skip to content

A US SaaS company launching in the EU wants one privacy programme — how can one request pipeline serve both GDPR and CCPA requests, and where must it branch?

level: seniorimportance: should knowfreq 48%

answer

  1. shared intake, regime-aware rules
  2. one month versus 45 days
  3. different rights menus
  4. opt-outs skip identity checks
  5. earliest deadline wins

basics

~20 s

One intake, identity and fulfilment pipeline can serve both if each request is tagged with its regime: branch on deadlines (GDPR one month plus two; CCPA 45 days plus 45), the rights offered, verification, and consent versus opt-out handling.

solid answer

~50 s

Share the plumbing, branch the rules. A single intake records **which regime applies** (a person in the EU, a California consumer, or both) and computes **per-regime deadlines**: under the GDPR, *without undue delay and in any event within one month*, extendable by **two further months** (Art. 12(3)); under the CCPA, confirm within **10 business days** and respond within **45 calendar days**, extendable once by **45** (1798.130(a)(2)(A); 11 CCR 7021). When both apply, work to the **earlier** date. The **rights menu** differs: restriction and objection exist only under the GDPR; opt-out of sale or sharing and the right to limit only under the CCPA. **Verification** differs: the GDPR lets a controller ask for more information only on reasonable doubts (Art. 12(6)); the CCPA scales certainty to sensitivity and forbids verifying opt-outs (11 CCR 7060, 7062). **Records** differ too: a 24-month request log in California (7101), accountability and Art. 30 records under the GDPR.

code

json · 16 lines
json
{
  "requestId": "rq-2026-10-00412",
  "receivedAt": "2026-10-05",
  "requestedAction": "delete",
  "regimes": ["GDPR", "CCPA"],
  "identityCheck": {
    "GDPR": "additional info requested: reasonable doubt, Art. 12(6)",
    "CCPA": "reasonable degree of certainty, 11 CCR 7062"
  },
  "deadlines": {
    "GDPR": {"respondBy": "2026-11-05", "maxWithExtension": "2027-01-05"},
    "CCPA": {"acknowledgeBy": "2026-10-19", "respondBy": "2026-11-19", "maxWithExtension": "2027-01-03"}
  },
  "effectiveRespondBy": "2026-11-05",
  "status": "verifying"
}

go deeper

for a junior

Recall the two headline deadlines: one month extendable by two under the GDPR, 45 days extendable by 45 under the CCPA.

for a middle

Explain where the rights menus, verification rules and records differ, and why the pipeline tags regimes at intake.

for a senior

Design the combined flow for a person under both regimes: earliest deadline, union of rights, stricter verification except for opt-outs.

for a principal

Decide how much to centralise, weighing one pipeline with regime rules against the cost of each new state or country regime.

