---
title: "US CCPA DSAR Workflow Guide"
canonical_url: "https://www.sorena.io/artifacts/us/california-consumer-privacy-act/dsar-workflow"
source_url: "https://www.sorena.io/artifacts/us/california-consumer-privacy-act/dsar-workflow"
author: "Sorena AI"
description: "US CCPA guidance for DSAR Workflow, with practical decisions, evidence, edge cases, and external source citations."
published_at: "2026-05-09"
updated_at: "2026-05-09"
keywords:
  - "US CCPA"
  - "DSAR Workflow"
  - "US CCPA DSAR Workflow"
  - "compliance checklist"
  - "practical guidance"
  - "Compliance"
  - "Regulatory guidance"
---
**[SORENA](https://www.sorena.io/)** - AI-Powered GRC Platform

[Home](https://www.sorena.io/) | [Solutions](https://www.sorena.io/solutions) | [Artifacts](https://www.sorena.io/artifacts) | [About Us](https://www.sorena.io/about-us) | [Contact](https://www.sorena.io/contact) | [Portal](https://app.sorena.io)

---

# US CCPA DSAR Workflow Guide

US CCPA guidance for DSAR Workflow, with practical decisions, evidence, edge cases, and external source citations.

*Artifact Guide* *US* *DSAR Workflow*

## US CCPA DSAR Workflow

DSAR Workflow decisions under the US CCPA should be written in operational language: who is in scope, what must happen, what evidence proves it, and when escalation is needed.

This guide converts official requirements for requests to delete, correct, know, opt-out of sale/sharing, limit the use and disclosure of sensitive personal information, and access or opt-out of ADMT into scope, evidence, ownership, and review decisions for practical implementation, supporting implementation planning and should be validated against jurisdiction-specific legal, contractual, and policy requirements before implementation.

This page maps US CCPA obligations for delete, correct, know, opt-out of sale/sharing, limit-use, and ADMT request handling to trigger conditions, accountable owners, required deadlines, evidence records, and review paths that product, legal, privacy, security, and compliance teams can apply.

## How should a DSAR Workflow run under the US CCPA?

Run the workflow as California privacy operations by routing each request type to the right intake path, verifying the consumer when required, checking the applicable response deadline, coordinating any deletion, correction, disclosure, opt-out, or limit action across service providers and contractors, and recording the evidence and review needed to show the request was handled correctly.

- Capture the request, product, role, data flow, jurisdiction, and deadline.
- Check the source-linked rule and route exceptions before implementation.
- Record the action taken, owner, reviewer, evidence location, and next review date.
- Keep a plain-language output that support, product, legal, security, and compliance teams can all understand.

Sources for this answer:

- [California Consumer Privacy Act (CCPA)](https://oag.ca.gov/privacy/ccpa?ref=sorena.io) - California Attorney General guidance confirms the consumer-request response clock and verification-use boundary that a CCPA request workflow must capture.
- [CCPA Updates, Cybersecurity Audits, Risk Assessments, Automated Decisionmaking Technology (ADMT), and Insurance Regulations](https://cppa.ca.gov/regulations/ccpa_updates.html?ref=sorena.io) - CPPA rulemaking source for updated CCPA operational requirements that can affect consumer-request workflows.
- [TEXT OF REGULATIONS](https://cppa.ca.gov/?ref=sorena.io) - CPPA regulations source for consumer-rights handling, request methods, verification, and response procedures.

## What fields should the DSAR Workflow template capture?

A useful template captures threshold, consumer/data category, request or signal type, notice location, vendor role, response deadline, evidence link, and escalation reason.

- Source URL and source quote.
- Entity, product, service, system, data category, and user group.
- Decision result, control action, owner, reviewer, due date, and escalation reason.
- Evidence attachment, approval note, exception note, and review cadence.

Sources for this answer:

- [CCPA Updates, Cybersecurity Audits, Risk Assessments, Automated Decisionmaking Technology (ADMT), and Insurance Regulations](https://cppa.ca.gov/regulations/ccpa_updates.html?ref=sorena.io) - Template field support for DSAR Workflow.
- [TEXT OF REGULATIONS](https://cppa.ca.gov/?ref=sorena.io) - Template field support for DSAR Workflow.
- [California Consumer Privacy Act Regulations (March 2023)](https://cppa.ca.gov/regulations/consumer_privacy_act.html?ref=sorena.io) - Template field support for DSAR Workflow.

## How should teams review and improve the DSAR Workflow?

Review the workflow after CPPA updates, ad-tech changes, new collection points, vendor changes, consumer complaints, enforcement advisories, or material product changes.

- Track recurring exception categories and update intake questions.
- Remove fields that never affect the decision.
- Add fields when reviews show missing source evidence or unclear ownership.
- Confirm the public page content and source-linked guidance stay aligned after each workflow update.

