What Are Your Rights When a Company Collects Your Personal Data?

Companies collect personal data when people shop, browse websites, use apps, join loyalty programs, request quotes, or create accounts. That information may include names, contact details, purchase histories, location data, browsing activity, device identifiers, financial information, and inferred interests.

In the United States, privacy rights depend on where the consumer lives, the type of company holding the information, and how the data is used. There is no single federal privacy law that gives every consumer identical rights over all personal data.

Start With the Privacy Notice

A company’s privacy notice should explain what information it collects, why it collects it, and which types of third parties receive it. Look for sections labeled “Privacy,” “Your Privacy Rights,” “State Privacy Rights,” or “Do Not Sell or Share My Personal Information.”

The notice may describe the collection of:

  • Contact and account information

  • Payment and transaction records

  • Browsing and search history

  • Location and device information

  • Biometric, health, or demographic data

  • Information obtained from data brokers

  • Inferences used for advertising or profiling

A privacy policy does not automatically mean every practice described in it is lawful or that the consumer agreed to every use. It is primarily a disclosure that can help identify the company’s practices and the rights that may apply.

Rights Available Under State Privacy Laws

A growing number of states have comprehensive consumer privacy laws. Their definitions, coverage, exemptions, and enforcement procedures differ.

Depending on the applicable law, a consumer may have the right to:

  • Confirm whether a company processes personal data

  • Access or obtain a copy of the data

  • Correct inaccurate information

  • Request deletion

  • Receive data in a portable format

  • Opt out of the sale of personal data

  • Opt out of targeted advertising

  • Opt out of certain profiling

  • Limit some uses of sensitive information

  • Appeal the denial of a request

  • Exercise privacy rights without unlawful discrimination

California law, for example, gives qualifying residents rights to know, delete, correct, and opt out of the sale or sharing of personal information. It also provides a right to limit certain uses and disclosures of sensitive information.

Colorado law gives covered consumers rights to access, correct, delete, and obtain portable copies of personal data. It also permits consumers to opt out of data sales, targeted advertising, and certain profiling.

Not every company is covered. Some laws apply only to businesses meeting revenue, data-volume, or other thresholds. Exemptions may also apply to employee records, business-to-business information, nonprofits, government records, or information regulated under another law.

Deletion Rights Have Exceptions

A right to delete does not necessarily require a company to erase every record connected to a person.

The company may be permitted or required to retain information needed to:

  • Complete a transaction

  • Provide a requested service

  • Detect fraud or security incidents

  • Maintain tax or financial records

  • Exercise or defend legal claims

  • Comply with another law

  • Honor an opt-out request

  • Protect the rights or safety of others

Deleting an account is not always the same as submitting a legal deletion request. Use the procedure identified in the company’s privacy notice.

If a company denies a qualifying request, it should explain why. Some state laws also require an appeal process.

You May Be Able to Opt Out of Data Sales and Advertising

State laws define “sale,” “sharing,” and “targeted advertising” differently. In some jurisdictions, a disclosure may qualify even when the company does not directly receive money.

Look for links labeled:

  • Do Not Sell or Share My Personal Information

  • Your Privacy Choices

  • Opt Out of Targeted Advertising

  • Limit the Use of My Sensitive Personal Information

Some states require covered businesses to recognize qualifying browser-based universal opt-out signals. Global Privacy Control is one example. Its legal effect depends on the consumer’s location, the business, and how the signal is configured.

Opting out of targeted advertising may not remove every advertisement. A company may still show contextual advertising based on the page being viewed rather than activity tracked across different services.

Sensitive Data May Receive Additional Protection

Privacy laws often provide additional protection for information such as precise geolocation, biometric identifiers, health information, racial or ethnic origin, religious beliefs, sexual orientation, citizenship status, and account credentials.

Some states require consent before a covered company processes specified sensitive data. Others allow consumers to limit its use or disclosure.

Specialized federal laws may also apply. For example:

  • The Fair Credit Reporting Act covers certain consumer-report information

  • The Gramm-Leach-Bliley Act applies to certain financial institutions

  • HIPAA applies to specified healthcare organizations and their business associates

  • COPPA protects personal information collected online from children under 13 in covered circumstances

These laws do not cover every business merely because it possesses financial, health, or children’s information. Coverage depends on the organization and how the information is collected or used.

How to Submit a Privacy Request

Use the request method listed in the company’s privacy notice. A message to general customer service may not reach the department handling formal privacy requests.

Clearly identify the right being exercised. A request might say:

I am requesting access to the personal data your company maintains about me, including the categories and specific pieces of information collected, its sources, the purposes for which it is used, and the categories of third parties that received it.

Provide enough information to locate and verify the account, but avoid sending unnecessary sensitive documents. Identity verification helps prevent impostors from accessing or deleting another person’s information.

Keep copies of:

  • The original request

  • The submission confirmation

  • The date and delivery method

  • Any case number

  • The company’s response

  • Any appeal or follow-up correspondence

Response deadlines vary by state. A company may sometimes extend its deadline after giving notice.

What Companies Generally Should Not Do

A company should not misrepresent how it collects, uses, secures, or shares personal information. The Federal Trade Commission may treat deceptive privacy statements and certain unfair data practices as violations of federal consumer protection law.

Covered companies also may not unlawfully discriminate against consumers for exercising state privacy rights. However, certain financial-incentive or loyalty programs may be permitted if required disclosures and safeguards are provided.

If a company requests substantially more information than appears necessary to verify identity, ask why it is needed and how it will be protected.

What to Do After a Denial

Read the denial carefully. The company may state that it is not covered by the law, that the request could not be verified, that an exception applies, or that the information falls outside the law’s scope.

If the applicable state law provides an appeal right, follow the stated procedure and explain why the decision should be reconsidered. Include the original request and response.

Unresolved concerns may be reported to the state attorney general or designated state privacy regulator. Deceptive or unfair data practices may also be reported to the FTC.

Most comprehensive state privacy laws are enforced primarily by government authorities rather than through individual lawsuits. Whether a consumer can sue directly depends on the law, alleged conduct, and resulting harm.

Personal-data rights are not uniform nationwide, but consumers may have meaningful control over access, correction, deletion, sales, advertising, and sensitive information. The practical first step is to find the company’s privacy notice, identify the applicable law, and submit a clear request through the designated channel.

This article provides general information, not individualized legal advice. Privacy rights, covered businesses, exemptions, deadlines, and enforcement options vary by state, jurisdiction, industry, and type of data.

Brian Comly

Brian Comly, M.S., OTR/L is a licensed occupational therapist with over 15 years of clinical experience in Philadelphia, specializing in spinal cord injuries, traumatic brain injury, stroke, and orthopedic rehabilitation. He is also a certified nutrition coach and founder of MindBodyDad. Brian is currently pursuing his Doctor of Occupational Therapy (OTD) to further his expertise in function, performance, coaching, and evidence-based practice.

A lifelong athlete who has competed in marathons, triathlons, trail runs, stair climbs, and obstacle races, he brings both first-hand experience and data-driven practice to his work helping others move, eat, and live stronger, healthier lives. Brian is also husband to his supportive partner, father of two, and his mission is clear: use science and the tools of real life to help people lead purposeful, high-performance lives.

https://MindBodyDad.com
Previous
Previous

Your Rights as a Patient: Medical Records, Privacy, and Informed Consent

Next
Next

What to Do If a Company Refuses to Correct Your Personal Information