What is Right to Delete?
Definition
The right to delete under CCPA/CPRA allows California consumers to request that a business delete any personal information it has collected about them. Businesses must comply within 45 days, with limited exceptions for legal obligations, security, and completing transactions.
In Depth
The right to delete is one of the most operationally challenging CCPA requirements because it requires organizations to identify and remove personal information across all systems, databases, backups, and third-party service providers. When a consumer submits a deletion request, the business must delete the information from its own records, direct its service providers and contractors to delete the information, and notify any third parties to whom the data was sold or shared. CPRA expanded this by requiring businesses to notify all third parties who received the data. There are several exceptions: businesses may retain data necessary to complete a transaction, detect security incidents, comply with legal obligations, exercise free speech, conduct research in the public interest, or enable internal uses aligned with consumer expectations. Organizations should implement automated workflows for processing deletion requests at scale, maintain a data map showing where personal information resides, and establish clear criteria for evaluating exception applicability. The 45-day response window can be extended by an additional 45 days if reasonably necessary, but the consumer must be notified of the extension.
Related Frameworks
Related Terms
Right to Know
The right to know under CCPA/CPRA grants California consumers the right to request that a business disclose what personal information it has collected, the sources of that information, the business purposes for collecting it, and the third parties with whom it has been shared or sold.
Right to Opt-Out
The right to opt-out under CCPA/CPRA allows California consumers to direct businesses to stop selling or sharing their personal information with third parties. Businesses must honor opt-out requests and provide a clear "Do Not Sell or Share My Personal Information" link on their website.
Sensitive Personal Information
Sensitive personal information under CPRA includes specific categories requiring heightened protections: government IDs, financial account credentials, precise geolocation, racial or ethnic origin, religious beliefs, union membership, mail/email/text content, genetic data, biometrics, health data, and sex life or orientation.
Data Retention
Data retention policies define how long different categories of data are stored, where they are stored, and when and how they are securely disposed of. Proper retention schedules balance legal obligations, business needs, and privacy requirements.
Generate compliance docs with PoliWriter
Stop reading about compliance and start achieving it. PoliWriter generates audit-ready policies customized to your organization in hours.
Get Started Free