Obtainer
Blog / Data Subject Rights 9 min read

Right to Correct Personal Data: How to Handle a Correction Request Under US State Laws

Last updated July 2026 · Obtainer

Request Studio
Requester
Compiled the manifest and drafted the response - illustrative sample request
0
records found
0
systems scanned
Data manifest
Response draft

Assembling the cover letter from the template...

You approve what is disclosed before anything ships

Helps you comply, not legal advice

The right to correct personal data lets a consumer require a business to fix inaccurate information it holds about them. Nineteen of the twenty comprehensive US state privacy laws now grant it, with Utah joining on July 1, 2026 and Iowa the only holdout. Under GDPR the same right is called rectification. In the US you generally have 45 days to respond, extendable once by another 45 with notice. The hard part is not the deadline. It is that one wrong value usually lives in six or eight systems, and a correction only counts when it reaches all of them.

What is the right to correct personal data?

It is a consumer's right to have inaccurate personal data about them corrected, taking into account the nature of the data and the purposes for which it is processed. That qualifier matters: the laws do not require you to accept every asserted correction. They require you to consider it, decide reasonably, and either make the fix or explain why you did not.

The wording differs slightly between statutes but the substance is consistent. California's CPRA gives consumers a right to correct inaccurate personal information and requires businesses to use commercially reasonable efforts. The Virginia-template states, which is most of them, give a right to correct inaccuracies in the consumer's personal data, taking into account the nature of the data and the purposes of processing. GDPR Article 16 gives a right to rectification without undue delay, plus a right to have incomplete data completed by means of a supplementary statement.

Which states have a right to correct?

JurisdictionCorrection rightResponse deadline
California (CCPA/CPRA)Yes, added by CPRA effective January 1, 202345 days, one 45-day extension
Virginia, Colorado, Connecticut, Texas, Oregon, Montana, Delaware, New Jersey, Minnesota, Maryland, Tennessee, New Hampshire, Nebraska, Indiana, Kentucky, Rhode Island, FloridaYes45 days, one 45-day extension
Utah (UCPA)Yes, added by House Bill 418 effective July 1, 202645 days, one 45-day extension
IowaNo correction right90 days, one 45-day extension
EU and UK (GDPR Article 16)Yes, rectification plus completionOne month, extendable by two

Utah's addition is the reason this matters right now. Utah is the newest correction obligation in the country, and it landed on companies that had built their request workflow around access and deletion only. The Utah Consumer Privacy Act compliance page covers the thresholds and the 30-day cure period that still applies there, and the wider July 2026 changes put it alongside Connecticut's threshold cut and New Jersey's cure sunset.

Right to correct versus right to rectification: are they the same?

Close, with two real differences. GDPR rectification includes an explicit right to have incomplete personal data completed, including by adding a supplementary statement, and it carries a downstream notification duty under Article 19: you must tell each recipient the data was disclosed to about the rectification, unless that proves impossible or involves disproportionate effort, and tell the person who those recipients were if they ask.

Most US state laws do not carry that Article 19 style notification duty in the same explicit form, and they do not have the completion right. What they do carry is the reasonableness qualifier, which gives you more room to decline a correction you have grounds to doubt, provided you explain the decision and, in states like Colorado, Connecticut, New Jersey, and Delaware, offer an appeal. Our full right to rectification guide works through the GDPR side in detail.

How to respond to a correction request, step by step

1. Log the request and start the clock on receipt

The 45 days run from receipt, not from the day you decide the request is valid, and not from the day identity verification finishes. Time spent verifying counts against you. Record the date, the channel it arrived on, and the exact wording of what the person claims is wrong.

2. Verify the requester before you change anything

Correction carries a risk access does not. An attacker who succeeds at an access request learns something. An attacker who succeeds at a correction request changes your record of who someone is: a mailing address, a phone number for password resets, a bank detail. Verify to a standard that matches the sensitivity of the field being changed, and be stricter for anything that could be used to take over an account.

