CCPA consumer request deadlines are among the easiest obligations to get wrong, because they start the moment a request arrives, not when the privacy team notices it. A request submitted through a web form on a Friday evening, a support chat or an email to a salesperson can all count, and the clock does not pause while someone decides who should handle it.
This guide sets out the response times for each type of request, how extensions and verification work, what to do when you cannot comply and how to build a workflow that meets the deadlines every time. It is written for privacy and operations teams at businesses covered by California’s privacy law. It is not legal advice; confirm details against the statute, the current regulations and the guidance from California regulators.
Free gap assessment
Could you evidence CCPA compliance today?
Score notices, consumer requests, opt-outs and vendor contracts, free, plus the 2026 risk assessment and cybersecurity audit duties.
Run the free CCPA/CPRA gap assessment → or View premium report sample
The basic CCPA consumer request deadlines
California residents have rights to know what personal information a business collects, to delete it, to correct inaccurate information, to opt out of its sale or sharing and to limit the use of sensitive personal information. The California Attorney General’s guidance states that businesses generally have 45 calendar days to respond to requests to know, delete and correct, and up to 15 business days to honor an opt-out request.
The regulations also expect you to confirm receipt of a request to know, delete or correct within a short period, commonly described as 10 business days. That confirmation is separate from the substantive response, and it should say when the requester can expect a full answer. If your process lacks an acknowledgment step, add one. See our overview of CCPA compliance for the program around these steps.
When does the clock start?
The 45 days run from the day you receive the request, regardless of the channel, and not from the day you verify the requester. A business cannot stop the clock by asking for more time informally. If you need an extension, the published rule allows one extension of up to 45 more days, for a total of 90 days, provided you notify the consumer within the initial period and explain the reason.
Train customer support, sales and any staff who receive messages to forward requests immediately to the privacy queue. A request that sits in a mailbox for two weeks is a compliance problem even if the privacy team then acts quickly.
Verification and the verifiable consumer request
For requests to know, delete and correct, businesses must verify that the requester is who they claim to be, to a degree appropriate to the sensitivity of the data. This is the verifiable consumer request. Use information you already hold where possible, such as matching account details, and avoid collecting more sensitive data just to verify. For opt-out requests, verification is generally not required, and you should not make the process harder than the opt-in process.
Authorized agents may also submit requests on behalf of consumers, with appropriate proof of authority. Decide in advance what documentation you will accept, and write it into your procedure so handling is consistent.
| Request type | Deadline (as published) | Notes |
|---|---|---|
| Know (categories or specific pieces) | 45 calendar days | Extendable once by up to 45 more days with notice |
| Delete | 45 calendar days | Subject to legal exceptions |
| Correct | 45 calendar days | Consider the nature of the data and its purposes |
| Opt out of sale or sharing | As soon as feasible, up to 15 business days | No account or verification is typically needed |
| Limit use of sensitive information | Follow the published response timing | Confirm current requirements with counsel |
Handling opt-out requests and preference signals
Opt-out of sale or sharing has the tightest timing: as soon as feasibly possible and no later than 15 business days, according to the Attorney General’s guidance. Automated opt-out preference signals from browsers are also relevant; see CCPA opt-out preference signal for how to recognize and honor them.
Make sure downstream partners receive the opt-out. Stopping a sale on your own website but leaving an advertising partner with the data does not meet the requirement. Record the date received, the date honored and the partners notified.
What the response must contain
A response to a request to know should give the categories or specific pieces of personal information requested, generally covering the 12 months before the request, unless a longer period applies under the current rules. A deletion response should confirm what was deleted, what was retained and why, and instruct service providers and contractors to delete as well. Our page on service providers vs contractors explains who must act on your instruction.
If you deny a request because an exception applies, explain the ground in plain language. Consumers may submit requests up to twice per year free of charge, and you may refuse requests that are manifestly unfounded or excessive, with an explanation.
A step-by-step workflow for CCPA consumer request deadlines
A workable process looks like this. Adapt each step to your systems.
