Back to Blog
GuidesMarch 28, 202612 min readReviewed by the PrivacyLawMap editorial teamLast reviewed July 25, 2026

How to Respond to Consumer Privacy Data Requests: A Multi-State Compliance Guide

Share:
Turn This Guide Into a Working Privacy SetupSponsored

Termly can generate and maintain your privacy policy, consent banner, and data-request workflow as requirements change.

Start Free with Termly

CCPA Requests in 2026: Is Your Business Ready?

As of July 25, 2026, a CCPA request is a California consumer’s instruction to know, access, delete, correct, opt out of sale or sharing, or limit certain uses of sensitive personal information. A compliant workflow must separate verifiable requests from opt-out and limit requests because they use different verification rules and response clocks.

PrivacyLawMap tracks 20 enacted comprehensive state privacy laws, but their effective dates and request rules are not identical. Whether it’s a California resident asking you to delete data, a Colorado consumer requesting access, or a Texas consumer opting out of a sale, your business needs a reliable intake and evidence process that applies the law currently in force for that consumer.

Getting it wrong can trigger enforcement. In its Todd Snyder decision, the California Privacy Protection Agency cited a privacy portal that failed to process opt-outs for 40 days, unnecessary data collection, and identity verification imposed on opt-out requests; the order included a $345,178 fine. Source check: CPPA enforcement announcement and CCPA request FAQ, retrieved July 25, 2026 (date_retrieved: 2026-07-25).

This guide shows how to build one consumer data request process across the 20 laws tracked on this site, with a CCPA-specific triage matrix for the exact deadlines, verification rule, and evidence artifact each request lane needs.

What Types of Consumer Requests Must You Handle?

Most state privacy laws grant consumers a similar core set of rights, though the specifics vary. Here are the five request types your business should be prepared to handle:

1. Right to Access / Right to Know

Consumers can request confirmation of whether you process their personal data and obtain a copy of that data. Every state with a comprehensive privacy law includes this right. Under California’s CCPA, you must disclose the categories and specific pieces of personal information collected, the sources, the business purposes, and the categories of third parties with whom you share it.

2. Right to Delete

Consumers can ask you to delete the personal data you’ve collected about them. All 20 state laws include data deletion rights, the closest US equivalent to the right to be forgotten, though exceptions vary. Common exceptions include data needed to complete a transaction, detect security incidents, comply with legal obligations, or exercise free speech.

3. Right to Correct

Most states (but notably not Iowa) give consumers the right to correct inaccurate personal data. Your correction process should verify the claimed inaccuracy before making changes, and you should inform any third parties you’ve shared the data with.

4. Right to Opt Out of Sale / Targeted Advertising / Profiling

This is the most enforcement-heavy area. States require businesses to honor opt-out requests for the sale of personal data, sharing for targeted advertising, and in many states, profiling that produces legal or similarly significant effects. Twelve states now also require recognition of universal opt-out mechanisms like Global Privacy Control (GPC).

5. Right to Data Portability

When consumers request a copy of their data, many states require you to provide it in a portable, readily usable format — a right commonly referred to as data portability. Typically this means a structured, machine-readable format like CSV or JSON.

CCPA Request Triage Matrix: Deadline, Verification, and Evidence

Do not send every California request through the same identity-verification flow. The official CPPA request FAQ separates requests to know, delete, or correct from opt-out and limit requests, while 11 CCR § 7060 prohibits identity verification for opt-out or limit requests. Use this control matrix to configure the workflow and preserve regulator-ready proof.

CCPA request laneResponse clockIdentity ruleEvidence to retain
Know / access, delete, or correct Confirm receipt within 10 business days; substantively respond within 45 calendar days. One 45-day extension is available with timely notice. Use a documented, reasonable method to verify the consumer or authorized agent. Match data already held when feasible and minimize new collection. Timestamped intake, acknowledgment, verification basis, systems searched, exception log, extension notice if used, and final response copy.
Opt out of sale or sharing Comply as soon as feasibly possible and no later than 15 business days. Do not require identity verification or account creation. Ask only for information needed to identify which data flows must stop. Request timestamp, suppression or consent-platform event, downstream notification, confirmation, and a test showing the sale/sharing stopped.
Global Privacy Control or another valid opt-out preference signal Route through the opt-out lane; do not wait for a separate form submission. Treat the signal as a valid request for the browser or device. Do not add a verification gate. Signal-detection log, consent-state change, blocked-tag or restricted-use record, and recurring browser test result.
Limit use or disclosure of sensitive personal information Comply as soon as feasibly possible and no later than 15 business days when the right applies. Do not require identity verification; collect only what is necessary to apply the limitation. Request timestamp, sensitive-data purpose mapping, limitation flag, vendor propagation record, and confirmation.

Why this matrix is different: a ticket marked “completed” is not enough. The evidence column maps each legal clock to the operational artifact an investigator can test. Source: CPPA FAQ and CCPA regulations, verified July 25, 2026 (date_retrieved: 2026-07-25).

Response Timelines: State-by-State Comparison

One of the trickiest parts of multi-state compliance is managing different response deadlines. Here’s what you need to know:

StateInitial ResponseExtensionTotal Maximum
California (CCPA/CPRA)45 days+45 days90 days
Virginia (VCDPA)45 days+45 days90 days
Colorado (CPA)45 days+45 days90 days
Connecticut (CTDPA)45 days+45 days90 days
Texas (TDPSA)45 days+45 days90 days
Oregon (OCPA)45 days+45 days90 days
Montana (MCDPA)45 days+15 days60 days
Most other states45 days+45 days90 days

Pro tip: Build your process around a 30-day target. This gives you buffer before any state’s deadline hits and accounts for the time needed to verify identity and locate all data.