Sources for this answer:

- [California Consumer Privacy Act (CCPA)](https://oag.ca.gov/privacy/ccpa?ref=sorena.io) - California Attorney General guidance supports CCPA consumer-request verification, limited use of verification data, and 45-calendar-day response tracking.
- [CCPA Updates, Cybersecurity Audits, Risk Assessments, Automated Decisionmaking Technology (ADMT), and Insurance Regulations](https://cppa.ca.gov/regulations/ccpa_updates.html?ref=sorena.io) - Review support for DSAR Workflow.
- [TEXT OF REGULATIONS](https://cppa.ca.gov/?ref=sorena.io) - Review support for DSAR Workflow.
- [California Consumer Privacy Act Regulations (March 2023)](https://cppa.ca.gov/regulations/consumer_privacy_act.html?ref=sorena.io) - Review support for DSAR Workflow.

*Recommended next step*

*Placement: after the practical guidance*

## Turn US CCPA DSAR Workflow into assigned work

This US CCPA guide turns DSAR Workflow into owners, evidence requests, review checkpoints, and reusable operating records inside Sorena.

- [Open Assessment Autopilot for US CCPA](/solutions/assessment.md): Turn DSAR Workflow into scoped questions, evidence fields, and review tasks.
- [Review US CCPA source evidence](/solutions/research-copilot.md): Use Research Copilot to answer follow-up questions with cited source material.
- [Talk through implementation](/contact.md): Review scope, evidence, owners, and the next compliance actions with Sorena.

## Primary sources

- [California Consumer Privacy Act (CCPA)](https://oag.ca.gov/privacy/ccpa?ref=sorena.io) - California Attorney General guidance supports CCPA consumer-request intake, verification limits, and 45-calendar-day response tracking.
  - Quote: "Businesses must respond to your request within 45 calendar days."
- [CCPA Updates, Cybersecurity Audits, Risk Assessments, Automated Decisionmaking Technology (ADMT), and Insurance Regulations](https://cppa.ca.gov/regulations/ccpa_updates.html?ref=sorena.io) - Supports DSAR Workflow under the US CCPA.
  - Quote: "CCPA Updates, Cybersecurity Audits, Risk Assessments, Automated Decisionmaking Technology (ADMT), and Insurance Regulations"
- [TEXT OF REGULATIONS](https://cppa.ca.gov/?ref=sorena.io) - Supports DSAR Workflow under the US CCPA.
  - Quote: "--- CA PRIVACY PROTECTION AGENCY - TEXT OF REGULATIONS (CCPA Updates, Cyber, Risk, ADMT, and Insurance Regulations) Page"
- [California Consumer Privacy Act Regulations (March 2023)](https://cppa.ca.gov/regulations/consumer_privacy_act.html?ref=sorena.io) - Supports DSAR Workflow under the US CCPA.
  - Quote: "On March 29, 2023, the Office of Administrative Law approved the California Privacy Protection Agency's regulations and filed"
- [Enforcement Advisory No. 2024-01 Applying Data Minimization to Consumer Requests](https://cppa.ca.gov/pdf/enfadvisory202401.pdf?ref=sorena.io) - Supports DSAR Workflow under the US CCPA.
  - Quote: "2024-01 Applying Data Minimization to Consumer Requests Short Title Enforcement Advisory No"

