Artifact GuideUSConsumer Rights Workflow

US CCPA Consumer Rights Workflow

Identify the right first. Delete, correct, know, ADMT access, opt-out, limit, and ADMT opt-out requests do not share one verification rule or one response clock.

Use the California regulations effective January 1, 2026 to assign the owner, deadline, identity check, exception analysis, downstream instruction, response, and retained evidence.

Author
Sorena AI
Published
May 9, 2026
Updated
Jul 27, 2026
Sections
4

Structured answer sets in this page tree.

Primary sources
3

Cited legal and guidance references.

Publication metadata
Sorena AI
Published May 9, 2026
Updated Jul 27, 2026
Overview

A California Consumer Privacy Act (CCPA) workflow should classify the right before treating the case as a , collecting identity data, or setting a deadline. Confirm receipt of delete, correct, know, and, when applicable, automated decisionmaking technology (ADMT) access and ADMT appeal requests within 10 business days and respond within 45 calendar days. Handle sale-or-sharing opt-outs, sensitive-personal-information limit requests, and applicable ADMT opt-outs through their separate non-verifiable paths. The ADMT duties apply to covered uses for significant decisions, with compliance required from January 1, 2027. The statute and regulations control the result; the case fields and tests below are practical evidence controls.

Section 1

How should the workflow classify and start a request?

Record the date received, channel, requested right, consumer or authorized-agent context, affected product or data flow, and the system owner. Treat a request received through an unlisted method as submitted or tell the consumer how to correct the deficiency. The 45-day clock starts on receipt, not after verification. A business may use one additional 45-day period when necessary if it tells the consumer and explains the reason, for a maximum of 90 calendar days.

Use a reasonable, documented identity-verification method for delete, correct, know, ADMT access, and ADMT appeal requests. For an account holder, use the existing account authentication when reasonable and require reauthentication before disclosure or deletion; for a non-account holder, match reliable data points and scale certainty to the sensitivity and risk. Do not require identity verification for sale-or-sharing opt-outs, sensitive-personal-information limit requests, or ADMT opt-outs. Ask only for information needed to complete those requests, and do not delay the scope that can already be honored.

  • Intake owner: classify the right and start every applicable clock on the date of receipt.
  • Privacy operations: match the verification level to the sensitivity of the data and the risk of unauthorized deletion, correction, or access.
  • Product or data owner: identify the systems, records, profiles, service providers, and contractors affected by the request.
  • Legal or privacy reviewer: identify the exact exception or verification failure before approving a denial.
Section 2

What action and evidence belong to each right?

For delete, correct, and know requests, search the systems and relationships covered by the applicable rule, apply any exception to the affected records rather than the whole request, and coordinate required action with service providers and contractors. A deletion record may be retained only for permitted purposes, such as preventing later sale or meeting legal duties. A correction decision should consider the nature of the information, how it was obtained, and documentation supplied by the consumer.

For sale-or-sharing opt-outs, stop the covered transfers as soon as feasibly possible and no later than 15 business days. A browser opt-out preference signal applies to that browser or device and associated profiles; if the consumer is known, it also applies to that consumer. Notify and instruct third parties that received the information in the interval between receipt and compliance as section 7026 requires.

A denial should state the request, the reason the business did not comply, and any available next step. Verification failure does not create a general license to ignore a request: the workflow should record what was matched, what additional information was requested, why the chosen verification level was reasonable, and which rule supports the result.

  • Know or access: retain the search scope, data sources checked, lookback period, verification result, disclosure method, and delivery date; distinguish categories from specific pieces and use reasonable security for delivery.
  • Delete or correct: retain the records changed or preserved, the exception relied on, downstream instructions, and completion evidence.
  • Opt-out or limit: retain the request or signal, affected identity scope, systems suppressed or restricted, completion time, and consumer-facing confirmation.
  • ADMT: retain the significant-decision use case, applicable notice, access or opt-out path, response, and any appeal record required by Article 11.
Section 3

Which branches and exceptions need explicit review?

A request may involve an authorized agent, a household, a minor, data held only by a service provider, a conflict with a financial incentive, a request for information older than 12 months, or information that a separate law requires the business to retain. These facts change the evidence or response path; they do not justify a generic rejection. For information collected on or after January 1, 2022, a request to know can reach beyond the preceding 12 months unless doing so is impossible or would involve disproportionate effort.

For an opt-out preference signal that conflicts with an account setting allowing sale or sharing, honor the signal unless the consumer later gives compliant consent. A financial-incentive conflict follows a narrower rule: the business may ask whether the consumer intends to withdraw from the program and must apply the regulation's outcome for the consumer's response or nonresponse.

