Skip to main content
  • Personal
  • Business
  • Foundation
    Close
  • Select Region
    • Global
    • India
    • MENA
  • mySHRM Login
  • MySHRM
    • Dashboard
    • Account
    • Logout
SHRM
  • Membership
    • Membership

      As a SHRM Member®, you’ll pave the path of your success with invaluable resources, world-class educational opportunities and premier events.

      Membership Tiers
      • Professional
      • Student
      • Global
      • Executive
      • Business
      Membership Benefits
  • Learning
    • Certification

      Validate your skills with the gold standard in HR

      • Choosing Your Certification
      • SHRM-CP
      • SHRM-SCP
      • How to Get Certified
      • Prepare for the Exam
      • Recertification
      Education Programs

      Expert-led training for real workplace change

      • eLearning
      • Essentials of HR
      • Seminars
      Specialty Credentials

      Go deep in your niche. Stand out in your field.

      • AI + HI Specialty Credential
      • People Manager Qualification (PMQ)
      Executive Voices

      Bring our experts to your stage.

  • Attend
    • Events

      Demonstrate your ability to apply HR principles to real-life situations.

      • SHRM26 Annual Conference & Expo
      • The AI+HI Project 2026
      • Talent 2026
      • Linkage Institute 2026
      • BLUEPRINT 2025
      State Conferences

      Attend a SHRM state event to network with other HR professionals and learn more about the future of work.

      Seminars

      Stand out from among your HR peers with the skills obtained from a SHRM Seminar.

      Webinars

      Learn live and on demand. Earn PDCs and gain immediate insights into the latest HR trends.

  • Resources
    • Resources

      Stay up to date with news and leverage our vast library of resources.

      • Flagships
      • HR Research
      • Legal & Compliance
      • Latest News & Trends
      • Tools & Guides
      • Webinars
      HR Topics
      • AI in the Workplace
      • Civility at Work
      • Compensation & Benefits
      • Inclusion & Diversity
      • Talent Acquisition
      • HR Technology
      • Workplace Violence Prevention
      Educational Programs

      Designed and delivered by HR experts to empower you with the knowledge and tools you need to drive lasting change in the workplace.

  • Community
    • Find a SHRM Chapter

      Easily find a local professional or student chapter in your area.

      • SHRM Northern California
      SHRM Connect

      Post polls, get crowdsourced answers to your questions and network with other HR professionals online.

      Membership Councils

      Learn about SHRM's five regional councils and the Membership Advisory Council (MAC).

      Volunteers

      Learn about volunteer opportunities with SHRM.

  • Shop
    • SHRM Store

      Shop for HR certifications, credentials, learning, events, merchandise and more.

      Workplace Essentials
      • SHRM Memberships
      • SHRM Certification
      • Specialty Credentials
      • HR Tools & Tech
      Education
      • Seminars
      • eLearning
      • Books
      Merchandise
      • Accessories
      • Apparel
      • Office & Home
Become a Member
Renew
Rejoin Now
Renew
Ask an HR Advisor
Close
  • Personal
  • Business
  • Foundation
  • Membership
    back
    Membership
    • Membership

      As a SHRM Member®, you’ll pave the path of your success with invaluable resources, world-class educational opportunities and premier events.

      Membership Tiers
      • Professional
      • Student
      • Global
      • Executive
      • Business
      Membership Benefits
  • Learning
    back
    Learning
    • Certification

      Validate your skills with the gold standard in HR

      • Choosing Your Certification
      • SHRM-CP
      • SHRM-SCP
      • How to Get Certified
      • Prepare for the Exam
      • Recertification
      Education Programs

      Expert-led training for real workplace change

      • eLearning
      • Essentials of HR
      • Seminars
      Specialty Credentials

      Go deep in your niche. Stand out in your field.

      • AI + HI Specialty Credential
      • People Manager Qualification (PMQ)
      Executive Voices

      Bring our experts to your stage.

  • Attend
    back
    Attend
    • Events

      Demonstrate your ability to apply HR principles to real-life situations.

      • SHRM26 Annual Conference & Expo
      • The AI+HI Project 2026
      • Talent 2026
      • Linkage Institute 2026
      • BLUEPRINT 2025
      State Conferences

      Attend a SHRM state event to network with other HR professionals and learn more about the future of work.

      Seminars

      Stand out from among your HR peers with the skills obtained from a SHRM Seminar.

      Webinars

      Learn live and on demand. Earn PDCs and gain immediate insights into the latest HR trends.

