Compliance Desk · SaaS, media, ad-tech and any business that sells or shares personal data
Privacy Request Desk 45 days
CCPA/CPRA and the other US state privacy laws (45-day response, 24-month records); GDPR Article 15 (one month).
- California requires at least two methods for consumers to submit access, deletion and correction requests, a response within 45 days (extendable once), identity verification, and records of requests kept for 24 months.
- By 2026 comparable laws apply in Virginia, Colorado, Connecticut, Utah, Texas, Oregon, Montana, Florida, Delaware, Iowa, Nebraska, New Hampshire, New Jersey, Tennessee, Minnesota, Maryland, Indiana, Kentucky and Rhode Island, most with 45-day deadlines.
- GDPR Article 15 gives EU residents access to their data within one month, extendable by two months for complex requests.
Primary source: https://cppa.ca.gov/regulations/
1. Generate your notice (free)
Fill the three fields and press Generate. The notice is plain-language text you can paste on your site; it points people to your request page (hosted here if you create a desk in step 2, or your own form).
2. Create your hosted desk
What the hosted desk does
- Public request page with the fields the law expects, including the good-faith statement and a typed signature.
- Ticket number and deadline (45 days) on every request; requesters get a status link.
- Your dashboard: countdowns, status updates (received, in review, actioned, declined with reason), notes, CSV and JSON export of the full log.
- Webhook to your own tools; no media is ever uploaded here.
Compliance Desk by agentexchange.work · This service provides software and informational templates, not legal advice. Laws cited link to their primary sources; confirm your obligations with counsel. · Privacy · Terms · Free check · llms.txt