For delete, correct, and know requests, search the systems and relationships covered by the applicable rule, apply any exception to the affected records rather than the whole request, and coordinate required action with service providers and contractors. A deletion record may be retained only for permitted purposes, such as preventing later sale or meeting legal duties. A correction decision should consider the nature of the information, how it was obtained, and documentation supplied by the consumer.
For sale-or-sharing opt-outs, stop the covered transfers as soon as feasibly possible and no later than 15 business days. A browser opt-out preference signal applies to that browser or device and associated profiles; if the consumer is known, it also applies to that consumer. Notify and instruct third parties that received the information in the interval between receipt and compliance as section 7026 requires.
A denial should state the request, the reason the business did not comply, and any available next step. Verification failure does not create a general license to ignore a request: the workflow should record what was matched, what additional information was requested, why the chosen verification level was reasonable, and which rule supports the result.