US State Law United States

Unified DSAR Intake: One System for All State Laws

Building a single consumer-rights request pipeline across all US state privacy laws: intake, verification, routing, the 45-day clock, appeals, and evidence.

Regulation

Consumer-rights provisions of comprehensive state privacy laws (2023-2026)

Max Penalty

Rights-response failures are per-violation offenses ($2,500-$20,000); ignored requests are the most common complaint category in AG reports

Enforcing Authority

State attorneys general; California CPPA

Official Source

cppa.ca.gov

Executive Summary

  • Every comprehensive state law grants overlapping consumer rights (access, correction, deletion, portability, opt-outs) on a 45-day clock with one 45-day extension, close enough to run one national pipeline instead of per-state processes.
  • The divergences that need handling: appeal processes (Virginia-lineage states require them; California does not), Oregon's and Delaware's specific-third-party lists, California's 12-month lookback and categories disclosures, and authorized-agent rules.
  • Verification must be proportionate: enough to prevent fraudulent access (data breaches via fake DSARs are real), but states prohibit requiring account creation and California limits what can be demanded for opt-outs.
  • Oregon's and other AGs' enforcement reports show the top complaint is simply non-response: requests lost in shared inboxes, unmonitored forms, and unrouted GPC signals.
  • The evidence layer matters as much as fulfillment: request logs, identity-verification records, response timestamps, and appeal outcomes are what an AG audit samples.

Rights requests are where privacy programs meet consumers directly, and where AG sweeps start, because failure is externally testable: a regulator (or journalist, or plaintiff’s firm) can submit a request and watch the clock. The design answer to twenty state variations is one pipeline built to the union of rights, the strictest clock, and the deepest evidence trail, with per-state behavior handled as response templates rather than separate systems.

Pipeline design

Intake without friction. A findable web form plus an email channel, linked from every privacy notice, no login requirement for non-account holders, an agent lane, and GPC treated as an automatic opt-out intake at the technical layer. Every request gets a timestamped ticket, the unmonitored-inbox failure is the most-cited violation in enforcement reports.

Routing on residency and right. State determines the response template (appeal language, lookback depth, third-party lists for Oregon and Delaware); right determines the fulfillment workflow and verification tier. Defaulting unknown-residency requesters to the most protective treatment is cheaper than adjudicating residency.

Fulfillment against the inventory. Access, deletion, and correction only work if the data inventory maps systems and service providers; deletion must propagate to processors on contract terms, and opt-outs must reach the ad stack, verify with a tag audit, not a checkbox.

Appeals and evidence. A distinct reviewer for appeals, AG-referral language in denials, and a retained evidence file: logs, verification records, timestamps, outcomes. This file is the audit; keep it like one.

Test the consumer-visible half yourself, intake findability, opt-out links, GPC response, with a free scan.

Frequently Asked Questions

Which rights must the unified intake support?

The union: access/confirmation, correction, deletion, portability, opt-out of targeted advertising, opt-out of sale/sharing, opt-out or limits on profiling, California's limit-SPI-use, and Oregon/Delaware third-party recipient lists. Plus appeals in every Virginia-lineage state (a denial must include appeal instructions, and appeal denials must include the AG complaint channel). Building the superset means no per-state feature gating and no risk of denying a right the requester's state grants.

How should the 45-day clock actually run?

Start at receipt (not verification completion, most states), respond within 45 days, extend once by 45 with notice and reason where reasonably necessary. Practical design: automated acknowledgment on receipt, verification within days (the clock does not pause for slow verification in most formulations), fulfillment SLAs at 30 days internally, and calendar alerts before statutory deadlines. Opt-outs run faster: California requires effectuation within 15 business days, and GPC signals apply immediately at the technical layer.

What verification is appropriate for each request type?

Risk-tiered: deletion and access to specific data need stronger verification (match multiple data points on file; for high-sensitivity data, a declaration under penalty of perjury per California's rules) than correction or opt-outs (California prohibits requiring verification for opt-out requests beyond what is needed to identify the consumer's data). Never require account creation for non-account-holders; never collect new sensitive data to verify. Failed verification gets a documented explanation, not silence.

How do authorized agents and household requests work?

California expressly permits authorized agents (with written permission and, for some requests, direct confirmation from the consumer); the Virginia-lineage states allow agents mainly for opt-outs, including via universal signals as the paradigm 'agent.' Data-broker deletion adds California's DROP mechanism routing bulk requests. The intake should have an agent lane with its own verification (agent authority plus consumer identity), because agent-submitted volume, from services like consumer-privacy platforms, is now a meaningful share of requests.

What does an AG audit of the rights process look for?

The Oregon DOJ's reports and California's enforcement history converge on: findable intake (privacy-policy links that work, no dark-pattern friction), response within deadlines, substantive completeness (all categories, all recipients where required), functioning appeals with AG-referral language, opt-outs that actually stop the processing (verified technically, not just recorded), and GPC signals honored. The evidence file, logs, timestamps, verification records, appeal dispositions, is what converts 'we comply' into a demonstrable fact.

Regulatory Crosswalk

GDPR DSARsCCPA/CPRAUK GDPR

Organizations subject to this regulation often operate under these overlapping frameworks. BD Emerson maps controls across frameworks to reduce duplicated compliance effort.

Evaluate your compliance posture now

BD Emerson's automated scanner audits your public-facing properties against your applicable regulations in minutes, not weeks.