Data Deletion Request Software: Handle Every CCPA Right to Delete and GDPR Deletion Request on Time
An access request ends in a document. A deletion request ends in an irreversible action, which is exactly why teams dread it. Obtainer treats a data deletion request as its own workflow: find every place the person's data lives, decide what the law lets you keep, delete the rest, and keep a record that proves you did.
found
scanned
Assembling the cover letter from the template...
Helps you comply, not legal advice
In short
A data deletion request is a person asking an organization to erase the personal data it holds about them, known as the right to delete under the CCPA and the right to erasure, or right to be forgotten, under Article 17 of the GDPR. A business has 45 calendar days to respond under the CCPA, extendable by another 45 days with notice, and one month under the GDPR, extendable by two months for complex requests. Deletion is harder than access for one reason: you cannot un-delete, and you still have to prove you deleted. Obtainer runs the request end to end. It verifies the requester, discovers every system holding that person's data, flags the records you are legally allowed or required to keep, such as data needed to complete a transaction, detect security incidents, or comply with a legal obligation, routes the rest for deletion, and produces a dated record of what was erased and what was retained and why. Nothing is deleted automatically: a human approves every erasure at a review gate, so you stay in control. Obtainer helps you comply. It is not legal advice, and the call on which exceptions apply stays with your team. Self-serve DSAR fulfillment from $49/mo, not a six-figure governance suite.
Last updated July 2026
What you get
Deletion requests, built for privacy, legal, and ops teams
Deletion needs discovery first
You cannot erase what you cannot find. Obtainer surfaces every system holding the person's data before anything is deleted, so a forgotten backup or CRM record does not turn into an incomplete deletion.
Keep what the law lets you keep
The right to delete is not absolute. Obtainer flags records that fall under a statutory exception, so your team can retain them deliberately instead of over-deleting and losing data you needed.
Proof you actually deleted
Every erasure lands in a dated record showing what was deleted, what was retained, and the reason. When a regulator or a consumer asks, you have an answer rather than a memory.
Nothing erases on its own
Deletion is irreversible, so it waits for a person. A human approves every erasure at the review gate, and you stay in control of what gets destroyed.
How it works
From an intake request to a ready-to-review response in four steps
Intake and verify
Log the deletion request and confirm the requester's identity, because deleting the wrong person's data is its own breach.
Discover every location
Obtainer finds where the person's data lives across your systems and compiles it into one reviewable manifest, including the copies teams forget.
Separate delete from retain
Records covered by a statutory exception are flagged for retention. Your team confirms the call, then the rest is queued for erasure.
Delete, notify, and log
A human approves, the data is erased, downstream recipients are notified where required, and the action is recorded as proof. Helps you comply, not legal advice.
Frequently asked
Questions teams ask about deletion requests
Can a company refuse to delete my data?
Yes, in defined situations. Both the CCPA and the GDPR let an organization keep personal data when an exception applies, for example when the data is needed to complete a transaction the consumer requested, to detect security incidents or fraud, to comply with a legal obligation, or to establish or defend a legal claim. A refusal has to be explained to the requester, and it should be documented, not assumed.
How long does a company have to delete my data?
Under the CCPA a business has 45 calendar days to respond to a verified deletion request, and it can take another 45 days if it tells the consumer why it needs the extra time. Under the GDPR the controller must act without undue delay and at the latest within one month, extendable by two further months for complex or numerous requests, provided the person is told.
Do I have to tell other companies to delete the data too?
Usually, yes. Under the CCPA a business must direct its service providers and contractors to delete the consumer's personal information, and notify third parties that bought or received it. Under Article 19 of the GDPR you must communicate the erasure to each recipient you disclosed the data to, unless that proves impossible or requires disproportionate effort.
What is the difference between the right to delete and the right to erasure?
They are the same idea under two laws. The right to delete is the CCPA term for a California consumer asking a business to erase their personal information. The right to erasure, also called the right to be forgotten, is the GDPR term under Article 17. The deadlines, the exceptions, and the paperwork differ, but the workflow you run internally is largely the same.
Does deleting the data mean deleting the backups?
Not always immediately. Regulators generally accept that data in backups cannot be surgically removed the moment a request lands. The common approach is to put the data beyond use, delete it from live systems, exclude it from restoration, and let it age out on the normal backup cycle. Document the approach, because the expectation is that it does not come back.
Run a data subject access request end to end
Obtainer finds where a person's data lives across your systems, compiles it into one manifest, drafts the deadline-safe response, and tracks the GDPR and CCPA clock. You review, redact, and approve what gets disclosed. Helps you comply; not legal advice.