Requirements for Businesses Collecting Large Amounts of Personal Information
Reference only: This requirement is not currently tested by the Privisy scanner. It is included for reference. Consult a qualified attorney to assess your compliance posture.
What it requires
The same 10,000,000-consumer trigger as § 7100(b) carries a second duty, and this one is public. A business that knows or reasonably should know that it, alone or in combination, buys, receives for its commercial purposes, sells, shares, or otherwise makes available for commercial purposes the personal information of 10,000,000 or more consumers in a calendar year must compile eight metrics for the previous calendar year: how many requests to delete, to correct, to know, to access ADMT, to opt out of sale/sharing, to limit, and to opt out of ADMT it received, complied with in whole or in part, and denied, plus the median or mean number of days it took to respond substantively to requests to delete, correct, know, opt out of sale/sharing, and limit. The two ADMT request counts were added by the rulemaking operative January 1, 2026. By July 1 of every year the business must disclose those metrics in its privacy policy, or on a page of its website linked from the privacy policy. It may break out denials by reason, and under subsection (b) it may count requests from all individuals rather than only consumers if it says so in the disclosure.
Legal text (excerpt)
(a) A business that knows or reasonably should know that it, alone or in combination, buys, receives for the business’s commercial purposes, sells, shares, or otherwise makes available for commercial purposes the personal information of 10,000,000 or more consumers in a calendar year shall: (1) Compile the following metrics for the previous calendar year: (A) The number of requests to delete that the business received, complied with in whole or in part, and denied; [...] (G) The number of requests to opt-out of ADMT that the business received, complied with in whole or in part, and denied; and (H) The median or mean number of days within which the business substantively responded to requests to delete, requests to correct, requests to know, requests to opt-out of sale/sharing, and requests to limit. (2) Disclose, by July 1 of every calendar year, the information compiled in subsection (a)(1) within their privacy policy or posted on their website and accessible from a link included in their privacy policy.
Primary source
California Privacy Protection Agency (CalPrivacy): § 7102: Requirements for Businesses Collecting Large Amounts of Personal Information ↗Legal notice: This page is for informational purposes only and does not constitute legal advice. The legal text excerpt is reproduced from official public sources and is current as of the stated effective date. Laws change: verify against the authoritative source and consult a licensed attorney for compliance guidance.