Obtainer
Use case

CCPA Compliance Software for Consumer Data Requests, the Right to Delete, and the 45-Day Deadline

A CCPA consumer request, whether it asks to know what you hold or to delete it, starts a 45-day clock, and gathering that data by hand across systems is where the time goes. Obtainer is CCPA compliance software that locates the data, compiles it into one reviewable manifest, and drafts a response you redact and approve before it sends.

See how it works
Discovery across your systems Human redaction gate Helps you comply, not legal advice
Request Studio
Requester
Compiled the manifest and drafted the response - illustrative sample request
0
records found
0
systems scanned
Data manifest
Response draft

Assembling the cover letter from the template...

You approve what is disclosed before anything ships

Helps you comply, not legal advice

In short

The CCPA, as amended by the CPRA, gives California consumers the right to know what personal information a business has collected about them and the right to have it deleted. You must respond within 45 calendar days of receiving a request, and you may take one extension of up to 45 more days if you tell the consumer why. The clock includes the time you spend verifying who they are, which is where teams lose weeks. Obtainer is CCPA compliance software for both rights: it intakes the consumer request, verifies the requester, finds where the person's data lives across your systems, compiles it into a single source-system manifest, drafts a deadline-safe response from templates, and tracks the 45-day deadline so it does not slip. For a deletion request it also separates the records you may keep under one of the nine statutory exceptions, such as completing a transaction, detecting security incidents, or complying with a legal obligation, from the records that must go, and it keeps a dated record of what was deleted and what was retained and why. Nothing is disclosed or erased automatically; every response passes a human redaction-and-approval gate, so you stay in control of what is disclosed. Obtainer helps you comply. It is not legal advice, so verifying the consumer's identity, applying exemptions, directing your service providers and contractors to delete, and any decision to deny stay with your team. It is self-serve from $49/mo and focuses on request fulfillment rather than bundling a governance suite.

// THE FIT

Why it fits

Privacy and legal teams handling CCPA consumer requests to know, access, or delete who want to gather the data, draft the response, and track the 45-day deadline self-serve.

Track the 45-day window

Obtainer logs when each consumer request arrives and tracks the CCPA 45-day deadline per request, including the extension, reducing the risk of missing the response date.

Both rights, one workflow

A request to know and a request to delete run through the same intake, verification, and discovery, then split: one ends in a manifest you disclose, the other in an erasure you approve.

Approve before you disclose or erase

A human redaction-and-approval gate fronts every response, and deletion cannot be undone, so nothing is destroyed until a person signs off. Helps you comply; not legal advice.

// FAQ

Questions

Common questions about this

How long do I have to respond to a CCPA request?

Forty-five calendar days from receipt of a verifiable consumer request, extendable once by another 45 days when reasonably necessary if you notify the consumer of the extension and the reason, for a 90-day maximum. Separately, you must acknowledge receipt of the request within 10 business days and explain how you will process it. Those are two distinct deadlines, and missing either is a countable violation.

What are the penalties for CCPA non-compliance?

Administrative fines reach $2,663 per violation and $7,988 per intentional violation or any violation involving a consumer you know is under 16. Those are the inflation-adjusted amounts in force through 2026, above the statute's original $2,500 and $7,500, and the California Privacy Protection Agency recalculates them every odd-numbered January. Penalties are counted per affected consumer, so a repeated process failure multiplies fast.

Does the CCPA still give me 30 days to fix a violation?

No. The CPRA removed the mandatory 30-day cure period effective January 1, 2023. A regulator may still weigh whether you remediated a problem, and good faith effort can affect the outcome, but you have no statutory right to a warning before enforcement. In practice the first missed deadline can be the violation rather than the notice.

Do CCPA rights cover employees and job applicants?

Yes. The CPRA removed the CCPA employee and HR data exemption on January 1, 2023, so California employees, former employees, job applicants, contractors, and board members have full rights to know, access, correct, and delete their workplace data on the same 45-day clock. HR data usually sits in different systems from customer data, which is why employee requests often take longer to fulfill.

Can consumers sue for a CCPA violation?

Only for a narrow category of security failures. California is the only state with a private right of action under its comprehensive privacy law, and it is limited to breaches of unencrypted and unredacted personal information caused by a failure to maintain reasonable security. Statutory damages run $107 to $799 per consumer per incident, or actual damages if higher. Mishandling an access or deletion request is a regulator matter, not something a consumer can sue over directly.

Run a data subject access request end to end

Obtainer finds where a person's data lives across your systems, compiles it into one manifest, drafts the deadline-safe response, and tracks the GDPR and CCPA clock. You review, redact, and approve what gets disclosed. Helps you comply; not legal advice.