  • Check signed authority and any direct consumer confirmation allowed for an authorized-agent request.
  • Separate information that must be retained under an exception, such as completing a transaction, security and integrity, legal compliance, or exercising legal claims, from information that can still be deleted.
  • Do not treat the absence of a later opt-out preference signal as consent when a known consumer previously sent one.
  • Escalate conflicting identities, fraud indicators, high-risk disclosures, and unclear statutory exceptions before the deadline expires.
Section 4

How should the workflow be reviewed?

Test the workflow when collection points, identity systems, ad-tech, ADMT uses, request portals, retention rules, or vendors change. Sample completed cases by right and confirm that intake dates, business-day and calendar-day clocks, verification data, search scope, exceptions, downstream instructions, delivery controls, and consumer responses agree.

Collect only the information needed to verify or complete the request. The CPPA's enforcement advisory applies the CCPA's data-minimization principle to request handling, so a convenient intake field is not enough reason to collect it.

  • Test one successful and one exception case for each right the business offers.
  • Reconcile request records with actual product, identity, suppression, deletion, and vendor-system state.
  • Check that the privacy policy describes the available rights, request methods, verification process, signal handling, and authorized-agent route.
  • Record corrective actions with an owner and due date when the evidence does not show that the request reached every required system.
Primary sources

