Which rights exist in which regimes, and where are the gaps?
The universal three: access (GDPR Article 15 with its metadata catalog; CCPA's right to know including categories sold/shared and specific pieces; PIPL Article 45; LGPD 18(II); APPI's disclosure right; PIPEDA Principle 9; Quebec; DPDP 11), deletion (Article 17's qualified erasure; CCPA deletion with service-provider propagation; PIPL 47; LGPD 18(VI); APPI's cease-of-use/erasure for violations; Quebec; DPDP 12), and correction (Article 16; now in every state law; PIPL 46; LGPD 18(III); APPI; Quebec; DPDP 12). The strong second tier, present in the GDPR family and patchily elsewhere: portability (Article 20's machine-readable export where processing rests on consent/contract and is automated; LGPD 18(V); Quebec's portability in force since September 2024; CCPA approximates it through access-format rules; PIPL 45's transfer-to-another-handler right where conditions are met; no APPI equivalent), objection (Article 21, absolute for direct marketing; LGPD's opposition right; no true US equivalent, the opt-outs play the role), restriction of processing (Article 18, largely a GDPR-family specialty), and withdrawal of consent as an operational right (universal in consent regimes, PIPL 15 requiring withdrawal as convenient as granting). The US-specific family: opt-out of sale (California's broad definition), sharing/cross-context behavioral advertising (CPRA), targeted advertising (the Virginia formulation adopted widely), profiling for decisions with legal or similarly significant effects (Colorado, Connecticut, and peers), plus limit-use-of-sensitive-PI (California's variant of the sensitive-consent gate), all with Global Privacy Control honoring mandatory in a growing state list. The automated-decision layer: GDPR Article 22's right not to be subject to solely automated significant decisions with human-intervention rights, PIPL 24's explanation-and-refusal right, LGPD 20's review right, and the CCPA ADMT rules phasing in; details in the ADM comparison. Gaps worth flagging in a matrix: no deletion right in Japan absent a violation, no general objection right in the US, no portability in several Asian regimes, and anti-discrimination/non-retaliation clauses (CCPA 1798.125, GDPR by doctrine) that constrain how you treat requesters everywhere.
What are the deadlines and extension mechanics per regime?
The clock table that configures the pipeline. GDPR/UK GDPR: one month from receipt, extendable by two further months for complexity or volume with notice within the first month (Article 12(3)); 'without undue delay' rides on top, so parking easy requests to day 29 is itself criticized. CCPA/CPRA: 45 days, extendable once by 45 with notice (access/deletion/correction); opt-outs of sale/share must be effectuated within 15 business days, and GPC signals processed as they arrive; the 12-month lookback for access (extendable to pre-2022 data on request unless impossible). Most other US states: 45 days plus a 45-day extension (Virginia, Colorado, Connecticut, and the family), with appeal processes mandatory, a distinctive state-law feature: the consumer can appeal your denial internally, and the appeal denial must include the AG complaint route. LGPD: 15 days for the full access statement (Article 19), immediate for the simplified declaration of processing existence, the tightest mainstream clock and the one that most often forces pipeline redesign. PIPL: 'timely' by statute with practice norms from implementing standards (the PIS specification's 30-day convention); refusals must be explained and a complaint channel provided. APPI: 'without delay,' with the two-week posture for disclosure in practice guidance. Quebec Law 25: 30 days, firm. PIPEDA: 30 days, extendable in defined circumstances with Commissioner-notified reasoning. India DPDP: as prescribed by the rules (the 2025 rules framework points to defined turnaround once fully commenced). Australia: APP 12's 'reasonable period' read as 30 days for access. The engineering translation: deadline, extension window, extension-notice requirement, and appeal mechanics are four columns in a configuration table keyed by jurisdiction, consumed by the same workflow engine, and the SLA dashboard alarms on the tightest applicable clock per request, which for a multinational is usually Brazil's.
How do exception and refusal grounds differ, and why does applying the wrong list matter?