## Related Topic Guides

- [California CCPA/CPRA Opt Out Signal Workflow Guide](/artifacts/us/california-consumer-privacy-act/opt-out-signal-workflow.md): California CCPA/CPRA guidance for Opt Out Signal Workflow, with practical decisions, evidence, edge cases, and external source citations.
- [CCPA Global Privacy Control (GPC): team obligations and technical implementation](/artifacts/us/california-consumer-privacy-act/faq/gpc.md): US CCPA guidance for GPC, with practical decisions, evidence, edge cases, and external source citations.
- [How should teams decide whether US CCPA applies?](/artifacts/us/california-consumer-privacy-act/faq/thresholds.md): US CCPA guidance for Thresholds, with practical decisions, evidence, edge cases, and external source citations.
- [US CCPA Applicability Test Guide](/artifacts/us/california-consumer-privacy-act/applicability-test.md): Practical guidance for the US CCPA applicability test, with practical decisions, evidence, edge cases, and external source citations.
- [US CCPA Compliance Checklist](/artifacts/us/california-consumer-privacy-act/checklist.md): Practical guidance for the US CCPA checklist, with practical decisions, evidence, edge cases, and external source citations.
- [US CCPA Compliance Guide](/artifacts/us/california-consumer-privacy-act/compliance.md): Practical guidance for the US CCPA compliance, with practical decisions, evidence, edge cases, and external source citations.
- [US CCPA Consumer Rights Workflow Guide](/artifacts/us/california-consumer-privacy-act/consumer-rights-workflow.md): US CCPA guidance for Consumer Rights Workflow, with practical decisions, evidence, edge cases, and external source citations.
- [US CCPA Contract Classification Workflow Guide](/artifacts/us/california-consumer-privacy-act/contract-classification-workflow.md): US CCPA guidance for Contract Classification Workflow, with practical decisions, evidence, edge cases, and external source citations.
- [US CCPA Dark Patterns Guide](/artifacts/us/california-consumer-privacy-act/dark-patterns.md): US CCPA guidance for Dark Patterns, with practical decisions, evidence, edge cases, and external source citations.
- [US CCPA Data Broker Crossover Guide](/artifacts/us/california-consumer-privacy-act/data-broker-crossover.md): US CCPA guidance for Data Broker Crossover, with practical decisions, evidence, edge cases, and external source citations.
- [US CCPA Deadlines and Compliance Calendar Guide](/artifacts/us/california-consumer-privacy-act/deadlines-and-compliance-calendar.md): US CCPA guidance for Deadlines and Compliance Calendar, with practical decisions, evidence, edge cases, and external source citations.
- [US CCPA Do not sell or share Guide](/artifacts/us/california-consumer-privacy-act/do-not-sell-or-share.md): US CCPA guidance for Do not sell or share, with practical decisions, evidence, edge cases, and external source citations.
- [US CCPA Do Not Sell Share Implementation Guide](/artifacts/us/california-consumer-privacy-act/do-not-sell-share-implementation.md): US CCPA guidance for Do Not Sell Share Implementation, with practical decisions, evidence, edge cases, and external source citations.
- [US CCPA DSAR Verification Guide](/artifacts/us/california-consumer-privacy-act/dsar-verification.md): US CCPA guidance for DSAR Verification, with practical decisions, evidence, edge cases, and external source citations.
- [US CCPA Enforcement And Penalties Guide](/artifacts/us/california-consumer-privacy-act/enforcement-and-penalties.md): US CCPA guidance for Enforcement And Penalties, with practical decisions, evidence, edge cases, and external source citations.
- [US CCPA Financial Incentives Guide](/artifacts/us/california-consumer-privacy-act/financial-incentives.md): US CCPA guidance for Financial Incentives, with practical decisions, evidence, edge cases, and external source citations.
- [US CCPA GPC Signal Guide](/artifacts/us/california-consumer-privacy-act/gpc.md): US CCPA guidance for GPC, with practical decisions, evidence, edge cases, and external source citations.
- [US CCPA Minors Guide](/artifacts/us/california-consumer-privacy-act/minors.md): US CCPA guidance for Minors, with practical decisions, evidence, edge cases, and external source citations.
- [US CCPA Notice at collection Guide](/artifacts/us/california-consumer-privacy-act/notice-at-collection.md): US CCPA guidance for Notice at collection, with practical decisions, evidence, edge cases, and external source citations.
- [US CCPA penalties and fines Guide](/artifacts/us/california-consumer-privacy-act/penalties-and-fines.md): US CCPA guidance for penalties and fines, with practical decisions, evidence, edge cases, and external source citations.
- [US CCPA Personal And Sensitive Pi Categories Guide](/artifacts/us/california-consumer-privacy-act/personal-and-sensitive-pi-categories.md): US CCPA guidance for Personal And Sensitive Pi Categories, with practical decisions, evidence, edge cases, and external source citations.
- [US CCPA Privacy Law FAQ](/artifacts/us/california-consumer-privacy-act/faq.md): Practical guidance for the US CCPA FAQ, with practical decisions, evidence, edge cases, and external source citations.
- [US CCPA Privacy Notices And Disclosures Guide](/artifacts/us/california-consumer-privacy-act/privacy-notices-and-disclosures.md): US CCPA guidance for Privacy Notices And Disclosures, with practical decisions, evidence, edge cases, and external source citations.
- [US CCPA Privacy Policy Guide](/artifacts/us/california-consumer-privacy-act/privacy-policy.md): US CCPA guidance for Privacy Policy, with practical decisions, evidence, edge cases, and external source citations.
