CCPA Right to Delete: Responding to a Deletion Request in 45 Days
Last updated July 2026 · Obtainer
found
scanned
Assembling the cover letter from the template...
Helps you comply, not legal advice
The CCPA right to delete gives a California consumer the right to ask a business to erase the personal information it has collected about them. You have 45 calendar days to respond, extendable by another 45 with notice. You can keep data that falls under one of nine statutory exceptions, and you must pass the deletion instruction down to your service providers, contractors, and the third parties you sold or shared the data with.
General information, not legal advice. The CCPA, as amended by the CPRA, is fact-specific, so take advice on the calls that are close.
The 45-day clock, and the part people get wrong
A business must respond to a verifiable consumer request within 45 calendar days of receiving it. That window includes the time you spend verifying the requester, which is the detail teams routinely miss: the clock starts when the request arrives, not when you finish checking who they are. Spend three weeks on verification and you have three weeks left to do the actual work.
You may take one extension of up to 45 additional days, for a maximum of 90, but only if you tell the consumer within the first 45 days and explain why you need the extra time. Silence is not an extension. If the deadline passes without a response, you have a compliance failure regardless of what you were doing internally.
| CCPA right to delete | GDPR right to erasure | |
|---|---|---|
| Who can ask | California consumers | Data subjects in the EU and EEA |
| Deadline | 45 days | One month |
| Extension | +45 days, with notice | +2 months for complex requests, with notice |
| Scope of the duty | Personal information collected from the consumer | Personal data, on six defined grounds |
| Exceptions | Nine statutory exceptions | Five under Article 17(3) |
| Downstream duty | Direct service providers and contractors to delete; notify third parties | Notify recipients under Article 19 |
If you operate in both jurisdictions, do not try to run one merged process on the strictest rule. The deadlines and the exceptions genuinely differ, and a single blended workflow tends to over-delete on one side and under-document on the other. The comparison of GDPR and CCPA data requests goes through the differences in full.
The nine exceptions: what you are allowed to keep
The right to delete is not absolute. A business may keep personal information where it is reasonably necessary to:
- Complete the transaction the information was collected for, provide a good or service the consumer requested, or perform a contract with them.
- Detect security incidents and protect against malicious, deceptive, fraudulent, or illegal activity.
- Debug and repair errors that impair intended functionality.
- Exercise free speech, or ensure another consumer's right to do so.
- Comply with the California Electronic Communications Privacy Act.
- Enable solely internal uses reasonably aligned with the consumer's expectations given their relationship with the business.
- Engage in peer-reviewed research in the public interest, where deletion would likely make it impossible.
- Comply with a legal obligation.
- Make other internal and lawful uses compatible with the context in which the information was provided.
In practice, three of these carry nearly all the weight: completing the transaction, complying with a legal obligation, and detecting security incidents or fraud. The ones to handle carefully are the internal use exceptions, because they are the most tempting and the most elastic. "Our analytics team finds this useful" is not an internal use aligned with the consumer's expectations. If you cannot state the exception in a sentence a regulator would accept, you should be deleting the record.
Whichever exception you rely on, apply it to the specific data, not to the request as a whole. A consumer who bought something from you two months ago can have their marketing profile deleted while you keep the invoice for tax purposes. That partial outcome, delete most of it and keep a defined slice, is the normal shape of a compliant response.
What you owe your service providers and third parties
Deleting the record in your own database is not the end of the job. When you receive a verified deletion request, you must direct your service providers and contractors to delete the consumer's personal information from their records too, and you must notify third parties that bought or received it. Under the CPRA amendments, the obligation travels downstream rather than stopping at your perimeter.
This is where most deletion programs actually break. The data was synced to a CRM, a support desk, an email platform, a warehouse, and a partner's list. The team deletes the CRM record and reports the request closed. Weeks later, one of the downstream systems mails the consumer, who now has proof that the deletion did not happen. Before you can pass an instruction downstream, you need an accurate list of who has the data, and that is a personal data discovery problem long before it is a legal one.
Verifying the requester without making it a wall
You must take reasonable steps to verify that the person asking is who they claim to be, because deleting the wrong person's data is its own harm, and an attacker who can trigger deletions is an attacker who can destroy your customer's records. But verification cannot be so burdensome that it discourages people from exercising the right. Demanding a notarized affidavit for a routine deletion is not a security measure, it is a deterrent, and regulators read it that way.
Match the check to the sensitivity. Confirming control of the email address on the account is usually proportionate for a low-risk record. Ask for more where the data is sensitive or the account is high-value, and document the standard you applied so it is consistent from request to request rather than invented each time.
Can a business refuse to delete data?
Yes, but only on a stated ground. If an exception applies, you may keep the data covered by it, and you must tell the consumer that you are doing so and why. You may also deny a request you cannot verify. What you cannot do is ignore the request, refuse without explanation, or charge the consumer for making it. Deletion requests are free, and the ability to charge or decline exists only for requests that are manifestly unfounded or excessive, which is a high bar you will rarely reach.
Data brokers and the DELETE Act
If your business is a registered data broker in California, the obligations go further. Under the DELETE Act, the state operates a deletion request platform, and from August 1, 2026, registered data brokers must access it and process the accumulated consumer deletion requests, then continue checking on a recurring 45-day cycle. Failure to do so carries per-request daily penalties.
Most businesses are not data brokers and this does not apply to them, so check the definition before you assume either way. What it does signal is direction of travel: the mechanics of deletion are being pushed toward automation and verifiable proof, not letters and good intentions. It also explains why so many consumers now arrive having used a service that sends removal requests to data brokers on their behalf, which means the volume of requests you see is unlikely to fall.
What a compliant response actually says
Whatever the outcome, the written reply needs to state what you deleted, what you retained and under which exception, whether you passed the instruction to service providers and third parties, and how the consumer can follow up. Keep a dated record of all of it. If a regulator asks how you handled a request from eighteen months ago, your record is the only answer available, because nobody's memory is going to reconstruct which systems were touched.
The letter itself is straightforward. The work underneath it is not: finding every system that holds the consumer's information, deciding record by record what an exception covers, deleting the rest, pushing the instruction downstream, and proving you did. Done by hand across a handful of tools, 45 days goes quickly.
Running it without the spreadsheet
That is exactly the workflow data deletion request software is built for. Obtainer intakes the request and verifies the consumer, discovers where their personal information lives across your connected systems, flags the records that fall under a statutory exception so you keep what you are entitled to keep, routes the rest for erasure, and produces a dated record of what was deleted and what was retained and why. The 45-day clock starts counting the moment the request lands rather than the moment someone remembers to log it.
Because deletion cannot be undone, nothing is erased automatically. A person approves every erasure at the review gate, so you stay in control of what gets destroyed. Obtainer helps you comply; it is not legal advice, and the call on which exception applies stays with your team. If the request you are holding is European rather than Californian, the deadline and the grounds are different, so read the guide to the right to erasure under the GDPR and use the matching erasure response template.
Run a data subject access request end to end
Obtainer finds where a person's data lives across your systems, compiles it into one manifest, drafts the deadline-safe response, and tracks the GDPR and CCPA clock. You review, redact, and approve what gets disclosed. Helps you comply; not legal advice.