Artifact GuideUSDSAR and Correction Workflow

US CPRA DSAR and Correction Workflow

Route California requests to know, delete, and correct through one case record while preserving each right's verification standard, search scope, exceptions, system action, vendor action, and response.

The final CCPA regulations set a 10-business-day acknowledgement and a 45-calendar-day response clock that starts on receipt, not after verification.

Author
Sorena AI
Published
May 9, 2026
Updated
Jul 24, 2026
Sections
3

Structured answer sets in this page tree.

Primary sources
5

Cited legal and guidance references.

Publication metadata
Sorena AI
Published May 9, 2026
Updated Jul 24, 2026
Overview

A asks a CCPA-covered business to fix inaccurate personal information using commercially reasonable efforts. Route it with requests to know and delete through one case record, but keep the rights and outcomes separate. Confirm receipt within 10 business days and respond within 45 calendar days from receipt, including verification time. When necessary, one explained extension may increase the total response period to 90 calendar days.

Section 1

How should a DSAR and Correction Workflow run under the US CPRA?

Confirm that the legal entity is a CCPA business and classify the request before searching systems. A business operating only online with a direct relationship to the consumer may provide an email request method. Other businesses must provide at least two methods, including a toll-free number and, when they maintain a website, a website method. A misdirected or technically deficient request must be treated as properly submitted or the consumer must receive instructions to fix it.

Match the verification strength to the right, data sensitivity, and harm from unauthorized action. For a non-accountholder, a categories request may use two reliable matching data points; a specific-pieces request may use three reliable matches plus a signed declaration. Deletion and correction require a reasonable or reasonably high degree of certainty based on risk. Try to verify a correction request with information other than the contested field.

A request to know covers the preceding 12 months by default. The consumer may ask for information collected on or after January 1, 2022 beyond that period unless production is impossible or would involve disproportionate effort. Do not disclose Social Security, government identification, financial or medical account, password, security-answer, or unique biometric values; describe the type with enough particularity instead.

For deletion, erase, deidentify, or aggregate covered information in active systems; notify service providers and contractors; and notify third parties that received a sale or sharing unless that is impossible or disproportionate. Archived or backup data may wait until restoration or next access. Delete non-exempt data, restrict any retained exempt data to the exception's purpose, and give a detailed partial or full denial.

For correction, decide whether the contested information is more likely than not accurate from the totality of the circumstances, including its nature, source, supporting records, consumer documentation, purpose, and consumer impact. Correct active systems and instruct service providers and contractors. Deletion may substitute only when it does not harm the consumer or the consumer consents.

  • Capture receipt, right asserted, request channel, business and consumer scope, account and authorized-agent context, acknowledgement date, 45-day deadline, extension notice and reason, and 90-day maximum deadline.
  • Match identity information already held before requesting more, collect only what verification needs, and apply stronger verification where unauthorized action would create greater harm.
  • Search named active, archived, and backup systems and every service provider or contractor; for access, include contracted personal information; preserve each result and the exact exception, impossibility, or disproportionate-effort facts.
  • Send correction or deletion instructions to applicable service providers and contractors, and send deletion notices to sale-or-sharing recipients unless the documented exception applies; record completion, delay, or refusal.
  • Deliver access data with reasonable security, state what was granted or denied, provide the required detailed explanation, and keep the request record for at least 24 months under section 7101.
Section 2

What fields should the DSAR and Correction Workflow template capture?

The privacy-operations owner should maintain the case record. Separate intake, verification, search, legal review, system action, recipient action, response, and closure so a reviewer can see where a request stalled and reproduce any denial.

  • Request ID, receipt and acknowledgement timestamps, asserted right, scope decision, authorized-agent evidence, and response clock.
  • Verification level, reliable matches, declaration when used, risk factors, data requested only for verification, result, and fraud or security escalation.
  • System, backup, service-provider, contractor, and third-party search or notice log; data located; access period; source and accuracy evidence; action; and exception provision.
  • Consumer response, prohibited-value handling, secure delivery method, extension or detailed denial explanation, owner, reviewer, downstream confirmations, closure date, and 24-month retention end.
Section 3

How should teams review and improve the DSAR and Correction Workflow?

