimum personal information** needed, the **possible negative impacts** on consumers, and **additional safeguards** such as encryption or automatic deletion | 7002(d) | Where a purpose fails 7002(a), the business must obtain **consent** under 11 CCR 7004 before processing for it (7002(e)), and even consented processing must be necessary and proportionate (7002(d)). Collecting new categories, or using data for incompatible purposes, also needs a **new notice at collection** (7002(f)). The regulation's own examples show the shape of the test: using data to **repair errors** that impair the requested service has a strong link to what the consumer expected; using cloud-storage data to research an **unrelated facial recognition** product has a weak one. ## Retention is a disclosed number Because 1798.100(a)(3) requires a period or criteria per category, retention becomes something a business publishes and can be held to. Two consequences: 1. A retention statement has to be **specific per category**: "as long as necessary" with no criteria does not tell the consumer anything. 2. The disclosed period itself must pass the necessity test; disclosing a long period does not make keeping data that long lawful. ## Applying it to "keep raw clickstream forever" Raw clickstream keyed to a device or account identifier is personal information: online identifiers and internet activity are listed categories in Civil Code 1798.140(v)(1)(A) and (F). The team's request fails on three counts: - **No purpose.** "It might be useful" is not a purpose disclosed to the consumer. - **No proportionality.** Most analytic questions need sessions, funnels or aggregates, not every raw event with its identifier, indefinitely. - **No disclosable retention.** "Forever" cannot be stated as a period that is reasonably necessary for any named purpose. A defensible design instead: 1. Name the purposes, for example product analytics, debugging, and security and integrity. 2. Give each a retention: raw events for a short debugging and security window; longer only in aggregated form. 3. Aggregate or **deidentify** past that window, then delete the raw events. 4. Publish the per-category retention in the notice at collection and keep the privacy policy consistent. 5. Treat any new use, such as training a model for an unrelated product, as a new purpose that needs a compatibility analysis and possibly a new notice and consent. ## Deidentified and aggregate data Information that is **deidentified** under Civil Code 1798.140(m) is outside the CCPA's definition of personal information, but only if the business takes reasonable measures against re-association, **publicly commits** not to re-identify, and **contractually binds recipients** to the same. Swapping a device ID for a hashed device ID that still links events to one person does not meet that bar. ## Mistakes interviewers listen for - Treating minimisation as a collection-time rule only, when 1798.100(c) covers use, retention and sharing. - Believing any purpose written into a privacy policy is automatically allowed. - Confusing pseudonymised event data with deidentified data.
- Under the CCPA regulations, the team says raw clickstream may help a future machine-learning product. Does that justify keeping it?No. A speculative future use is not a purpose disclosed at collection. It must pass the compatibility test of 11 CCR 7002(c), and the regulation's weak-link example (storage data reused for an unrelated facial-recognition product) points against it. If it fails, 7002(e) requires consent and 7002(f) a new notice.
- Under the CCPA, does hashing the device identifier take the clickstream outside these rules?Not by itself. Data escapes only if it is **deidentified** under Civil Code 1798.140(m): it cannot reasonably be linked to a consumer, and the business takes reasonable measures, publicly commits not to re-identify, and contractually binds recipients. A stable hash that still links one person's events remains personal information.
- Under the CCPA regulations, is using clickstream to fix a bug that breaks checkout a compatible purpose?Yes, in the regulation's own terms: 11 CCR 7002(c)(3) calls repairing errors that impair the intended functionality of the requested service a **strong link** to the consumer's expectations, and debugging is a listed business purpose in 1798.140(e)(3). The data used must still be necessary and proportionate.
saying these in an interview costs you the question
- Stating 'we retain data indefinitely' satisfies the CCPA retention disclosure.
- CCPA data minimisation governs collection only, not retention or use.
- Any purpose listed in the privacy policy is automatically permitted.
- Clickstream keyed by a device ID is not personal information.
- The CCPA's minimisation rules apply only to sensitive personal information.