Back to the hub

What is the CCPA right to delete?

Under California Civil Code section 1798.105, a consumer can ask a business to delete personal information the business collected from them. The business must comply within 45 days of a verifiable request and direct its service providers and contractors to delete too, unless one of the eight exceptions in section 1798.105(d) applies.

Applies to: For-profit businesses subject to the CCPA that collect personal information from California consumers and must handle consumer requests to delete it.

Find out what applies to you

Run the free 2-minute Obligation Scan and get a plain-language list of what your business has to do, and by when.

Run the free 2-minute Obligation Scan

The right to delete is the CCPA request consumers reach for most, and the one businesses most often mishandle. It is not an absolute erase button, and it is not limited to a single database. Section 1798.105 sets out exactly what a consumer can ask you to delete, how quickly you have to act, and the narrow set of reasons that let you keep the data.

What can a consumer ask you to delete?

Under California Civil Code section 1798.105(a), a consumer has the right to request that a business delete any personal information about the consumer that the business collected from the consumer. The phrase "collected from the consumer" matters. It covers what you gathered directly, such as an account signup, a purchase, or a support ticket. A business also has to disclose this right, under section 1798.130, so consumers know it exists.

How fast must you respond?

You have 45 days from a verifiable consumer request. You must promptly determine whether the request really comes from the consumer or an authorized agent, but that verification step does not buy you extra time beyond the 45 days. Deletion reaches past your own systems: section 1798.105(c) requires you to direct your service providers and contractors to delete the personal information from their records, and to notify any third parties, unless doing so proves impossible or involves disproportionate effort.

When can you keep the data?

Section 1798.105(d) lists eight exceptions, and each one is gated by the same condition: you keep the data only where it is reasonably necessary for the business, service provider, or contractor to maintain it in order to achieve that purpose. Read them narrowly and record which one applies, because a vague "we need it" is not one of them.

How it fits your other CCPA duties

Deletion does not stand alone. A consumer who can ask you to delete can also ask you to know and correct their data, and can use a Do Not Sell or Share request to stop the flow of their information to third parties. All of it depends on the upfront notice at collection that tells consumers what you hold in the first place.

Next step

If you are not sure your deletion process meets the 45-day clock or handles service providers correctly, the free 2-minute Obligation Scan checks whether the CCPA applies to you and lists the request-handling steps you owe, so a deletion request does not turn into an enforcement problem. The US state privacy laws hub shows how California's rights compare with the other state laws. Other states run different clocks: Virginia allows 45 days plus one 45-day extension and a separate 60-day appeal window.

Section 1798.105(c): deletion is a three-way notification duty

The part of the section that turns a deletion request into an operational problem is subdivision (c), and it is quoted far less often than the exceptions.

Section 1798.105(c)(1) reads: "A business that receives a verifiable consumer request from a consumer to delete the consumer's personal information pursuant to subdivision (a) of this section shall delete the consumer's personal information from its records, notify any service providers or contractors to delete the consumer's personal information from their records, and notify all third parties to whom the business has sold or shared the personal information to delete the consumer's personal information unless this proves impossible or involves disproportionate effort."

Three obligations sit in that sentence, not one.

Delete from your own records. Notify service providers and contractors to delete from theirs. And notify all third parties to whom you have sold or shared the information.

The qualifier at the end, "unless this proves impossible or involves disproportionate effort," attaches to the notification duties rather than excusing the deletion itself, and it is a standard you would have to be able to explain. Not having a list of who received the data is not the same thing as disproportionate effort, because the list is something the statute assumes you can produce.

This is also where the service provider or third party classification does real work a second time. The notification duty splits along the same line: service providers and contractors are told to delete, while third parties are told to delete only where you sold or shared the data to them.

The one record you are allowed to keep

Section 1798.105(c)(2) creates a narrow and useful permission: "The business may maintain a confidential record of deletion requests solely for the purpose of preventing the personal information of a consumer from being sold, for compliance with laws or for other purposes solely to the extent permissible under this title."

So keeping a suppression list is expressly contemplated. The limits are in the wording. The record must be confidential, and it must exist solely for the stated purposes. A "deleted users" table that also feeds reactivation marketing is not the record subdivision (c)(2) permits.

Delete less by collecting less

The cheapest deletion request is the one that touches three systems instead of thirty, and that is a function of what you collected in the first place.

Section 1798.100(c) requires that collection, use, retention, and sharing be reasonably necessary and proportionate to the purpose, and Section 1798.100(a)(3) bars retention beyond what is reasonably necessary for each disclosed purpose. A business that runs those data minimization rules properly arrives at a deletion request with a shorter inventory, fewer recipients to notify under subdivision (c)(1), and fewer records to test against the eight exceptions below.

What are the eight exceptions in Section 1798.105(d)?

The subdivision opens with the condition that governs all eight: a business, or a service provider or contractor acting pursuant to its contract with the business, "shall not be required to comply with a consumer's request to delete the consumer's personal information if it is reasonably necessary for the business, service provider, or contractor to maintain the consumer's personal information in order to" do one of the following.

(1) "Complete the transaction for which the personal information was collected, fulfill the terms of a written warranty or product recall conducted in accordance with federal law, provide a good or service requested by the consumer, or reasonably anticipated by the consumer within the context of a business' ongoing business relationship with the consumer, or otherwise perform a contract between the business and the consumer."

(2) "Help to ensure security and integrity to the extent the use of the consumer's personal information is reasonably necessary and proportionate for those purposes."

(3) "Debug to identify and repair errors that impair existing intended functionality."

(4) "Exercise free speech, ensure the right of another consumer to exercise that consumer's right of free speech, or exercise another right provided for by law."

(5) "Comply with the California Electronic Communications Privacy Act pursuant to Chapter 3.6 (commencing with Section 1546) of Title 12 of Part 2 of the Penal Code."

(6) "Engage in public or peer-reviewed scientific, historical, or statistical research that conforms or adheres to all other applicable ethics and privacy laws, when the business' deletion of the information is likely to render impossible or seriously impair the ability to complete such research, if the consumer has provided informed consent."

(7) "To enable solely internal uses that are reasonably aligned with the expectations of the consumer based on the consumer's relationship with the business and compatible with the context in which the consumer provided the information."

(8) "Comply with a legal obligation."

Two drafting points are easy to miss. Exception (7) is a single exception, not two: internal use has to be both aligned with the consumer's expectations and compatible with the context of collection, so a business cannot satisfy one half and skip the other. And exception (6) is the only one that requires the consumer's informed consent, which makes it far narrower than a general research carve-out.

The section carries no subdivisions after (d), and the version currently printed by California Legislative Information is the Proposition 24 text: "Amended November 3, 2020, by initiative Proposition 24, Sec. 5. Effective December 16, 2020. Operative January 1, 2023."

Compliance checklist

  • Offer at least two ways to submit a deletion request, including a toll-free number unless you operate exclusively online with a direct consumer relationship.
  • Verify that the person making the request is the consumer or an authorized agent before deleting anything.
  • Delete the personal information you collected from the consumer, and tell your service providers, contractors, and third parties to do the same.
  • Check the eight section 1798.105(d) exceptions before refusing, and tell the consumer which one you are relying on.
  • Respond within 45 days of the verifiable request, and log how you handled it.

Sources

Last verified: 2026-09-18

Informational, not legal advice.