Each of these is a refusal this regime lets a counterparty attempt, paired with the answer to it. Reading them before you write is worth more than any amount of polish on the letter itself.
Verification used to run out the clock
high likelihoodWe need to verify you before we can respond. Please complete this identity check.
What answers it
Verification is required, but the 45 days runs from the date the business RECEIVED your request — not from the date it finished verifying you. Reply to the verification promptly, and if the response then arrives after day 45 counted from your original request, say so explicitly. The regulations also cap what a business may ask for: it must not collect new personal information from you for verification if it can match against what it already holds.
Cal. Civ. Code § 1798.130(a)(2) — 45 days to respond, extendable by a further 45 — § 1798.130(a)(2)
"We do not sell your personal information"
high likelihoodWe do not sell personal information, so there is nothing for you to opt out of.
What answers it
The CPRA added "sharing" precisely because of this answer. "Sharing" means disclosure for cross-context behavioural advertising, whether or not money changes hands. Ask specifically: do you SHARE personal information for cross-context behavioural advertising? Any site running third-party ad tech almost certainly does, and the "Do Not Sell or Share My Personal Information" link is mandatory where it does.
Cal. Civ. Code § 1798.100 et seq. (California Consumer Privacy Act, as amended by the CPRA) — §§ 1798.100–1798.199.100
"We are not a covered business"
high likelihoodWe do not meet the applicability thresholds in your state's law, so we are not required to respond to your request.
What answers it
Make them say which threshold they fall under, in writing. The thresholds differ sharply between states — Texas and Nebraska use a small-business test rather than a revenue figure, Montana and Delaware have low consumer-count thresholds, and a company that sells personal data is usually covered at a much lower volume. A business that will not identify the threshold it relies on is worth reporting to the Attorney General for exactly that reason.
They ignore the appeal too
high likelihood(silence)
What answers it
Good. Almost every one of these statutes requires the controller, when it denies an appeal, to give you a written explanation AND a mechanism to contact the Attorney General. Silence on an appeal is therefore two violations, not one, and it converts a complaint about a request into a complaint about the statutory appeal machinery — which is the sort of thing enforcement divisions actually act on.
Endless identity verification
high likelihoodWe cannot action your request until you verify your identity. Please send a copy of your passport, a utility bill, and a selfie holding your ID.
What answers it
A controller may use reasonable measures to verify identity, but it may only ask for information it actually needs and already holds a basis to check. Demanding a passport scan from someone whose account you identify by email address is disproportionate and is itself a data-minimisation problem. Offer to verify through the same channel you already use to log in, state that you consider the demand excessive, and note that the response clock is running.
"We hold no personal data about you"
high likelihoodA search of our systems returned no personal data relating to you.
What answers it
Ask for that in writing, signed, together with a description of the systems searched and the search terms used. A nil return is a substantive answer that the controller must stand behind, and it is frequently wrong: it usually means one production database was searched and backups, CRM, marketing, support tickets, call recordings, and third-party processors were not. Name the systems you believe hold your data, including any you have interacted with.
Global Privacy Control quietly ignored
medium likelihood(no response — the site simply does not act on the signal)
What answers it
11 CCR § 7025 requires a business to treat an opt-out preference signal as a valid request to opt out of sale and sharing. Ignoring GPC is a discrete, demonstrable violation, and it is the fact pattern the CPPA and the Attorney General have publicised enforcement on. Take a screenshot showing the signal enabled and the site still setting advertising cookies, and report it.
11 CCR § 7025 — opt-out preference signals must be treated as a valid request to opt out — § 7025
"We are only a service provider / processor"
medium likelihoodWe process this data on behalf of our business customers. Direct your request to them.
What answers it
A processor still has to assist the controller and, in most of these statutes, to help the consumer reach the controller. Ask for the identity and contact details of the controller. If they will not tell you who they process for, they are asserting a status whose only condition they refuse to evidence.
Blanket confidentiality or trade-secret refusal
medium likelihoodThe information you have requested is commercially confidential / contains our trade secrets / is proprietary.
What answers it
Confidentiality and intellectual-property carve-outs are narrow and must be applied item by item, not as a blanket. The correct response is redaction of the protected element and disclosure of the rest, with a schedule explaining what was withheld and why. Ask for that schedule.
Refusal because the data mentions someone else
medium likelihoodWe cannot disclose these records because they contain the personal data of other individuals.
What answers it
The presence of third-party data is a reason to redact, not to refuse. The controller must consider whether it can disclose with the third party removed, whether the third party has consented, and whether it is reasonable to disclose without consent. A blanket refusal on this ground is not a lawful answer.
"Your request is manifestly excessive"
medium likelihoodYour request is manifestly unfounded or excessive, so we are refusing it / charging a fee.
What answers it
The burden of showing that a request is manifestly unfounded or excessive is on the controller, and it is a high bar — the regulator guidance treats it as exceptional, not as a routine response to a broad request. Ask the controller to state, in writing, the specific grounds and the evidence for them. If you have made only one request, say so. A single, first, ordinary request is not excessive.