Obtainer
Blog / Process 8 min read

Data Subject Request Appeal: How to Handle a Denied Privacy Request

Last updated July 2026 · Obtainer

Request Studio
Requester
Compiled the manifest and drafted the response - illustrative sample request
0
records found
0
systems scanned
Data manifest
Response draft

Assembling the cover letter from the template...

You approve what is disclosed before anything ships

Helps you comply, not legal advice

A data subject request appeal is the second look a consumer is entitled to when you deny their privacy request. Nearly every comprehensive US state privacy law requires you to offer a conspicuous appeal process, tell the person how to use it when you deny them, and answer the appeal in writing within a set number of days, usually 60. Utah is the only state that does not require one. If you deny a request and never mention the appeal route, that omission is a separate violation from the denial, and it is the kind of process gap regulators look for first.

This is a practical guide to what the appeal actually is, which states mandate it and on what clock, what a compliant appeal response has to contain, and where teams get it wrong. It applies to any consumer rights request you turn down: access, deletion, correction, portability, or an opt-out you decline to honor.

What a data subject request appeal is

An appeal is a formal reconsideration of a denied request, handled inside your company before the consumer goes to a regulator. The Virginia-model state laws, which 18 of the 20 comprehensive statutes follow, borrowed the structure from administrative practice: if a controller declines to act on a request, the consumer can ask the controller to look again, and the controller has to give a written decision with reasons. If the appeal is also denied, the law requires you to provide a way to contact the state attorney general or file a complaint.

The appeal is not the same as the original request, and its clock is separate. The response window on the first request has already run or been extended by the time a denial goes out. The appeal starts a new, shorter deadline that begins when the consumer submits the appeal, not when they filed the original request. Treating the two as one timeline is a common way to miss the appeal deadline while believing you are still inside the first one.

Which states require a privacy request appeal

The table below sets out the appeal obligation and the time you have to answer, by regime. The figures are the response windows written into each statute. Verify the current text before you rely on any single row, because these laws are amended often.

RegimeAppeal process required?Time to answer an appeal
Virginia, Texas, and most Virginia-model statesYes60 days from receipt of the appeal, in writing with reasons
ColoradoYes45 days, extendable by 60 more when reasonably necessary with notice
MinnesotaYes45 days, with a 60-day extension available on notice
MarylandYes60 days from receipt of the appeal
TennesseeYes60 days from receipt of the appeal
FloridaYes60 days from receipt of the appeal
IowaYes60 days from receipt of the appeal
UtahNoThe UCPA is the only comprehensive state law with no appeal right at all
California (CCPA / CPRA)No formal appealNo statutory appeal step; a consumer dissatisfied with the outcome complains to the CPPA or the Attorney General
GDPRNo controller appealNo internal appeal; the person lodges a complaint with a supervisory authority and has a right to a judicial remedy

Two things are worth reading off that table. First, Utah is the outlier. If you build a single appeal workflow for your whole footprint, it will be more generous than Utah requires, which is harmless, but do not assume the reverse and skip appeals because Utah skips them. Every other state that has passed a comprehensive law expects the route to exist. Second, California and the GDPR do not use a controller-side appeal at all, so a process copied from the CCPA will be missing a step your Virginia-model states require. The state-by-state applicability guide covers which laws reach your business in the first place.

What a compliant appeal response has to include

Answering an appeal is not just re-sending the denial. The statutes are specific about what the written decision contains, and a response that skips these elements can be non-compliant even if the underlying decision was correct.

  • A clear statement of the action taken or not taken, so the consumer knows whether the appeal changed anything.
  • A written explanation of the reasons for the decision. A denial that relies on an exemption should name the basis, not gesture at one.
  • A way to contact the attorney general or submit a complaint if the appeal is also denied. Most Virginia-model laws make this an express requirement, and it is easy to forget because it feels like inviting the regulator in.
  • The response inside the statutory window, delivered through a method the consumer can access. A decision made on time but sent to an address nobody checks is still a late response in practice.

The appeal should also be decided by someone other than the person who made the original call where you can manage it. That is not always spelled out in the statute, but a reconsideration that lands on the same desk and reaches the same answer with no fresh review reads badly if a regulator later asks how the appeal was handled. Teams that already map each obligation to the control that satisfies it tend to route appeals to a second reviewer by default, which is what makes the reconsideration real rather than a formality.

Why the appeal route is a separate compliance risk

The denial and the appeal are two distinct obligations, and you can comply with one while failing the other. A correct, well-reasoned denial that never tells the consumer how to appeal is still a violation of the appeal-notice requirement. So is a denial that mentions an appeal but points to a form that does not work, or one that quietly lets the appeal clock lapse because it was filed under the original request.

