Guide

DSAR Deadlines and Scope: CCPA/CPRA vs. GDPR Compared

GDPR and CCPA both give people the right to request their data, but the deadlines, scope, and fee rules differ enough that treating them as identical creates real compliance gaps.

Published August 13, 2026·Last updated August 13, 2026

If your business has both EU/UK visitors and California visitors, you’re handling data subject requests under two different legal frameworks that look similar on the surface but diverge on specifics that actually matter for how you respond.

Response deadlines

  • GDPR: one month from receipt, extendable by up to two further months for complex or numerous requests, with the individual notified of the extension within the original month.
  • CCPA/CPRA: 45 days from receipt, extendable by another 45 days when reasonably necessary, with notice to the requester before the initial period expires.

CCPA’s clock is longer by default, but both frameworks require you to notify the requester if you’re taking an extension, silence isn’t an option under either law.

What can be requested

GDPR’s rights are broader by default: access, rectification, erasure, portability, restriction of processing, and objection to processing (particularly direct marketing) are all in scope depending on the request.

CCPA/CPRA rights center on: the right to know what’s collected and why, the right to delete, the right to correct inaccurate data, and the right to opt out of the sale or sharing of personal information, plus limiting use of sensitive personal information under CPRA.

The practical difference: a CCPA “right to know” request is closer to GDPR’s access right, but CCPA doesn’t have a direct equivalent to GDPR’s data portability right in the same form, and GDPR doesn’t have an explicit “opt out of sale” mechanism, because GDPR’s consent-based model handles that differently.

Fees

  • GDPR: the first copy of your data must be provided free of charge. A “manifestly unfounded or excessive” repeat request can carry a reasonable fee, but this is the exception, not the norm.
  • CCPA/CPRA: also generally free for two requests within a 12-month period. Excessive or clearly unfounded requests can be charged a reasonable fee, or refused, with the reason documented.

Both frameworks default to free, treat a fee as the exception you’d need to justify, not a routine option.

Our recommendation

Enzuzo

Running both frameworks off one process is easier when your consent tooling already distinguishes EU/UK visitors from California visitors. Enzuzo's region-aware banners pair with its data subject request handling so you're not maintaining two separate systems.

Try Enzuzo

Verification requirements

GDPR expects “reasonable” verification, proportional to the sensitivity and scope of the request. CCPA/CPRA is more explicit for some request types: for a request to delete or know specific pieces of personal information, businesses are expected to verify identity to a “reasonably high degree of certainty,” which can mean requiring more than a single email confirmation, especially for sensitive data categories.

One process, two clocks

The practical approach for most small and mid-size businesses isn’t running two separate DSAR programs, it’s running one intake and fulfillment process that:

  1. Flags which regulation applies based on the requester’s location and the nature of the request.
  2. Applies whichever deadline is shorter as the internal target when it isn’t obvious which law governs.
  3. Documents the legal basis for the response either way, in case the request is later escalated.

The bottom line

GDPR and CCPA/CPRA overlap enough that one intake process can usually handle both, but the deadlines, request types, and verification expectations aren’t identical. Building your process around the stricter of the two, and knowing where they actually diverge, avoids gaps that only show up when a regulator asks specifically.

This guide is educational and not legal advice. For your specific situation, consult a privacy attorney.