skip to content

Under the CCPA, a customer-service team handles 300 consumer requests a month — what response deadlines apply, and what must it record?

level: middleimportance: must knowfreq 55%

answer

  1. the clock starts at receipt
  2. 10 business days to acknowledge
  3. 45 calendar days, one extension
  4. 90 days is the ceiling
  5. a log kept 24 months

basics

~20 s

Under the CCPA regulations, a business confirms receipt within 10 business days and responds within 45 calendar days of receipt, extendable once by 45 with notice and reasons, then logs each request and response for at least 24 months (11 CCR 7021, 7101).

solid answer

~50 s

For requests to know, delete and correct, 11 CCR 7021(a) requires the business to **confirm receipt within 10 business days** and explain how it will process the request. Civil Code 1798.130(a)(2)(A) and 7021(b) then require a response **within 45 calendar days of receipt**; the clock runs from the day the request arrives, **regardless of time spent verifying**, and a consumer still unverified at day 45 may be denied. Where reasonably necessary the business may extend **once, by up to 45 more days** (90 in total), if it tells the consumer within the first 45 days and gives the reason. A refusal must be explained within the same window (1798.145(h)(2)). Under 7101 it keeps a record of every request and response for **at least 24 months**: date, nature, manner of the request, date and nature of the response, and the basis for any denial.

code

json · 12 lines
json
{
  "requestId": "req-2026-09-0147",
  "dateReceived": "2026-09-03",
  "natureOfRequest": "request_to_delete",
  "mannerSubmitted": "toll_free_phone",
  "acknowledgedOn": "2026-09-10",
  "extensionNoticeSentOn": null,
  "dateOfResponse": "2026-10-09",
  "natureOfResponse": "denied_in_part",
  "denialBasis": "transaction records retained to complete the consumer's pending order",
  "retainRecordUntil": "2028-10-09"
}

go deeper

for a junior

Recall the numbers and their units: 10 business days to acknowledge, 45 calendar days to respond, one 45-day extension, 24 months of records.

for a middle

Explain that the clock starts at receipt, not verification, and what a valid extension notice or denial must contain and when.

for a senior

Show how you would instrument a ticketing flow so no request silently crosses day 45 and the log proves every deadline was met.

for a principal

Decide how request handling scales, whether to automate intake and verification, and how the 24-month log itself stays minimised and secure.

## The clock for know, delete and correct requests Under the CCPA as amended by the CPRA, the deadline sits in two places. Civil Code **1798.130(a)(2)(A)** sets **45 days** to disclose, correct or delete after receiving a verifiable consumer request, extendable once. The CPPA regulations at 11 CCR **7021** turn that into a timeline a support team can run: 1. **Day 0: receipt.** The 45-day period begins on the day the business receives the request, *regardless of time required to verify it* (7021(b)). Verification is expected promptly but does not pause the clock (1798.130(a)(2)(A)). 2. **Within 10 business days: acknowledge.** Confirm receipt and describe, in general, the verification process and when to expect a response, unless the request has already been granted or denied (7021(a)). A phone request can be acknowledged orally on the call. 3. **Within 45 calendar days: respond**, or send an **extension notice** with the reason. 4. **At most 90 calendar days from receipt: final response**, if the one extension was taken (7021(b); 1798.145(h)(1)). These deadlines cover requests to **know, delete and correct**. Requests to opt out of sale or sharing and to limit sensitive-data use run on their own, shorter clocks in 11 CCR 7026 and 7027. ## What the extension and a denial require | Situation | Rule | Source | |---|---|---| | Needs more time | one extension of up to 45 days, noticed inside the first 45, with the reason | 1798.130(a)(2)(A); 7021(b); 1798.145(h)(1) | | Cannot verify by day 45 | may deny the request | 7021(b) | | Not acting on it | tell the consumer why, and any appeal rights, without delay and within the response period | 1798.145(h)(2) | | Manifestly unfounded or excessive | may charge a reasonable fee or refuse, bearing the burden of proof | 1798.145(h)(3) | The days are **calendar** days in 7021(b); in this timeline only the acknowledgement is counted in business days. Extensions are not rolling: there is one, and 90 days is the ceiling. ## The records the team must keep 11 CCR **7101** requires records of consumer requests **and how the business responded** for **at least 24 months**, kept with reasonable security. A ticket or log is fine if each entry carries: - the **date of the request**; - the **nature** of the request; - the **manner** in which it was made; - the **date of the response**; - the **nature of the response**; - the **basis for denial**, if denied in whole or in part. Where a business verifies a request for specific pieces with a signed declaration, it keeps the declarations as part of these records (7062(c)). The log has its own purpose limit: it may be used only to review and improve CCPA compliance processes and shared with a third party only to meet a legal obligation (7101(d)). And 7101(e) cuts the other way: a business need not retain personal information solely in case a consumer asks for it later. ## Sizing it for 300 requests a month At 300 a month the team carries roughly **7,200 log entries** inside any 24-month window, and on any given day dozens of requests sit somewhere between receipt and response. The practical implications: - Store **received date** as the clock anchor, and compute two due dates per ticket: acknowledgement (10 business days) and response (45 calendar days). - Alert on requests approaching day 45 without a response or an extension notice. - Record the extension notice date, because the right to extend depends on it having gone out inside the first 45 days. - Make the denial basis a required field whenever the response is not a full grant. - Everyone handling these inquiries must know the CCPA's requirements and how to direct consumers (1798.130(a)(6); 11 CCR 7100(a)). Two duties switch on only at scale: a business handling the personal information of **10,000,000 or more consumers** in a calendar year must keep a documented training policy (7100(b)) and publish yearly request metrics by **July 1** (7102). A 300-a-month team is not triggered by its request volume; the threshold counts consumers whose data the business handles. ## Common mistakes - Starting the clock at verification instead of receipt. - Treating 45 days as business days. - Sending a second extension notice. - Purging request tickets after a year to save storage.

  • Under the CCPA regulations, verification of a deletion request is still pending on day 44. What are the options?
    The clock did not pause for verification. The business may **deny** the request because it could not verify the consumer within 45 days (11 CCR 7021(b)), telling the consumer why (1798.145(h)(2)), or, if more time is **reasonably necessary**, send the one extension notice with its reason before day 45 and finish within 90 days.
  • Under the CCPA regulations, can the request log be used to train a churn-prediction model?
    No. 11 CCR 7101(d) allows record-keeping information to be used only as reasonably necessary to review and modify the business's CCPA compliance processes, and it may be shared with third parties only to comply with a legal obligation.
  • Under the CCPA regulations, when must a business publish yearly metrics about the requests it handles?
    When it buys, receives, sells, shares or otherwise makes available the personal information of **10,000,000 or more consumers** in a calendar year. It then compiles, per request type, requests received, complied with and denied, plus the median or mean days to respond, and discloses them **by July 1** (11 CCR 7102).

saying these in an interview costs you the question

  • The 45 days start only once the requester's identity is verified.
  • The CCPA response window is 45 business days.
  • A business can keep extending as long as it keeps notifying the consumer.
  • Request records can be purged after 12 months.
  • The request log may be reused for product analytics because it is internal.