Artifact GuideUSConsumer Rights Workflow

US CPRA Consumer Rights Workflow

Use this workflow to process California requests to know, delete, correct, opt out of sale or sharing, and limit sensitive-personal-information use or disclosure.

Add the covered automated-decisionmaking branches by January 1, 2027, including access and either opt-out or a qualifying appeal path where applicable. Route every request by right because verification, deadlines, exceptions, recipients, and response evidence differ.

Author
Sorena AI
Published
May 9, 2026
Updated
Jul 25, 2026
Sections
3

Structured answer sets in this page tree.

Primary sources
7

Cited legal and guidance references.

Publication metadata
Sorena AI
Published May 9, 2026
Updated Jul 25, 2026
Overview

Start by identifying the right and confirming that the requester is a California consumer whose information is handled by a covered business. Requests to know, delete, and correct require risk-based identity verification, acknowledgement within 10 business days, and a response within 45 calendar days from receipt, with one explained extension of up to 45 more days when necessary. Opt-out and limit requests must not be conditioned on identity verification and must be completed as soon as feasibly possible, no later than 15 business days. A complete workflow also covers authorized agents, Global Privacy Control, minors, statutory exceptions, downstream instructions, denials, and records showing what the business did.

Section 1

How should a Consumer Rights Workflow run under the US CPRA?

At intake, record the request exactly as received, including a request sent through a non-designated channel. An exclusively online business with a direct relationship to the consumer may designate email for delete, correct, and know requests. Other businesses must provide at least two methods, including a toll-free number, and a website method if they maintain a website. If a request is deficient for a reason unrelated to verification, treat it as submitted or tell the consumer how to cure it.

For delete, correct, and know requests, acknowledge receipt within 10 business days and explain the verification process and expected response date. The 45-calendar-day response clock starts on receipt, not after verification. When necessary, the business may extend once for up to 45 additional calendar days, but it must notify the consumer and explain the delay within the first period.

Verify from information already maintained whenever possible. Match the method to the sensitivity of the information, the harm from unauthorized deletion, correction, or disclosure, fraud risk, and the reliability of the data points. Reauthenticate a password-protected account before deleting, correcting, or disclosing data. For non-account holders, a categories request requires a reasonable degree of certainty; a request for specific pieces requires a reasonably high degree. Verify a correction request using information other than the disputed field. Delete newly collected verification data as soon as practical after the request, except for required request records.

Do not verify an opt-out, limit, or, once applicable, ADMT opt-out request. Ask only for information needed to apply the choice and do not require an account. A valid such as Global Privacy Control applies to the browser or device and, when the business knows the consumer, to the associated consumer. Complete sale or sharing opt-outs and limit requests as soon as feasibly possible and no later than 15 business days, notify affected recipients for the regulatory interval, and provide a way for the consumer to confirm completion where required.

Add the automated decisionmaking technology (ADMT) branches when the business uses ADMT to make a significant decision that provides or denies financial or lending services, housing, education enrollment or opportunities, employment or independent-contracting opportunities or compensation, or healthcare services. Advertising alone is not a significant decision under this definition. Covered uses that began before January 1, 2027, must comply with Article 11 by January 1, 2027. The workflow then needs pre-use notice and access paths, plus either an opt-out path or an applicable exception such as a qualifying human appeal, in addition to the established CCPA rights.

  • Intake owner: capture receipt time, channel, asserted right, California-consumer and covered-business decision, authorized-agent status, account context, systems and data involved, and every applicable clock.
  • Verification owner: verify only delete, correct, know, and covered ADMT access requests. If verification fails, state the result and apply any required fallback, such as evaluating an unverified specific-pieces request as a categories request.
  • Data and system owners: search the systems, archives, data brokers, service providers, contractors, and third parties that can hold responsive information; record each match, action, exception, and no-record result.
  • Privacy and legal: identify the exact statutory or regulatory exception, decide whether it covers all or only part of the information, and approve any claim that action is impossible, involves disproportionate effort, or is fraudulent or abusive.
  • Response owner: send the completion, partial completion, or denial in plain language; include the specific basis for a denial, required opt-out or deletion alternatives, and ADMT appeal information where applicable.
  • Records owner: keep the request and response log for at least 24 months, secure it, restrict its use to compliance review, and do not retain other personal information solely to answer a future request.
Section 2

What fields should the Consumer Rights Workflow template capture?

The record should let a reviewer reconstruct the request without storing more identity material than verification requires. Separate intake, scope, right, verification, system search, legal exception, downstream action, response, and closure. The required 24-month ticket or log must include the request date, nature, submission method, response date, response nature, and denial basis; the additional fields below make the operational result testable.

Use one parent case with right-specific child actions when a consumer asserts several rights. This prevents a delete exception from being copied into an opt-out decision or a 45-day request clock from being applied to a 15-business-day opt-out.

