DSAR Response Process: CCPA vs GDPR Side-by-Side Comparison

A detailed side-by-side comparison of CCPA and GDPR DSAR response requirements: timelines, scope of access rights, identity verification, format, delivery, and handling dual-triggered requests.

Last updated: 2026-08-02

Two Laws, Two Processes, One Inbox

If your business is subject to both the GDPR and the CCPA, you already know that handling data subject access requests means navigating two different sets of rules. The underlying principle is the same — people have the right to know what personal data you hold about them — but the timelines, scope, verification requirements, and response formats diverge in ways that matter.

Disclaimer: This article is for informational purposes only and does not constitute legal advice. Privacy regulations are complex and change frequently. You should consult a qualified attorney for guidance specific to your business. The information here is based on the GDPR (in particular Articles 12 and 15), the UK GDPR, and the CCPA/CPRA (Cal. Civ. Code §§ 1798.100–1798.199.100), as of the date of publication.

This guide provides a practical side-by-side comparison of the CCPA and GDPR DSAR processes, covering every stage from receipt to delivery. If you handle requests under both laws, this is the reference you need.

For the full CCPA process in detail, see our CCPA DSAR process guide. For the GDPR and UK GDPR process, see how to respond to a DSAR.

Timeline Comparison

Standard Deadline

  • GDPR / UK GDPR: One calendar month from receipt of the request (Article 12(3)). "One month" follows calendar month rules — a request received on January 15 is due by February 15. If the corresponding date does not exist (e.g., January 31 in a month with fewer than 31 days), the deadline is the last day of the following month.
  • CCPA: 45 calendar days from receipt of the verifiable consumer request (Cal. Civ. Code § 1798.130(a)(2)).

Extension

  • GDPR / UK GDPR: Up to two additional months (three months total) for complex or numerous requests. The data subject must be notified of the extension and the reasons within the first month.
  • CCPA: Up to 45 additional calendar days (90 calendar days total) when reasonably necessary. The consumer must be notified of the extension and the reasons within the initial 45-day period.

Acknowledgment

  • GDPR / UK GDPR: No specific acknowledgment deadline, but best practice is to acknowledge promptly. The ICO recommends acknowledging receipt as soon as possible.
  • CCPA: Must acknowledge receipt within 10 business days (Cal. Code Regs. tit. 11, § 7023(a)). The acknowledgment should confirm the request type and provide information about the expected response timeline.

Practical Impact

The GDPR deadline is tighter. If you receive a request that triggers both laws, the GDPR's one-month deadline is your binding constraint. Missing the GDPR deadline while still being within the CCPA's 45 days does not protect you from a GDPR complaint.

Scope of Access Rights

What Must Be Disclosed

GDPR / UK GDPR (Article 15):

  • A copy of the personal data being processed
  • The purposes of the processing
  • The categories of personal data concerned
  • The recipients or categories of recipients
  • The envisaged retention period or the criteria used to determine it
  • The right to request rectification, erasure, or restriction
  • The right to lodge a complaint with a supervisory authority
  • The source of the data (if not collected directly from the data subject)
  • The existence of automated decision-making, including profiling, and meaningful information about the logic and consequences

CCPA (Cal. Civ. Code § 1798.100):

  • The categories of personal information collected in the preceding 12 months
  • The categories of sources from which the information was collected
  • The business or commercial purpose for collecting or selling the information
  • The categories of third parties with whom the information is shared
  • The specific pieces of personal information collected about the consumer

Key Differences

Time scope. Under the GDPR, the right of access covers all personal data currently being processed — there is no time limit. Under the CCPA, the standard obligation covers the preceding 12 months, though the CPRA amendments allow consumers to request information going back further if it was collected on or after January 1, 2022.

Supplementary information. The GDPR requires more supplementary information than the CCPA. The GDPR mandates disclosure of retention periods, automated decision-making logic, and the specific rights available to the data subject. The CCPA requires disclosure of categories of sources, business purposes, and third-party sharing, but does not require the same level of detail about decision-making logic or retention.

Definition of personal data. The GDPR's "personal data" covers any information relating to an identified or identifiable natural person. The CCPA's "personal information" covers information that identifies, relates to, describes, is reasonably capable of being associated with, or could reasonably be linked to a particular consumer or household. In practice, both definitions are broad, but the CCPA's inclusion of household-level data is unique.

Sale and sharing disclosure. The CCPA specifically requires disclosure of whether personal information has been sold or shared and the categories of third parties involved. The GDPR requires disclosure of recipients but does not have the same "sale" concept.

Identity Verification Compared

GDPR / UK GDPR

The GDPR does not prescribe specific verification methods. Article 12(6) states that where the controller has "reasonable doubts" about the identity of the requester, the controller may request additional information necessary to confirm the data subject's identity.

In practice, this means:

  • If the request comes from a verified channel (e.g., a logged-in account), additional verification may not be needed
  • For unverified requests, reasonable verification is expected — matching two or more data points the requester provides against your records
  • The level of verification should be proportionate to the sensitivity of the data and the risk of disclosure to the wrong person
  • There is no requirement for a declaration under penalty of perjury

CCPA

The CCPA has more structured verification requirements, codified in regulations:

  • Right to know (categories): Reasonable degree of certainty — match at least two data points
  • Right to know (specific pieces): Reasonably high degree of certainty — match at least three data points plus a signed declaration under penalty of perjury
  • Right to delete: Reasonable degree of certainty — match at least two data points
  • Right to opt out: Minimal verification — enough to match the request to the consumer's data
  • Right to correct: Reasonable degree of certainty — match at least two data points

Practical Impact

The CCPA's verification requirements are more prescriptive, particularly for specific-pieces requests where the perjury declaration is required. Under the GDPR, you have more flexibility to determine what verification is appropriate, but this flexibility comes with the responsibility to justify your approach if challenged.

