A Data Subject Request — typically a "delete my data" or "export my data" request — is the moment a privacy policy becomes real. Here's what the law requires, what tools typically deliver, and how Cal Clear handles it.
GDPR Article 12: one month, extendable by two
GDPR requires a response within one month of request receipt, extendable by two additional months for complex cases. For most scheduling data requests, one month is generous — the scheduling tool should be able to respond within days.
CCPA: 45 days, extendable by 45
CCPA's consumer-side deletion right gives companies 45 days (extendable to 90). Some California advocates argue this is too long for simple data; expect tightening in future amendments.
State-by-state US variation
Colorado (CPA): 45 days. Virginia (CDPA): 45 days. Connecticut: 45 days. Texas (new, 2024): 45 days. The US state floor has converged on 45 days for response.
Best-in-class: under 24 hours
The ideal DSR response is automatic: the user triggers deletion from their account settings, and the system processes within hours. Any tool that requires a manual ticket queue is falling short of the bar.
This is part of our privacy-first scheduling pillar guide — 18 articles covering every privacy angle.
Frequently Asked Questions
How fast does Cal Clear respond to DSRs?
Self-serve deletion is instant — click 'delete my account' and your booking metadata is scheduled for deletion within 24 hours. Manual deletion requests are processed within 72 hours.
Does Cal Clear charge for DSR responses?
No. Under GDPR, the first response to a DSR must be free. Cal Clear treats all DSRs as free, always.
Try privacy-first scheduling, free
Cal Clear runs zero trackers on booking pages and auto-deletes booking data on your schedule. Start at calclear.app.