  • Resources
    back
    Resources
    • Resources

      Stay up to date with news and leverage our vast library of resources.

      • Flagships
      • HR Research
      • Legal & Compliance
      • Latest News & Trends
      • Tools & Guides
      • Webinars
      HR Topics
      • AI in the Workplace
      • Civility at Work
      • Compensation & Benefits
      • Inclusion & Diversity
      • Talent Acquisition
      • HR Technology
      • Workplace Violence Prevention
      Educational Programs

      Designed and delivered by HR experts to empower you with the knowledge and tools you need to drive lasting change in the workplace.

  • Community
    back
    Community
    • Find a SHRM Chapter

      Easily find a local professional or student chapter in your area.

      • SHRM Northern California
      SHRM Connect

      Post polls, get crowdsourced answers to your questions and network with other HR professionals online.

      Membership Councils

      Learn about SHRM's five regional councils and the Membership Advisory Council (MAC).

      Volunteers

      Learn about volunteer opportunities with SHRM.

  • Shop
    back
    Shop
    • SHRM Store

      Shop for HR certifications, credentials, learning, events, merchandise and more.

      Workplace Essentials
      • SHRM Memberships
      • SHRM Certification
      • Specialty Credentials
      • HR Tools & Tech
      Education
      • Seminars
      • eLearning
      • Books
      Merchandise
      • Accessories
      • Apparel
      • Office & Home
Become a Member
Renew
Rejoin Now
Renew
Ask an HR Advisor
  • Select Region
    • Global
    • India
    • MENA
SHRM
mySHRM Login
  • MySHRM
    • Dashboard
    • Account
    • Logout
Close

  1. Topics & Tools
  2. Employment Law & Compliance
  3. California: How Much Data is Too Much?
Share
  • Linked In
  • Facebook
  • Twitter
  • Email

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Vivamus convallis sem tellus, vitae egestas felis vestibule ut.


Error message details.

Copy button
Reuse Permissions

Request permission to republish or redistribute SHRM content and materials.


Learn More
News

California: How Much Data is Too Much?

May 3, 2024 | Darcey M. Groden, CIPP/US, Usama Kahf, CIPP/US and Anne Yarovoy Khan © Fisher Phillips

Someone typing on their laptop with graphic images of locks superimposed on the computer

Businesses take heed: California state officials have warned that the law prohibits you from collecting unnecessary data and retaining data for longer than necessary. The California Privacy Protection Agency published its first Enforcement Advisory on data minimization under the state’s hallmark data privacy law on April 2, focusing on a very specific context: when businesses respond to consumer requests under the California Consumer Privacy Act (CCPA). Here is what you need to know and the four key steps you can take to avoid over-collecting data when you respond to CCPA consumer requests—including from employees and job applicants.

What is Data Minimization and Why Issue an Enforcement Advisory?

While an Enforcement Advisory is not meant to interpret the CCPA or make new law, it nevertheless provides insight into what a likely priority of the agency will be going forward. And the April 2 Enforcement Advisory is clear in providing a warning to businesses.

The agency appears to have the impression that businesses are requesting too much information from consumers when they submit a CCPA consumer request. As it states: “Data minimization is a foundational principle of the CCPA.” This principle is undermined when you make it too hard for consumers to exercise CCPA rights that effectuate data minimization, or you ask for too much information to verify a consumer’s identity.

Data minimization is premised on the CCPA requirement that a business’s collection, use, retention, and sharing of consumer personal information be “reasonably necessary and proportionate to achieve the purposes for which the personal information was collected or processed.” Whether the collection, use, retention, and/or sharing of personal information is reasonably necessary and proportionate to achieve the purpose identified is based on the following:

  • The minimum personal information necessary to achieve the purpose identified, or any purpose for which the business obtains the consumer’s consent (meaning a use of the data that you’ve disclosed to the consumer at or before you collected the data from the consumer, or that you can prove was consented to by the consumer).
  • The possible negative impacts on consumers.
  • The existence of additional safeguards for the personal information to specifically address the possible negative impacts on consumers.

To illustrate the concept, the Enforcement Advisory highlights this principle as seen in the CCPA rules regarding opt-out preference signals (aka global privacy controls), requests to opt-out of the sale/sharing of personal information, requests to limit the use and disclosure of sensitive personal information, and the general rules regarding verification of a consumer’s identity.