Review missed deadlines, verification failures, repeated correction disputes, incomplete downstream responses, and inconsistent exceptions. Re-test after identity, account, data-store, retention, or vendor changes, and sample closed cases to confirm that the response matches recorded system actions.

  • Measure acknowledgement and response time from receipt even when verification remains open; record which cases used the one extension and why it was necessary.
  • Test whether corrected information stays corrected when systems synchronize or a data broker later supplies the old value.
  • For a repeated correction request within six months, treat it as new when the consumer supplies new or additional accuracy documentation; document any fraud or abuse conclusion.
  • Sample deletion exceptions, backup delays, third-party notices, access lookback decisions, and secure delivery against the final consumer response.
Primary sources

References and citations

cppa.ca.gov
Referenced sections
  • CPPA regulations source for operational CCPA request handling, notices, verification, and workflow controls.
"On March 29, 2023, the Office of Administrative Law approved the California Privacy Protection Agency’s regulations and filed them with the Secretary of State."
cppa.ca.gov
Referenced sections
  • CPPA FAQ source confirming CPRA amendments added consumer privacy rights and business obligations relevant to DSAR intake.
"The CPRA amended the CCPA by adding additional consumer privacy rights and obligations for businesses"
Related guides

Explore more topics

California CCPA and CPRA Applicability Test
Decide whether the CCPA as amended by the CPRA applies, using California nexus, current business thresholds, related-entity rules, and data-specific exemptions.
California CCPA and CPRA Compliance Checklist
A California CCPA/CPRA implementation checklist covering scope, notices, rights, opt-outs, vendor contracts, retention, security, and 2026 regulations.
California CCPA/CPRA Deadlines and Compliance Calendar
Track California CCPA and CPRA request clocks, phased 2026 regulation deadlines, recurring metrics, and separate Delete Act dates.
California CCPA/CPRA Penalties, Fines, and Private Damages
Understand current California CCPA and CPRA fine caps, who enforces them, the limited private action for security breaches, and the evidence to preserve.
California CPRA FAQ
Practical California CPRA FAQ guidance with implementation decisions, evidence, edge cases, and official California source citations.
California CPRA Requirements Guide
California CCPA/CPRA requirements for covered businesses: notices, rights, opt-outs, data-use limits, contracts, security, and phased 2026 rules.
California CPRA Risk Assessments, Cybersecurity Audits, and ADMT Guide
Apply the separate California trigger tests, duties, phase-in dates, evidence, and consumer rights for risk assessments, cybersecurity audits, and ADMT.
California Data Broker Deletion Workflow Guide
California Delete Act and CPRA-adjacent guidance for data broker deletion workflows, with practical decisions, evidence, edge cases, and official citations.
California Data Broker Registry and DROP Guide
California Delete Act guide to data-broker scope, annual registration, DROP processing from August 1, 2026, deletion, opt-out fallback, metrics, and audits.
California Delete Act data broker registry and DROP guide
California Delete Act guidance for the data broker registry and Delete Request and Opt-Out Platform (DROP), with owners, evidence, and official sources.
CCPA vs CPRA: What Changed in California Privacy Law
Compare the original CCPA with the CPRA amendments, including scope thresholds, new rights, contracts, retention, enforcement, and implementation steps.
CPPA Regulations Tracker | CCPA and CPRA
Track the in-force 2023 and 2026 CCPA regulations, their legal status, affected processing, and phased risk, audit, and ADMT deadlines.
CPRA enforcement advisories: CPPA investigations, fines, and risk mitigation
US CPRA guidance for Enforcement Advisories, with practical decisions, evidence, edge cases, and external source citations.
CPRA Global Privacy Control (GPC): opt-out requirements and enforcement FAQ
US CPRA guidance for GPC, with practical decisions, evidence, edge cases, and external source citations.
CPRA vs Colorado Privacy Act: Practical Comparison
Compare California and Colorado privacy law on scope, consumer rights, opt-outs, sensitive data, contracts, assessments, and enforcement.
CPRA vs Virginia VCDPA: Practical Comparison
