What Is the Deadline to Respond to a CPRA Deletion Request?

What Is the Deadline to Respond to a CPRA Deletion Request?
Quick answer: You have 45 calendar days from receipt to respond to a deletion request under California's privacy law, and a separate 10 business day deadline to confirm you received it. The 45 days includes the time you spend verifying who the person is, so verification does not buy you extra days. You can extend once by another 45 days, taking the total to 90, but only if you notify the consumer within the first 45 with the reason. Deleting your own records is only half the job, because you also have to pass the instruction to the vendors holding that data for you.

Two Deadlines Run at the Same Time

Merchants usually hear about the 45 days and miss the shorter one, which is the deadline most often blown.

The first clock is confirmation. Within 10 business days of receiving a request, you have to acknowledge it and tell the consumer how you will process it and roughly when. This is a short note, not the outcome. Sending it late is a compliance failure even if you delete everything perfectly on day twenty.

The second clock is the substantive response, due within 45 calendar days of receipt. Calendar days, so weekends and holidays are inside the count. That response tells the person what you did, what you deleted, and if you kept anything, which exception you relied on.

Note the mismatch. Confirmation is measured in business days and the response is measured in calendar days. That is not a typo in the regulation, and building your process around the wrong unit is an easy way to be a few days late. A store on OpoShop that records both due dates when the request lands avoids the problem entirely.

When the Clock Starts, and Where Verification Fits

The 45 days runs from receipt of the request, not from the moment you finish verifying identity. This is the single biggest structural difference from the GDPR timetable and it catches out merchants who handle both.

Under California rules, verification happens inside your window. You are expected to verify a deletion request to a reasonable degree of certainty, and for sensitive deletions to a higher standard, but the time you spend doing that is your time, not extra time.

That has a practical consequence. Verification has to start immediately.

  • Day 0: Request received through any channel, including your webform, email, or a toll-free route if you operate one.
  • Within a few days: Verification request sent if you cannot match the person to an account from what they already gave you.
  • Within 10 business days: Confirmation of receipt sent, regardless of whether verification is complete.
  • Within 45 calendar days: Substantive response delivered, with the outcome and any exceptions applied.

Requests can also come from an authorised agent acting for the consumer, and you can ask for proof of that authorisation. You can ask the consumer to verify their own identity directly with you as well. What you cannot do is require them to create an account, because access to the right cannot be conditioned on signing up.

For an OpoShop merchant, most requests come from someone with an order history, so verification is usually a match against the email on file plus a confirming detail like a recent order number.

Log requests with due dates

The Extension, and What Genuinely Justifies It

You get one extension of up to 45 additional days, for a maximum of 90 days total from receipt.

The conditions are specific. You have to notify the consumer within the original 45 day period, and the notice has to include the reason for the delay. An extension you take silently is not an extension, it is a missed deadline with extra steps.

Reasonable grounds look like genuine complexity. Data spread across several systems that do not talk to each other, a request that requires careful separation of one person's data from another's, or an unusually high volume of requests arriving at once after a public incident.

Being short staffed is not a justification, and neither is a busy sales season. Regulators consider request handling part of running the business, in the same way that shipping orders is.

Most ecommerce deletions on an OpoShop store do not need the extension. A typical store holds customer records, orders, an email marketing profile, support tickets and some advertising identifiers, which is a day of work once you know the map. If you are reaching for the extension routinely, the real problem is that nobody has written down where the data lives.

What You Must Delete, and What You Are Allowed to Keep

Deletion under California rules is not absolute, and the exceptions are broader than many merchants expect. Knowing them prevents both over-deleting and under-deleting.

You can generally retain what you need to complete the transaction the data was collected for, to detect security incidents or fraud, to comply with a legal obligation, to exercise or defend legal claims, and for certain internal uses reasonably aligned with the consumer's expectations.

Order and tax records are the practical example. You are legally required to retain transaction records for tax purposes, so you keep them, and you tell the consumer that you kept them under a legal obligation exception. What goes is the marketing profile, the advertising identifiers, the behavioural data, and the account details you no longer need.

  • Delete: Marketing lists, behavioural and advertising identifiers, browsing profiles, non-essential account data.
  • Keep with an exception: Transaction and tax records, fraud and chargeback evidence, records tied to an active legal claim.
  • Deidentify as an alternative: Where you need aggregate history, strip identifiers so the record can no longer be linked to a person.
  • Always explain: Tell the consumer what you kept and which exception you relied on.

The second half of the job is downstream. You have to direct your service providers and contractors to delete the same data, and notify third parties you sold or shared it with unless that proves impossible or involves disproportionate effort. For a store on OpoShop that means your email platform, support desk, reviews app and advertising audiences all need the same instruction.

How to Process a Deletion Request Inside the Window

Consistency is what keeps you inside 45 days. Every request should follow the same path, in the same order, with the same template.