The Enforcement Advisory further provides two factual scenarios where a business should consider and implement data minimization: in a response to a consumer request to opt-out of the sale/sharing of personal information; and when verifying a consumer’s identity in response to a CCPA request to delete personal information.

Data Minimization Through Opting Out of Sharing and Selling of Personal Information

In the first scenario, the Enforcement Advisory reminds businesses that you cannot require a consumer to verify their identity in connection with a request to opt out of the sale or sharing of consumer personal information or a request to limit the use and disclosure of their sensitive personal information. That means your process for receiving, processing and responding to these two types of requests cannot include an identity verification step. While you may need additional information to effectuate the opt-out, this is not the same as verifying a consumer’s identity. And, when you need additional information, you should ask for the minimum amount necessary to effectuate the request.

The Enforcement Advisory first posits the scenario of a consumer opting out of cross-context behavioral advertising through an opt-out preference signal. Certain web browsers enable users to set up such signals so that the browser sends an automatic signal to the website that the user has opted out of the sharing of data through cookies for targeted ad purposes. In such case, you would not need additional information to read, process and comply with the out-out signal.

However, if you sold or shared personal information offline and were unable to connect the online user with their offline activities, you would need additional information to effectuate the offline opt-out. That being said, the information requested should only be sufficient to effectuate that offline request. Asking for unrelated personal information—for example, asking for a driver’s license to opt-out of having a business sell a consumer’s purchasing history—would likely be in excess of what you need, according to this Enforcement Advisory.

Data Minimization When Verifying a Consumer’s Identity

In the second scenario, the Enforcement Advisory walks through an example of how you may apply the principle when receiving consumer requests to delete personal information. Here, the agency did not provide any easy or suggested answers—instead, it put forward a series of questions (without any suggested answers) that you can ask in evaluating what information to request when evaluating whether to delete consumer data.

Despite avoiding answers to its own questions, the questions themselves provide some insight into what you should consider when determining how to verify an identity:

  • Evaluate the harm of an unauthorized deletion to the consumer. While the example focuses on destruction of information of sentimental value, you should also consider whether the destruction of information could have economic or other significant negative impacts. Where the potential harm to a consumer is on the higher end of the spectrum, more stringent verification will be required. Where the information to be deleted is not significant, you need not overcomplicate the verification process. The key takeaway here is that the verification process cannot be a one-size-fits-all approach.
  • Evaluate the harm of asking for additional, new information from the consumer. If you ask for highly sensitive information such as a driver’s license or social security number, the consumer is at risk of identity theft if a data breach occurs. While not addressed in the Enforcement Advisory, you should also ask yourselves how requesting information from consumers that you do not already have—and thus cannot verify—helps you confirm the identity of the consumer.

It is important to emphasize that what is not at issue is any harm to your business. The agency’s questions are consumer-centered, considering only the benefits and harms they face. When determining the appropriate verification process, you should view your processes through that lens.

Your 4 Next Steps: A Compliance Guide

In order to best position your organization for compliance, consider the following four steps:

1. Review Your Practices

Review your mechanism for processing requests to opt out of selling/sharing of personal information and to limit the use or disclosure of personal information. If you are verifying identities to process these requests, you need to stop immediately. If you need additional information to figure out who a person is so that you can process the request (perhaps they have a common name!), you should only ask for the minimum amount of information needed to process or effectuate the request.

2. Determine If it’s Time for Global Privacy Controls

If your website uses third-party cookies, pixels, beacons, tags or other tracking technology or discloses data to third parties that is then used for targeted advertising and does not currently process or accept Global Privacy Controls as an opt-out preference signal, you must get this set up now.

3. Ensure Your Verification Processes are on Point

Review how you are verifying consumer identities for Requests to Know/Access, Delete and Correct. You ideally should be verifying identities based on information already in your possession. That requires you to look at what you have and tailor the verification questions you ask based on that data. While it may be easier to just ask for a copy of a driver’s license or other government ID, you may end up collecting information that you do not already have (and information that is considered sensitive information under the CCPA to boot), thus subverting the data minimization standards encompassed in the law.

4. Purge Stale Data

While not addressed specifically in the Enforcement Advisory, the CCPA prohibits you from retaining personal information longer than you have a legitimate business purpose to do so. If your business does not have a data retention schedule or does not follow its data retention schedule, you should make it a priority. This includes ensuring that vendors that process and store data on your behalf also follow through with deletion of stale data. “Our vendor won’t or can’t delete the data” is likely not a good excuse anymore. The law requires stale data to be deleted, so there has to be a workable solution whereby data that you are legally responsible for can be deleted—wherever it resides.