Compare California and Virginia privacy law on scope, rights, sale, advertising, sensitive data, contracts, assessments, and enforcement.
US CPRA Compliance Guide
Build a CCPA/CPRA compliance program for scope, notices, consumer rights, opt-outs, vendor contracts, retention, security, and phased 2026 duties.
US CPRA Consumer Rights Workflow Guide
Run California CCPA and CPRA requests to know, delete, correct, opt out, limit, and access or opt out of covered ADMT, with deadlines, verification, exceptions, and evidence.
US CPRA Contract Terms Guide
Required CCPA/CPRA contract terms for service providers, contractors, and third parties, with role tests, clause checks, and evidence.
US CPRA Contracts Contractors and Service Providers Guide
Classify CCPA recipients as service providers, contractors, or third parties and apply the correct purpose limits, contracts, and consumer instructions.
US CPRA Correction Rights Guide
Handle CCPA correction requests: verification, accuracy review, documentation, system and vendor updates, response timing, denials, and records.
US CPRA Cyber Audit Readiness Workflow Guide
US CPRA guidance for Cyber Audit Readiness Workflow, with practical decisions, evidence, edge cases, and external source citations.
US CPRA GPC Handling Guide
How businesses subject to the CCPA must detect, apply, test, and document Global Privacy Control opt-out signals.
US CPRA GPC Handling Workflow Guide
A California GPC workflow for signal detection, browser and profile scope, conflicts, downstream suppression, 15-business-day completion, and test evidence.
US CPRA Retention Guide
How to set, disclose, implement, and review personal-information retention periods under the California CCPA and CPRA.
US CPRA Risk Assessment Intake Workflow Guide
Screen the six CPPA risk-assessment triggers, record exceptions and evidence, hold covered launches for approval, and track review and submission dates.
US CPRA Risk Assessment Template Guide
US CPRA guidance for CPRA Risk Assessment Template, with practical decisions, evidence, edge cases, and external source citations.
US CPRA Risk Assessments and Cybersecurity Audits Guide
Apply the separate CPPA trigger tests for processing-level risk assessments and entity-level annual cybersecurity audits, with phase-in dates and evidence.
US CPRA Sensitive Personal Information Guide
Classify California sensitive personal information, distinguish category status from the right to limit, and apply notices, assessments, controls, and deadlines.
US CPRA Sensitive Personal Information Limits Guide
Decide when California's right to limit applies, map uses to section 7027(m), implement the 15-business-day restriction, and preserve evidence.
US CPRA Sharing and Cross-Context Behavioral Advertising Guide
How to classify advertising data flows as sharing for cross-context behavioral advertising under the California CCPA and CPRA.
What counts as sharing under the California CPRA?
How to identify sharing for cross-context behavioral advertising and implement California notice, opt-out, preference-signal, contract, and recordkeeping duties.
What should teams do about ADMT under the US CPRA?
Decide whether California's ADMT rules cover an automated decision, then apply the 2027 notice, access, opt-out, appeal, and evidence requirements.
What should teams do about Contract Terms under the US CPRA?
Classify California data recipients and check the required service-provider, contractor, third-party, subcontractor, monitoring, and remediation terms.
What should teams do about Correction Rights under the US CPRA?
Handle a California request to correct with the right verification, 10-day confirmation, 45-day response, accuracy test, denial rules, and downstream evidence.
What should teams do about Cybersecurity Audits under the US CPRA?
US CPRA guidance for Cybersecurity Audits, with practical decisions, evidence, edge cases, and external source citations.
What should teams do about retention under the California CPRA?
California CPRA guidance for retention, including data minimization, privacy policy disclosures, evidence records, and official source citations.
What should teams do about Sensitive Personal Information Limits under the US CPRA?
US CPRA guidance for Sensitive Personal Information Limits, with practical decisions, evidence, edge cases, and external source citations.
When is a CPRA risk assessment required?
When California businesses must conduct CPRA risk assessments, what each report must contain, and the review, retention, and filing deadlines.