Consumer privacy · How-to

Responding to consumer privacy requests

A step-by-step workflow for requests to know, delete and correct personal information, and for opt-outs, with every deadline the CCPA and its regulations set.

Last reviewed

The deadlines

  • 10 business days to confirm receipt of a request to know, delete or correct.
  • 45 calendar days to respond, counted from receipt, with one 45-day extension if you tell the consumer why.
  • 15 business days, at most, to stop selling or sharing after an opt-out.

Two tracks: verified requests and opt-outs

The CCPA treats requests in two different ways, and mixing them up is one of the most common enforcement problems.

Know, delete, correctOpt out of sale/sharing, limit sensitive PI
Verify identity?Yes, in proportion to the riskNo. Verification is prohibited
Confirm receiptWithin 10 business daysProvide a way to confirm it was processed
CompleteWithin 45 calendar days (plus one 45-day extension)As soon as feasible; no later than 15 business days
Source11 CCR §§ 7021, 7060–706211 CCR §§ 7026, 7027, 7060(b)

Step 1: Take in the request

Offer at least two designated methods for submitting requests, including a toll-free telephone number. A business that operates exclusively online and has a direct relationship with the consumer may offer only an email address (Civ. Code § 1798.130(a)(1)). Your privacy policy must explain how to submit requests and how you verify them (11 CCR § 7011(e)).

Consumers may use an authorized agent. The regulations set out what you can require from an agent (11 CCR § 7063). The CalPrivacy action against Honda faulted placing unnecessary burdens on agents.

Step 2: Confirm within 10 business days

For requests to know, delete or correct, confirm receipt within 10 business days. The confirmation should describe how you'll verify the request and when the consumer can expect a response (11 CCR § 7021(a)).

Step 3: Verify, in proportion to risk

Match what the consumer gives you against information you already hold. Avoid collecting new sensitive data for verification unless you need it. The more sensitive the data and the greater the risk of harm, the stricter the verification should be (11 CCR § 7060(c)).

  • Password-protected account holders can generally be verified through the existing authentication, using the process in 11 CCR § 7061.
  • Categories of information: a "reasonable degree of certainty," for example matching two data points (11 CCR § 7062(b)).
  • Specific pieces of information: a "reasonably high degree of certainty," for example three data points plus a signed declaration under penalty of perjury (11 CCR § 7062(c)).
  • Deletion and correction: either standard, depending on the sensitivity of the information and the risk of harm from wrongful deletion or correction (11 CCR § 7062(d)).

Step 4: Respond within 45 calendar days

The 45 days run from the day you receive the request, regardless of how long verification takes. You may take up to 45 more days (90 in total) if you notify the consumer and explain why (Civ. Code § 1798.130(a)(2); 11 CCR § 7021(b)).

  • Access responses must be in a portable, structured, commonly used, machine-readable format (Civ. Code § 1798.130(a)).
  • Deletion reaches your service providers and contractors too, and you must notify third parties you sold or shared the information with, unless that proves impossible or involves disproportionate effort. The statute lists exceptions, such as completing a transaction, security, and legal obligations (Civ. Code § 1798.105).
  • Denials should explain the basis, including when you can't verify the consumer.

Opt-outs are different

Opt-out requests and requests to limit sensitive personal information must be easy:

  • Don't require a verifiable consumer request or an account (11 CCR § 7026(c)–(d)). You may ask for a name, but not, in the regulation's example, a photo of the consumer holding a driver's license (11 CCR § 7060(b)).
  • Deny a request as fraudulent only on a good-faith, reasonable and documented belief, and tell the consumer why (11 CCR § 7026(e)).
  • Stop selling or sharing within 15 business days, and notify third parties that received the information after the request and before you complied (11 CCR § 7026(f)).
  • Treat browser signals like Global Privacy Control as opt-outs. See Honoring Global Privacy Control.

In the Todd Snyder decision, a misconfigured privacy portal left opt-outs unprocessed for 40 days. CalPrivacy said responsibility stays with the business that uses a third-party privacy tool.

Keep records

Keep records of consumer requests and how you responded for at least 24 months (11 CCR § 7101). Businesses that handle the personal information of 10 million or more consumers a year must also publish request metrics by July 1 each year (11 CCR § 7102).

Checklist

  • Two or more intake methods, including a toll-free number unless you're online-only with a direct relationship.Civ. Code § 1798.130(a)(1)
  • A calendar that tracks 10 business days to confirm and 45 calendar days to respond, starting on receipt.11 CCR § 7021
  • A written verification method that scales with the sensitivity of the data.11 CCR §§ 7060–7062
  • Opt-out and limit requests routed around verification, and completed within 15 business days.11 CCR §§ 7026, 7027
  • Deletion instructions passed to service providers, contractors and third parties that received the data.Civ. Code § 1798.105
  • A 24-month request log.11 CCR § 7101

Official sources