What Is the Deadline to Respond to a CPRA Deletion Request?

Two Deadlines Run at the Same Time
Merchants usually hear about the 45 days and miss the shorter one, which is the deadline most often blown.
The first clock is confirmation. Within 10 business days of receiving a request, you have to acknowledge it and tell the consumer how you will process it and roughly when. This is a short note, not the outcome. Sending it late is a compliance failure even if you delete everything perfectly on day twenty.
The second clock is the substantive response, due within 45 calendar days of receipt. Calendar days, so weekends and holidays are inside the count. That response tells the person what you did, what you deleted, and if you kept anything, which exception you relied on.
Note the mismatch. Confirmation is measured in business days and the response is measured in calendar days. That is not a typo in the regulation, and building your process around the wrong unit is an easy way to be a few days late. A store on OpoShop that records both due dates when the request lands avoids the problem entirely.
When the Clock Starts, and Where Verification Fits
The 45 days runs from receipt of the request, not from the moment you finish verifying identity. This is the single biggest structural difference from the GDPR timetable and it catches out merchants who handle both.
Under California rules, verification happens inside your window. You are expected to verify a deletion request to a reasonable degree of certainty, and for sensitive deletions to a higher standard, but the time you spend doing that is your time, not extra time.
That has a practical consequence. Verification has to start immediately.
- Day 0: Request received through any channel, including your webform, email, or a toll-free route if you operate one.
- Within a few days: Verification request sent if you cannot match the person to an account from what they already gave you.
- Within 10 business days: Confirmation of receipt sent, regardless of whether verification is complete.
- Within 45 calendar days: Substantive response delivered, with the outcome and any exceptions applied.
Requests can also come from an authorised agent acting for the consumer, and you can ask for proof of that authorisation. You can ask the consumer to verify their own identity directly with you as well. What you cannot do is require them to create an account, because access to the right cannot be conditioned on signing up.
For an OpoShop merchant, most requests come from someone with an order history, so verification is usually a match against the email on file plus a confirming detail like a recent order number.
The Extension, and What Genuinely Justifies It
You get one extension of up to 45 additional days, for a maximum of 90 days total from receipt.
The conditions are specific. You have to notify the consumer within the original 45 day period, and the notice has to include the reason for the delay. An extension you take silently is not an extension, it is a missed deadline with extra steps.
Reasonable grounds look like genuine complexity. Data spread across several systems that do not talk to each other, a request that requires careful separation of one person's data from another's, or an unusually high volume of requests arriving at once after a public incident.
Being short staffed is not a justification, and neither is a busy sales season. Regulators consider request handling part of running the business, in the same way that shipping orders is.
Most ecommerce deletions on an OpoShop store do not need the extension. A typical store holds customer records, orders, an email marketing profile, support tickets and some advertising identifiers, which is a day of work once you know the map. If you are reaching for the extension routinely, the real problem is that nobody has written down where the data lives.
What You Must Delete, and What You Are Allowed to Keep
Deletion under California rules is not absolute, and the exceptions are broader than many merchants expect. Knowing them prevents both over-deleting and under-deleting.
You can generally retain what you need to complete the transaction the data was collected for, to detect security incidents or fraud, to comply with a legal obligation, to exercise or defend legal claims, and for certain internal uses reasonably aligned with the consumer's expectations.
Order and tax records are the practical example. You are legally required to retain transaction records for tax purposes, so you keep them, and you tell the consumer that you kept them under a legal obligation exception. What goes is the marketing profile, the advertising identifiers, the behavioural data, and the account details you no longer need.
- Delete: Marketing lists, behavioural and advertising identifiers, browsing profiles, non-essential account data.
- Keep with an exception: Transaction and tax records, fraud and chargeback evidence, records tied to an active legal claim.
- Deidentify as an alternative: Where you need aggregate history, strip identifiers so the record can no longer be linked to a person.
- Always explain: Tell the consumer what you kept and which exception you relied on.
The second half of the job is downstream. You have to direct your service providers and contractors to delete the same data, and notify third parties you sold or shared it with unless that proves impossible or involves disproportionate effort. For a store on OpoShop that means your email platform, support desk, reviews app and advertising audiences all need the same instruction.
How to Process a Deletion Request Inside the Window
Consistency is what keeps you inside 45 days. Every request should follow the same path, in the same order, with the same template.
Three parts of that sequence do most of the work.
1. Treat confirmation as a same-week task
The 10 business day confirmation is easy to automate and easy to forget. Write the acknowledgement once and reuse it.
