How long do you have to respond to a privacy request in each state?
Most US state privacy laws give a business 45 days to answer a consumer request, extendable once by 45 more: California, Texas, Virginia, Delaware and Minnesota all work that way. Iowa is the outlier at 90 days. Appeals usually run a separate 60-day clock, with Minnesota the exception.
Applies to: Businesses subject to more than one US state privacy law that need a single request-handling calendar covering the different response deadlines, extensions, and appeal windows each state sets.
Find out what applies to you
Run the free 2-minute Obligation Scan and get a plain-language list of what your business has to do, and by when.
Run the free 2-minute Obligation ScanIf you operate in several states, the request calendar is the thing most likely to trip you, because the numbers look similar until they are not.
The deadlines side by side
| Law | Initial response | Extension | Appeal decision | Free responses |
|---|---|---|---|---|
| California CCPA | 45 days | once, +45 | n/a | not specified here |
| Texas TDPSA | 45 days | once, +45 | by the 60th day | not specified here |
| Virginia VCDPA | 45 days | once, +45 | within 60 days | twice annually |
| Delaware DPDPA | 45 days | once, +45 | within 60 days | once per 12 months |
| Minnesota MCDPA | 45 days | once, +45 | within 45 days, +60 | twice annually |
| Iowa | 90 days | once, +45 | within 60 days | twice annually |
Every figure above is taken from the statute text, cited in full at the end of this page.
The one rule that makes this manageable
Build a single 45-day workflow measured from receipt and you satisfy all of them.
Forty-five days is the shortest initial deadline in the group, so meeting it meets California, Texas, Virginia, Delaware and Minnesota outright, and lands comfortably inside Iowa's 90. The failure mode runs the other way: a business that reads Iowa first and builds a 90-day process is in breach the moment a Virginia or Delaware consumer submits a request.
The extension is conditional in every state
None of these states grant an automatic extension. The pattern is consistent: the extension is available once, it must be reasonably necessary taking into account the complexity and number of requests, and the consumer must be told inside the initial response period, with a reason.
Texas puts it as informing the consumer of the extension within the initial 45-day response period together with the reason. Delaware, Virginia, Minnesota and Iowa all use the same construction against their own clocks. An extension taken silently on the last day is not an extension in any of them.
Declining is still a response
Each of these laws requires a refusal to arrive inside the initial deadline, carrying two things: why you declined, and how to appeal.
Iowa adds a sensible wrinkle at 715D.3(2)(b): for a suspected fraudulent request the controller may simply state that it was unable to authenticate the request, rather than explaining its reasoning to a possible attacker.
Appeals run on their own clock
The appeal window is separate from the request window, and it is the part teams most often leave unbuilt.
Texas, Virginia, Delaware and Iowa all land on 60 days from receipt of the appeal, with a written explanation of the reasons. Minnesota is the exception: 45 days, extendable by 60 additional days where reasonably necessary.
Two further obligations attach to a denied appeal. Most of these states require you to hand the consumer a route to the regulator. Iowa requires an online mechanism to contact the attorney general with no "if available" qualifier, where Delaware and Virginia allow an alternative method. And Minnesota alone requires the controller to maintain records of all appeals and its responses for at least 24 months, and to produce them to the attorney general on written request during an investigation.
Where the clock starts
Receipt, in all six. Not the moment you finish verifying identity.
This matters because verification is where request handling actually slows down. Several of these laws let you decline where you cannot authenticate using commercially reasonable efforts, and let you ask for more information, but none of them stop the clock while you do it.
Next step
Knowing the deadlines only helps once you know which laws reach you, and the applicability tests differ more than the deadlines do. The free 2-minute Obligation Scan checks your business against every US state privacy law and GDPR and tells you which ones apply. For the applicability side, see privacy thresholds by state; for the two ends of the range here, see Iowa's 90-day deadline and Delaware's 45 days with a single free request.
Compliance checklist
- Run one 45-day clock from receipt across all states, since that satisfies every deadline verified here.
- Treat the extension as conditional everywhere: each state requires you to notify the consumer inside the initial period and give a reason.
- Take the extension once only; no state examined here allows it twice.
- Answer refusals inside the same initial window with the justification and appeal instructions, because declining is still a response.
- Run a separate appeal calendar at 60 days, and note Minnesota answers appeals in 45 days with a 60-day extension rather than a flat 60.
- Track free responses per consumer, because the allowance differs: Delaware permits one per 12-month period where Iowa and Virginia permit two annually.
- In Minnesota, retain appeal records and your responses for at least 24 months, which no other state here requires.
Sources
- Tex. Bus. & Com. Code 541.052, 541.053 (controller response; appeal), Texas Constitution and Statutes
- Va. Code 59.1-577 (personal data rights; consumers), Virginia Law
- 6 Del. C. 12D-104 (consumer personal data rights), The Delaware Code Online
- Minn. Stat. 325M.14 (consumer personal data rights), 2025 Minnesota Statutes
- Iowa Code 715D.3 (consumer data rights), Iowa Legislature
Last verified: 2026-08-23
Informational, not legal advice.