  • Intake: request ID, exact receipt date and channel, right or rights asserted, consumer and business scope decision, account or device context, authorized-agent proof, and acknowledgement, response, extension, and completion deadlines.
  • Verification: data points or account method used, required degree of certainty, result, reauthentication, fraud flag, additional data collected and deleted, and the reason verification was not required for opt-out or limit requests.
  • Search: systems, date range, personal-information categories, exclusions from disclosure, service providers, contractors, third parties, data brokers, archives, and backups searched or instructed, with owner and completion evidence.
  • Decision: action by category, statutory exception and facts, impossible or disproportionate-effort analysis, partial action, correction source and supporting documents, denial reviewer, and consumer-facing explanation.
  • Downstream and closure: recipient instructions and acknowledgements, Global Privacy Control or account association, confirmation state, response copy, extension notice, ADMT appeal if applicable, closure date, and 24-month deletion date for the case record.
Section 3

How should teams review and improve the Consumer Rights Workflow?

Review the workflow when a request misses its clock, a system or recipient is omitted, a correction is overwritten, verification collects unnecessary data, an fails, or similar requests produce inconsistent results. Re-test after material changes to products, identity systems, data stores, retention schedules, contracts, sale or sharing flows, sensitive-personal-information uses, ADMT, or the CCPA regulations.

Run a sample request for each right through production-like systems. Include a logged-out Global Privacy Control signal, an account holder, a non-account holder seeking specific pieces, a partial deletion with a backup copy, a correction fed by a data broker, an authorized agent, and a request that reaches a service provider or contractor. Confirm that the public privacy policy, support scripts, system behavior, downstream instructions, and retained ticket tell the same story.

  • Monthly operations review: inspect overdue cases, verification failures, denials, exceptions, downstream failures, and repeat consumer contacts.
  • At least annual legal and design review: re-evaluate request methods, verification methods, privacy-policy disclosures, authorized-agent handling, and whether a reasonable verification method now exists for previously unverifiable data.
  • Release review: test new identifiers, data stores, vendors, advertising integrations, sensitive-data uses, and ADMT before launch and after material changes.
  • Large-volume check: a business that, alone or in combination, buys, receives for commercial purposes, sells, shares, or otherwise makes available for commercial purposes the personal information of 10 million or more consumers in a calendar year must compile request metrics and publish the prior-year figures by July 1.
  • Training: keep staff who answer privacy inquiries informed about the CCPA and request routes; businesses at the 10-million-consumer threshold also need a documented training policy for responsible personnel.
Primary sources

References and citations

cppa.ca.gov
Referenced sections
  • Sections 7062, 7100 through 7102, and Article 11 establish annual verification review, staff training, request metrics, and the January 1, 2027 ADMT phase-in; production testing is an implementation practice, not a prescribed test.
cppa.ca.gov
Referenced sections
  • Official CPPA rulemaking page confirming approval and effectiveness of the binding March 2023 CCPA regulations.
"On March 29, 2023, the Office of Administrative Law approved the California Privacy Protection Agency’s regulations and filed"
cppa.ca.gov
Referenced sections
  • Official, non-binding CPPA guidance confirming that the CPRA added consumer rights and business obligations.
"The CPRA amended the CCPA by adding additional consumer privacy rights and obligations for businesses"
nist.gov
Referenced sections
  • Voluntary, non-binding NIST crosswalk material for organizing privacy-control evidence; it does not establish CCPA review duties.
"Organizations should not assume implementation of these Privacy Framework activities or outcomes means that they have met the"
Related guides

