Join our Newsletter — 33% off our NHI Course
Governance, Ownership & Risk

AB-1564

← Back to Glossary
By NHI Mgmt Group Updated September 25, 2026 Domain: Governance, Ownership & Risk

A California amendment that clarified which businesses must provide a toll-free phone number for consumer privacy requests. It created different channel requirements for in-person businesses, in-person businesses with websites, and exclusively online businesses. The amendment is often used to determine how many request methods must be offered.

What AB-1564 Changes for Consumer Privacy Requests

AB-1564 matters because it did not create privacy rights from scratch, it clarified the privacy-request handling channels businesses must offer and how those obligations vary by business model. The practical effect is that compliance teams can no longer treat “contact us” as a one-size-fits-all answer.

The amendment is best understood as a channel-allocation rule. It tells organisations when a toll-free number is required, when other request methods may satisfy the obligation, and how in-person operations differ from exclusively online businesses. That makes the term useful not only for legal interpretation, but also for designing intake workflows, customer support scripts, and privacy notices.

How the Amendment Differentiates Business Types

AB-1564 draws a distinction between businesses with physical presence, businesses that have both physical locations and websites, and businesses that operate only online. The request-method obligation changes with that classification, so the same privacy right can produce different operational requirements depending on how the business interacts with consumers.

This matters because the legal test is not simply whether a business has a website. A company may need to support one set of request channels for walk-in consumers and another set for web-based consumers, which means legal interpretation and service design have to stay aligned. In practice, the business model becomes part of the compliance analysis.

Why It Matters for Privacy Operations

For privacy programs, AB-1564 is a routing and coverage problem as much as a legal one. The organisation has to ensure that consumers can submit privacy requests through the methods the rule expects, and that those methods are actually monitored, logged, and operationally supported.

It also affects documentation. Privacy notices, request intake pages, call-centre procedures, and escalation paths should all describe the same supported channels. When those materials drift apart, consumers may be given an incomplete or misleading path to exercise their rights, even if the underlying legal right still exists.

How to Read AB-1564 in Practice

Practitioners usually use AB-1564 as a reference point when deciding whether a privacy-request workflow is complete. The key question is not just “Do we have a request process?” but “Does this process satisfy the channel requirement for this business type?”

That distinction helps avoid two common mistakes: overbuilding a toll-free process where it is not required, or underbuilding request access where it is required. For multi-channel organisations, the safest interpretation is to map request methods to the actual consumer touchpoints the business operates and then validate that each required path is reachable in practice.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

NIST SP 800-53 Rev 5 sets the technical controls, while GDPR and ISO/IEC 27001:2022 define the regulatory obligations.

FrameworkControl / ReferenceRelevance
GDPRArt. 12 — Transparent information, communication and modalities for the exercise of data subject rightsAB-1564 addresses how privacy requests must be offered and handled through consumer-facing channels.
Recommendation — Align request channels and notices so consumers can exercise privacy rights through the required modalities.
ISO/IEC 27001:2022A.5.34 — Privacy and protection of PIIAB-1564 affects how privacy-request processes are governed and documented within the privacy control set.
Recommendation — Document the required request methods and verify they are consistently supported in operating procedures.
NIST SP 800-53 Rev 5AP-1 — Privacy Program PlanAB-1564 is a privacy-governance rule that should be reflected in the organisation’s privacy program.
Recommendation — Incorporate the amendment’s channel requirements into the privacy program plan and operating controls.

Deepen Your Knowledge

Sign up to our weekly newsletter — get 33% off our NHI Foundation Level Course

    NHIMG Editorial Note
    Reviewed and updated by the NHIMG editorial team on September 25, 2026.
    NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org