3. Find every copy of the value, not the first one

This is where correction requests go wrong. A single attribute like a home address will typically sit in your production database, a warehouse or BI copy, a CRM record, a support ticketing tool, an email or SMS platform, a billing system, and at least one vendor that received an export. Fixing the source of truth and calling it done leaves the person's data inaccurate everywhere else, and the next export re-propagates the old value. If you already run a platform that connects your apps, APIs, and databases, that integration surface is exactly the inventory you need to work through, because every connector is a place the wrong value may have landed.

4. Decide, and write the reason down

You are allowed to decline. If a consumer asserts a correction you have documented, authoritative evidence against, say a legal name that conflicts with an identity document you verified, you can refuse, taking into account the nature of the data and the purposes of processing. What you cannot do is refuse silently. Record the reason, tell the consumer, and give them the appeal route if the applicable state requires one.

5. Push the correction downstream and record it

Where the law or good practice requires it, notify the recipients you disclosed the data to. Under GDPR that is an explicit Article 19 duty. In the US it is generally good practice and, in California, the regulations expect commercially reasonable efforts including instructing service providers and contractors to make the correction. Keep a dated record of what changed, in which systems, and when, because that record is the only thing that proves the correction actually happened.

Frequently asked questions

How long do I have to respond to a data correction request?

Forty-five calendar days from receipt in almost every comprehensive US state privacy law, with one extension of up to 45 more days when reasonably necessary, provided you tell the consumer about the extension and the reason within the original window. Florida allows only a 15-day extension, and Iowa does not grant a correction right at all, so a correction request from an Iowa resident is not an ICDPA obligation in the first place. Under GDPR the deadline is one month from receipt, extendable by a further two months for complex or numerous requests, again with notice inside the first month.

Can I refuse to correct personal data?

Yes, in defined circumstances. US state laws let you weigh the nature of the personal data and the purposes of processing, so a correction you have credible, documented grounds to doubt can be declined. Under GDPR you may also restrict processing while accuracy is contested rather than making the change. In both cases you must tell the person you refused, explain why, and provide an appeal or complaint route where the applicable law requires one.

Does the CCPA include a right to correct?

Yes. The CPRA amendments added it effective January 1, 2023. A California consumer can request correction of inaccurate personal information, and the business must use commercially reasonable efforts to correct it, including instructing service providers and contractors that hold the data. You have 45 days to respond, extendable once by another 45 days with notice, and the request must be verified before you act.

What is the difference between correcting data and deleting it?

Correction fixes an inaccurate value and keeps the record. Deletion removes the record, subject to statutory exceptions such as completing a transaction, security, or complying with a legal obligation. Consumers sometimes ask for deletion when correction is what they actually want, and the reverse. Read the request for what it asks in substance rather than the label, and if it is genuinely ambiguous, ask before you act, because deletion cannot be undone.

Do I have to tell third parties about a correction?

Under GDPR, yes, unless it proves impossible or would involve disproportionate effort, and you must name the recipients if the person asks. In the US the duty is less explicit but California expects commercially reasonable efforts that include directing service providers and contractors. Practically, if you exported the wrong value to a vendor, you should assume you need to fix it there too, or the next sync will overwrite your correction.

Where this fits in the broader rights picture

Correction is one of a set. Under GDPR there are eight data subject rights, and under CCPA six consumer rights, and the operational spine underneath all of them is the same: verify the person, find where their data actually lives, decide what applies, act, and document it. The data subject rights pillar maps the full set, and the deadline table by state covers the clocks.

Obtainer handles the operational half of a correction request: it intakes the request, discovers where the person's data lives across your systems so you can see every copy of the value in question, compiles one reviewable manifest with source badges, drafts the response, and tracks the 45-day clock. Nothing is changed automatically. A person reviews and approves before anything moves. Obtainer helps you comply. It is not legal advice, so the decision to accept or refuse a correction stays with your team. Self-serve from $49/mo.

Run a data subject access request end to end

Obtainer finds where a person's data lives across your systems, compiles it into one manifest, drafts the deadline-safe response, and tracks the GDPR and CCPA clock. You review, redact, and approve what gets disclosed. Helps you comply; not legal advice.