The deadlines
- 10 business days to confirm receipt of a request to know, delete or correct.
- 45 calendar days to respond, counted from receipt, with one 45-day extension if you tell the consumer why.
- 15 business days, at most, to stop selling or sharing after an opt-out.
Two tracks: verified requests and opt-outs
The CCPA treats requests in two different ways, and mixing them up is one of the most common enforcement problems.
| Know, delete, correct | Opt out of sale/sharing, limit sensitive PI | |
|---|---|---|
| Verify identity? | Yes, in proportion to the risk | No. Verification is prohibited |
| Confirm receipt | Within 10 business days | Provide a way to confirm it was processed |
| Complete | Within 45 calendar days (plus one 45-day extension) | As soon as feasible; no later than 15 business days |
| Source | 11 CCR §§ 7021, 7060–7062 | 11 CCR §§ 7026, 7027, 7060(b) |
Step 1: Take in the request
Offer at least two designated methods for submitting requests, including a toll-free telephone number. A business that operates exclusively online and has a direct relationship with the consumer may offer only an email address (Civ. Code § 1798.130(a)(1)). Your privacy policy must explain how to submit requests and how you verify them (11 CCR § 7011(e)).
Consumers may use an authorized agent. The regulations set out what you can require from an agent (11 CCR § 7063). The CalPrivacy action against Honda faulted placing unnecessary burdens on agents.
Step 2: Confirm within 10 business days
For requests to know, delete or correct, confirm receipt within 10 business days. The confirmation should describe how you'll verify the request and when the consumer can expect a response (11 CCR § 7021(a)).
Step 3: Verify, in proportion to risk
Match what the consumer gives you against information you already hold. Avoid collecting new sensitive data for verification unless you need it. The more sensitive the data and the greater the risk of harm, the stricter the verification should be (11 CCR § 7060(c)).
- Password-protected account holders can generally be verified through the existing authentication, using the process in 11 CCR § 7061.
- Categories of information: a "reasonable degree of certainty," for example matching two data points (11 CCR § 7062(b)).
- Specific pieces of information: a "reasonably high degree of certainty," for example three data points plus a signed declaration under penalty of perjury (11 CCR § 7062(c)).
- Deletion and correction: either standard, depending on the sensitivity of the information and the risk of harm from wrongful deletion or correction (11 CCR § 7062(d)).
Step 4: Respond within 45 calendar days
The 45 days run from the day you receive the request, regardless of how long verification takes. You may take up to 45 more days (90 in total) if you notify the consumer and explain why (Civ. Code § 1798.130(a)(2); 11 CCR § 7021(b)).
- Access responses must be in a portable, structured, commonly used, machine-readable format (Civ. Code § 1798.130(a)).
- Deletion reaches your service providers and contractors too, and you must notify third parties you sold or shared the information with, unless that proves impossible or involves disproportionate effort. The statute lists exceptions, such as completing a transaction, security, and legal obligations (Civ. Code § 1798.105).
- Denials should explain the basis, including when you can't verify the consumer.
Opt-outs are different
Opt-out requests and requests to limit sensitive personal information must be easy:
- Don't require a verifiable consumer request or an account (11 CCR § 7026(c)–(d)). You may ask for a name, but not, in the regulation's example, a photo of the consumer holding a driver's license (11 CCR § 7060(b)).
- Deny a request as fraudulent only on a good-faith, reasonable and documented belief, and tell the consumer why (11 CCR § 7026(e)).
- Stop selling or sharing within 15 business days, and notify third parties that received the information after the request and before you complied (11 CCR § 7026(f)).
- Treat browser signals like Global Privacy Control as opt-outs. See Honoring Global Privacy Control.
In the Todd Snyder decision, a misconfigured privacy portal left opt-outs unprocessed for 40 days. CalPrivacy said responsibility stays with the business that uses a third-party privacy tool.
Keep records
Keep records of consumer requests and how you responded for at least 24 months (11 CCR § 7101). Businesses that handle the personal information of 10 million or more consumers a year must also publish request metrics by July 1 each year (11 CCR § 7102).
Checklist
- Two or more intake methods, including a toll-free number unless you're online-only with a direct relationship.Civ. Code § 1798.130(a)(1)
- A calendar that tracks 10 business days to confirm and 45 calendar days to respond, starting on receipt.11 CCR § 7021
- A written verification method that scales with the sensitivity of the data.11 CCR §§ 7060–7062
- Opt-out and limit requests routed around verification, and completed within 15 business days.11 CCR §§ 7026, 7027
- Deletion instructions passed to service providers, contractors and third parties that received the data.Civ. Code § 1798.105
- A 24-month request log.11 CCR § 7101