Explore more topics

California CCPA and CPRA Applicability Test
Decide whether the CCPA as amended by the CPRA applies, using California nexus, current business thresholds, related-entity rules, and data-specific exemptions.
California CCPA and CPRA Compliance Checklist
A California CCPA/CPRA implementation checklist covering scope, notices, rights, opt-outs, vendor contracts, retention, security, and 2026 regulations.
California CCPA/CPRA Deadlines and Compliance Calendar
Track California CCPA and CPRA request clocks, phased 2026 regulation deadlines, recurring metrics, and separate Delete Act dates.
California CCPA/CPRA Penalties, Fines, and Private Damages
Understand current California CCPA and CPRA fine caps, who enforces them, the limited private action for security breaches, and the evidence to preserve.
California CPRA FAQ
Practical California CPRA FAQ guidance with implementation decisions, evidence, edge cases, and official California source citations.
California CPRA Requirements Guide
California CCPA/CPRA requirements for covered businesses: notices, rights, opt-outs, data-use limits, contracts, security, and phased 2026 rules.
California CPRA Risk Assessments, Cybersecurity Audits, and ADMT Guide
Apply the separate California trigger tests, duties, phase-in dates, evidence, and consumer rights for risk assessments, cybersecurity audits, and ADMT.
California Data Broker Deletion Workflow Guide
California Delete Act and CPRA-adjacent guidance for data broker deletion workflows, with practical decisions, evidence, edge cases, and official citations.
California Data Broker Registry and DROP Guide
California Delete Act guide to data-broker scope, annual registration, DROP processing from August 1, 2026, deletion, opt-out fallback, metrics, and audits.
California Delete Act data broker registry and DROP guide
California Delete Act guidance for the data broker registry and Delete Request and Opt-Out Platform (DROP), with owners, evidence, and official sources.
CCPA vs CPRA: What Changed in California Privacy Law
Compare the original CCPA with the CPRA amendments, including scope thresholds, new rights, contracts, retention, enforcement, and implementation steps.
CPPA Regulations Tracker | CCPA and CPRA
Track the in-force 2023 and 2026 CCPA regulations, their legal status, affected processing, and phased risk, audit, and ADMT deadlines.
CPRA enforcement advisories: CPPA investigations, fines, and risk mitigation
US CPRA guidance for Enforcement Advisories, with practical decisions, evidence, edge cases, and external source citations.
CPRA Global Privacy Control (GPC): opt-out requirements and enforcement FAQ
US CPRA guidance for GPC, with practical decisions, evidence, edge cases, and external source citations.
CPRA vs Colorado Privacy Act: Practical Comparison
Compare California and Colorado privacy law on scope, consumer rights, opt-outs, sensitive data, contracts, assessments, and enforcement.
CPRA vs Virginia VCDPA: Practical Comparison
Compare California and Virginia privacy law on scope, rights, sale, advertising, sensitive data, contracts, assessments, and enforcement.
US CPRA Compliance Guide
Build a CCPA/CPRA compliance program for scope, notices, consumer rights, opt-outs, vendor contracts, retention, security, and phased 2026 duties.
US CPRA Contract Terms Guide
Required CCPA/CPRA contract terms for service providers, contractors, and third parties, with role tests, clause checks, and evidence.
US CPRA Contracts Contractors and Service Providers Guide
Classify CCPA recipients as service providers, contractors, or third parties and apply the correct purpose limits, contracts, and consumer instructions.
US CPRA Correction Rights Guide
Handle CCPA correction requests: verification, accuracy review, documentation, system and vendor updates, response timing, denials, and records.
US CPRA Cyber Audit Readiness Workflow Guide
US CPRA guidance for Cyber Audit Readiness Workflow, with practical decisions, evidence, edge cases, and external source citations.
US CPRA DSAR and Correction Workflow Guide
US CPRA guidance for DSAR and Correction Workflow, with practical decisions, evidence, edge cases, and external source citations.
US CPRA GPC Handling Guide
How businesses subject to the CCPA must detect, apply, test, and document Global Privacy Control opt-out signals.
US CPRA GPC Handling Workflow Guide
A California GPC workflow for signal detection, browser and profile scope, conflicts, downstream suppression, 15-business-day completion, and test evidence.
US CPRA Retention Guide
How to set, disclose, implement, and review personal-information retention periods under the California CCPA and CPRA.
US CPRA Risk Assessment Intake Workflow Guide
Screen the six CPPA risk-assessment triggers, record exceptions and evidence, hold covered launches for approval, and track review and submission dates.
US CPRA Risk Assessment Template Guide
US CPRA guidance for CPRA Risk Assessment Template, with practical decisions, evidence, edge cases, and external source citations.
US CPRA Risk Assessments and Cybersecurity Audits Guide
Apply the separate CPPA trigger tests for processing-level risk assessments and entity-level annual cybersecurity audits, with phase-in dates and evidence.
US CPRA Sensitive Personal Information Guide
Classify California sensitive personal information, distinguish category status from the right to limit, and apply notices, assessments, controls, and deadlines.
US CPRA Sensitive Personal Information Limits Guide
Decide when California's right to limit applies, map uses to section 7027(m), implement the 15-business-day restriction, and preserve evidence.
US CPRA Sharing and Cross-Context Behavioral Advertising Guide
How to classify advertising data flows as sharing for cross-context behavioral advertising under the California CCPA and CPRA.
What counts as sharing under the California CPRA?
How to identify sharing for cross-context behavioral advertising and implement California notice, opt-out, preference-signal, contract, and recordkeeping duties.
What should teams do about ADMT under the US CPRA?
Decide whether California's ADMT rules cover an automated decision, then apply the 2027 notice, access, opt-out, appeal, and evidence requirements.
What should teams do about Contract Terms under the US CPRA?
Classify California data recipients and check the required service-provider, contractor, third-party, subcontractor, monitoring, and remediation terms.
What should teams do about Correction Rights under the US CPRA?
Handle a California request to correct with the right verification, 10-day confirmation, 45-day response, accuracy test, denial rules, and downstream evidence.
What should teams do about Cybersecurity Audits under the US CPRA?
US CPRA guidance for Cybersecurity Audits, with practical decisions, evidence, edge cases, and external source citations.
What should teams do about retention under the California CPRA?
California CPRA guidance for retention, including data minimization, privacy policy disclosures, evidence records, and official source citations.
What should teams do about Sensitive Personal Information Limits under the US CPRA?
US CPRA guidance for Sensitive Personal Information Limits, with practical decisions, evidence, edge cases, and external source citations.
When is a CPRA risk assessment required?
When California businesses must conduct CPRA risk assessments, what each report must contain, and the review, retention, and filing deadlines.