Use plain-language intake
Requesters should be able to describe what they want without choosing legal conclusions. The response team can then review request type and next steps.
- Offer access, deletion, correction, opt-out, and general request options.
- Collect enough account context to begin review.
- Send ambiguous requests to a person for review.
| Request | Published baseline | Do not assume |
|---|---|---|
| Know, delete, correct | CPPA states confirmation within 10 business days and response within 45 calendar days | That verification or exceptions are identical |
| Opt out of sale or sharing | Provide the designated route and process the request | That identity verification should mirror a request to know |
| Limit sensitive information | Route and document the consumer's choice | That it is the same action as deletion |
Track target dates carefully
Deadline handling should remain reviewable. Suggested dates can help teams prioritize, but exceptions and pauses need documented rationale.
- Show due soon and overdue cases.
- Document verification and clarification holds.
- Escalate cases that need legal or compliance review.
Deliver responses securely
Responses can include sensitive personal data. Controlled delivery links give teams better expiration, revocation, and access history than attachments.
- Use secure links for response packets.
- Keep delivery activity attached to the case.
- Review response materials before sending.
Separate the requested outcome from the internal work
A customer may ask to stop a particular use of information, correct a detail, or receive a copy of records. Preserve that wording before deciding which teams and review steps are needed.
- Record each distinct requested outcome so one part is not lost during assignment.
- Ask the responsible reviewer to confirm the handling approach for that request.
- Keep the response understandable to the customer rather than repeating internal status labels.
Use a case review checklist
This is an operational checklist for organizing work, not a statement of legal requirements. Your reviewer determines which requirements and exceptions apply to the circumstances.
- Confirm the request wording, account context, and responsible owner.
- Review any verification need, applicable timing, and unresolved questions.
- Check that system task results support the response and that delivery and closure are recorded.
Build the response around the requested right
California's official guidance distinguishes the content and handling of each right. A response to know may need categories and specific pieces plus source, purpose, and recipient-category information. A deletion response should communicate the outcome of the deletion request; a correction response addresses the inaccurate information identified. Opt-out and limit requests are choices to implement, not disclosure packets.
- For know requests, map each required category of information to a reviewed response element.
- For delete or correct requests, record the systems acted on, outcome, and any human-reviewed basis for a different result.
- For sale or sharing opt-out, do not require the same identity verification used for specific-piece disclosure; use the designated method and current California rules.
- Treat authorised-agent handling, sensitive information, exceptions, and required notices as separate review points.
Sources
Sources checked September 20, 2026. These primary and regulator materials support the legal-rule summaries above; check the current rules that apply to your organization.
- California Attorney General: California Consumer Privacy Act — Official overview of consumer rights, designated request methods, verification, and 45-calendar-day responses.
- California Privacy Protection Agency: frequently asked questions — Official operational summary, including confirmation and response time frames for requests to know, delete, and correct.
Common questions
Does Privacy Requests provide CCPA legal advice?
No. It provides workflow tooling for intake, tracking, review, delivery, and audit history. Legal interpretation remains with the customer's team.
Can one workflow handle CCPA and other privacy requests?
Yes. A workflow can handle multiple request types while letting the team set labels, assignment rules, target dates, and review steps.
What should teams document for CCPA-style requests?
Teams should document intake, verification, ownership, task work, response approval, delivery, exceptions, and closure.
Run privacy requests in one controlled workflow
Privacy Requests helps teams manage intake, verification, tasks, response preparation, secure delivery, and audit history without a broad enterprise suite.
Start free