Each of these is a refusal this regime lets a counterparty attempt, paired with the answer to it. Reading them before you write is worth more than any amount of polish on the letter itself.
"We are not a covered business"
high likelihoodWe do not meet the applicability thresholds in your state's law, so we are not required to respond to your request.
What answers it
Make them say which threshold they fall under, in writing. The thresholds differ sharply between states — Texas and Nebraska use a small-business test rather than a revenue figure, Montana and Delaware have low consumer-count thresholds, and a company that sells personal data is usually covered at a much lower volume. A business that will not identify the threshold it relies on is worth reporting to the Attorney General for exactly that reason.
They ignore the appeal too
high likelihood(silence)
What answers it
Good. Almost every one of these statutes requires the controller, when it denies an appeal, to give you a written explanation AND a mechanism to contact the Attorney General. Silence on an appeal is therefore two violations, not one, and it converts a complaint about a request into a complaint about the statutory appeal machinery — which is the sort of thing enforcement divisions actually act on.
Endless identity verification
high likelihoodWe cannot action your request until you verify your identity. Please send a copy of your passport, a utility bill, and a selfie holding your ID.
What answers it
A controller may use reasonable measures to verify identity, but it may only ask for information it actually needs and already holds a basis to check. Demanding a passport scan from someone whose account you identify by email address is disproportionate and is itself a data-minimisation problem. Offer to verify through the same channel you already use to log in, state that you consider the demand excessive, and note that the response clock is running.
"We hold no personal data about you"
high likelihoodA search of our systems returned no personal data relating to you.
What answers it
Ask for that in writing, signed, together with a description of the systems searched and the search terms used. A nil return is a substantive answer that the controller must stand behind, and it is frequently wrong: it usually means one production database was searched and backups, CRM, marketing, support tickets, call recordings, and third-party processors were not. Name the systems you believe hold your data, including any you have interacted with.
"We are only a service provider / processor"
medium likelihoodWe process this data on behalf of our business customers. Direct your request to them.
What answers it
A processor still has to assist the controller and, in most of these statutes, to help the consumer reach the controller. Ask for the identity and contact details of the controller. If they will not tell you who they process for, they are asserting a status whose only condition they refuse to evidence.
Blanket confidentiality or trade-secret refusal
medium likelihoodThe information you have requested is commercially confidential / contains our trade secrets / is proprietary.
What answers it
Confidentiality and intellectual-property carve-outs are narrow and must be applied item by item, not as a blanket. The correct response is redaction of the protected element and disclosure of the rest, with a schedule explaining what was withheld and why. Ask for that schedule.
Refusal because the data mentions someone else
medium likelihoodWe cannot disclose these records because they contain the personal data of other individuals.
What answers it
The presence of third-party data is a reason to redact, not to refuse. The controller must consider whether it can disclose with the third party removed, whether the third party has consented, and whether it is reasonable to disclose without consent. A blanket refusal on this ground is not a lawful answer.
"Your request is manifestly excessive"
medium likelihoodYour request is manifestly unfounded or excessive, so we are refusing it / charging a fee.
What answers it
The burden of showing that a request is manifestly unfounded or excessive is on the controller, and it is a high bar — the regulator guidance treats it as exceptional, not as a routine response to a broad request. Ask the controller to state, in writing, the specific grounds and the evidence for them. If you have made only one request, say so. A single, first, ordinary request is not excessive.