Join our Newsletter — 33% off our NHI Course

What is the difference between deleting consumer personal information and limiting use of sensitive personal information under CPRA?

Deletion is a broader right that asks the business to remove personal information and instruct downstream recipients to do the same, subject to legal and operational exceptions. Limiting use of sensitive personal information is narrower. It restricts how the business may use or disclose especially sensitive data, while leaving some processing in place when it is allowed by law or needed for permitted business purposes.

How Deletion Differs from Limiting Sensitive Data Use

CPRA treats these as different controls with different outcomes. Deletion is an erasure right, so the business is being asked to remove personal information from its systems and push that request downstream where the law requires it. Limiting use of sensitive personal information is narrower. It changes how sensitive data may be used or disclosed, but it does not necessarily require full removal.

That distinction matters operationally. Deletion aims at data removal and propagation of that removal, while limitation is about constraining permitted processing so the business can still keep some sensitive information for allowed purposes. For teams managing search, analytics, backups, and records systems, the real question is whether the data must disappear, or whether its use must simply be narrowed.

What Each Right Changes in Practice

Deletion usually requires a stronger lifecycle response because the business must locate the information, remove it where appropriate, and verify which records or recipients are exempt. It is closer to a data-retention and data-disposal decision. Limiting use of sensitive personal information is more like a processing boundary decision: the data may remain, but the ways it can be used, shared, or disclosed are constrained.

In practice, deletion requests often force inventory and propagation work across systems that were never designed for perfect erasure, such as logs, archives, or third-party processors. Limiting use of sensitive personal information is typically handled through policy, access, and workflow controls, so the organization can continue permitted operations without broad internal use of that data.

Why the CPRA Distinction Matters for Governance

The legal and operational burden is not the same. Deletion is broader because it affects retention, downstream handling, and exception management. Limiting use of sensitive personal information is narrower because it preserves some lawful processing while narrowing exposure. For privacy programs, that means different intake, routing, and evidence requirements for each request type.

Organizations that blur the two usually make one of two mistakes: they either over-delete and lose data needed for lawful business purposes, or they under-limit and continue using sensitive data more broadly than the user has the right to restrict. A clean control design keeps deletion workflows separate from use-limitation workflows, even when the same data subject may exercise both rights.

Risk and Threat Considerations

These rights create different exposure patterns. Deletion failures can leave personal information circulating in systems, backups, or vendor environments after a request should have been honored. Limitation failures usually do not create the same removal problem, but they can still expose the business to inappropriate internal use, disclosure, or overbroad processing of sensitive data.

Failure mechanism: Deletion breaks down when inventories are incomplete, recipients are not tracked, or exception handling is too loose to distinguish lawful retention from unnecessary retention. Limitation breaks down when teams treat “can keep” as “can use freely” and fail to enforce processing boundaries.

Impact: The first risk is residual personal information that should have been removed and may continue to be shared or retained unlawfully. The second is excess use of sensitive personal information, which can increase privacy exposure, raise compliance findings, and widen the blast radius if the data is later misused or disclosed.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

NIST SP 800-53 Rev 5 and NIST CSF 2.0 set the technical controls, while GDPR and ISO/IEC 27001:2022 define the regulatory obligations.

Framework Control / Reference Relevance
GDPR A.5.15 — Information Security Policy Deletion and use-limitation depend on clear policy-driven handling rules.
Recommendation — Define separate privacy-handling procedures for erasure and use restrictions.
ISO/IEC 27001:2022 A.5.34 — Privacy and protection of PII CPRA request handling is a privacy governance and PII control issue.
Recommendation — Document privacy request workflows for deletion and sensitive-data limitation.
NIST SP 800-53 Rev 5 DM-2 — Data Minimization and Retention Deletion maps to reducing retained personal data and governing retention scope.
AC-6 — Least Privilege Limiting use of sensitive data depends on restricting who may access or use it.
Recommendation — Minimise retained personal data and enforce retention limits by data class. Restrict access to sensitive data to the minimum roles and uses required.
NIST CSF 2.0 PR.DS-01 — Data-at-rest is protected Both rights depend on protecting stored personal data during retention and deletion.
Recommendation — Protect stored personal data while deletion and restriction workflows execute.

Practitioner Guidance

What to verify: Separate the request types in your intake and fulfillment process, then verify that your data map shows where deletion must propagate and where sensitive-use limits must be enforced instead. If a record is subject to an exception, document the exception path explicitly rather than routing it into a generic refusal.

Decision rule: If the user is asking for removal, treat it as a deletion workflow with propagation and exception review; if the user is asking to stop broader use of sensitive data, treat it as a use-limitation workflow with policy enforcement and access narrowing. Do not collapse them into one privacy ticket.

Practitioner takeaway: The key control difference is lifecycle versus use boundary, deletion removes data from circulation where required, while limiting use keeps some data in place but constrains what the business may do with it.