Obtainer
DELETE - RIGHT TO ERASURE

Data Deletion Request Software: Handle Every CCPA Right to Delete and GDPR Deletion Request on Time

An access request ends in a document. A deletion request ends in an irreversible action, which is exactly why teams dread it. Obtainer treats a data deletion request as its own workflow: find every place the person's data lives, decide what the law lets you keep, delete the rest, and keep a record that proves you did.

See pricing
Discovery across your systems Human redaction gate Helps you comply, not legal advice
Request Studio
Requester
Compiled the manifest and drafted the response - illustrative sample request
0
records found
0
systems scanned
Data manifest
Response draft

Assembling the cover letter from the template...

You approve what is disclosed before anything ships

Helps you comply, not legal advice

In short

A data deletion request is a person asking an organization to erase the personal data it holds about them, known as the right to delete under the CCPA and the right to erasure, or right to be forgotten, under Article 17 of the GDPR. A business has 45 calendar days to respond under the CCPA, extendable by another 45 days with notice, and one month under the GDPR, extendable by two months for complex requests. Deletion is harder than access for one reason: you cannot un-delete, and you still have to prove you deleted. Obtainer runs the request end to end. It verifies the requester, discovers every system holding that person's data, flags the records you are legally allowed or required to keep, such as data needed to complete a transaction, detect security incidents, or comply with a legal obligation, routes the rest for deletion, and produces a dated record of what was erased and what was retained and why. Nothing is deleted automatically: a human approves every erasure at a review gate, so you stay in control. Obtainer helps you comply. It is not legal advice, and the call on which exceptions apply stays with your team. Self-serve DSAR fulfillment from $49/mo, not a six-figure governance suite.

Last updated July 2026

// CAPABILITY

What you get

Deletion requests, built for privacy, legal, and ops teams

Deletion needs discovery first

You cannot erase what you cannot find. Obtainer surfaces every system holding the person's data before anything is deleted, so a forgotten backup or CRM record does not turn into an incomplete deletion.

Keep what the law lets you keep

The right to delete is not absolute. Obtainer flags records that fall under a statutory exception, so your team can retain them deliberately instead of over-deleting and losing data you needed.

Proof you actually deleted

Every erasure lands in a dated record showing what was deleted, what was retained, and the reason. When a regulator or a consumer asks, you have an answer rather than a memory.

Nothing erases on its own

Deletion is irreversible, so it waits for a person. A human approves every erasure at the review gate, and you stay in control of what gets destroyed.

// 4 STEPS

How it works

From an intake request to a ready-to-review response in four steps

01

Intake and verify

Log the deletion request and confirm the requester's identity, because deleting the wrong person's data is its own breach.

02

Discover every location

Obtainer finds where the person's data lives across your systems and compiles it into one reviewable manifest, including the copies teams forget.

03

Separate delete from retain

Records covered by a statutory exception are flagged for retention. Your team confirms the call, then the rest is queued for erasure.

04

Delete, notify, and log

A human approves, the data is erased, downstream recipients are notified where required, and the action is recorded as proof. Helps you comply, not legal advice.

// FAQ

Frequently asked

Questions teams ask about deletion requests

Can a company refuse to delete my data?

Yes, in defined situations. Both the CCPA and the GDPR let an organization keep personal data when an exception applies, for example when the data is needed to complete a transaction the consumer requested, to detect security incidents or fraud, to comply with a legal obligation, or to establish or defend a legal claim. A refusal has to be explained to the requester, and it should be documented, not assumed.

How long does a company have to delete my data?

Under the CCPA a business has 45 calendar days to respond to a verified deletion request, and it can take another 45 days if it tells the consumer why it needs the extra time. Under the GDPR the controller must act without undue delay and at the latest within one month, extendable by two further months for complex or numerous requests, provided the person is told.

Do I have to tell other companies to delete the data too?

Usually, yes. Under the CCPA a business must direct its service providers and contractors to delete the consumer's personal information, and notify third parties that bought or received it. Under Article 19 of the GDPR you must communicate the erasure to each recipient you disclosed the data to, unless that proves impossible or requires disproportionate effort.

What is the difference between the right to delete and the right to erasure?

They are the same idea under two laws. The right to delete is the CCPA term for a California consumer asking a business to erase their personal information. The right to erasure, also called the right to be forgotten, is the GDPR term under Article 17. The deadlines, the exceptions, and the paperwork differ, but the workflow you run internally is largely the same.

Does deleting the data mean deleting the backups?

Not always immediately. Regulators generally accept that data in backups cannot be surgically removed the moment a request lands. The common approach is to put the data beyond use, delete it from live systems, exclude it from restoration, and let it age out on the normal backup cycle. Document the approach, because the expectation is that it does not come back.

Run a data subject access request end to end

Obtainer finds where a person's data lives across your systems, compiles it into one manifest, drafts the deadline-safe response, and tracks the GDPR and CCPA clock. You review, redact, and approve what gets disclosed. Helps you comply; not legal advice.