Use this workflow to process California requests to know, delete, correct, opt out of sale or sharing, and limit sensitive-personal-information use or disclosure.
Add the covered automated-decisionmaking branches by January 1, 2027, including access and either opt-out or a qualifying appeal path where applicable. Route every request by right because verification, deadlines, exceptions, recipients, and response evidence differ.
Start by identifying the right and confirming that the requester is a California consumer whose information is handled by a covered business. Requests to know, delete, and correct require risk-based identity verification, acknowledgement within 10 business days, and a response within 45 calendar days from receipt, with one explained extension of up to 45 more days when necessary. Opt-out and limit requests must not be conditioned on identity verification and must be completed as soon as feasibly possible, no later than 15 business days. A complete workflow also covers authorized agents, Global Privacy Control, minors, statutory exceptions, downstream instructions, denials, and records showing what the business did.
1
Section 1
How should a Consumer Rights Workflow run under the US CPRA?
At intake, record the request exactly as received, including a request sent through a non-designated channel. An exclusively online business with a direct relationship to the consumer may designate email for delete, correct, and know requests. Other businesses must provide at least two methods, including a toll-free number, and a website method if they maintain a website. If a request is deficient for a reason unrelated to verification, treat it as submitted or tell the consumer how to cure it.
For delete, correct, and know requests, acknowledge receipt within 10 business days and explain the verification process and expected response date. The 45-calendar-day response clock starts on receipt, not after verification. When necessary, the business may extend once for up to 45 additional calendar days, but it must notify the consumer and explain the delay within the first period.
Verify from information already maintained whenever possible. Match the method to the sensitivity of the information, the harm from unauthorized deletion, correction, or disclosure, fraud risk, and the reliability of the data points. Reauthenticate a password-protected account before deleting, correcting, or disclosing data. For non-account holders, a categories request requires a reasonable degree of certainty; a request for specific pieces requires a reasonably high degree. Verify a correction request using information other than the disputed field. Delete newly collected verification data as soon as practical after the request, except for required request records.
Do not verify an opt-out, limit, or, once applicable, ADMT opt-out request. Ask only for information needed to apply the choice and do not require an account. A valid such as Global Privacy Control applies to the browser or device and, when the business knows the consumer, to the associated consumer. Complete sale or sharing opt-outs and limit requests as soon as feasibly possible and no later than 15 business days, notify affected recipients for the regulatory interval, and provide a way for the consumer to confirm completion where required.
Add the automated decisionmaking technology (ADMT) branches when the business uses ADMT to make a significant decision that provides or denies financial or lending services, housing, education enrollment or opportunities, employment or independent-contracting opportunities or compensation, or healthcare services. Advertising alone is not a significant decision under this definition. Covered uses that began before January 1, 2027, must comply with Article 11 by January 1, 2027. The workflow then needs pre-use notice and access paths, plus either an opt-out path or an applicable exception such as a qualifying human appeal, in addition to the established CCPA rights.
Intake owner: capture receipt time, channel, asserted right, California-consumer and covered-business decision, authorized-agent status, account context, systems and data involved, and every applicable clock.
Verification owner: verify only delete, correct, know, and covered ADMT access requests. If verification fails, state the result and apply any required fallback, such as evaluating an unverified specific-pieces request as a categories request.
Data and system owners: search the systems, archives, data brokers, service providers, contractors, and third parties that can hold responsive information; record each match, action, exception, and no-record result.
Privacy and legal: identify the exact statutory or regulatory exception, decide whether it covers all or only part of the information, and approve any claim that action is impossible, involves disproportionate effort, or is fraudulent or abusive.
Response owner: send the completion, partial completion, or denial in plain language; include the specific basis for a denial, required opt-out or deletion alternatives, and ADMT appeal information where applicable.
Records owner: keep the request and response log for at least 24 months, secure it, restrict its use to compliance review, and do not retain other personal information solely to answer a future request.
What fields should the Consumer Rights Workflow template capture?
The record should let a reviewer reconstruct the request without storing more identity material than verification requires. Separate intake, scope, right, verification, system search, legal exception, downstream action, response, and closure. The required 24-month ticket or log must include the request date, nature, submission method, response date, response nature, and denial basis; the additional fields below make the operational result testable.
Use one parent case with right-specific child actions when a consumer asserts several rights. This prevents a delete exception from being copied into an opt-out decision or a 45-day request clock from being applied to a 15-business-day opt-out.
Intake: request ID, exact receipt date and channel, right or rights asserted, consumer and business scope decision, account or device context, authorized-agent proof, and acknowledgement, response, extension, and completion deadlines.
Verification: data points or account method used, required degree of certainty, result, reauthentication, fraud flag, additional data collected and deleted, and the reason verification was not required for opt-out or limit requests.
Search: systems, date range, personal-information categories, exclusions from disclosure, service providers, contractors, third parties, data brokers, archives, and backups searched or instructed, with owner and completion evidence.
Decision: action by category, statutory exception and facts, impossible or disproportionate-effort analysis, partial action, correction source and supporting documents, denial reviewer, and consumer-facing explanation.
Downstream and closure: recipient instructions and acknowledgements, Global Privacy Control or account association, confirmation state, response copy, extension notice, ADMT appeal if applicable, closure date, and 24-month deletion date for the case record.
How should teams review and improve the Consumer Rights Workflow?
Review the workflow when a request misses its clock, a system or recipient is omitted, a correction is overwritten, verification collects unnecessary data, an fails, or similar requests produce inconsistent results. Re-test after material changes to products, identity systems, data stores, retention schedules, contracts, sale or sharing flows, sensitive-personal-information uses, ADMT, or the CCPA regulations.
Run a sample request for each right through production-like systems. Include a logged-out Global Privacy Control signal, an account holder, a non-account holder seeking specific pieces, a partial deletion with a backup copy, a correction fed by a data broker, an authorized agent, and a request that reaches a service provider or contractor. Confirm that the public privacy policy, support scripts, system behavior, downstream instructions, and retained ticket tell the same story.
At least annual legal and design review: re-evaluate request methods, verification methods, privacy-policy disclosures, authorized-agent handling, and whether a reasonable verification method now exists for previously unverifiable data.
Release review: test new identifiers, data stores, vendors, advertising integrations, sensitive-data uses, and ADMT before launch and after material changes.
Large-volume check: a business that, alone or in combination, buys, receives for commercial purposes, sells, shares, or otherwise makes available for commercial purposes the personal information of 10 million or more consumers in a calendar year must compile request metrics and publish the prior-year figures by July 1.
Training: keep staff who answer privacy inquiries informed about the CCPA and request routes; businesses at the 10-million-consumer threshold also need a documented training policy for responsible personnel.
Sections 7062, 7100 through 7102, and Article 11 establish annual verification review, staff training, request metrics, and the January 1, 2027 ADMT phase-in; production testing is an implementation practice, not a prescribed test.
Sections 7020 through 7027 and 7060 through 7063 govern request methods, response timing, verification, and the separate delete, correct, know, opt-out, and limit paths.