Darcey M. Groden, CIPP/US is an attorney with Fisher Phillips in San Diego. Usama Kahf, CIPP/US and Anne Yarovoy Khan are attorneys with Fisher Phillips in Irvine, Calif. © 2024 Fisher Phillips. All rights reserved. Reposted with permission.

ESG, Ethics & Compliance
Privacy & Security Compliance

Was this resource helpful?

Leave Feedback

SHRM-CP Promo Image
Validate your HR expertise

Earning your SHRM-CP credential makes you a recognized expert and leader in the HR field.

Get Certified


Related Content

(opens in a new tab)
News
How One Company Uses Digital Tools to Boost Employee Well-Being

Learn how Marsh McLennan successfully boosts staff well-being with digital tools, improving productivity and work satisfaction for more than 20,000 employees.

(opens in a new tab)
News
A 4-Day Workweek? AI-Fueled Efficiencies Could Make It Happen

The proliferation of artificial intelligence in the workplace, and the ensuing expected increase in productivity and efficiency, could help usher in the four-day workweek, some experts predict.

(opens in a new tab)
News
Rising Demand for Workforce AI Skills Leads to Calls for Upskilling

As artificial intelligence technology continues to develop, the demand for workers with the ability to work alongside and manage AI systems will increase. This means that workers who are not able to adapt and learn these new skills will be left behind in the job market.

HR Daily Newsletter

Stay up to date with the latest HR news, trends, and expert advice each business day.

Success title

Success caption

Manage Subscriptions
Our Brands

SHRM Foundation Logo
SHRM Executive Network Logo
CEO Circle Logo
SHRM Business Logo
SHRM Linkage Logo
SHRM Labs
Overview

  • About SHRM
  • Careers at SHRM
  • Press Room
  • Contact SHRM
  • Post an HR Job
SHRM Named to Newsweek's 2026 America's Top Online Learning Provider List
Advocacy

  • SHRM Advocacy
  • Federal Policies
  • State Affairs
  • Global Policy
  • Take Action
  • SHRM E2 Initiative
Brand Partnership

  • Partnership Opportunities
  • Advertise with Us
  • Exhibit & Sponsorship
  • Recertification Providers
  • Book a Speaker
Member Resources

  • Ask an HR Advisor
  • SHRM Newsletters
  • SHRM Flagships
  • Topics & Tools
  • Find an HR Job
  • Vendor Directory

© 2026 SHRM. All Rights Reserved
SHRM provides content as a service to its readers and members. It does not offer legal advice, and cannot guarantee the accuracy or suitability of its content for a particular purpose. Disclaimer

Follow Us

  • LinkedIn
  • Facebook
  • Twitter
  • Instagram
  • YouTube
Feedback

  1. Your Privacy Choices

  2. Terms of Use

  3. Accessibility

  4. Privacy Policy

Join SHRM for Exclusive Access to Professional Content

SHRM Members enjoy unlimited access to articles and exclusive professional content resources.

Already a member? Login
Free Article

Login to unlock unlimited access or join SHRM today to get unlimited access to articles and member-exclusive resources.

Already a member? Login
Limit Reached

You've reached the limit of 1 free article this month. Join to access unlimited articles and member-only resources.

Already a member? Login
Free Article

Login to unlock unlimited access or join SHRM today to get unlimited access articles and member-exclusive resources.

Already a member? Login
Limit Reached

You've reached the limit of 1 free article this month. Join the Executive Network and enjoy unlimited content.

Already a member? Login
Unlock Your Career with SHRM Membership

Please enjoy this free resource! Join SHRM for unlimited access to exclusive articles and tools.

Already a member? Login
Join SHRM for Exclusive Access to Professional Premium Content

SHRM Members enjoy unlimited access to articles and exclusive professional premium resources.

Already a member? Login
Join SHRM for Exclusive Access to Student Content

SHRM Members enjoy unlimited access to articles and exclusive member resources.

Already a member? Login
Join SHRM for Exclusive Access to Executive Network Content

SHRM member enjoys unlimited access to articles and exclusive executive member resources.

Already a member? Login

Your membership is almost expired! Renew today for unlimited access to member content.

Renew now

Your membership has expired. Renew today for unlimited access to member content.

Renew Now

Your Executive Network membership is nearing its expiration. Renew now to maintain access.

Renew Now

Your membership has expired. Renew your Executive Network benefits today.

Renew Now