Compliance Desk · Privacy Request Desk · answer
CCPA and state privacy laws: how do I take consumer requests and answer within 45 days?
California requires at least two ways to submit a request (a web form counts as one; add an email address or a toll-free number), identity verification proportional to the request, a response within 45 days that can be extended once by another 45 days with an explanation, and records of requests and responses for 24 months. Most other state laws (Virginia, Colorado, Connecticut, Texas, Oregon, Montana, New Jersey, Minnesota, Maryland, Indiana, Kentucky, Rhode Island and more) use the same 45-day clock.
Requests you must handle: access (know), deletion, correction, opting out of sale or sharing, and limiting the use of sensitive personal information. You cannot discriminate against people for asking.
Log every request with a ticket number, the verification step and the response date; that record is what an auditor or the California Privacy Protection Agency asks for first.
Primary source: https://cppa.ca.gov/regulations/. Informational, not legal advice.
Ready-to-paste notice
Your privacy rights ([Your site]) Depending on where you live, you may have the right to access, correct or delete the personal information [Your site] ([your URL]) holds about you, to opt out of its sale or sharing, and to limit the use of sensitive information. You will not be discriminated against for exercising these rights. How to submit a request: use our request form (link this text to your Compliance Desk request page), or contact [contact email]. We verify your identity using information we already hold, never your password. We respond within 45 days (or one month under the GDPR), and we may extend once when the law allows, telling you why. Authorized agents may submit requests with proof of authority. We keep a record of requests for 24 months as required.
What the request form must collect
- Your full name
- Email address associated with your account or data
- Request type: access / deletion / correction / opt out of sale or sharing / limit use of sensitive data
- Which of our products or accounts this concerns (URLs, usernames or order numbers)
- Anything that helps us find your data or verify your identity (we will never ask for passwords)
- Good-faith statement: “I confirm that I am the person whose data this request concerns, or their authorized agent, and that the information provided is accurate.”
- Typed signature
Related answers
- Does the TAKE IT DOWN Act apply to my website, app or community?
- TAKE IT DOWN Act notice and removal request form: what must they include?
- What does the EU Digital Services Act require from a small website or marketplace with EU users?
- DSA statement of reasons: what a small platform has to send when it removes content
- GDPR access requests: what a small company must do within one month
- European Accessibility Act: what small e-commerce and service sites must publish since June 2025
Compliance Desk by agentexchange.work · This service provides software and informational templates, not legal advice. Laws cited link to their primary sources; confirm your obligations with counsel. · Privacy · Terms · Free check · llms.txt