If you handle dual-triggered requests, apply the CCPA's verification standard (since it is more specific) while ensuring your approach also satisfies the GDPR's reasonableness requirement.

Format and Delivery

Response Format

GDPR / UK GDPR: The data must be provided in a "commonly used electronic form" if the request was made electronically (Article 15(3)). The GDPR also grants a right to data portability (Article 20), which requires data to be provided in a "structured, commonly used and machine-readable format" — but this applies only to data provided by the data subject and processed by automated means on the basis of consent or contract.

CCPA: For specific-pieces requests, the information must be delivered in a "portable and, to the extent technically feasible, readily usable format" that allows the consumer to transmit the information to another entity. Common formats include JSON, CSV, and PDF.

Delivery Method

GDPR / UK GDPR: No specific delivery method is prescribed, but the response must be provided securely. If the request was made electronically, the information should normally be provided electronically unless the data subject requests otherwise.

CCPA: The response should be delivered through the consumer's account with the business (if they have one) or by mail or electronically at the consumer's choice. For specific-pieces requests delivered electronically, the format must be portable and usable.

Charging for Responses

GDPR / UK GDPR: The first copy of the data must be provided free of charge. A reasonable fee based on administrative costs can be charged for further copies, or for requests that are manifestly unfounded or manifestly excessive.

CCPA: Responses are free of charge. A fee can only be charged for requests that are manifestly unfounded or excessive (a standard rarely met in practice).

Handling Dual-Triggered Requests

When a single request triggers both the CCPA and the GDPR, you need a strategy. Here is the practical approach.

Step 1: Identify Applicable Laws

Determine which laws apply based on:

  • Where the data subject is located
  • Where your business is established
  • Whether your business targets or monitors individuals in specific jurisdictions
  • Whether CCPA thresholds are met

If both the GDPR and CCPA apply, proceed with a dual-compliance response.

Step 2: Apply the Shorter Deadline

Use the GDPR's one-month deadline as your target. If you meet this deadline, you are automatically within the CCPA's 45-day window. If you need an extension, notify the data subject within the first month (satisfying the GDPR's notification requirement, which is stricter than the CCPA's).

Step 3: Apply the Broader Scope

Provide all information required by the GDPR's Article 15 (which is the more comprehensive disclosure requirement) plus any CCPA-specific disclosures not covered by the GDPR. In practice, the main CCPA-specific additions are:

  • Explicit disclosure of categories of personal information sold or shared (using the CCPA's sale/sharing framework)
  • Disclosure of business or commercial purposes using the CCPA's categories

Step 4: Apply the Stricter Verification

Use the CCPA's verification standards (since they are more prescriptive) while ensuring the process is also reasonable under the GDPR. For specific-pieces requests, this means three-point matching plus a perjury declaration.

Step 5: Deliver in a Compliant Format

Provide the data electronically in a structured, portable format (such as JSON or CSV supplemented with a readable PDF summary). This satisfies both the GDPR's "commonly used electronic form" requirement and the CCPA's "portable and readily usable" requirement.

Step 6: Document Both Compliance Streams

In your records, note which laws apply to the request and how your response satisfies each. This documentation is essential if you face a complaint or audit under either regime.

Summary Comparison Table

| Element | GDPR / UK GDPR | CCPA | | --- | --- | --- | | Standard deadline | 1 calendar month | 45 calendar days | | Maximum with extension | 3 months | 90 calendar days | | Acknowledgment deadline | No specific requirement | 10 business days | | Time scope of data | All data currently processed | Preceding 12 months (extendable) | | Verification standard | Reasonable, proportionate | Tiered (2-point, 3-point + perjury declaration) | | Supplementary information | Extensive (Article 15) | Categories, sources, purposes, third parties | | Cost to data subject | Free (first copy) | Free | | Fee for excessive requests | Reasonable fee or refusal | Rarely applicable | | Response format | Commonly used electronic form | Portable, readily usable | | Right to data portability | Yes (Article 20, limited scope) | Implicit in format requirements | | Sale/sharing disclosure | Not applicable | Required |

Common Mistakes

Applying the wrong deadline. If both laws apply, you must meet the shorter deadline. Using the CCPA's 45 days when the GDPR's one month has already passed is a violation.

Providing CCPA-scope data for a GDPR request. The CCPA's default 12-month lookback is narrower than the GDPR's requirement to provide all data currently processed. Limiting a GDPR response to 12 months of data is non-compliant.

Under-verifying CCPA-specific-pieces requests. If you use the GDPR's flexible verification approach for a CCPA specific-pieces request without meeting the three-point plus perjury declaration standard, you are non-compliant with the CCPA.

Ignoring sale/sharing disclosures. GDPR responses do not require explicit sale/sharing categorization. If the CCPA also applies, you must add these disclosures even if your GDPR response is otherwise comprehensive.

For more on handling requests that span multiple jurisdictions, see our guide on cross-border DSARs.

References

Last reviewed: August 2026. Both the GDPR and CCPA frameworks continue to evolve through enforcement actions, regulatory guidance, and legislative amendments. Verify all statutory references against the current text of the law and consult qualified legal counsel before making compliance decisions for your business.

Related Guides

Handle Both Laws With Confidence

Our DSAR Compliance Guide includes dual-jurisdiction checklists and response templates designed for businesses subject to both the GDPR and CCPA.

Read the DSAR Compliance Guide