16.2 California Consumer Privacy Act (CCPA) / CPRA Obligations for HR Data

Key Takeaways

  • Effective January 1, 2023, the California Privacy Rights Act (CPRA) eliminated the temporary human resources data exemption under the California Consumer Privacy Act (CCPA, Civil Code § 1798.100 et seq.), extending full consumer privacy protections to job applicants, current employees, former employees, and independent contractors.
  • A business is subject to the CCPA/CPRA if it does business in California and satisfies at least one threshold: (1) annual gross revenues exceeding $25 million; (2) annually buys, sells, or shares personal information of 100,000+ consumers or households; or (3) derives 50%+ of annual revenues from selling or sharing consumer data.
  • Covered employers must issue a comprehensive, written 'Notice at Collection' to job applicants, employees, and contractors at or before personal data is collected, detailing categories of personal information collected, business purposes, retention periods, and Sensitive Personal Information (SPI) disclosures.
  • California workers possess statutory privacy rights: Right to Know/Access, Right to Correct inaccurate data, Right to Delete, and Right to Limit Use of Sensitive Personal Information; however, the Right to Delete is subject to critical statutory employment exceptions for payroll, tax, litigation, and personnel records.
  • The California Privacy Protection Agency (CPPA) enforces compliance through statutory administrative penalties of up to $2,500 per non-willful violation and $7,500 per intentional violation; a private right of action is available to employees solely for data breaches involving unencrypted sensitive personal information resulting from inadequate security.
Last updated: September 2026

16.2 California Consumer Privacy Act (CCPA) / CPRA Obligations for HR Data

Executive Summary: On January 1, 2023, California fundamentally transformed human resources administration when the temporary statutory exemption for employment-related personal information expired under the California Privacy Rights Act of 2020 (CPRA). As a result, the California Consumer Privacy Act (CCPA, Cal. Civ. Code § 1798.100 et seq.) now applies in full force to human resources data. Covered California employers must treat job applicants, current employees, former employees, independent contractors, and emergency beneficiaries as "consumers" endowed with robust data privacy rights. Employers must provide a detailed "Notice at Collection" before gathering candidate or worker data, safeguard "Sensitive Personal Information" (SPI), and establish administrative mechanisms to respond to formal Data Subject Access Requests (DSARs). While employees possess rights to access, correct, and request deletion of personal information, California employers must understand the statutory exceptions that protect essential payroll, tax, personnel, and litigation records from mandatory deletion.


The Expiration of the HR Data Exemption

When the California Legislature originally enacted the CCPA in 2018, it recognized that employment relationships involve continuous, involuntary data collection distinct from commercial retail transactions. Consequently, the Legislature enacted a temporary moratorium—codified at California Civil Code § 1798.145(m)—exempting human resources and business-to-business (B2B) data from most CCPA requirements, requiring only a basic collection notice for applicants and employees.

However, when California voters approved Proposition 24 (the CPRA) in November 2020, the measure set a hard sunset date of January 1, 2023 for the HR data moratorium. Despite intense employer lobbying, the California Legislature allowed the exemption to lapse. Effective January 1, 2023, California became the first jurisdiction in the United States to subject employee and workforce data to comprehensive omnibus consumer privacy regulations.

Covered Individuals: Who Qualifies as a Workforce "Consumer"?

Under Civil Code § 1798.145, CCPA protections apply to all natural persons residing in California who interact with a covered business in an employment or workforce capacity:

  • Job Applicants: Prospective candidates submitting resumes, applications, or background check materials;
  • Current Employees: Full-time, part-time, temporary, and seasonal employees performing work in California;
  • Former Employees: Separated or retired workers whose records remain stored in corporate archives;
  • Independent Contractors & Consultants: Freelancers, gig workers, and individual service providers;
  • Beneficiaries and Emergency Contacts: Family members, spouses, dependents, and emergency contacts whose personal information is collected for benefits enrollment or emergency administration.

