Skip to main content
CCPA-PRIVACY-COMPLIANCE5 MIN READ

Sensitive PI Needs a Tighter Purpose

Apply a purpose-limit test to sensitive personal information under CCPA.

Sensitivity changes the design burden. The more revealing the data, the tighter the purpose and retention should be. Name the sensitivity Do not hide behind the word data. Call out precise geolocation, health preference, government ID, credential, biometric signal, or other sensitive category so the review has the right level of care. Test the purpose A sensitive field should map to a specific user-requested service, security need, legal requirement, or clearly disclosed purpose. Personalization by itself is usually too broad unless the team can explain the exact use. Minimize before you message The best limit-use control is often not collecting…

Read the full lesson

Sign up free — one personalized lesson every day, matched to your role and goals.

Already have an account? Sign in

← Back to library
Contact us