Businesses that operate primarily in person but also maintain a web presence should offer at least three ways for consumers to submit requests: a web form, a toll-free phone number, and a paper form. In-person businesses without a website should still provide at least two methods, typically a toll-free number and a paper form submitted in person or by mail. The key is making each channel readily available and operational.
How AB-1564 Changes the Channel Design Requirement
AB-1564 does not change the substance of a consumer request, but it does change the minimum channel design for businesses that are primarily in person. The practical question is whether the business has a web presence, because that determines whether consumers must be given three request paths or only two. Compliance depends on making the listed channels genuinely usable, not merely naming them.
For a business with a website, the channel set should be treated as a three-part intake model: web form, toll-free phone number, and paper form. For a business without a website, the standard drops to two methods, usually a toll-free number plus a paper option that can be submitted in person or by mail. The control objective is consumer access, so each method should be easy to find and operate consistently.
What “Readily Available” Means in Practice
Readily available means the request path is visible, functional, and staffed or monitored in a way that lets a consumer actually use it. If a business lists a toll-free number but routes callers into a dead end, or provides a web form that does not reach the privacy or customer service team, the channel exists only on paper. That weakens compliance and creates avoidable consumer friction.
Channel design should also account for the business’s operating model. A store-based or appointment-based business may receive most requests offline, but the in-person experience still has to include a workable paper process and a way to receive and track submissions. If the site is part of the business, the website should not be treated as decorative, it becomes part of the request intake obligation.
Building a Request Process That Holds Up Under Review
The strongest approach is to standardize the intake workflow behind each channel so the consumer experience is different, but the back-end handling is the same. That means one queue, one ownership model, one response timeline, and one method for logging receipt and completion. The channels can differ, but the business should not end up with separate ad hoc processes that produce inconsistent responses or missed deadlines.
It also helps to document exactly which channels are offered, where they are published, and who owns maintenance. For in-person businesses, the most common failure is not legal theory, it is operational drift: the paper form is available at one location but not another, the phone line is correct but unmanaged, or the website is updated without syncing the offline materials. Clear ownership prevents those gaps from becoming compliance issues.
Risk and Threat Considerations
Weak request-channel design creates compliance exposure because consumers may not be able to submit access or deletion requests through the required paths, or may abandon the process when the channel is hard to find or unreliable. The risk is usually operational rather than technical, but the consequence is still regulatory: the business can look noncompliant even if it intended to offer access.
Failure mechanism: Channel failure usually comes from incomplete publication, broken routing, stale contact details, missing paper inventory, or an intake process that is not monitored by the team responsible for fulfillment.
Impact: The business can miss valid requests, lose evidence that a request was received, create inconsistent response handling across locations, and increase the likelihood of complaints or enforcement scrutiny.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
NIST SP 800-53 Rev 5 sets the technical controls, while ISO/IEC 27001:2022 defines the regulatory obligations.
| Framework | Control / Reference | Relevance |
|---|---|---|
| NIST SP 800-53 Rev 5 | AU-6 — Audit Record Review, Analysis, and Reporting | Request channels need logged intake and traceable handling to support consumer request processing. |
| AC-2 — Account Management | Consumer request workflows need ownership and controlled access to the fulfillment process. | |
| Recommendation — Log each consumer request and review intake records for missed or delayed handling. Assign and manage ownership for the request-handling process and its operators. | ||
| ISO/IEC 27001:2022 | A.5.34 — Privacy and protection of PII | CCPA request channels exist to support privacy rights handling and consumer request processing. |
| A.5.16 — Identity management | The intake process must reliably identify and route consumer requests to the right handler. | |
| Recommendation — Define and operate request channels as part of your privacy-rights handling process. Ensure request intake is consistently routed to the team responsible for consumer rights. | ||
Practitioner Guidance
What to verify: Confirm that each channel is publicly listed, staffed or monitored, and tied to a single internal owner who can route requests into the fulfillment workflow. The test is simple: a consumer should be able to submit a request without needing local knowledge of the store, manager, or privacy team.
What good looks like: The website, phone script, and paper form all point to the same request process, and each submission path produces the same tracking and response discipline. If a location cannot reliably support paper intake, or if a phone line is not actually toll-free and operational, treat that as a control gap rather than a minor inconvenience.
Practitioner takeaway: AB-1564 compliance is less about having “some” contact method and more about proving that every required consumer path is discoverable, usable, and linked to a real back-end process.
Related resources from NHI Mgmt Group
- How should regulated businesses structure an AML programme to detect money laundering across different customer and transaction channels?
- How should crypto firms structure staking services so they stay compliant while still serving retail and institutional users?
- How should crypto exchanges in India structure AML and KYC controls to stay compliant with current rules?
- How should security teams structure access request tickets for governance?
Deepen Your Knowledge
Reviewed and updated by the NHIMG editorial team on September 25, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org