Covered Employer Thresholds under CCPA/CPRA

Not every California employer is subject to the CCPA. The statute applies strictly to for-profit legal entities that "do business in the State of California" and meet at least one of the following three statutory thresholds under Civil Code § 1798.140(d):

┌─────────────────────────────────────────────────────────────────────────────┐
│                     CCPA / CPRA COVERAGE THRESHOLDS                         │
├─────────────────────────────────────────────────────────────────────────────┤
│  A for-profit business operating in California is covered if it meets       │
│  ANY ONE of the following criteria:                                         │
│                                                                             │
│  1. Gross Annual Revenue:                                                   │
│     • Exceeded $25 million in the preceding calendar year (as of Jan 1).     │
│                                     OR                                      │
│  2. Data Volume / Commercial Scale:                                         │
│     • Annually buys, sells, or shares personal information of 100,000 or    │
│       more consumers, households, or devices.                               │
│                                     OR                                      │
│  3. Revenue from Data Monetization:                                         │
│     • Derives 50% or more of its annual gross revenues from selling or      │
│       sharing consumers' personal information.                              │
└─────────────────────────────────────────────────────────────────────────────┘

[!IMPORTANT] Exam Trap: Global Revenue Triggers California Compliance For the $25 million revenue threshold, California courts and the CPPA measure the entity's aggregate annual gross revenues worldwide, not merely revenue generated inside California. A mid-sized multinational company with $30 million in total global revenue and only three remote employees living in California is fully subject to CCPA HR compliance for those California workers.


Mandatory HR Compliance: The Notice at Collection

The cornerstone of employer compliance under California Civil Code § 1798.100(a) and 11 CCR § 7012 is the Notice at Collection for Human Resources Data. This notice must be provided to applicants, employees, and contractors at or before the point of data collection.

Timing of Notice Delivery

  • Job Applicants: The notice must be presented on the applicant tracking system (ATS) portal, linked on job postings, or provided immediately before a candidate submits personal details, resumes, or background screening consents.
  • New Hires: Provided alongside the onboarding packet or offer letter prior to collecting Form W-4, direct deposit, or Form I-9 data.
  • Current Employees: Provided annually or redistributed whenever the employer plans to collect a new category of personal information or repurpose existing data for a previously undisclosed business purpose.

Mandatory Content Elements of the HR Privacy Notice

Under CPPA regulations (11 CCR § 7012), the Notice at Collection must clearly detail:

  1. Categories of Personal Information Collected: Granular enumeration of data classes (e.g., identifiers, professional credentials, internet activity on work devices);
  2. Categories of Sensitive Personal Information (SPI) Collected: Specific disclosure of SSNs, health data, financial accounts, or biometrics;
  3. Business Purposes for Use: Explicit statement of operational reasons for each category (e.g., payroll processing, benefits management, compliance with tax codes, workplace security);
  4. Selling or Sharing Disclosures: Clear statement indicating whether the employer "sells" personal information or "shares" it for cross-context behavioral advertising (almost universally answered "No" in standard HR operations);
  5. Data Retention Periods: The exact retention timeframe for each category (e.g., "Retained for 4 years following termination per California Labor Code § 1174"), or, if not feasible, the specific objective criteria used to determine that retention period;
  6. Link to Full Privacy Policy: A direct hyperlink or accessible path to the comprehensive corporate HR privacy policy detailing employee statutory rights.

Personal Information vs. Sensitive Personal Information (SPI)

The CPRA introduced a heightened, critical sub-classification: Sensitive Personal Information (SPI) under Civil Code § 1798.140(ae). Handling SPI imposes stricter administrative constraints.

Category ClassStatutory Scope under CCPA / CPRAHR Workplace Examples
Standard Personal Information (PI)Any information that identifies, relates to, describes, or could reasonably be linked to an individual.Legal name, home address, personal telephone, resume history, performance reviews, compensation, attendance logs, work email.
Sensitive Personal Information (SPI): Government IdentifiersCore personal identification credentials issued by state or federal authorities.Social Security number (SSN), driver's license number, state ID card, passport number, visa document numbers.
SPI: Financial & Account CredentialsFinancial account credentials allowing access to funds.Bank routing and account numbers for direct deposit; corporate credit card numbers; account passwords.
SPI: Demographic & Protected CharacteristicsInformation revealing racial, ethnic, or personal identity traits.Racial or ethnic origin, religious or philosophical beliefs, union membership, sexual orientation, citizenship status.
SPI: Health, Medical & Genetic DataInformation concerning an individual's health, medical condition, or biology.Disability accommodation medical notes, workers' compensation records, genetic screening, drug test results.
SPI: Biometric Data & Precise GeolocationPhysiological identifiers and real-time physical tracking.Fingerprint or facial recognition data for time clocks; precise GPS tracking within a 1,850-foot radius.

