On any given day, 361.1 million mailpieces are processed and delivered by the US Postal Service. The whole endeavor is an exercise in coordination, each item making its way from the sender’s hands to the one right recipient among millions.

This process isn’t just a logistical feat. Each step also includes verification, security measures, and compliance safeguards.

CCPA privacy rights requests work the same way.

When privacy rights requests come in, they must be checked, sorted, and delivered to the right person and at the right time. But unlike the postal system, which has had nearly 250 years to refine its workflows and build a (sometimes tenuous) trust with the public, privacy rights requests are a much newer discipline. CCPA only took effect in 2020, and the rules have been a moving target ever since.

That leaves a lot of businesses scrambling for a process that helps them ferry a request that lands in an inbox into a verified, on-time response. Here’s how to build one.

What is the CCPA?

The California Consumer Privacy Act (CCPA) is both the oldest and one of the most consequential state data privacy laws in the United States. While it created a broad range of requirements for businesses, it also offers consumers detailed rights to their personal data.

These rights generally apply when a business is subject to the CCPA, with some exceptions.

Core CCPA privacy rights include:

  • The right to know what personal information a business has collected about them, including the categories and specific pieces of information, the sources of that information, the purposes for collecting, using, selling, sharing, or disclosing it, and the categories of third parties involved
  • The right to delete personal information a business collected from them, subject to certain exceptions
  • The right to correct inaccurate personal information a business maintains about them
  • The right to limit certain uses and disclosures of sensitive personal information*
  • The right to opt out of the sale of personal information and the sharing of personal information for cross-context behavioral advertising
  • The right not to receive discriminatory treatment for exercising CCPA rights

What is sensitive personal information?

CCPA defines sensitive personal information broadly. It can cover:

  • Social Security, driver’s license, and other government ID numbers
  • Account login credentials and financial account information
  • Precise geolocation
  • Racial or ethnic origin
  • Religious or philosophical beliefs
  • Union membership
  • The contents of personal communications
  • Genetic, neural, and biometric data
  • Information about a consumer’s health, sex life, or sexual orientation

Businesses are obligated to notify consumers either when or before they collect any sensitive information, explain why they’re collecting and using it, and whether the business will sell or share that information.

Automated decision-making rights

California has also adopted regulations governing certain uses of automated decision-making technology (ADMT). 

When a business relies on ADMT to make significant decisions about a consumer (for example, decisions related to a job application), the consumer may have the right to receive notice of that use, request meaningful information about the ADMT, and, where applicable, opt out of its use.

Who enforces CCPA laws?

CCPA is enforced by both the California Attorney General and the California Privacy Protection Agency. Civil penalties can reach up to $2,663 per violation or $7,988 for each intentional violation. 

Additionally, if there is a data breach, businesses may find themselves facing statutory damages of $107 to $799 per consumer, per incident.

Step 1: Inform consumers what their rights are under CCPA

The postal service plasters its rules everywhere: what you can send, what it costs, how to track it, and more. No one has to guess.

A privacy notice has a similar job. It’s where consumers learn what rights they have and how to use them:

  • Each right they have under CCPA 
  • How they can submit a request and what they’ll need to do to verify their identity
  • How long they should expect to wait for a response

A few friendly reminders about your privacy notice while we’re on the subject. Your privacy notice should:

  • Be available everywhere you collect data, not just on one privacy page
  • Be written in plain language that’s readable across devices and accessible to people with disabilities
  • Be provided in the languages your audience actually uses
  • Be reviewed at least once a year, and any time your data practices change

(There’s more, but we cover that in this privacy notice article.)

Step 2: Set up ways for them to submit their requests

When it comes to sending stuff, people like to have options. The post office places a drop box on the corner and a counter in every branch. There are also outdoor postal boxes, third-party approved shippers, and, of course, mailing from home.

CCPA is no different. From a compliance perspective, there are certain options that need to be available for privacy rights requests.

  • Businesses that operate exclusively online and have a direct relationship with consumers generally may provide an email address for requests to know, delete, and correct. (SB 923 amends this and beginning January 1, 2027, these businesses must also provide an online method, like a web form or portal, in addition to an email address).
  • Other businesses must provide at least two designated submission methods, including a toll-free telephone number.
  • If those businesses maintain a website, one of their submission methods must be available through the website. An online form is one common option, but it is not the only one.

You can manage this intake yourself or use a third-party tool, and put someone in charge of monitoring every channel so nothing sits unanswered. An unwatched channel is just as problematic as not having one at all, because the clock starts the moment a request arrives, whether or not anyone is there to catch it.

Step 3: Implement processes to verify who’s making the request

No one hands over a certified package without checking ID first. In privacy rights requests, verification represents that check. If this step isn’t honored, a rights request can turn into a breach (both legally and a breach of trust with consumers).

Use a reasonable, risk-based verification method. You can do this by matching what you check to what you already have. If the only thing in your system is an email address, asking for a driver’s license is out of proportion, and it means collecting more sensitive information than you held before the request came in. 

