Rights requests are where privacy programs meet consumers directly, and where AG sweeps start, because failure is externally testable: a regulator (or journalist, or plaintiff’s firm) can submit a request and watch the clock. The design answer to twenty state variations is one pipeline built to the union of rights, the strictest clock, and the deepest evidence trail, with per-state behavior handled as response templates rather than separate systems.
Pipeline design
Intake without friction. A findable web form plus an email channel, linked from every privacy notice, no login requirement for non-account holders, an agent lane, and GPC treated as an automatic opt-out intake at the technical layer. Every request gets a timestamped ticket, the unmonitored-inbox failure is the most-cited violation in enforcement reports.
Routing on residency and right. State determines the response template (appeal language, lookback depth, third-party lists for Oregon and Delaware); right determines the fulfillment workflow and verification tier. Defaulting unknown-residency requesters to the most protective treatment is cheaper than adjudicating residency.
Fulfillment against the inventory. Access, deletion, and correction only work if the data inventory maps systems and service providers; deletion must propagate to processors on contract terms, and opt-outs must reach the ad stack, verify with a tag audit, not a checkbox.
Appeals and evidence. A distinct reviewer for appeals, AG-referral language in denials, and a retained evidence file: logs, verification records, timestamps, outcomes. This file is the audit; keep it like one.
Test the consumer-visible half yourself, intake findability, opt-out links, GPC response, with a free scan.