1
Timestamp on arrival
Record the request the day it lands and set both due dates, ten business days for confirmation and forty five calendar days for the response.
2
Confirm receipt fast
Send the acknowledgement within a few days, explaining how you will process the request and what you may need from them.
3
Verify to a reasonable standard
Match the request to an account using details you already hold, and only ask for more where identity is genuinely unclear.
4
Delete across every system
Remove the data from your store records and instruct every vendor and advertising platform holding it on your behalf.
5
Respond with specifics
Tell the consumer what was deleted, what was retained, and which exception justified anything you kept.

Three parts of that sequence do most of the work.

1. Treat confirmation as a same-week task

The 10 business day confirmation is easy to automate and easy to forget. Write the acknowledgement once and reuse it.

It should say you received the request, that you are processing it, what you may need to verify identity, and when they can expect the outcome. Two short paragraphs. Sending it promptly also reduces follow-up messages, which is worth the effort on its own.

2. Build the vendor list before the first request

Deleting from your own admin is the easy part. The part that takes days is remembering every third-party system that holds a copy.

List them once: email marketing, SMS, support desk, reviews, loyalty, analytics, advertising audiences, and any fulfilment or returns tool. Keep the deletion instructions for each one next to the name. An OpoShop merchant with that list on hand can complete a full deletion in an afternoon rather than a fortnight.

3. Write a response that documents your reasoning

The response is your evidence. Do not just say "done".

Say what categories you deleted, name the systems, state anything you retained and the exception you relied on, and note the date. Keep a copy. If the consumer later complains that you did not delete their order history, your response already explains why the law let you keep it.

CPRA Deletion vs GDPR Erasure vs a Do Not Sell Opt-Out

These three get conflated constantly, and they have different clocks and different outcomes. Handling all three the same way means you will be late on one of them.

Request typeDeadlineWhat actually happensCommon exceptions
CPRA deletion45 calendar days, extendable to 90Data deleted and vendors instructedTransaction records, fraud, legal obligations
GDPR erasureOne calendar month, extendable to threeData erased where no lawful basis to keep itLegal obligation, legal claims, public interest
Do not sell or share15 business days to stop sharingSharing stops, the account and data remainLimited, the opt-out is close to absolute

CPRA deletion has the longest clock but the widest downstream obligation, because you must push the instruction to your service providers and third parties.

GDPR erasure runs faster and is scoped by lawful basis rather than a fixed exception list. Same spirit, different mechanics, and a shorter deadline.

The opt-out is not deletion at all, and confusing the two causes real damage. A shopper asking you to stop selling or sharing their data expects to keep their account and their order history. Deleting it because you misread the request is a worse outcome than doing nothing. Keeping the three types visibly separate in your OpoShop request queue prevents that mistake.

What We Recommend for [OpoShop](https://oposhop.io) Merchants

Set this up as a small operational routine and it stops being a legal worry.

Three things to put in place. One published intake route for privacy requests, linked from your footer and your privacy notice. A written map of every system holding customer data, including your advertising platforms. Two response templates, one for confirmation and one for the outcome.

Then run every request the same way. Timestamp on arrival, set both due dates, confirm within 10 business days, verify against what you already hold, delete across every system, and respond with specifics you keep a copy of.

If you sell to California and to Europe, track the request type explicitly, because the deadlines differ and so do the exceptions. If your California volume is low, the routine still matters, since the first request usually arrives with no warning.

Best answer: You have 45 calendar days from receipt to complete and respond to a CPRA deletion request, plus a 10 business day deadline to confirm receipt, with one optional 45 day extension you must announce inside the original window. Track both dates from the day the request lands in your OpoShop store, delete across every connected vendor, and state exactly what you retained and why.

Two dates, one vendor list, two templates. That is the entire process.

Track deletion deadlines

FAQs

Is the CPRA deadline 45 business days or calendar days?

Calendar days. The 45 day response window counts weekends and holidays. The separate 10 day confirmation deadline is measured in business days, which is why it helps to record both dates against the request in your OpoShop queue rather than tracking one.

Does verifying identity pause the 45 day clock?

No. Verification happens inside the window, so time spent confirming who the person is comes out of your 45 days. That is why verification should start in the first few days rather than the third week.

Do I have to delete a customer's order history?

Usually not. Transaction and tax records are typically retained under a legal obligation exception. You delete the marketing and behavioural data, keep the required records, and tell the consumer exactly which exception you applied.

What if the request comes from someone else acting for the customer?

Authorised agents can submit requests on a consumer's behalf. You may ask the agent for proof of authorisation and may ask the consumer to confirm directly, provided you do not turn that into an obstacle course.

Do I have to tell my apps and vendors to delete too?

Yes. Service providers and contractors holding the data on your behalf must be instructed to delete it, and third parties you sold or shared data with should be notified. This is why a written vendor list saves so much time.

What happens if I miss the deadline?

The consumer can complain to the California Privacy Protection Agency or the Attorney General, which typically starts with questions about your process. There is a cure concept in some circumstances, but the reliable answer is to respond on time with documentation.

Want both clocks tracked automatically? Handle deletion requests where your storefront already lives.

Set up request tracking

Ready to dive in?

Learn more