A good starting point can be the verification process used by your customer service team; that process already exists!

One notable exception is that you can’t require verification for opt-out requests. CCPA doesn’t permit it, so an opt-out has to go through even without an identity check.

Step 4: Validate the request and respond (on time)

Before you respond to a request, identify which right is being exercised, and whether you have to act on it or can deny it. Some requests fall under an exemption; the right to delete, for example, has exceptions that may allow you to keep certain data. If you deny a request, tell the consumer and give the reason.

You can also refuse a request that’s manifestly unfounded or excessive, particularly if it’s repetitive, or charge a reasonable fee to fulfill it. If you do, tell the consumer why. The right to delete has its own set of exceptions, such as letting you keep data you still need to complete a transaction or honor a warranty (just a few examples of the many).

Regardless of whether you’re fulfilling or denying a request, it has to be done within CCPA’s deadlines. 

You must:

  • Acknowledge access, correction, and deletion requests within 10 business days
  • Respond to those requests within 45 calendar days
  • Complete opt-out requests within 15 business days
  • A business may take one additional 45-day extension when reasonably necessary if it notifies the consumer and explains the reason within the initial 45-day period

One rule applies to every request: don’t disclose a consumer’s Social Security number, driver’s license or government ID number, financial account number, health or medical ID, account password, or security questions and answers. That information should stay out of any response you send.

Step 5: Set up a “Do not sell or share” opt-out

Some people put a “no junk mail” notice on the mailbox. That’s essentially what an opt-out is, a standing signal rather than a one-off request.

Under the CCPA, consumers can tell you to stop selling or sharing their personal information, and that choice stays in effect until they change it. A “sale” means disclosing personal information for money or other valuable consideration, and “sharing” means disclosing it for cross-context behavioral advertising; the opt-out covers both. To comply, companies need to display the official opt-out icon ( California Consumer Privacy Act (CCPA) Opt-Out Icon ) alongside the text “Your Privacy Choices,” or include a “Do Not Sell or Share My Personal Information” link. If a company uses “Your Privacy Choices,” the icon alone or the text alone does not satisfy the requirement. Both, together, are required.

(There are some important points to note here. To start, these requirements aren’t limited to cookies. If you sell or share other categories of information, you need to uphold this requirement as well. And if you have cross-device tracking taking place, the opt-out has to function across all devices; a recent Disney enforcement action landed the company $2.75 million in penalties for this type of violation.)

The rules are different for younger consumers. You need opt-in consent to sell or share the personal information of consumers aged 13 to 16, and a parent’s consent for anyone under 13.

The opt-out link also has to work everywhere. Test it end to end and confirm it loads on every domain, lets a consumer set a preference, and holds that preference across sessions and devices, including when someone moves between desktop and mobile. A link that points to a generic privacy notice instead of a functional preference center won’t meet the requirement; neither does one that works on a desktop but doesn’t on a phone.

You also have to honor the Global Privacy Control signal, which lets a browser opt out automatically.

Step 6: Pass requests to your service providers and third parties

Your response isn’t finished when you act on it. If a service provider or third party also holds the data, fulfilling your obligation may be in limbo.

But this is a situation where an ounce of prevention is worth a pound of the cure.

When onboarding new vendors, make sure you exercise a thorough due diligence process and clearly outline your terms in contracts. Your service provider and contractor contracts should require them to act on rights requests you pass along, so any deletion request or opt-out you honor carries through to them.

However, the contract only carries so much weight. It’s just as important that you have a clear workflow for identifying and sending requests to them when one comes in and holding them to a fulfillment timeline that allows you to meet your own.

Step 7: Maintain thorough and accurate request records

Every letter, postcard, and package traversing the postal system leaves a trail: when it was sent, where it went, who signed for it. Your rights requests need the same trail, both to prove you did what the law requires and to track issues before they turn into problems.

When building a system for your request records, it’s vital that you capture sufficient information to reconstruct requests. Generally speaking, it should include what was asked for, when it arrived, how you verified it, and how you resolved it.

Like any data-based system, retention policies should also be factored in: where will you retain those records and for how long? It’s also worth tracking a few metrics, like request volume, response times, and escalation rates, since that’s where you’ll see the request workflows buckle before they break.

CCPA compliance for businesses that want requests handled right

Handled well, a privacy rights request is a routine piece of business, checked, sorted, and delivered on time. Handled poorly, it’s a missed deadline, a misrouted disclosure, or a breach of trust you can’t easily win back. 

However, CCPA has its own unique requirements, and there are 20+ other states (plus GDPR) with their own obligations. By devising a privacy strategy, companies can create processes and policies that work across these different laws. Red Clover Advisors can help you build privacy rights request processes tailored to your obligations, processes that hold up as your business grows and the rules keep moving. Our privacy rights consulting services and managed privacy operations support your program from day one through every stage of growth.

Ready to get the fundamentals in place? Download our Practical CCPA Basics Checklist, then schedule a call and let Red Clover be your guide.

Downloadable Resource

A Practical Checklist CCPA Basics Checklist