Back to the hub

CCPA 90 day extension: how long does a business really have?

There is no 90 day extension under the CCPA. Cal. Civ. Code 1798.130(a)(2)(A) gives 45 days from receipt of a verifiable consumer request, extendable once by a further 45 days when reasonably necessary, provided notice of the extension reaches the consumer inside the first 45 day period. Ninety days is the ceiling.

Applies to: Businesses covered by the CCPA that receive verifiable consumer requests to know, delete, or correct personal information about California residents.

Find out what applies to you

Run the free 2-minute Obligation Scan and get a plain-language list of what your business has to do, and by when.

Run the free 2-minute Obligation Scan

"CCPA 90-day extension" is a phrase the statute never uses, and the gap between the phrase and the text causes real misses. The CCPA gives you 45 days. You can buy one more block of 45. Ninety is the ceiling you land on, not the extension you take.

What Section 1798.130(a)(2)(A) requires

The duty is to disclose and deliver the required information free of charge, correct inaccurate personal information, or delete personal information, based on the consumer's request, within 45 days of receiving a verifiable consumer request. The next sentence is the one businesses lean on: the time period may be extended once by an additional 45 days when reasonably necessary, provided the consumer is provided notice of the extension within the first 45-day period.

Three conditions are stacked in that sentence, and all of them are load-bearing. The extension is available once. It has to be reasonably necessary. And the notice has to land inside the original 45 days.

The verification trap

The most common way a business blows the deadline is by treating identity verification as preliminary work that happens before the clock starts. Section 1798.130(a)(2)(A) closes that off directly. The business shall promptly take steps to determine whether the request is a verifiable consumer request, "but this shall not extend the business' duty to disclose and deliver the information, to correct inaccurate personal information, or to delete personal information within 45 days of receipt of the consumer's request."

Receipt starts the clock. A month spent chasing the consumer for identity documents is a month of the 45 days, not a month before them. If verification is genuinely slow, that is a reason to take the extension early, not a reason to argue the deadline moved.

Notice on day 46 does not work

Because the extension is conditioned on notice inside the first 45-day period, a business that goes quiet and then writes on day 50 to announce an extension has not extended anything. It has missed the deadline and then described the miss. Build the extension decision into the workflow at around day 30, while there is still time to send valid notice.

How the response has to be delivered

The same provision sets the delivery mechanics. The disclosure shall be made in writing and delivered through the consumer's account with the business, if the consumer maintains one, or by mail or electronically at the consumer's option if they do not, in a readily useable format that allows the consumer to transmit the information from one entity to another without hindrance. A response that only appears inside a support ticket the consumer cannot export is not obviously compliant.

How California compares

California's 45 plus 45 is the common US pattern, but it is not universal. Iowa gives controllers 90 days to respond in the first place under Iowa Code Section 715D.3(2)(a), extendable once by 45 more. Oregon, Indiana, Colorado and Texas all start at 45 days but differ on the appeal clock. If you operate across several states, see the response deadlines by state comparison, and read the 45-day rule itself for what the base period covers.

Next step

If consumer requests are arriving faster than your process handles them, the free 2-minute Obligation Scan identifies which state deadlines apply to your business and what each one requires at the 45-day and appeal stages. The US state privacy laws hub sets the rest of the request workflow out in order.

Compliance checklist

  • Timestamp every consumer request on receipt, because the 45 days runs from receipt and not from the point you finish verifying identity.
  • Decide whether an extension is 'reasonably necessary' before day 45, and record the reason, since the statute permits the extension only on that basis.
  • Send the extension notice to the consumer inside the first 45-day period, not at the end of it, and keep proof of when it was sent.
  • Take the extension once only. Cal. Civ. Code Section 1798.130(a)(2)(A) allows a single 45-day extension, so 90 days is a hard ceiling rather than a rolling one.
  • Deliver the response in writing through the consumer's account, or by mail or electronically at the consumer's option if they have no account, in a readily useable format.

Sources

Last verified: 2026-09-02

Informational, not legal advice.