## Share the plumbing, branch the rules Most of a request pipeline is regime-neutral: an intake form, identity matching, a search across systems for the person's data, fulfilment jobs that export, delete or correct, and a response. The **rules** that govern each stage differ between the **GDPR** and the **CCPA** as amended by the CPRA. The durable design tags each request with its applicable regime or regimes at intake and lets the rules, not separate pipelines, vary. ## Where the pipeline must branch | Stage | GDPR | CCPA as amended by the CPRA | |---|---|---| | Deadline | without undue delay, within **one month**; extendable by **two further months**, with notice and reasons within the first month (Art. 12(3)) | acknowledge within **10 business days** (11 CCR 7021(a)); respond within **45 calendar days** of receipt; one extension of **45** with notice inside the first 45 (1798.130(a)(2)(A); 7021(b)) | | Refusal | reasons and the right to complain and seek a judicial remedy, within one month (Art. 12(4)) | reasons and any appeal rights, within the response period (1798.145(h)(2)) | | Rights menu | access, rectification, erasure, restriction, portability, objection, Art. 22 (Arts. 15-22) | know, delete, correct, opt out of sale or sharing, limit sensitive data, non-discrimination | | Identity | may request additional information where there are **reasonable doubts** (Art. 12(6)) | documented method, certainty scaled to sensitivity (11 CCR 7060-7062); **no verification** for opt-out or limit requests (7060(b)) | | Fees | free; fee or refusal for manifestly unfounded or excessive requests (Art. 12(5)) | free; fee or refusal for manifestly unfounded or excessive requests (1798.145(h)(3)) | | Records | accountability (Art. 5(2)); records of processing activities (Art. 30) | request log kept **24 months** (11 CCR 7101) | Two rows look alike on purpose: both regimes make requests free and allow a fee or refusal for manifestly unfounded or excessive ones. The deadline row is where teams most often slip, by treating 45 days and one month as interchangeable. ## The consent and opt-out layer The preference store behind the pipeline carries different meanings per regime: - **GDPR consent** is recorded per purpose with proof (Art. 7(1)); withdrawal must be as easy as giving it (Art. 7(3)); an objection to direct marketing stops that processing (Art. 21(2)-(3)). - **CCPA opt-outs** are recorded as a direction not to sell or share, and a limit on sensitive-data use; a business that sells or shares must treat a valid **opt-out preference signal** as an opt-out request (11 CCR 7025(b)), and must stop selling or sharing no later than **15 business days** after receipt (7026(f)(1)). One record can hold both, but a GDPR "consent withdrawn" and a CCPA "opted out of sharing" must stay distinct fields: they trigger different downstream actions. ## Resolving a person covered by both A California resident who is in the EU while using an EU-established service can fall under both regimes, provided the company is also a CCPA business. The pipeline should: 1. Record every applicable regime, not just the first match. 2. Compute each regime's deadline and track the **earliest**; send the CCPA acknowledgement inside 10 business days regardless. 3. Offer the **union** of rights, then apply each right's own conditions and exceptions. 4. Verify to the **stricter** applicable standard, except for CCPA opt-outs, which may not be gated on identity. 5. Log the request in a form that satisfies the CCPA's 24-month record and the GDPR's accountability duty together. ## Fulfilment: same job, different scope Even when both regimes ask for "the same" action, the fulfilment step needs regime parameters: - **Look-back.** A CCPA request to know covers, by default, the **12 months** before the request (1798.130(a)(2)(B)); GDPR access under Art. 15 has no such window. - **Exceptions.** Erasure under the GDPR and deletion under the CCPA carry **different** grounds for refusal, so the retention-hold check runs once per applicable regime. - **Format.** Both expect portable, commonly used electronic formats where feasible, so one export format can usually serve both. ## Misconceptions - That one month and 45 days are the same deadline. - That the GDPR's extension and the CCPA's extension have the same length. - That opt-out requests should pass the same identity checks as access requests. - That a single "privacy status" boolean can represent both regimes.

  • For a request under both regimes, which extension rule should the pipeline apply?
    Each on its own terms. Under the GDPR the controller may extend by **two further months**, telling the person within the first month with reasons (Art. 12(3)); under the CCPA, once by **45 days**, with notice inside the first 45 (1798.130(a)(2)(A)). The earlier of the two deadlines, with or without extension, governs the combined response.
  • Why must a California opt-out of sale skip the identity check an EU access request might need?
    11 CCR 7060(b) forbids requiring identity verification to opt out of sale or sharing or to limit, allowing only information necessary to complete the request. Access requests under the GDPR carry disclosure risk, so Art. 12(6) permits asking for more information on reasonable doubts; the opt-out does not.

saying these in an interview costs you the question

  • The GDPR's one month and the CCPA's 45 days are the same deadline.
  • Both regimes allow the same length of extension.
  • CCPA opt-out requests should pass the same identity checks as access requests.
  • One boolean privacy flag can represent GDPR consent and CCPA opt-out.
  • A request covered by both regimes should follow only the later deadline.