The Right to Limit Use of Sensitive Personal Information

Under Civil Code § 1798.121, consumers generally possess the right to direct a business to limit its use of SPI strictly to necessary operational tasks. However, in the HR context:

  • The Employment Safe Harbor: When an employer uses an employee's SPI strictly to perform core employment services—such as using an SSN to remit payroll taxes to the EDD, using bank account numbers for direct deposit, collecting race/ethnicity to file mandatory federal EEO-1 reports, or reviewing medical restrictions to conduct the FEHA interactive process—the employer is operating within the statutory safe harbor (11 CCR § 7027).
  • Limitation Trigger: An employee cannot compel an employer to stop using their SSN or direct deposit info. The Right to Limit Use of SPI is triggered only if the employer attempts to monetize or use that SPI for secondary purposes outside core human resources operations.

Employee Statutory Privacy Rights under CCPA/CPRA

Covered California employers must establish formalized internal protocols to intake, verify, and resolve Data Subject Access Requests (DSARs) submitted by workers within 45 calendar days (with a single 45-day extension permitted for complex requests upon timely notice).

┌─────────────────────────────────────────────────────────────────────────────┐
│                     CALIFORNIA WORKFORCE PRIVACY RIGHTS                     │
├─────────────────────────────────────────────────────────────────────────────┤
│  1. Right to Know / Access (Civ. Code § 1798.110):                          │
│     • Request copies of specific pieces of personal information collected.  │
│                                     ▼                                       │
│  2. Right to Correct (Civ. Code § 1798.106):                                │
│     • Require employer to correct demonstrably inaccurate personal records. │
│                                     ▼                                       │
│  3. Right to Delete (Civ. Code § 1798.105):                                 │
│     • Request deletion of data, SUBJECT TO major statutory HR exceptions.   │
│                                     ▼                                       │
│  4. Right to Non-Discrimination / Non-Retaliation (§ 1798.125):             │
│     • Absolute protection against retaliation for exercising privacy rights.│
└─────────────────────────────────────────────────────────────────────────────┘

1. Right to Know and Access (§ 1798.110)

Employees may request that the employer disclose:

  • The specific pieces of personal information collected about them;
  • The categories of sources from which the data was gathered;
  • The business or commercial purpose for collecting the data; and
  • The categories of third parties (e.g., payroll processors, benefit brokers, 401(k) administrators) to whom the employer disclosed the data.

2. Right to Correct Inaccurate Personal Information (§ 1798.106)

Employees have the right to request that an employer correct inaccurate personal information. Upon receiving a verified request, the employer must evaluate the documentation provided and make necessary corrections across its internal databases and third-party vendors.

3. Right to Delete (§ 1798.105) & Major Statutory HR Exceptions

A pervasive point of confusion among employees and HR practitioners is the Right to Delete. While an employee can formally demand the deletion of their personal information, an employer is NOT legally required to delete records that fall under statutory exemptions codified in Civil Code § 1798.105(d):

  • Legal Compliance Exemption: Employers must retain payroll, tax, wage, and hour records to comply with the California Labor Code, Internal Revenue Code, and Employment Development Department (EDD) regulations (e.g., Labor Code § 1174 requires payroll record retention for at least 3 years; federal IRS rules require 4 years).
  • Statutory Personnel File Rights: Employers are required by California Labor Code § 1198.5 to maintain personnel records for a minimum of 3 years following termination to satisfy employee inspection rights.
  • Litigation and Defense of Legal Claims: Data necessary to defend against anticipated or pending lawsuits (e.g., FEHA discrimination claims, wrongful termination, or wage disputes) cannot be deleted. Overwriting or destroying records subject to a litigation hold constitutes sanctionable spoliation of evidence.
  • Internal Operational Consistency: Retaining performance reviews or disciplinary logs strictly to maintain internal consistency and ensure fair workplace evaluations.

