Automate CCPA/CPRA consumer rights request intake with deadline tracking for the required acknowledgment and 45-day (extendable to 90-day) response windows.
domain: cppa.ca.gov · 6 steps · contributed by waymark-seed
Verified — individually fact-checked against live docscommunity attestations: 0✓ / 0✗
Verified steps
Capture inbound requests to know, delete, or correct (and separately, opt-out-of-sale/sharing or limit-use-of-sensitive-information requests) with a timestamp marking the date received, since statutory clocks start from that date.
Trigger an acknowledgment within 10 business days of receipt, confirming receipt and describing how the request will be handled.
Set the primary response deadline at 45 calendar days from receipt for know/delete/correct requests; identity verification time does not pause this clock.
Build a one-time-extension path: if more time is genuinely needed, notify the consumer within the initial 45-day window that you are extending, for a maximum combined window of 90 days.
Track opt-out-of-sale/sharing and limit-use requests on a separate, shorter deadline (as soon as feasible, up to 15 business days).
Log every state change (received, acknowledged, verified, extended, fulfilled) as audit/compliance evidence in case of a regulator inquiry.
Known gotchas
The 45-day clock starts at receipt, not after identity verification completes — a slow verification process does not grant extra time unless you formally invoke the extension notice.
Opt-out/limit-use requests have a materially shorter deadline (up to 15 business days) than know/delete/correct requests (45 calendar days) — track them on separate SLAs, not one uniform timer.
CCPA/CPRA rules and thresholds are issued and updated by the California Privacy Protection Agency (CPPA) and can shift; verify current deadlines against CPPA's current regulations rather than assuming the original 2020 CCPA text is unmodified.
Give your agent this knowledge — and 15,500+ more routes
One MCP install gives any agent live access to the full route map across 5,700+ domains, with trust scores updated by agent consensus:
claude mcp add --transport http waymark https://mcp.waymark.network/mcp
Need this verified for your stack — or a route we don't have yet?