References and citations

Related guides

Explore more topics

California Data Brokers: CCPA, Registration, and DROP Duties
Decide whether a CCPA business is also a California data broker and track registration, privacy metrics, DROP deletion, vendor, and audit duties.
CCPA Contract Classification: Service Provider or Third Party?
Classify CCPA recipients from their actual processing and contracts, then document the clauses, restrictions, monitoring, and opt-out consequences.
CCPA Dark Patterns: Rules, Examples, and Review Checklist
Check a CCPA privacy interface for clear language, symmetrical choices, unnecessary steps, and other designs that can invalidate consent.
CCPA Deadlines and Compliance Calendar
Track CCPA request clocks, annual duties, DROP dates, and phased 2026-2030 deadlines for risk assessments, ADMT, and cybersecurity audits.
CCPA Do Not Sell or Share Guide
Classify CCPA sales and sharing, provide valid opt-out methods, honor preference signals, stop disclosures within 15 business days, and notify recipients.
CCPA Do Not Sell or Share: Implementation and Testing
Implement CCPA sale-or-sharing opt-outs across links, GPC, consent state, ad tech, recipients, confirmation, privacy disclosures, and evidence.
CCPA Do Not Sell or Share: Scope and Implementation
Determine whether a transfer is a CCPA sale or sharing, provide the required opt-out path, honor preference signals, and propagate the choice.
CCPA DSAR Workflow: Intake, Verification, and Response
Run CCPA data-subject requests from intake through verification, search, exception review, downstream action, response, and retained evidence.
CCPA Financial Incentives: Notice, Consent, and Data Value
Assess a loyalty, discount, payment, or service program under the CCPA and document notice, opt-in, withdrawal, and data-value requirements.
CCPA Global Privacy Control (GPC): team obligations and technical implementation
Implement Global Privacy Control as a CCPA sale and sharing opt-out across browsers, devices, known accounts, and relevant downstream systems.
CCPA Minors: Opt-In Rules for Consumers Under 16
Apply the CCPA's under-13 parent authorization and age-13-to-15 consumer opt-in rules for sale or sharing of personal information.
CCPA Notice at Collection: Timing, Content, and Examples
Place a CCPA notice where consumers encounter it before collection and disclose categories, purposes, retention, sale or sharing, and required links.
CCPA Opt-Out Signal Workflow: Detect, Apply, and Test GPC
Process CCPA opt-out preference signals across browsers, devices, profiles, accounts, offline data, conflicts, recipients, and confirmation controls.
CCPA Penalties and Fines: Current Amounts
See current CCPA fines, civil penalties, security-breach damages, adjustment rules, and the facts needed before estimating exposure.
CCPA Personal and Sensitive Information Categories
Classify personal and sensitive personal information under the current CCPA, including exclusions and the duties each category can trigger.
CCPA Privacy Policy Template: Required Content and Review
Draft and maintain a CCPA privacy policy covering data practices, rights, request methods, GPC handling, minors, contacts, and the last-updated date.
CCPA Risk Assessments, Cybersecurity Audits, and ADMT
Apply California's regulations effective January 1, 2026 for risk-assessment triggers, phased cybersecurity audits, ADMT rights, evidence, reviews, and CPPA submissions.
CCPA vs CPRA: What Changed and Which Rules Apply
Compare the original CCPA with the CPRA amendments and learn why current California privacy work must use the CCPA as amended, not two separate laws.
CCPA vs GDPR: Scope, Rights, Duties, and Evidence
Compare the California CCPA and EU GDPR by scope, roles, legal basis, rights, advertising transfers, contracts, security, deadlines, and enforcement.
Does the CCPA apply to my business? Threshold guide
Apply the CCPA revenue, data-volume, and sale-or-sharing revenue thresholds, then check California nexus, control, joint ventures, roles, and exemptions.
US CCPA Applicability Test Guide
Apply the CCPA entity-by-entity: test California nexus, for-profit control, current thresholds, related-entity routes, exemptions, and processing roles.
US CCPA Compliance Checklist
A verifiable CCPA checklist for scope, data mapping, notices, rights, opt-outs, contracts, retention, security, risk assessments, audits, ADMT, and evidence.
US CCPA Compliance Guide
Build a CCPA operating model for entity scope, data mapping, notices, rights, opt-outs, contracts, retention, security, assessments, audits, ADMT, and evidence.
US CCPA Dark Patterns Guide
Review CCPA privacy interfaces for plain language, symmetry, minimal steps, neutral presentation, valid consent, and reliable opt-out operation.
US CCPA Data Broker Crossover Guide
Test whether a CCPA business is also a California data broker, then assign registration, metrics, DROP, deletion, downstream, and audit duties.
US CCPA DSAR Verification Guide
Verify CCPA know, delete, correct, and ADMT-access requests with request-specific, secure, minimized methods without adding friction to opt-outs.
US CCPA Enforcement and Penalties Guide
Understand CPPA investigations, Attorney General civil actions, CCPA administrative orders, current penalties, and the limited security-breach private action.
US CCPA Financial Incentives Guide
Decide whether a CCPA financial-incentive rule applies, then document the notice, data-value method, opt-in, withdrawal, and nondiscrimination checks.
US CCPA GPC Signal Guide
Implement Global Privacy Control under the CCPA across browsers, devices, accounts, ad technology, downstream recipients, and consumer notices.
US CCPA Minors Guide
Apply the CCPA opt-in rules for selling or sharing personal information of consumers under 16, including age bands, authorization, notices, and evidence.
US CCPA Notice at collection Guide
Build a CCPA Notice at Collection for online and offline collection points, including categories, purposes, sale or sharing, retention, links, and change control.
US CCPA Personal and Sensitive PI Categories Guide
Classify CCPA personal information and sensitive personal information, apply exclusions, and map each category to notices, rights, retention, security, sale, and sharing.
US CCPA Privacy Law FAQ
Direct answers on CCPA scope, rights, notices, opt-outs, GPC, minors, sensitive information, financial incentives, and data brokers.
US CCPA Privacy Notices and Disclosures Guide
Choose and maintain each CCPA consumer notice: privacy policy, collection, sale or sharing, sensitive-information limits, financial incentives, and ADMT.
US CCPA Privacy Policy Guide
Build and maintain a CCPA privacy policy covering online and offline practices, 12-month disclosures, consumer rights, request methods, and annual updates.
US CCPA Requirements Guide
Plain-language CCPA requirements covering scope, minimization, notices, rights, opt-outs, contracts, security, records, risk assessments, audits, and ADMT.
US CCPA Scope and Thresholds Guide
CCPA scope and threshold reference covering the current $26,625,000 revenue threshold, the 100,000-consumer-or-household test, related entities, and exemptions.
US CCPA Service Provider Contractor and Third Party Contracts Guide
Classify CCPA recipients and check the distinct contract terms for service providers, contractors, and third parties before disclosing personal information.
US CCPA Service Provider Contractor Contracts Guide
Check CCPA service-provider and contractor agreements for specific purposes, use restrictions, consumer-request support, subcontractors, and remediation.
US CCPA Thresholds Guide
Apply the CCPA business thresholds per legal entity, including the 2025 CPI-adjusted revenue amount, volume and sale-or-sharing tests, and control routes.
What must a CCPA privacy policy include?
A practical guide to CCPA privacy-policy content, placement, annual updates, consumer rights, request methods, and supporting evidence.
What must CCPA service-provider contracts include?
Required CCPA contract terms, role checks, subcontractor flow-downs, oversight rights, and evidence for service providers and contractors.
What should teams do about consumer request verification under the CCPA?
Choose a proportionate CCPA verification method for know, delete, and correct requests without collecting unnecessary identity data.
When does the CCPA require risk assessments or cyber audits?
CCPA triggers, deadlines, evidence, retention, and submission duties for risk assessments and annual cybersecurity audits.