- Official California privacy-rights overview used to align DSAR and correction request intake language with CCPA rights.
"The right to correct inaccurate personal information that a business has about them"
Route California requests to know, delete, and correct through one case record while preserving each right's verification standard, search scope, exceptions, system action, vendor action, and response.
The final CCPA regulations set a 10-business-day acknowledgement and a 45-calendar-day response clock that starts on receipt, not after verification.
Structured answer sets in this page tree.
Cited legal and guidance references.
A asks a CCPA-covered business to fix inaccurate personal information using commercially reasonable efforts. Route it with requests to know and delete through one case record, but keep the rights and outcomes separate. Confirm receipt within 10 business days and respond within 45 calendar days from receipt, including verification time. When necessary, one explained extension may increase the total response period to 90 calendar days.
Confirm that the legal entity is a CCPA business and classify the request before searching systems. A business operating only online with a direct relationship to the consumer may provide an email request method. Other businesses must provide at least two methods, including a toll-free number and, when they maintain a website, a website method. A misdirected or technically deficient request must be treated as properly submitted or the consumer must receive instructions to fix it.
Match the verification strength to the right, data sensitivity, and harm from unauthorized action. For a non-accountholder, a categories request may use two reliable matching data points; a specific-pieces request may use three reliable matches plus a signed declaration. Deletion and correction require a reasonable or reasonably high degree of certainty based on risk. Try to verify a correction request with information other than the contested field.
A request to know covers the preceding 12 months by default. The consumer may ask for information collected on or after January 1, 2022 beyond that period unless production is impossible or would involve disproportionate effort. Do not disclose Social Security, government identification, financial or medical account, password, security-answer, or unique biometric values; describe the type with enough particularity instead.
For deletion, erase, deidentify, or aggregate covered information in active systems; notify service providers and contractors; and notify third parties that received a sale or sharing unless that is impossible or disproportionate. Archived or backup data may wait until restoration or next access. Delete non-exempt data, restrict any retained exempt data to the exception's purpose, and give a detailed partial or full denial.
For correction, decide whether the contested information is more likely than not accurate from the totality of the circumstances, including its nature, source, supporting records, consumer documentation, purpose, and consumer impact. Correct active systems and instruct service providers and contractors. Deletion may substitute only when it does not harm the consumer or the consumer consents.
The privacy-operations owner should maintain the case record. Separate intake, verification, search, legal review, system action, recipient action, response, and closure so a reviewer can see where a request stalled and reproduce any denial.
Review missed deadlines, verification failures, repeated correction disputes, incomplete downstream responses, and inconsistent exceptions. Re-test after identity, account, data-store, retention, or vendor changes, and sample closed cases to confirm that the response matches recorded system actions.
This US CPRA guide turns DSAR and Correction Workflow into owners, evidence requests, review checkpoints, and reusable operating records in Sorena.
Turn DSAR and Correction Workflow into scoped questions, evidence fields, and review tasks.
Use Research Copilot to answer follow-up questions with cited source material.
Review scope, evidence, owners, and the next compliance actions with Sorena.
"The right to correct inaccurate personal information that a business has about them"
"right to request a business that maintains inaccurate personal information about the consumer to correct that inaccurate personal information"
"On March 29, 2023, the Office of Administrative Law approved the California Privacy Protection Agency’s regulations and filed them with the Secretary of State."
"The CPRA amended the CCPA by adding additional consumer privacy rights and obligations for businesses"