skip to content

Under the CCPA, a retail app sends users' precise location to an ad network — what does the right to limit sensitive personal information add?

level: middleimportance: should knowfreq 38%

answer

  1. a radius in feet
  2. sensitive, not ordinary
  3. what an average consumer expects
  4. a second link or one combined
  5. 15 business days again

basics

~20 s

Precise geolocation is sensitive personal information under Civil Code 1798.140(ae), so besides the opt-out of sharing, 1798.121 lets users limit its use to what an average consumer expects for the service and other permitted purposes.

solid answer

~50 s

Sending location to an ad network for targeting elsewhere is **sharing**, and a sale if paid, so the opt-out applies. But **precise geolocation**, data locating a consumer within a circle of **1,850 feet** radius (`1798.140(w)`), is also **sensitive personal information** (`1798.140(ae)`). Civil Code `1798.121` lets a consumer direct the business to **limit** its use to what is necessary to provide the goods or services an average consumer would reasonably expect, plus listed purposes such as security, safety, short-term transient use and services on the business's behalf. A business using sensitive data beyond those purposes must offer a **'Limit the Use of My Sensitive Personal Information'** link or the combined link (`1798.135(a)`). The CCPA regulations (11 CCR 7027) require compliance within **15 business days**, notice to service providers, contractors and third parties, and a **12-month** wait before asking again. Sensitive data not processed to infer characteristics is outside the right.

go deeper

for a junior

Recall that precise geolocation is sensitive personal information under the CCPA and that consumers can limit its use, separately from opting out of sharing.

for a middle

Explain the 1,850-foot definition, the average-consumer-expectation standard in 1798.121, and what the Limit link and the 15-business-day deadline require.

for a senior

Show how you would split location uses into permitted and limitable, propagate a limit request to service providers and third parties, and evidence it.

for a principal

Decide whether location-based marketing is worth the Limit link and the programme behind it, or whether to confine location to permitted purposes and skip it.

## Two rights, one data flow Under the CCPA as amended by the CPRA, a retail app that sends users' location to an ad network so that they can be targeted in other apps engages two separate rights: 1. **The opt-out of sale and sharing** (`1798.120`): disclosure to a third party for cross-context behavioural advertising is sharing, whether paid or not. 2. **The right to limit** (`1798.121`): because the data is **sensitive personal information**, the consumer can also restrict how the business itself **uses and discloses** it. ## Why location is sensitive `1798.140(w)` defines **precise geolocation** as data derived from a device and used, or intended to be used, to locate a consumer within an area **equal to or less than a circle with a radius of 1,850 feet**, except as regulations prescribe. `1798.140(ae)(1)(C)` lists a consumer's precise geolocation as **sensitive personal information**, alongside government identifiers, account credentials, racial or ethnic origin, religious beliefs, union membership, message contents, genetic and neural data, biometric processing for identification, and health and sex-life information. ## What the right to limit allows Under `1798.121(a)`, the consumer may direct the business to limit its use of sensitive personal information to: - what is **necessary to perform the services or provide the goods reasonably expected by an average consumer** who requests them; - certain business purposes listed in `1798.140(e)`: security and integrity, short-term transient use, performing services on the business's behalf, and quality and safety of its own products; - uses authorised by regulation. The CCPA regulations list those permitted purposes in 11 CCR 7027(m), with examples. A navigation feature may use precise location to give directions; a gaming app, whose average user would not expect it to need location, may not. | Use of the precise location | Permitted after a request to limit? | |---|---| | Directions to the store the user asked to find | Yes: the service the user expects | | Detecting account-takeover fraud from impossible travel | Yes: resisting fraudulent or illegal actions | | Sending it to an ad network for targeting in other apps | No, and it is also sharing | | Building a profile of the user's store visits for marketing | No | `1798.121(d)` and 7027(a) add a boundary: sensitive personal information collected or processed **without the purpose of inferring characteristics** about a consumer is not subject to the right to limit, though it remains personal information for every other purpose. ## The link and the method - A business that uses or discloses sensitive personal information beyond the permitted purposes must post a **'Limit the Use of My Sensitive Personal Information'** link, or use one combined link, such as the Alternative Opt-out Link, 'Your Privacy Choices' (`1798.135(a)(2)-(3)`; 11 CCR 7015). - It must offer **two or more methods**, with an interactive form behind the link at minimum for online collection; a cookie banner is not by itself an acceptable method (7027(b)). - No account and no verifiable consumer request may be required (7027(d)-(e)). ## After a request to limit 11 CCR 7027(g) requires the business to: 1. **Stop** the disallowed uses as soon as feasibly possible and **no later than 15 business days** after receiving the request; 2. **Tell service providers and contractors** using the data for other purposes, and instruct them to comply within the same time; 3. **Notify third parties** that received the data for other purposes between the request and compliance, and direct them to comply and forward the request. It must wait **at least 12 months** before asking the consumer to consent to wider use again (7027(l); `1798.135(c)(4)`), and may offer granular choices only alongside a single 'limit everything' option (7027(i)). ## The design point Location pipelines need two independent switches per user: one that stops third-party sharing, and one that confines the app's own use of location to the expected service and the permitted purposes. Treating the opt-out as sufficient leaves internal marketing uses of the location in place; treating the limit as sufficient stops the location feed but leaves the rest of the user's shared data, such as device identifiers and browsing activity, flowing to the ad network.

  • The app only uses location to show the nearest store and never infers anything about the user. Must it offer the Limit link?
    No. 11 CCR 7027(m) says a business that uses sensitive personal information only for the permitted purposes, reasonably necessary and proportionate, need not post a notice of the right to limit or provide a method. Showing the nearest store is the service an average consumer expects, and data processed without inferring characteristics is outside the right.
  • May the app ask a user who limited location use to reconsider next week?
    No. 11 CCR 7027(l) and Civil Code 1798.135(c)(4) require waiting at least 12 months from the request before asking the consumer to consent to using or disclosing their sensitive personal information for additional purposes, unless the regulations allow otherwise.

saying these in an interview costs you the question

  • Treats precise location as ordinary personal information with no extra right
  • Thinks the right to limit bans every use of sensitive data
  • Believes a cookie-settings banner handles requests to limit
  • Assumes honouring the opt-out of sharing also satisfies the right to limit
  • Applies the limit in the app but not to service providers using the data