Because a refusal is the highest-risk act in rights fulfillment, it is what complainants forward to regulators, and its validity depends entirely on the regime-specific exception list. Deletion exceptions: GDPR Article 17(3) permits retention for expression/information freedom, legal obligations, public health, archiving/research, and legal claims, notably no general 'business purposes' exception; CCPA 1798.105(d) enumerates its own list, completing the transaction, security and fraud, debugging, legal compliance, internal uses reasonably aligned with expectations, and the lists do not coincide: 'internal uses aligned with expectations' defends nothing in Europe, and Article 17(3)(e)'s legal-claims ground is broader than its California cousin. Access exceptions: GDPR Article 15(4) protects others' rights and freedoms (the third-party-data redaction duty), member-state law adds privilege and regulatory carve-outs, and the manifestly-unfounded-or-excessive refusal (Article 12(5)) is deliberately narrow, the ICO's guidance requires case-by-case justification and warns against volume alone as grounds; CCPA excludes certain security-sensitive data and caps repetition (twice in 12 months); trade secrets defend redactions nearly everywhere but rarely whole refusals. US state opt-outs have almost no exceptions, which surprises teams: a sale opt-out cannot be refused for business necessity, only fulfilled through the service-provider restructuring the statute contemplates. Sectoral overlays complicate further: HIPAA's access right runs on its own 30-day clock with its own denial grounds (and OCR has run an enforcement initiative on exactly this right since 2019), FCRA governs consumer-report file disclosure, and employment records attract member-state and provincial specialties. The operational disciplines: exception decisions are per-item, not per-request (withhold the privileged document, produce the rest); every withholding is logged with its legal ground (the withholding log is the refusal's defense); refusals are drafted or reviewed by counsel with the regime's appeal/complaint language included (mandatory in the state laws); and the exception table lives in the configuration layer beside the clocks, versioned as laws move.
How do verification and agent-request rules compare?
The two failure directions, over-verification obstructing rights and under-verification leaking data, are policed everywhere, with regime-specific mechanics. GDPR: proportionality doctrine, Recital 64 and EDPB guidance direct use of data you already hold, authentication into the existing account as the preferred method, and 'reasonable doubts' as the trigger for requesting more; demanding government ID for low-sensitivity contexts draws DPA criticism (several DPAs have fined excessive ID demands), and newly collected verification documents carry their own minimization and retention duties. CCPA regulations: the most prescriptive system, verification tiers scaled to sensitivity (reasonable degree for categories, reasonably high degree for specific pieces, matching two or three data points respectively, with declarations under penalty of perjury for the highest tier), an express ban on requiring account creation, fee-free verification, and detailed authorized-agent mechanics, businesses may require the agent's written authorization plus direct consumer confirmation, with power-of-attorney requests bypassing some checks; opt-outs, by design, require no verification at all (only fraud screening), because the remedy is low-risk. The state family broadly follows the CCPA's shape with local variations; Colorado's rules add universal-opt-out-mechanism recognition details. LGPD and PIPL: proportionate identity proof with less codified doctrine, agent requests via formal authorization; APPI: procedures the handler defines and publishes, within reasonableness. Quebec: identity verification plus the distinctive requirement that access be granted in an intelligible transcription. The operational convergence worth building to: authenticate-in-account as default everywhere, tiered step-up keyed to the matrix's sensitivity column, documented method per request, agent-request workflows for the US, and verification-failure responses that state what would suffice, since silent drops convert into complaints on every regime's books.
What does a jurisdiction-configured fulfillment architecture look like?
One machine, one configuration table, per-regime rendering. The machine (shared): intake normalization across channels (portal, email routing, GPC signal ingestion) into case records; identity verification with tiered step-up; scoping against the data inventory (systems, identifiers, vendor holdings); orchestrated collection and deletion with per-system evidence; human review for exemptions, third-party redaction, and adverse contexts; delivery through authenticated channels; and closure with the full audit trail, the same pipeline this library's DSAR automation guide details. The configuration table (per jurisdiction, the matrix operationalized): applicable rights list (drives which request types the portal offers a given user); clock, extension, and appeal parameters; verification tier rules and agent mechanics; exception lists per right; response-content requirements (Article 15's metadata catalog versus CCPA's categories-and-purposes disclosures versus LGPD's declaration formats); format rules (portability's machine-readable requirement, Quebec's intelligible transcription); anti-discrimination constraints; and complaint-route language for refusals and appeal denials. Jurisdiction resolution, the step teams underspecify: which configuration applies is a legal-mapping decision (user residency and the regime's scope tests, not IP geolocation alone), it must handle multi-regime individuals (an EU resident using your US service may hold GDPR rights; a Californian's household data spans persons), and the safest architecture defaults ambiguous cases to the more protective configuration rather than litigating edge cases per request. Governance around the machine: quarterly configuration review against legal change (this matrix decays as fast as the laws move), synthetic-request testing per jurisdiction (the fire drill that catches the broken Brazilian clock before a real 15-day request does), and metrics segmented by regime, cycle time versus clock, extension rate, refusal rate with grounds, appeal outcomes, because aggregate SLAs hide the jurisdiction that is quietly failing.