California's regulators have made clear, in a run of 2025 and 2026 enforcement actions, that they judge the mechanism rather than the outcome. A request process that is technically available but effectively unusable draws the same scrutiny as no process at all. The safe reading for appeals is the same: the route has to exist, be findable, work, and be answered on its own clock. If you miss the deadline, the late appeal becomes its own problem on top of the original denial, and our guide to a missed DSAR deadline walks through what that exposes you to.

How to build an appeal workflow that holds up

The appeal is short, it is time-boxed, and it usually arrives when the consumer is already unhappy, which is exactly the moment a process shows whether it was built for real. Three things keep it defensible.

Stamp the appeal with its own arrival date

The appeal deadline runs from when the appeal is submitted, not from the original request. Log the appeal as a new item with its own received date and its own clock, and calculate the deadline from the law that applies, since Colorado runs 45 days and most states run 60. Guessing which state a consumer sits in is the same problem you solved on intake, and the deadline table by state has each number.

Reopen the discovery, do not just reread the denial

Most appeals argue that you missed something: a system you did not search, a record you should have found, a category you excluded. A genuine reconsideration means running the search again, not rereading the first answer. Knowing where the person's data actually lives across your systems is what lets you say, with evidence, whether the original response was complete. That is the same discovery work the first request needed, which is why a tool that maps data location makes the appeal answerable instead of a guess.

Keep the record of both decisions

An appeal is where a documented trail earns its keep. If a regulator later reviews the file, the useful record shows the original request and its denial with reasons, the appeal and its arrival date, who reviewed it, what was searched the second time, and the written decision that went out. That record is a by-product of handling the request in a system rather than a mailbox, and it is the difference between a defensible reconsideration and a he-said-she-said.

Obtainer is built for this. It intakes the request and stamps the arrival date, finds where the person's data lives across your systems, compiles it into one reviewable manifest with the source system on each item, drafts a deadline-safe response, and tracks the statutory clock per request and per appeal. A human redacts and approves before anything is disclosed or erased. Obtainer helps you comply. It is not legal advice, so the denial decision, the exemption call, and the appeal outcome stay with your team. Start with DSAR automation or the privacy team workflow.

Frequently asked questions

What is a data subject request appeal?

It is a formal reconsideration a consumer can request after you deny a privacy request, handled inside your company before they escalate to a regulator. Most US state privacy laws require you to offer a conspicuous appeal process, tell the consumer how to use it when you deny them, and respond in writing with reasons within a set number of days. If you deny the appeal too, you must give the consumer a way to contact the attorney general or file a complaint.

Which states require a privacy request appeal process?

Almost all of them. Virginia, Texas, Colorado, Connecticut, Maryland, Minnesota, Tennessee, Florida, Iowa, and the rest of the Virginia-model states require a conspicuous appeal process for denied requests. Utah is the only comprehensive state privacy law that does not grant an appeal right. California and the GDPR do not use a controller-side appeal; instead the person complains to the regulator, and under the GDPR also has a right to a judicial remedy.

How long do I have to respond to a data subject request appeal?

In most states, 60 days from receipt of the appeal, delivered in writing with the reasons for your decision. Colorado gives you 45 days, extendable by 60 more when reasonably necessary if you notify the consumer, and Minnesota uses 45 days with a 60-day extension available. The appeal clock is separate from and starts later than the clock on the original request, so calculate it from the date the appeal was submitted.

What happens if I do not offer an appeal process?

Failing to provide an appeal route, or denying a request without telling the consumer how to appeal, is a violation separate from the denial itself. It is the kind of process gap a regulator identifies quickly, and it can turn a defensible denial into an enforcement matter. In the states that require it, the appeal mechanism has to exist, be findable, actually work, and be answered on its statutory clock.

Who should decide a data subject request appeal?

Where you can manage it, someone other than the person who made the original decision. The statutes do not always require independent review, but an appeal that reaches the same desk and the same answer with no fresh search is hard to defend if a regulator asks how it was handled. A real reconsideration reruns the data discovery and documents what was searched the second time, rather than rereading the first denial.

Is a data subject request appeal the same under the CCPA?

No. The CCPA and CPRA do not include a controller-side appeal step. A California consumer who is unhappy with how you handled a request does not appeal to you; they file a complaint with the California Privacy Protection Agency or the Attorney General. This is one of the ways a request process copied from California can be missing a step that the Virginia-model states require, so check each law that applies to you rather than assuming one process fits all.

Run a data subject access request end to end

Obtainer finds where a person's data lives across your systems, compiles it into one manifest, drafts the deadline-safe response, and tracks the GDPR and CCPA clock. You review, redact, and approve what gets disclosed. Helps you comply; not legal advice.