- [US CCPA Privacy Policy Template Guide](/artifacts/us/california-consumer-privacy-act/ccpa-privacy-policy-template.md): US CCPA guidance for CCPA Privacy Policy Template, with practical decisions, evidence, edge cases, and external source citations.
- [US CCPA Requirements Guide](/artifacts/us/california-consumer-privacy-act/requirements.md): Practical guidance for the US CCPA requirements, with practical decisions, evidence, edge cases, and external source citations.
- [US CCPA Risk And Cyber Audits Guide](/artifacts/us/california-consumer-privacy-act/risk-and-cyber-audits.md): US CCPA guidance for Risk And Cyber Audits, with practical decisions, evidence, edge cases, and external source citations.
- [US CCPA Scope and Thresholds Guide](/artifacts/us/california-consumer-privacy-act/scope-and-thresholds.md): US CCPA guidance for Scope and Thresholds, with practical decisions, evidence, edge cases, and external source citations.
- [US CCPA Service Provider Contractor And Third Party Contracts Guide](/artifacts/us/california-consumer-privacy-act/service-provider-contractor-and-third-party-contracts.md): US CCPA guidance for Service Provider Contractor And Third Party Contracts, with practical decisions, evidence, edge cases, and external source citations.
- [US CCPA Service Provider Contractor Contracts Guide](/artifacts/us/california-consumer-privacy-act/service-provider-contractor-contracts.md): US CCPA guidance for Service Provider Contractor Contracts, with practical decisions, evidence, edge cases, and external source citations.
- [US CCPA Thresholds Guide](/artifacts/us/california-consumer-privacy-act/thresholds.md): US CCPA guidance for Thresholds, with practical decisions, evidence, edge cases, and external source citations.
- [US CCPA vs CPRA Guide](/artifacts/us/california-consumer-privacy-act/ccpa-vs-cpra.md): US CCPA guidance for CCPA vs CPRA, with practical decisions, evidence, edge cases, and external source citations.
- [US CCPA vs GDPR Guide](/artifacts/us/california-consumer-privacy-act/ccpa-vs-gdpr.md): US CCPA guidance for CCPA vs GDPR, with practical decisions, evidence, edge cases, and external source citations.
- [What should teams do about consumer request verification under the CCPA?](/artifacts/us/california-consumer-privacy-act/faq/dsar-verification.md): US CCPA guidance for consumer request verification, with practical decisions, evidence, edge cases, and external source citations.
- [What should teams do about Dark Patterns under the US CCPA?](/artifacts/us/california-consumer-privacy-act/faq/dark-patterns.md): US CCPA guidance for Dark Patterns, with practical decisions, evidence, edge cases, and external source citations.
- [What should teams do about Data Broker Crossover under the US CCPA?](/artifacts/us/california-consumer-privacy-act/faq/data-broker-crossover.md): US CCPA guidance for Data Broker Crossover, with practical decisions, evidence, edge cases, and external source citations.
- [What should teams do about Do not sell or share under the US CCPA?](/artifacts/us/california-consumer-privacy-act/faq/do-not-sell-or-share.md): US CCPA guidance for Do not sell or share, with practical decisions, evidence, edge cases, and external source citations.
- [What should teams do about Financial Incentives under the US CCPA?](/artifacts/us/california-consumer-privacy-act/faq/financial-incentives.md): US CCPA guidance for Financial Incentives, with practical decisions, evidence, edge cases, and external source citations.
- [What should teams do about Minors under the California CCPA?](/artifacts/us/california-consumer-privacy-act/faq/minors.md): US CCPA guidance for Minors, with practical decisions, evidence, edge cases, and external source citations.
- [What should teams do about Notice at collection under the US CCPA?](/artifacts/us/california-consumer-privacy-act/faq/notice-at-collection.md): US CCPA guidance for Notice at collection, with practical decisions, evidence, edge cases, and external source citations.
- [What should teams do about Personal And Sensitive Pi Categories under the US CCPA?](/artifacts/us/california-consumer-privacy-act/faq/personal-and-sensitive-pi-categories.md): US CCPA guidance for Personal And Sensitive Pi Categories, with practical decisions, evidence, edge cases, and external source citations.
- [What should teams do about Privacy Policy under the US CCPA?](/artifacts/us/california-consumer-privacy-act/faq/privacy-policy.md): US CCPA guidance for Privacy Policy, with practical decisions, evidence, edge cases, and external source citations.
- [What should teams do about Risk And Cyber Audits under the US CCPA?](/artifacts/us/california-consumer-privacy-act/faq/risk-and-cyber-audits.md): US CCPA guidance for Risk And Cyber Audits, with practical decisions, evidence, edge cases, and external source citations.
- [What should teams do about Service Provider And Contractor Contracts under the US CCPA?](/artifacts/us/california-consumer-privacy-act/faq/service-provider-and-contractor-contracts.md): US CCPA guidance for Service Provider And Contractor Contracts, with practical decisions, evidence, edge cases, and external source citations.


---

[Privacy Policy](https://www.sorena.io/privacy) | [Terms of Use](https://www.sorena.io/terms-of-use) | [DMCA](https://www.sorena.io/dmca) | [About Us](https://www.sorena.io/about-us)

(c) 2026 Sorena AB (559573-7338). All rights reserved.

Source: https://www.sorena.io/artifacts/us/california-consumer-privacy-act/dsar-workflow
