Skip to main content

The deadline starts the moment they ask

Jurisdiction
California, other US states, the EU and UK. Deadlines differ.
Last reviewed
2026-09-16

What it is

A data subject request, or consumer request, is somebody exercising a legal right over the personal information you hold about them: to know what you have, to get a copy, to correct it, to delete it, or to opt out of its sale or sharing.

Does it apply to you

  • You are subject to a privacy statute that grants the right, which most businesses with a website now are in at least one jurisdiction.
  • A request arrives. It does not have to use particular words, arrive through a particular channel, or mention a statute. An email saying delete my details is a request.

What being wrong costs

Missing a deadline is itself the violation, separately from anything you did with the data. Under California law the response window is 45 days with a permitted extension; under the GDPR it is generally one month. Because the clock starts on receipt rather than on recognition, a request sitting unread in a shared inbox is already running.

What it demands

  • Recognizing a request when it arrives, through any channel a person could reasonably use.
  • Verifying who is asking, proportionately to the sensitivity of what is being asked for.
  • Responding within the statutory window, and telling the person if you are extending it where an extension is permitted.
  • Carrying out deletion across the data you actually hold, including backups and anything passed to a processor.

What WebSpark does

  • A request form is published on your site and linked from the privacy documents, so requests arrive in a channel built to track them.
  • Every request is recorded with its arrival date and the policy version that governed it, so the deadline is visible to everyone handling it.
  • Deletion runs across the stored record, and what was deleted is logged.

What you can show

  • A request log with dates received, dates answered, and outcomes.
  • A deletion log, which is the part a regulator asks about.

What stays yours

  • Requests about data held outside the website: your CRM, your mailing list, your accounting system.
  • Deciding whether an exemption applies to a particular request. Several statutes allow refusal in defined circumstances, and that is a legal judgement.

Sources

  1. California Consumer Privacy Act (CCPA)California Office of the Attorney General
  2. Regulation (EU) 2016/679, Articles 12 to 23EUR-Lex, Publications Office of the European Union

WebSpark describes obligations and evidences what a site does. It does not provide legal advice, and this page is not a substitute for a lawyer who knows your business.