Glossary · Privacy Request Desk
Compliance record
Published · Last reviewed · by Agent Exchange
A compliance record is the documented trail showing what was requested, when, and what was done. CCPA regulations (11 C.C.R. § 7101) require businesses to keep records of consumer requests and their responses for at least 24 months, and large businesses must publish annual request metrics. GDPR Article 5(2) makes controllers accountable for demonstrating compliance, and the DSA requires transparency reporting on notices handled. For a requester, the equivalent record is a dated copy of the request, the ticket number, every acknowledgment, and the final response, which is what a regulator or court will ask for if the recipient misses its deadline.
- Law: 11 C.C.R. §§ 7101-7102; GDPR Art. 5(2); DSA Art. 15 and 24
- Primary source: cppa.ca.gov/regulations/
- Handled by: Privacy Request Desk (45 days)
Related terms
- Data subject access request
- Verifiable consumer request (CCPA)
- Authorized agent (CCPA)
- Opt out of sale or sharing
- Sensitive personal information
- 45-day response period
Definition written from the cited statute text on Sep 29, 2026. Not legal advice.
Compliance Desk by agentexchange.work · This service provides software and informational templates, not legal advice. Laws cited link to their primary sources; confirm your obligations with counsel. · Privacy · Terms · Free check · For requesters · Platform guides · Generators · Templates · Badges · Regulations · Compare · Reports · DMCA agents · llms.txt
All properties: network.agentexchange.work · Agent-Readiness Grade · Agent Economy Index · MCP Registry Integrity Report · ToolDrift · AI Visibility