Obtainer
Blog / Fundamentals 9 min read

Data Subject Request Deadlines by State: How Long You Have to Respond in 2026

Last updated July 2026 · Obtainer

Request Studio
Requester
Compiled the manifest and drafted the response - illustrative sample request
0
records found
0
systems scanned
Data manifest
Response draft

Assembling the cover letter from the template...

You approve what is disclosed before anything ships

Helps you comply, not legal advice

Eighteen of the twenty comprehensive US state privacy laws give you 45 days to respond to a verified data subject request, and let you extend that once by another 45 days when the request is complex, for a cap of 90 days. Two states break the pattern: Iowa allows 90 days plus a 45-day extension, the longest window in the country, and Florida allows only a 15-day extension, for a 60-day ceiling. The clock starts when you receive a request you can tie to a real person, not when you get around to it. Under the GDPR the deadline is different: one calendar month, extendable by two more.

General information, not legal advice. Deadlines have exceptions and your specific facts control, so confirm the rule that applies before you rely on it.

How long do you have to respond to a data subject request?

For most US state laws the answer is 45 calendar days from a verified request. California set the pattern with the CCPA, and nearly every state that followed the Virginia template copied it, so a company operating in twenty states is mostly working to one number rather than twenty. The extension is usually uniform too: one additional 45-day period when reasonably necessary, provided you tell the person within the first 45 days and explain why. That gives a worst case of 90 days. Iowa and Florida are the two exceptions, in opposite directions, and both are in the table below.

LawBase deadlineExtensionMaximum
California (CCPA / CPRA)45 days+45 days90 days
Colorado (CPA)45 days+45 days90 days
Texas (TDPSA)45 days+45 days90 days
Virginia (VCDPA)45 days+45 days90 days
Connecticut, Oregon, Montana, and the other Virginia-model states45 days+45 days90 days
Florida (FDBR)45 days+15 days60 days
Iowa (ICDPA)90 days+45 days135 days
GDPR (EU / UK)1 month+2 months3 months

The one thing to watch under the CCPA is a separate, shorter clock at the front: California requires you to confirm receipt of a request within 10 business days and describe how you will handle it. That acknowledgment is easy to miss because it is not the 45-day response, but skipping it is its own compliance gap.

Florida is the outlier on the extension. The Florida Digital Bill of Rights keeps the 45-day base deadline but allows only a 15-day extension, so your ceiling is 60 days instead of the 90 that every Virginia-model state permits. If you handle requests under several state laws at once, Florida sets the hardest internal deadline, and building your workflow to that shorter window keeps you safe under the others automatically.

Iowa is the outlier in the other direction, and it is the more dangerous one. The Iowa Consumer Data Protection Act gives you 90 days from an authenticated request, extendable by 45 more, so the ceiling is 135 days. That is triple Florida's base deadline and the longest response window of any US state privacy law. The danger is not that Iowa is lenient, it is that almost nobody serves Iowa residents exclusively. A team that internalizes 90 days as the number will be 45 days late in Virginia, Texas, Colorado, and every other Virginia-model state. Track the clock per request against the law that actually applies to that requester, and never let the most generous state set your default.

When does the clock start?

The deadline runs from the day you receive a request you can verify, not the day you decide to work on it. In practice that means two things happen before the count begins in earnest: you confirm the request is from the person it claims to be, and you confirm it is a request the law covers. Identity verification is part of the window, not a pause on it, so a slow verification step eats into the same 45 days you need for the actual work. Most laws expect you to use commercially reasonable methods to verify, scaled to how sensitive the requested data is.

A request does not have to arrive on your official form or use legal language to count. If a person asks, in a way a reasonable business would understand, to see or delete their data, the clock is running. Building your intake so that any inbound request is logged and dated the moment it lands is the difference between a defensible timeline and a guess.

What can extend the deadline?

You can take the extra 45 days when a request is genuinely complex or when you are handling a high volume from the same person, but the extension is not automatic. You have to notify the consumer within the initial 45-day period, tell them you are extending, and give the reason. Miss that notice and you have blown past the deadline even though the law technically allowed you more time. Treat the extension as a decision you document, not a buffer you assume. That matters more than it used to, because most states no longer give you a right to cure a violation, so a blown deadline is enforceable on the first miss rather than after a warning letter.

What actually eats the 45 days?

Almost never the drafting. The time goes to finding the data. A single person's records sit in your production database, your warehouse, your billing system, your help desk, your marketing tools, and a pile of exported files and PDFs that no query touches. Teams routinely burn three weeks locating everything, then rush the review. When personal data is trapped in scanned contracts or statements, pulling it out by hand is its own delay, which is why teams lean on automated document data extraction to turn those files into searchable records before the clock forces a shortcut.

The fix is to compress discovery, not the review. Personal data discovery surfaces where a person's data lives across your systems in one pass, so the 45 days go to human judgment, redaction, and approval instead of a scavenger hunt. From there, deadline tracking records when each request arrived and counts the state-specific clock per request, so a response does not slip past day 45 because it fell off someone's calendar.

State deadlines vs the GDPR month

If you handle both US and EU requests, the two systems do not line up, and defaulting to the shorter one keeps you safe. The GDPR gives one calendar month, which is usually a few days shorter than 45 days, and its extension rules are stricter: two extra months only for complex or numerous requests, with notice inside the first month. A team that treats every request as if the GDPR clock applies will never be late under a US law, but the reverse is not true. Our GDPR vs CCPA comparison breaks down where the two regimes diverge beyond the deadline.

One more clock sits outside the comprehensive laws entirely. Washington's My Health My Data Act covers consumer health data that HIPAA does not reach, and it requires a response without undue delay and within 45 days, extendable once by 45 more. It has no size threshold, so it can apply to you even where a comprehensive state law does not, and it is the only US privacy law a consumer can sue you over directly. Nevada and Connecticut have their own health data rules. The consumer health data privacy laws guide covers which ones are actually in force.

Eighteen of the twenty comprehensive laws share the same 45-day base, so for most of your footprint the real variable is how fast you can find the data and how reliably you can prove you hit the date. Iowa and Florida are the exceptions worth tracking separately. Getting all of it under control is what CCPA compliance software like Obtainer is built to do: log the request, find the data, draft the response, and track each statutory clock so the deadline is a fact you can show, not a date you hope you met.

Run a data subject access request end to end

Obtainer finds where a person's data lives across your systems, compiles it into one manifest, drafts the deadline-safe response, and tracks the GDPR and CCPA clock. You review, redact, and approve what gets disclosed. Helps you comply; not legal advice.