Manages CCPA/CPRA consumer rights requests: right to know, delete, correct, opt-out of sale/sharing, limit sensitive data. Includes verification, exceptions, 45-day responses.
npx claudepluginhub mukul975/privacy-data-protection-skills --plugin privacy-skills-completeThis skill uses the workspace's default tool permissions.
The California Consumer Privacy Act (CCPA), as amended by the California Privacy Rights Act (CPRA), grants California consumers specific rights regarding their personal information. This skill provides the operational workflow for handling CCPA consumer requests, including the right to know, right to delete, right to correct, right to opt-out of sale/sharing, and the right to limit use of sensi...
Conducts multi-round deep research on GitHub repos via API and web searches, generating markdown reports with executive summaries, timelines, metrics, and Mermaid diagrams.
Dynamically discovers and combines enabled skills into cohesive, unexpected delightful experiences like interactive HTML or themed artifacts. Activates on 'surprise me', inspiration, or boredom cues.
Generates images from structured JSON prompts via Python script execution. Supports reference images and aspect ratios for characters, scenes, products, visuals.
The California Consumer Privacy Act (CCPA), as amended by the California Privacy Rights Act (CPRA), grants California consumers specific rights regarding their personal information. This skill provides the operational workflow for handling CCPA consumer requests, including the right to know, right to delete, right to correct, right to opt-out of sale/sharing, and the right to limit use of sensitive personal information.
Consumers have the right to request that a business disclose:
Consumers have the right to request that a business delete any personal information about the consumer which the business has collected. The business must delete the consumer's personal information from its records, notify service providers and contractors to delete, and notify third parties who purchased or received the information to delete.
Exceptions to deletion (Section 1798.105(d)):
Consumers have the right to direct a business that sells or shares their personal information to third parties to stop selling or sharing that personal information. A business must provide a clear and conspicuous "Do Not Sell or Share My Personal Information" link on its website.
A business shall not discriminate against a consumer because the consumer exercised any of their CCPA rights, including by:
Added by CPRA: consumers have the right to request correction of inaccurate personal information.
Added by CPRA: consumers have the right to limit a business's use of their sensitive personal information to purposes necessary to perform the services or provide the goods requested.
CCPA requires at least two methods for submitting requests:
CCPA regulations (11 CCR Section 7060-7064) require verification proportional to the type of request:
| Request Type | Verification Standard | Method |
|---|---|---|
| Right to know — categories | Reasonable degree of certainty | Match at least 2 data points (name + email, name + account number) |
| Right to know — specific pieces | Reasonably high degree of certainty | Match at least 3 data points + signed declaration under penalty of perjury |
| Right to delete | Reasonable degree of certainty | Match at least 2 data points |
| Right to correct | Reasonable degree of certainty | Match at least 2 data points |
| Right to opt-out of sale | No verification required (unless fraudulent) | Confirm association with the business |
If the consumer has a password-protected account, the business may verify through the existing authentication process.
| Request Type | Response Deadline | Format |
|---|---|---|
| Right to know | 45 calendar days (extendable by 45 additional days with notice) | Written (email or postal), in a portable and readily useable format |
| Right to delete | 45 calendar days (extendable by 45 additional days) | Written confirmation |
| Right to correct | 45 calendar days (extendable by 45 additional days) | Written confirmation |
| Right to opt-out | 15 business days | Written confirmation |
| Right to limit sensitive PI | 15 business days | Written confirmation |
When a consumer exercises any CCPA right, the business must not:
Financial incentive programmes (e.g., loyalty programmes) must be disclosed in the privacy notice and require consumer opt-in consent. The incentive must be reasonably related to the value of the consumer's data.