[!CAUTION] What Can Actually Be Deleted? In practice, the Right to Delete in HR applies to non-essential, discretionary data. Examples include: internal corporate directory photographs, voluntary wellness survey responses, employee biometric timekeeping data after the employee leaves, or non-essential job applicant resumes for candidates who were not hired and where the statute of limitations for hiring claims has passed.

4. Right to Non-Discrimination / Non-Retaliation (§ 1798.125)

Under Civil Code § 1798.125, an employer must not discriminate or retaliate against an applicant or employee because they exercised any privacy right under the CCPA. An employer cannot discharge, demote, deny promotion, discipline, or reduce the compensation of a worker who files a Right to Know or Right to Correct request.


Enforcement: CPPA Authority, Civil Penalties & Data Breaches

Compliance enforcement is overseen by a dedicated state regulatory agency.

The California Privacy Protection Agency (CPPA)

Established by Proposition 24, the California Privacy Protection Agency (CPPA) is the first independent privacy regulator in the United States. The CPPA possesses full administrative power to audit covered businesses, subpoena records, investigate consumer and employee complaints, and initiate administrative enforcement actions alongside the California Attorney General.

Statutory Civil Penalties (Civil Code § 1798.155)

If an employer fails to provide an HR Notice at Collection, ignores verified DSAR requests, or misuses sensitive employee data, the CPPA or the Attorney General may seek substantial administrative penalties in civil court:

  • Non-Willful Violations: Up to $2,500 per violation.
  • Willful / Intentional Violations: Up to $7,500 per violation.

Operational Multiplier: These statutory penalties apply per violation, per employee. If a covered employer with 1,000 California workers deliberately fails to provide an HR Notice at Collection, the statutory penalty exposure can reach $7,500,000 ($7,500 × 1,000 employees).

The Narrow Private Right of Action: Data Breaches Only

A critical legal distinction for the PHRca exam: Individual employees DO NOT have a private right of action to sue an employer for failing to provide a Notice at Collection or refusing a DSAR request. Enforcement of regulatory compliance belongs exclusively to the CPPA and the California Attorney General.

Under Civil Code § 1798.150, an employee possesses a private right of action to file a civil lawsuit against an employer under the CCPA solely when:

  1. The employee's non-encrypted and non-redacted personal information (specifically sensitive credentials like SSN, driver's license, health data, or financial accounts);
  2. Is subject to an unauthorized access, exfiltration, theft, or disclosure (a data breach);
  3. As a result of the employer's failure to implement and maintain reasonable security procedures and practices appropriate to the nature of the information.

In such data breach lawsuits, employees may recover statutory damages ranging from $100 to $750 per consumer per incident, or actual damages, whichever is greater, alongside injunctive relief and attorney's fees.

Loading diagram...
CCPA/CPRA Employee Data Request (DSAR) Resolution Workflow
Test Your Knowledge

A terminated warehouse operations manager at a California fulfillment center with $80 million in annual gross revenue submits a formal written CCPA request demanding that the company 'immediately and permanently delete every trace of my personal information, including my personnel file, performance appraisals, timecard punch histories, Form W-2s, and records of the internal investigation regarding my termination.' How must the employer respond under Civil Code § 1798.105?

A
B
C
D
Test Your Knowledge

A California biotechnology firm with $45 million in annual revenue implements a new biometric palm-scanner timekeeping system for its 350 laboratory technicians and gathers applicants' Social Security numbers on web forms. The company fails to provide an HR Notice at Collection or any privacy disclosures at or before the point of gathering this data. During an audit, the California Privacy Protection Agency (CPPA) cites the company for deliberate and willful non-compliance across its workforce. What is the employer's statutory liability under the CCPA/CPRA?

A
B
C
D
Test Your Knowledge

A software engineer employed by an enterprise software company in San Diego discovers that the company's internal HR database lists an incorrect hire date and incorrectly categorizes her position as 'Junior Engineer' rather than 'Senior Staff Engineer,' adversely affecting her consideration for equity grants and promotions. She submits a formal request with supporting offer letters and promotion notices requesting a correction under the CCPA. The HR Director denies the request, stating: 'The CCPA applies only to external consumers shopping on our website, not to internal employee job data.' Did the employer violate California law?

A
B
C
D