Step-by-Step: Building Your Consumer Request Process

Step 1: Provide Clear Request Channels

California generally requires at least two designated methods for requests to know, delete, or correct: one must be a toll-free phone number and, if the business has a website, one must be available through the website. A business that operates exclusively online and has a direct relationship with the consumer may provide an email address instead. Most other states require at least one clear method. Best practice is to offer a web form, an email address, and any additional channel the applicable law requires.

Make your request mechanisms easy to find. The privacy policy should prominently link to them, and for opt-out requests, a clear “Do Not Sell My Personal Information” link should appear in the website footer.

Step 2: Verify the Requestor’s Identity

For requests to know, delete, or correct, use a documented, commercially reasonable method to verify that the requestor is the consumer or an authorized agent: match known account information, send a verification message to an existing contact point, or use data already on file. Avoid collecting new sensitive information unless it is necessary for verification. Critically, do not verify identity for an opt-out or limit request. The CPPA’s data-minimization enforcement advisory applies this distinction directly to consumer requests.

Step 3: Acknowledge the Request

For a California request to know, delete, or correct, send confirmation within 10 business days. Your acknowledgment should confirm receipt, state the type of request, provide an expected completion date, and note any additional verification step. Opt-out and limit requests use the separate 15-business-day maximum in the matrix above.

Step 4: Locate and Process the Data

This is where a data inventory becomes essential. You need to search all systems where consumer data may reside: CRM databases, email marketing platforms, analytics tools, customer support logs, backup systems, and third-party processors. Notify any service providers or third parties you’ve shared the data with about deletion or correction requests.

Step 5: Respond to the Consumer

Your response generally must be free of charge (California permits a request to know up to twice in a 12-month period). For access requests, provide data in a portable format. For deletion requests, confirm what was deleted and identify any exception applied. For opt-out and limit requests, stop the relevant processing as soon as feasibly possible and no later than 15 business days, then retain proof that downstream systems and recipients received the change.

Step 6: Document Everything

Maintain records of every request received, verification steps taken, actions performed, and responses sent. California requires businesses to maintain these records for 24 months. This documentation is your first line of defense in an enforcement investigation.

Appeals Process

Several states (Colorado, Connecticut, Virginia, and others) require you to provide an appeals process when you deny a consumer request. The appeal must be reviewed within 45–60 days, and if denied again, you must inform the consumer how to contact the state Attorney General. Building this process proactively shows good faith and prevents escalation.

Multi-State Compliance Strategy

Rather than building separate processes for each state, adopt the most protective standard across all laws:

  • Offer all five request types to all consumers regardless of state — this is simpler than gating by location.
  • Use the shortest timeline as your target (aim for 30 days).
  • Honor valid GPC signals wherever required — and consider one universal workflow if your systems can apply it consistently.
  • Provide an appeals process for all denials — even in states that don’t require it.
  • Document everything for at least 24 months.

Use our Privacy Law Calculator to determine which state laws apply to your business, then review the specific state-by-state comparison for any unique requirements.

Common Mistakes That Trigger Enforcement

  • Adding friction to opt-out — requiring account creation, multi-step verification, or repeated confirmations (Ford, $375K fine).
  • Ignoring GPC signals — failing to detect or honor the Sec-GPC header (multi-state enforcement sweep, 2026).
  • Not having a clear request method — burying the request form deep in your site or requiring calls only.
  • Slow or no response — missing the 45-day window entirely or failing to acknowledge receipt.
  • Over-collecting during verification — asking for more personal data than needed to confirm identity.

The Bottom Line

Consumer data requests are not going away. With 20 enacted comprehensive laws in this site’s tracker and regulators testing request-handling friction, a robust DSAR process is a core compliance control. One shared intake system can support multiple states, but it still needs state-aware deadlines, verification rules, appeal paths, and effective-date logic. Start with a data inventory, establish clear request channels, train your team, and document every decision.

Check whether your business falls under these laws with our Privacy Law Calculator, and use our GPC Compliance Checker to verify your universal opt-out readiness.

FAQ: CCPA Request Handling

What is a CCPA request?

A CCPA request is a California consumer’s exercise of a privacy right, such as a request to know, access, delete, correct, opt out of sale or sharing, or limit certain uses of sensitive personal information. Businesses should classify the request before choosing a verification step or deadline.

How long does a business have to respond to a CCPA request?

For requests to know, delete, or correct, confirm receipt within 10 business days and respond within 45 calendar days; one 45-day extension is available with notice. Opt-out and limit requests must be honored as soon as feasibly possible and no later than 15 business days.

Should a business verify identity for a CCPA opt-out request?

No. California regulations say a business must not require identity verification for a request to opt out of sale or sharing or a request to limit. The business may ask only for non-burdensome information needed to apply the request to the correct data.

How many CCPA request methods must a business provide?

Businesses generally must provide at least two designated methods for requests to know, delete, or correct, including a toll-free number and, when the business has a website, a website method. A qualifying online-only business with a direct consumer relationship may use an email address.

This article provides general educational information and is not legal advice. Consult qualified legal counsel for guidance specific to your organization. Last verified: July 25, 2026 against the CPPA request FAQ, current CCPA regulations, and CPPA enforcement materials (date_retrieved: 2026-07-25).

Put This Guide Into PracticeSponsored

Termly can turn the requirements above into a maintained privacy policy, consent banner, and data-request workflow.

Start Free with Termly