DEV Community

ahmed isam
ahmed isam

Posted on Originally published at digital-footprint-health.shop

How Long Should a Deletion Request Take? GDPR One Month vs CCPA 45 Days

--
title: "How Long Should a Deletion Request Take? GDPR One Month vs CCPA 45 Days"
description: "GDPR allows one month and CCPA allows 45 days, and both permit a single extension with notice. This covers how each clock is counted, when an extension is valid, why verifiability is a moving part, and the escalation sequence that works once the deadline has passed."
tags: ["privacy", "gdpr", "ccpa", "law"]

canonical_url: https://digital-footprint-health.shop/blog/deletion-request-response-timeline

A deletion request goes out and then nothing happens for a while. No confirmation, no estimate, and no sense of how hard to push. There is a firmer footing than that. GDPR and CCPA both set statutory response deadlines, and the gap between them is one month against 45 days, plus a different extension mechanism.

The two baseline deadlines

Regime Statutory deadline Extension Clock starts
GDPR (EU) One month Up to two further months, with reasons On receipt of the request
CCPA / CPRA (California) 45 days Up to 45 more days, with prior notice On receipt of a verifiable request

The extension column carries the practical weight. Both regimes allow one, and both require notice before it applies. An organisation that goes quiet past the deadline is already out of compliance.

Calendar month versus calendar days

The GDPR month is generally a calendar month. A request received on 3 July is answered by 3 August, and if that date lands on a holiday it usually rolls to the next working day.

The CCPA 45 days are calendar days, weekends and holidays included. Applying the calendar-month logic to a California entity will get your dates wrong, which matters when you chase.

When an extension is valid

Extensions are not automatic. Under GDPR the reason has to appear in the first response, for example a high volume of requests or complex data flows. Under CCPA notice has to reach you within the original 45 days, with the reason stated. In both cases the first reply itself has to arrive. Notice sent after the deadline does not extend anything.

The clock starts earlier than people assume

Counting does not begin once you have explained everything clearly. It begins when the organisation receives the request, not when it agrees the request is actionable. Delivery is the trigger, which is exactly why proof of delivery matters.

Submission method therefore decides the starting point. Registered mail and timestamped email establish it far more easily than a web form. With a web form, a screenshot of the confirmation page plus the auto-reply email is the minimum evidence to keep.

Verifiability is a moving part

CCPA requires a verifiable request. If the organisation cannot confirm you are the person whose data is in question, it may ask for more information. Those requests have to be reasonable, like confirming the email tied to the account, rather than demanding a scanned identity document well beyond what the situation calls for.

Does a verification request pause the clock? Not automatically. It can justify an extension, but only where the organisation notified you inside the deadline. No notice plus no answer still counts as a missed deadline.

Escalating in order

Resending the same email rarely moves things. Four steps, in sequence, work better.

  • Send a dated follow-up. Cite the original request date, the statutory deadline and the number of days overdue. Ask for a written response. Its main job is to create a record.
  • File with a regulator. EU member states each have a data protection authority and California has its own privacy agency. Complaints do not require a lawyer and most can be filed through an online form.
  • Keep the whole trail. Request date, reply dates, and the content and channel of every exchange, arranged chronologically in one document.
  • Assess further options. Where there are actual damages some jurisdictions allow a private right of action, though thresholds and scope vary and need separate analysis.

The first and third steps cost the least and pay off most directly. Plenty of requests finally move because of one follow-up letter with a date on it.

Data brokers play by different rules

Platforms usually have a settled process and answer close to the limit. Data brokers split into two groups. Some run automated intake and reply quickly. Others depend on manual review and drift toward the far end of the extension.

A third group sits outside your jurisdiction entirely, where the statutory deadline has no direct hold. The outcome then depends on whether the organisation wants to cooperate and whether it has affiliated entities somewhere the deadline does bind. Working that out is more useful than sending more reminders.

A follow-up schedule worth reusing

When Action Why
Day of submission Save the receipt and auto-reply Fixes the start of the clock
Day 7 Confirm the request was accepted Rules out non-delivery
Day 25 (GDPR) / Day 40 (CCPA) Remind them that an extension notice is due Forces the notice
3 days past the deadline Send the dated follow-up Creates overdue evidence
2 weeks overdue File the regulator complaint Adds outside pressure

Tighten the spacing to fit the situation but keep the order. Chasing internally before escalating produces a stronger complaint file.

An in-product flow is not a statutory deadline

A platform's own bulk delete runs as a product flow. It is not bound by the deadlines above and is usually much faster, though it has its own limits.

The statutory right applies where the other party controls the decision: third-party reposts, data broker files and search engine caches. Separating the two routes saves a lot of wasted chasing.

Top comments (0)