- Day 0: log the request in a tracker with the received date and channel
- Within 10 business days: send acknowledgment with the expected response date
- Days 1 to 10: verify identity and confirm the request scope
- Days 10 to 30: search systems, compile or delete data, instruct providers
- Days 30 to 40: legal and privacy review of the response
- Before day 45: send the response, or an extension notice with reasons
- After: record the outcome and keep the file for the required period
Penalties and enforcement context
Missing deadlines can expose a business to enforcement. Our guide to CCPA penalties covers the fines and the regulators involved. Enforcement attention has included how businesses handle opt-outs and consumer requests, so a documented, timely process is also your best defense.
Other California obligations are growing around the same topic. Read about the California Delete Act, which adds a centralized mechanism for data brokers, and the newer regulations on automated decision-making technology and CCPA risk assessments. Compare with CCPA vs GDPR if you also serve EU residents.
Free privacy risk assessment
Which privacy risks would hurt the people whose data you hold?
List your personal data and processing, pick from 38 privacy risk scenarios, rate them for the people concerned and for you, and plan treatment with ISO 27701 controls. You get a heat map, a process score and the findings an auditor would raise, free.
Run the free privacy risk assessment → or View premium report sample
Templates for managing requests
Templates remove guesswork: request intake forms, verification procedures, response letters, extension notices, denial letters and a request log. The CCPA-CPRA Compliance Toolkit includes editable versions for these, so you can put a compliant workflow in place quickly.
For the official description of consumer rights and business responsibilities, see the California Attorney General CCPA page. Templates do not replace a review of your actual data flows, so also test your process with mock requests every quarter.
Building a tracker that proves you met the CCPA consumer request deadlines
A spreadsheet or ticketing queue is enough if it captures the right fields. Record the request ID, the date and channel of receipt, the requester type, the request type, the acknowledgment date, the verification method and result, the extension decision and reason, the response date, the outcome and the person who approved it. Add automatic due-date formulas based on the received date so the tracker shows the 10-business-day acknowledgment date, the 45-day response date and the 15-business-day opt-out date. Color-code items approaching the deadline and send reminders to the owner and their manager.
Review the tracker weekly. Any request within ten days of its deadline and not yet in legal review deserves attention. At the end of each quarter, report the number of requests by type, the median response time and the number of extensions. Those figures tell leadership whether the process scales, and they become the evidence you show a regulator or customer if asked how you manage consumer rights.
Preparing for volume spikes
Request volume can jump after a news event, a breach or a marketing campaign. Plan for that by automating search in your main systems, keeping a list of data owners for each system and agreeing on a fast path for simple requests such as opt-outs. A trained backup for each role keeps the queue moving during holidays. These planning steps matter because the deadline does not move when your team is busy.
Training staff on CCPA consumer request deadlines
Short, regular training keeps the process working. Teach front-line staff to recognize a request in any wording, to forward it the same day and not to give legal answers themselves. Teach the privacy team the clock rules, the acknowledgment step and the extension notice. Test the training with mock requests and time how long it takes them to reach the queue. Repeat after any staff change, and keep attendance records. Well-trained staff are the cheapest way to meet the CCPA consumer request deadlines consistently and to avoid the silent misses that cause most problems.
Common mistakes with CCPA consumer request deadlines
Businesses often miss requests that arrive through informal channels. They start the clock after verification instead of receipt. They forget to tell service providers to delete. They collect excessive identity data for verification. They also fail to keep records, which makes it difficult to prove timeliness. Audit a sample of requests each quarter for on-time completion and completeness, and fix the gaps.
CCPA Consumer Request Deadlines FAQ
How long do I have to respond to a CCPA request?
Generally 45 calendar days for requests to know, delete and correct, with one extension of up to 45 more days if you notify the consumer. Opt-outs must be honored as soon as feasible, up to 15 business days.
Does verification pause the deadline?
No. The 45 days run from receipt. Start verification immediately and ask for extra information quickly.
Can a consumer make unlimited requests?
Consumers may submit requests to know up to twice in a 12-month period free of charge, and you may refuse requests that are manifestly unfounded or excessive.
Do service providers have to delete data too?
Yes. When you delete at a consumer’s request you must notify service providers and contractors to delete as well, subject to exceptions.
Is this legal advice?
No. Confirm details against the statute and current regulations, and ask counsel about edge cases.