How Long Does a Deletion Request Take? GDPR 30 Days vs CCPA 45 Days
Once a deletion request is out the door, most people land in an uncertain middle: no confirmation it arrived, no sense of how long to wait, no idea how hard to push. There is a firmer footing than that. GDPR and CCPA both set statutory response deadlines, and the main difference between them is a month versus 45 days, plus how extensions work.
This covers the deadlines and the mechanics around them. How to draft the request itself, including which legal basis to cite, is a separate topic covered in the deletion request template.
The two baseline deadlines
Start with the two numbers people cite most, then take them apart.
| Regime | Statutory deadline | Extension | Clock starts |
|---|---|---|---|
| GDPR (EU) | One month | Up to two further months, with reasons | On receipt of the request |
| CCPA / CPRA (California) | 45 days | Up to 45 more days, with prior notice | On receipt of a verifiable request |
| China PIPL | No fixed number; prompt handling required | Case by case | On receipt of the application |
Note the extension column. Both regimes allow extensions, and both require notice to use them. An organisation that simply goes quiet past the deadline is already out of compliance.
How the month and the 45 days are counted
The GDPR month is generally counted as a calendar month. A request received on 3 July is answered by 3 August. Where that lands on a holiday, it usually rolls to the next working day.
The CCPA 45 days are calendar days, weekends and holidays included. That distinction matters when you chase: applying the calendar-month logic to a California entity will get your dates wrong.
When an extension is valid
Extensions are not automatic. Under GDPR, the reason has to appear in the first response, for example a high volume of requests or complex data flows. Under CCPA, notice has to reach you within the original 45 days with the reason stated. In both cases the first reply itself has to arrive. You cannot extend by sending notice after the deadline has passed.
The clock starts earlier than most people assume
A common misunderstanding is that counting begins once you have explained everything clearly. It does not. It begins when the organisation receives the request, not when it agrees the request is actionable. The moment delivery happens, the clock runs, and that is exactly why proof of delivery carries weight.
Submission method therefore matters. Registered mail and timestamped email establish the starting point far more easily than a web form. With a web form, a screenshot of the confirmation page plus the auto-reply email is the minimum evidence to keep.
Verifiability is a moving part
CCPA explicitly requires a verifiable request. If the organisation cannot confirm you are the person whose data is in question, it may ask for more information. Those requests have to be reasonable, such as confirming the email tied to the account, not demanding a scanned identity document that goes well beyond what is necessary.
Does a verification request pause the clock? Not automatically. It can justify an extension, but only if the organisation notified you within the deadline. No notice and no answer still counts as a missed deadline.
What to do once the deadline passes
Escalating in order tends to work better than resending the same email.
- Send a dated follow-up. Cite the original request date, the statutory deadline and the number of days overdue, and ask for a written response. Its main job is to create a record.
- File with a regulator. EU member states each have a data protection authority, and California has its own privacy agency. Complaints do not require a lawyer and can be filed through an online form.
- Keep the whole trail. Request date, reply dates, and the content and channel of every exchange, arranged chronologically in one document.
- Assess further options. Where there are actual damages, some jurisdictions allow a private right of action, but thresholds and scope vary widely and need separate analysis.
Of the four, the first and third cost the least and pay off most directly. Plenty of requests finally move because of one follow-up letter with a date on it.
Data brokers behave differently
Platforms usually have a settled process and answer close to the statutory limit. Data brokers split into two groups. Some run automated intake and respond quickly. Others depend on manual review and drift toward the end of the extension.
There is also a group outside your jurisdiction entirely, where the statutory deadline has no direct hold. The practical outcome then depends on whether the organisation wants to cooperate and whether it has affiliated entities in a jurisdiction that does bind it. Working that out is more useful than sending more reminders.
A follow-up schedule you can reuse
Turned into a timeline, the rules are easier to work through.
| When | Action | Purpose |
|---|---|---|
| Day of submission | Save the submission receipt and auto-reply | Fixes the start of the clock |
| Day 7 | Confirm the request was accepted | Rules out non-delivery |
| Day 25 (GDPR) / Day 40 (CCPA) | Send a reminder asking about extension | Forces the extension notice |
| 3 days after the deadline | Send the dated follow-up | Creates overdue evidence |
| 2 weeks overdue | File the regulator complaint | Brings in outside pressure |
Tighten the spacing to fit your situation, but keep the order. Chasing internally before escalating produces a stronger complaint file.
An in-product flow is not the same as a statutory deadline
A platform's own deletion features, such as an in-account bulk delete, run as a product flow. They are not bound by the deadlines above and are usually much faster, though they have limits of their own, covered in why old tweets will not delete.
The statutory right applies where the other party controls the decision: third-party reposts, data broker files, search engine caches. Separating the two routes saves a lot of wasted chasing. For how a GDPR request plays out against a platform specifically, see filing an erasure request.
About digital-footprint-health.shop
Knowing what you have actually exposed makes any outgoing request far more precise. Upload an X archive at the homepage of digital-footprint-health.shop and the tool parses every post locally, returning a tiered list covering contact details, location data, institutional ties and opinion posts. The archive never leaves your machine. The check is free and read-only and deletes nothing. Cleanup scope and pricing sit on the pricing page, and the method write-ups are collected in the blog index.
Frequently Asked Questions
Is the GDPR month 30 days or a calendar month?
Generally a calendar month. A request received on 3 July is due by 3 August, and a non-working day is usually pushed to the next working day. CCPA counts 45 calendar days instead, so match the counting method to the regime when you calculate dates.
What is required for a valid extension?
Notice plus a stated reason. GDPR requires the reason in the first response and allows up to two further months. CCPA requires notice within the original 45 days and allows 45 more. Silence past the deadline is not a valid extension and still counts as overdue.
If there is no reply, when can I file a complaint?
Once the statutory deadline has passed. A steadier sequence is to send a follow-up citing the original date and the number of days overdue, wait about a week, and file if nothing comes back. The complaint then carries a complete communication record, which tends to move faster.
Are a platform's own deletion tools bound by these deadlines?
No. In-product deletion is a product flow, usually far faster than the statutory deadline, but it has its own limits around date ranges and volume. The statutory deadlines apply where the other party holds the decision, such as third-party reposts or data broker files.
Check your own X/Twitter footprint
Free on-device scan. Your archive never leaves your computer.
Start Free CheckRelated Reads
The Right to Be Forgotten: Getting Search Engines to Delist Your Old Tweets
The right to be forgotten is not a delete-everything button. It governs search results, not the underlying page. Here is the three-layer model: kill the source, request delisting, chase the copies.
Using the GDPR Right to Erasure on X: Steps and a Request Template
The delete button on a platform and the right to erasure under Article 17 of the GDPR are not the same instrument. The first removes your own content. The second can require the platform to address a wider set of personal data, and it comes with a statutory response deadline. Here are the conditions, a five-step submission flow, and a template you can adapt.
Archive First, Erasure Second: Ordering Your Data Rights Requests
Portability and erasure are two separate requests, and the order you file them changes what you receive. Requesting an archive first leaves you a complete evidence trail. Filed the other way round, your portability response shrinks substantially. Here are the statutory deadlines, how the two interact, and how to word each request.