← Back to Blog
Compliance & Legal2026-09-30·Digital Footprint Health Team

How Long Does a Deletion Request Take? GDPR 30 Days vs CCPA 45 Days

deletion requestGDPRCCPAdata complianceprivacy rights

Once a deletion request is out the door, most people land in an uncertain middle: no confirmation it arrived, no sense of how long to wait, no idea how hard to push. There is a firmer footing than that. GDPR and CCPA both set statutory response deadlines, and the main difference between them is a month versus 45 days, plus how extensions work.

This covers the deadlines and the mechanics around them. How to draft the request itself, including which legal basis to cite, is a separate topic covered in the deletion request template.

The two baseline deadlines

Start with the two numbers people cite most, then take them apart.

RegimeStatutory deadlineExtensionClock starts
GDPR (EU)One monthUp to two further months, with reasonsOn receipt of the request
CCPA / CPRA (California)45 daysUp to 45 more days, with prior noticeOn receipt of a verifiable request
China PIPLNo fixed number; prompt handling requiredCase by caseOn receipt of the application

Note the extension column. Both regimes allow extensions, and both require notice to use them. An organisation that simply goes quiet past the deadline is already out of compliance.

How the month and the 45 days are counted

The GDPR month is generally counted as a calendar month. A request received on 3 July is answered by 3 August. Where that lands on a holiday, it usually rolls to the next working day.

The CCPA 45 days are calendar days, weekends and holidays included. That distinction matters when you chase: applying the calendar-month logic to a California entity will get your dates wrong.

When an extension is valid

Extensions are not automatic. Under GDPR, the reason has to appear in the first response, for example a high volume of requests or complex data flows. Under CCPA, notice has to reach you within the original 45 days with the reason stated. In both cases the first reply itself has to arrive. You cannot extend by sending notice after the deadline has passed.

The clock starts earlier than most people assume

A common misunderstanding is that counting begins once you have explained everything clearly. It does not. It begins when the organisation receives the request, not when it agrees the request is actionable. The moment delivery happens, the clock runs, and that is exactly why proof of delivery carries weight.

Submission method therefore matters. Registered mail and timestamped email establish the starting point far more easily than a web form. With a web form, a screenshot of the confirmation page plus the auto-reply email is the minimum evidence to keep.

Verifiability is a moving part

CCPA explicitly requires a verifiable request. If the organisation cannot confirm you are the person whose data is in question, it may ask for more information. Those requests have to be reasonable, such as confirming the email tied to the account, not demanding a scanned identity document that goes well beyond what is necessary.

Does a verification request pause the clock? Not automatically. It can justify an extension, but only if the organisation notified you within the deadline. No notice and no answer still counts as a missed deadline.

What to do once the deadline passes

Escalating in order tends to work better than resending the same email.

  1. Send a dated follow-up. Cite the original request date, the statutory deadline and the number of days overdue, and ask for a written response. Its main job is to create a record.
  2. File with a regulator. EU member states each have a data protection authority, and California has its own privacy agency. Complaints do not require a lawyer and can be filed through an online form.
  3. Keep the whole trail. Request date, reply dates, and the content and channel of every exchange, arranged chronologically in one document.
  4. Assess further options. Where there are actual damages, some jurisdictions allow a private right of action, but thresholds and scope vary widely and need separate analysis.

Of the four, the first and third cost the least and pay off most directly. Plenty of requests finally move because of one follow-up letter with a date on it.

Data brokers behave differently

Platforms usually have a settled process and answer close to the statutory limit. Data brokers split into two groups. Some run automated intake and respond quickly. Others depend on manual review and drift toward the end of the extension.

There is also a group outside your jurisdiction entirely, where the statutory deadline has no direct hold. The practical outcome then depends on whether the organisation wants to cooperate and whether it has affiliated entities in a jurisdiction that does bind it. Working that out is more useful than sending more reminders.

A follow-up schedule you can reuse

Turned into a timeline, the rules are easier to work through.

WhenActionPurpose
Day of submissionSave the submission receipt and auto-replyFixes the start of the clock
Day 7Confirm the request was acceptedRules out non-delivery
Day 25 (GDPR) / Day 40 (CCPA)Send a reminder asking about extensionForces the extension notice
3 days after the deadlineSend the dated follow-upCreates overdue evidence
2 weeks overdueFile the regulator complaintBrings in outside pressure

Tighten the spacing to fit your situation, but keep the order. Chasing internally before escalating produces a stronger complaint file.

An in-product flow is not the same as a statutory deadline

A platform's own deletion features, such as an in-account bulk delete, run as a product flow. They are not bound by the deadlines above and are usually much faster, though they have limits of their own, covered in why old tweets will not delete.

The statutory right applies where the other party controls the decision: third-party reposts, data broker files, search engine caches. Separating the two routes saves a lot of wasted chasing. For how a GDPR request plays out against a platform specifically, see filing an erasure request.

About digital-footprint-health.shop

Knowing what you have actually exposed makes any outgoing request far more precise. Upload an X archive at the homepage of digital-footprint-health.shop and the tool parses every post locally, returning a tiered list covering contact details, location data, institutional ties and opinion posts. The archive never leaves your machine. The check is free and read-only and deletes nothing. Cleanup scope and pricing sit on the pricing page, and the method write-ups are collected in the blog index.

Frequently Asked Questions

Is the GDPR month 30 days or a calendar month?

Generally a calendar month. A request received on 3 July is due by 3 August, and a non-working day is usually pushed to the next working day. CCPA counts 45 calendar days instead, so match the counting method to the regime when you calculate dates.

What is required for a valid extension?

Notice plus a stated reason. GDPR requires the reason in the first response and allows up to two further months. CCPA requires notice within the original 45 days and allows 45 more. Silence past the deadline is not a valid extension and still counts as overdue.

If there is no reply, when can I file a complaint?

Once the statutory deadline has passed. A steadier sequence is to send a follow-up citing the original date and the number of days overdue, wait about a week, and file if nothing comes back. The complaint then carries a complete communication record, which tends to move faster.

Are a platform's own deletion tools bound by these deadlines?

No. In-product deletion is a product flow, usually far faster than the statutory deadline, but it has its own limits around date ranges and volume. The statutory deadlines apply where the other party holds the decision, such as third-party reposts or data broker files.

Check your own X/Twitter footprint

Free on-device scan. Your archive never leaves your computer.

Start Free Check

Related Reads

Published on 2026-09-30. Last updated 2026-09-30.