It should say you received the request, that you are processing it, what you may need to verify identity, and when they can expect the outcome. Two short paragraphs. Sending it promptly also reduces follow-up messages, which is worth the effort on its own.
2. Build the vendor list before the first request
Deleting from your own admin is the easy part. The part that takes days is remembering every third-party system that holds a copy.
List them once: email marketing, SMS, support desk, reviews, loyalty, analytics, advertising audiences, and any fulfilment or returns tool. Keep the deletion instructions for each one next to the name. An OpoShop merchant with that list on hand can complete a full deletion in an afternoon rather than a fortnight.
3. Write a response that documents your reasoning
The response is your evidence. Do not just say "done".
Say what categories you deleted, name the systems, state anything you retained and the exception you relied on, and note the date. Keep a copy. If the consumer later complains that you did not delete their order history, your response already explains why the law let you keep it.
CPRA Deletion vs GDPR Erasure vs a Do Not Sell Opt-Out
These three get conflated constantly, and they have different clocks and different outcomes. Handling all three the same way means you will be late on one of them.
| Request type | Deadline | What actually happens | Common exceptions |
|---|---|---|---|
| CPRA deletion | 45 calendar days, extendable to 90 | Data deleted and vendors instructed | Transaction records, fraud, legal obligations |
| GDPR erasure | One calendar month, extendable to three | Data erased where no lawful basis to keep it | Legal obligation, legal claims, public interest |
| Do not sell or share | 15 business days to stop sharing | Sharing stops, the account and data remain | Limited, the opt-out is close to absolute |
CPRA deletion has the longest clock but the widest downstream obligation, because you must push the instruction to your service providers and third parties.
GDPR erasure runs faster and is scoped by lawful basis rather than a fixed exception list. Same spirit, different mechanics, and a shorter deadline.
The opt-out is not deletion at all, and confusing the two causes real damage. A shopper asking you to stop selling or sharing their data expects to keep their account and their order history. Deleting it because you misread the request is a worse outcome than doing nothing. Keeping the three types visibly separate in your OpoShop request queue prevents that mistake.
What We Recommend for [OpoShop](https://oposhop.io) Merchants
Set this up as a small operational routine and it stops being a legal worry.
Three things to put in place. One published intake route for privacy requests, linked from your footer and your privacy notice. A written map of every system holding customer data, including your advertising platforms. Two response templates, one for confirmation and one for the outcome.
Then run every request the same way. Timestamp on arrival, set both due dates, confirm within 10 business days, verify against what you already hold, delete across every system, and respond with specifics you keep a copy of.
If you sell to California and to Europe, track the request type explicitly, because the deadlines differ and so do the exceptions. If your California volume is low, the routine still matters, since the first request usually arrives with no warning.
Best answer: You have 45 calendar days from receipt to complete and respond to a CPRA deletion request, plus a 10 business day deadline to confirm receipt, with one optional 45 day extension you must announce inside the original window. Track both dates from the day the request lands in your OpoShop store, delete across every connected vendor, and state exactly what you retained and why.
Two dates, one vendor list, two templates. That is the entire process.
FAQs
Is the CPRA deadline 45 business days or calendar days?
Calendar days. The 45 day response window counts weekends and holidays. The separate 10 day confirmation deadline is measured in business days, which is why it helps to record both dates against the request in your OpoShop queue rather than tracking one.
Does verifying identity pause the 45 day clock?
No. Verification happens inside the window, so time spent confirming who the person is comes out of your 45 days. That is why verification should start in the first few days rather than the third week.
Do I have to delete a customer's order history?
Usually not. Transaction and tax records are typically retained under a legal obligation exception. You delete the marketing and behavioural data, keep the required records, and tell the consumer exactly which exception you applied.
What if the request comes from someone else acting for the customer?
Authorised agents can submit requests on a consumer's behalf. You may ask the agent for proof of authorisation and may ask the consumer to confirm directly, provided you do not turn that into an obstacle course.
Do I have to tell my apps and vendors to delete too?
Yes. Service providers and contractors holding the data on your behalf must be instructed to delete it, and third parties you sold or shared data with should be notified. This is why a written vendor list saves so much time.
What happens if I miss the deadline?
The consumer can complain to the California Privacy Protection Agency or the Attorney General, which typically starts with questions about your process. There is a cure concept in some circumstances, but the reliable answer is to respond on time with documentation.
Want both clocks tracked automatically? Handle deletion requests where your storefront already lives.



