CCPA Privacy FAQs: Is a business required to provide access to all information about the consumer maintained through a loyalty program?

Yes.

Some of the rights conferred by the CCPA are limited to data collected “from the consumer,”1 whereas other rights apply to data “collected about” a consumer.2 Access rights are part of the latter category.  As a result, if a business receives an access request from a member of a loyalty program, the CCPA requires that the business disclose “the specific pieces of personal information it has collected about that consumer.”3  This may be interpreted by courts as indicating that information must be disclosed regardless of whether the information was collected from the consumer directly, was received from a third party (e.g., a retailer, or a commercial partner), or was generated internally by a business.