Overview
This check confirms the presence of a "Limit the Use of My Sensitive Personal Information" link on pages where required for businesses that use or disclose sensitive personal information (SPI) (race, precise geolocation, biometric identifiers, health data, and similar categories) for purposes beyond what is necessary to provide the requested good or service.
Note: This guide is provided for informational purposes only and does not constitute legal advice. Consult qualified legal counsel regarding your organization's specific CCPA/CPRA compliance obligations.
Why it is important
The obligation is highly conditional: it applies only when SPI is used or disclosed beyond the minimum necessary purpose, and a combined "Your Privacy Choices" link that covers both sale/share opt-out and SPI limitation is an accepted alternative to a separate link. Treating this as a blanket requirement on every page risks flagging false positives, so this check works best paired with a short internal questionnaire confirming whether the SPI-limitation obligation even applies to your specific data flows before you scope the audit.
Implementation
Determine organization-level applicability first, before scoping any pages: does the business use or disclose SPI for a purpose beyond delivering the requested good or service? This is a data-flow and legal question, not something ObservePoint can answer on its own. Resolve it with legal/privacy counsel and document the determination. If the answer is no, this check is not applicable and no further steps are needed.
If applicable, determine page-level scope: identify specifically which pages collect or process SPI (not every page on the property will), using the same page-classification approach as the Notice at Collection checks. This is also an organization-specific determination.
There is no pre-built ObservePoint report for this check, since "missing the link" is only meaningful against the specific page list produced above. Run a targeted Audit against just those pages, then manually verify each one for the presence of either a standalone "Limit the Use of My Sensitive Personal Information" link or a combined "Your Privacy Choices" link near the SPI collection point.
Re-run this verification whenever the qualifying page list changes (new SPI-collecting features, new data flows) rather than on a fixed recurring schedule, since the trigger for this check is a business/data-flow change, not routine site drift.
Remediation
For remediation, follow the next steps:
If the applicability review shows SPI is used only for the minimum necessary purpose, document that determination and treat this check as not applicable rather than remediating a non-issue, over-adding this link where it isn't required adds consumer confusion without a compliance benefit.
Where applicability is confirmed and the link is missing, add it near the SPI collection point or consolidate it into your "Your Privacy Choices" link if you are using the combined-link approach, and update the underlying opt-out
mechanism to actually restrict the downstream SPI use, not just display the link.
Route any ambiguous applicability determination to legal/privacy counsel before making a site-wide change.
Conclusion
Because this obligation is conditional rather than universal, the highest-value step is confirming applicability first, from there the check itself is a straightforward extension of the same link-presence pattern used elsewhere in this policy
