Summary. A rights request is a deadline running against a company that usually does not know where its data lives. This checklist covers the operational path from intake to closure: recognizing a request whatever channel it arrives through, verifying identity without over-collecting, determining which statutes apply, searching systems and vendors, applying exemptions, responding on time, handling appeals, and logging everything. Separate phases cover opt-out signals, which run on a shorter clock, and the requests companies forget to plan for.


What this checklist is for. Running a defensible rights-request process. For the statutory landscape, see State Consumer Privacy Laws.


Phase 1 — Intake

  • Provide at least the required channels: a web form, and in California a toll-free number for businesses that operate exclusively online only where required, plus an email address. Confirm current requirements for each applicable state.
  • Train every customer-facing function to recognize a request. A request is valid however it arrives — support ticket, chat, email to a salesperson, social media, or a letter.
  • Timestamp receipt the day it arrives. The clock starts on receipt, not on routing.
  • Route to a single owner with a tracked ticket.
  • Acknowledge receipt promptly (California requires confirmation within 10 business days for verifiable consumer requests).
  • Identify the request type: know/access, delete, correct, portability, opt out of sale or sharing, opt out of targeted advertising, opt out of profiling, limit use of sensitive data.
  • Identify whether the requester is a consumer, employee, applicant, or business contact — California covers all of them; most other states do not cover employment data.

Why this matters. The most common compliance failure is not a wrong answer; it is a request that sat in a support queue for three weeks because nobody recognized it.

Phase 2 — Verify identity

  • Match the request to an existing record using data you already hold.
  • Apply a risk-proportionate standard: more assurance for deletion and sensitive data than for a simple opt-out.
  • Do not over-collect. Requiring a government ID or a notarized affidavit for a routine request is itself a privacy problem and may be an unlawful barrier.
  • Use existing account authentication where the consumer has an account.
  • For authorized agents, obtain written authorization signed by the consumer, and (where permitted) verify with the consumer directly. An agent submitting an opt-out generally faces a lighter burden.
  • For households, apply the heightened requirements where the statute provides them.
  • If identity cannot be verified, respond explaining why, and treat an unverifiable access or deletion request as an opt-out where the statute directs.

Why this matters. Verification protects against a bad actor using the rights process to extract or destroy someone else's data — a real and recurring attack. It also cannot become an obstacle course; regulators have treated excessive verification as a dark pattern.

Phase 3 — Determine the applicable law and the scope

  • Determine the requester's state of residence (and whether any non-US regime applies).
  • Identify which statutes apply to your business for that resident, and which rights that statute grants — the rights differ (no correction right in Iowa or Utah; no profiling opt-out in several states; California's "limit sensitive PI" instead of opt-in consent).
  • Confirm the deadline: generally 45 days, extendable once by an additional 45 (California) or 45 to 60 (varies) with notice of the reason.
  • Identify exempt data: HIPAA protected health information, GLBA financial data, FCRA consumer reports, driver's license data, and employment data outside California.
  • Identify whether the request touches data held as a service provider/processor for another controller — you must notify the controller and follow its instructions rather than acting unilaterally.

Phase 4 — Search

  • Use the data map to identify every system holding the individual's data: production databases, CRM, marketing platform, support desk, analytics, data warehouse, logs, backups, email, and file shares.
  • Search derived and inferred data, not just data the consumer submitted.
  • Query vendors and subprocessors with a standing process and a contractual obligation to assist.
  • Address backups deliberately: most regimes accept that deletion from backups may occur on the normal restoration cycle, with the data placed beyond use in the meantime. Document the approach.
  • Check unstructured repositories where a reasonable search would find the data.
  • Record what was searched and what was found.

Why this matters. The response you can defend is the one where the search methodology is documented. "We searched our systems" is not a methodology.

