Consumer Rights Request
A consumer rights request is a formal request an individual makes under a privacy law to exercise control over their personal information held by an organization. Depending on the law, this can include asking to see what data is held, to have it deleted or corrected, to limit how it is used, to opt out of its sale or sharing, or to receive a copy in a portable form. Laws granting these rights also typically prohibit organizations from discriminating against consumers who exercise them.
A Consumer Rights Request is the formal mechanism through which a data subject invokes statutory privacy rights against a controlling entity, most commonly associated in the U.S. context with the CCPA/CPRA framework. Commonly asserted rights include the right to know/access, the right to delete, the right to correct, the right to limit use of sensitive personal information, the right to opt out of the sale or sharing of personal information, the right to data portability, and the right to non-discrimination for exercising these rights. It is functionally analogous to, but legally distinct from, the GDPR's Data Subject Access Request (DSAR); the exact enumerated rights, procedural obligations, verification requirements, and response timelines vary by governing statute and jurisdiction. This entry addresses the privacy-compliance concept and does not concern insurance coverage terms; whether the costs of responding to such requests, or liability arising from mishandling them, fall within a cyber policy depends on the specific policy wording, endorsements, and exclusions.
Why it matters
Consumer rights requests translate abstract privacy statutes into concrete operational obligations. When an individual asks to see, delete, correct, or receive a copy of their data, or to opt out of its sale or sharing, an organization must locate that data across systems, verify the requester's identity, respond within the timeline set by the governing statute, and do so without penalizing the consumer for having asked. Because laws such as the CCPA/CPRA framework grant these rights and impose procedural obligations, mishandling a request, whether through delay, incomplete response, or inadvertent disclosure to an imposter, can create regulatory exposure and reputational harm. The enumerated rights, verification standards, and response deadlines vary by jurisdiction, so an organization operating across multiple regimes cannot assume a single process satisfies every applicable law.
Who it's relevant to
Inside CRR
Common questions
Answers to the questions practitioners most commonly ask about CRR.