Phase 5 — Apply exemptions correctly

Before deleting or disclosing, confirm no exemption applies. Common grounds to retain data despite a deletion request:

  • Complete the transaction or provide the requested service.
  • Detect and address security incidents and fraud.
  • Debug and repair errors.
  • Exercise free speech or another right.
  • Comply with a legal obligation (tax, employment, sector retention rules).
  • Legal claims: establishment, exercise, or defense — this is why an active litigation hold overrides deletion. See Litigation Hold and Evidence Preservation Checklist.
  • Internal uses reasonably aligned with the consumer's expectations.
  • Confirm any exemption applies to that data, not to the whole record — partial deletion is often the right answer.

Phase 6 — Respond

  • Respond in writing, in the format the statute requires, within the deadline.
  • For access, provide the categories and, where required, the specific pieces of personal information, the sources, the business purposes, and the categories of third parties. Note the California limitation on disclosing certain sensitive identifiers (government ID numbers, financial account numbers, account passwords, security questions) even in response to an access request.
  • For portability, provide a readily usable, machine-readable format that permits transmission to another entity.
  • For deletion, delete and direct service providers and contractors to delete, and notify third parties to whom the data was sold or shared where required.
  • For correction, correct and instruct service providers to do the same; you may consider the totality of circumstances and the nature of the data in assessing accuracy.
  • If denying in whole or part, state the reason and the basis, and inform the consumer of the appeal right where the state provides one (most states other than California).
  • Do not charge a fee or discriminate for exercising rights; financial incentive programs require specific notice and consent.
  • Do not require the consumer to create an account to make a request.

Phase 7 — Opt-out signals, which run on a different track

  • Honor the Global Privacy Control and other recognized universal opt-out mechanisms in every state that requires it, treating the signal as a valid request without further verification.
  • Process opt-outs promptly (California specifies 15 business days for sale/sharing opt-outs, including forwarding to third parties to whom data was sold or shared in the prior 90 days).
  • Confirm the signal actually suppresses tags and propagates to ad platforms through their consent APIs — verify by network trace, not by vendor assurance.
  • Do not ask a consumer who has sent a valid signal to confirm again, which regulators treat as an unlawful obstacle.
  • Maintain the opt-out link(s) required by the applicable statutes.

Phase 8 — Log, measure, and close

  • Maintain a request log: date received, type, state, verification method and outcome, systems searched, exemptions applied, action taken, date responded, appeal outcome.
  • Track metrics required by law — California requires businesses handling personal information of large numbers of consumers to compile and disclose annual request metrics.
  • Retain the log per the retention schedule; do not retain the personal information collected for verification longer than necessary.
  • Review denial patterns quarterly; a high denial rate usually indicates a scoping or verification problem rather than a legal one.
  • Feed findings back into the data map and the retention schedule.

Common mistakes

  • Requests missed in a support queue because only the privacy portal was monitored.
  • Over-verification, requiring ID for an opt-out.
  • Forgetting the vendors, so data survives at a processor after deletion.
  • Deleting data subject to a litigation hold or a statutory retention obligation.
  • Ignoring employee and applicant requests in California.
  • Honoring the opt-out in the consent banner but not suppressing the tags.
  • No appeal process in states that require one.
  • No log, so the program cannot be demonstrated to a regulator.
  • Treating backups as out of scope without documenting the approach.

Primary authority

  • California: Cal. Civ. Code §§ 1798.100-1798.199.100 (CCPA as amended by the CPRA) and the CPPA regulations; the Delete Act for data brokers.
  • Other states: the comprehensive consumer privacy statutes of Virginia, Colorado, Connecticut, Utah, Texas, Oregon, Montana, Delaware, New Jersey, New Hampshire, Nebraska, Iowa, Indiana, Tennessee, Minnesota, Maryland, Rhode Island, Kentucky, and others; check the currently effective list and each statute's rights and deadlines.
  • Sector overlays: HIPAA; GLBA; FCRA; COPPA; state biometric and health data statutes.
  • International: GDPR Articles 12-23 for EU/EEA data subjects, with a one-month baseline response period.

Related

This checklist is educational and not legal advice. Rights, deadlines, and verification standards vary by state and change frequently. Consult qualified privacy counsel about your particular program.