Announcing Agent Commander - The First Integrated solution from Veeam + Securiti.ai enabling the scaling of safe AI agents

View
Veeam

The Funniest Evening at RSA with Hasan Minhaj

Hasan Minhaj Request ticket
View

Right to delete under California Consumer Privacy Act (CCPA)

Published May 26, 2021 / Updated October 24, 2024
Author

Omer Imran Malik

Data Privacy Legal Manager, Securiti

FIP, CIPT, CIPM, CIPP/US

Listen to the content

Ever since the GDPR came into effect on May 25th, 2018, there were speculations on what sorts of impact it may have on businesses. Nearly 2 years later, with cumulative fines totalling a whopping €466,681,568, there is no doubt about GDPR’s financial impact on non-compliant organizations.

What is Right to Deletion under CCPA?

Judging by the impact of GDPR, compliance with CCPA is going to be a critical undertaking for every company falling under its ambit. With respect to fines, GDPR has an upper cap of 4% of global turnover as the highest penalty whereas CCPA has no upper cap and fines can go up to $750 per incident in cases of breach and even higher in cases where the Attorney General of California brings a civil action for violation of the CCPA requirements. Thus the CCPA can potentially cost businesses millions of dollars in penalties.

For example, if the Equifax breach of 2017 that affected 147M people, including approximately 15M Californians, had happened AFTER the implementation of CCPA, Equifax would have had to pay up to $11 Billion in fines and penalties, compared to a paltry $425M that it had to ultimately pay for settlement.

Therefore, compliance is absolutely critical as the CCPA ensures that consumers know everything about their data rights and how they can exercise those rights. These include:

  • The right to access the personal information that a business holds on them
  • The right to know the personal information a business plans on collecting at or before the point of collection
  • The right to opt in or out of marketing, analytics, and other similar activities
  • The right to equal services without discrimination
  • The right to request deletion of personal data

Right to Deletion under CCPA

Under “Right to Deletion Under CCPA” You have the option to ask businesses to remove any personal data they have collected from you, as well as tell their service providers to do the same. However, there are a few exceptions to this rule, such as when the business is legally obligated to retain the information. In other words, once a consumer requests an organization to delete their data, the organization has a specific period of time to fulfill this request after proper verification. This is true with a few exceptions detailed in the subsequent section.

Eligibility and Verification

The CCPA and corresponding requirement to honor the right to deletion only applies to organizations doing business with or providing services to Californians, and meet one of the following conditions:

  1. Have annual gross revenues in excess of $25 million
  2. Handle the personal information of at least 50,000 consumers or devices
  3. Derive 50 percent or more in annual revenue from selling consumers’ personal information

A business that receives a data deletion request will need to take reasonable actions to accurately verify the authenticity of the request and respond to the consumer if it has accepted or denied the request.

Timeline to comply

Section 1798.145(g)(1) provides organizations 45 days to respond to a verifiable consumer request. This period may be extended by another 45 days where necessary based on  complexity and volume of requests. Organizations must inform the consumer of the extension within 45 days of accepting the verified request. If the organization is not going to delete the information, it must inform the consumer without delay (and under no circumstances beyond the time period permitted for a response), the reason for declining the request along with any information on the right to appeal this decision.

Fees Charged

Businesses may only charge a fee to a consumer for the right to delete under CCPA if the consumer’s requests are deemed to be excessive in nature. If a consumer engages in repetitive requests that the business can demonstrate are excessive, it may either charge a reasonable fee or decline the repetitive request(s).

Options to Delete

In responding to a request to delete, a business may present the consumer with the choice to delete select portions of their personal information only if a global option to delete all personal information is also offered and more prominently presented than the other choices.

Opt-out Option

If a business that denies a consumer’s request to delete sells personal information and the consumer has not already made a request to opt-out, the business shall ask the consumer if they would like to opt-out of the sale of their personal information and shall include either the contents of, or a link to, the notice of right to opt-out.

Exceptions to The Right to Deletion Under CCPA

There are several exceptions to the right of deletion that organizations can leverage to deny the request. These exceptions can be invoked, for example, if it is necessary for the organization to retain the personal information on the basis of one or of the following:

  1. Logs, Errors and Cybersecurity: An interesting exemption to the right to deletion granted to businesses by CCPA is the need to maintain server logs of their consumers data in order to prevent and/or detect cybersecurity incidents like malware attacks, spam, phishing, and other fraudulent activities. In addition, consumers’ personal information can be retained if they aid in repair and maintenance of functionalities of various computer programs.
  2. Medical Studies & Research: The CCPA also allows organizations to retain personal information of a consumer to primarily aid in medical studies and research that can greatly contribute to a medical cause, provided that:
    • That the impediment caused by erasure of a consumer’s personal information will be substantial
    • That the personal information does not violate a person’s privacy or goes against established societal and cultural norms
    • That the consumer has earlier agreed to have the personal information used for the states purpose
  3. Provision of Services: This exemption revolves around a business’s necessity to retain personal information of a consumer that submits a request for deletion to provide a certain level of service that cannot be provided if the person's information is erased. For example, to complete a transaction, perform a contract, or to develop  the existing relationship between a consumer and the business.
  4. Searching Personal Online Accounts: In the state of California, if the police want to search an individual’s phone, email or other personal online account, they need to obtain a warrant from the government as per the California Electronic Communication Privacy Act of 2016. The CCPA allows businesses to refuse a right to erase requests of a consumer whose personal online account data has been requested by the police.
  5. Miscellaneous: Other exemptions provided to businesses to retain personal information of consumers are to solely use this information for a businesses’ internal processes, to comply with laws and regulations, and for other governmental duties. The key to exemptions is to use personal information in contexts for which the consumer initially consented to and thus are aligned with their expectations.

In cases where a business denies a consumer’s request to delete under a specific exception, the business shall undergo the following process:

  • Inform the consumer that it will not comply with the consumer’s request and describe the basis for the denial, including any conflict with federal or state law, or exception to the CCPA, unless prohibited from doing so by law;
  • Delete the consumer’s personal information that is not subject to the exception
  • Not use the consumer’s personal information retained for any other purpose than provided for by that exception.

Complying with the right to deletion requests under CCPA using manual methods requires a lot of time, resources and capital. Even then, organizations may risk non-compliance because of human error.

This could be a financial disaster for organizations and tarnish their reputation.  To avoid non-compliance and fulfill these requests in a cost-effective and productive manner, organizations can deploy privacy management solutions that utilize automation to reduce request fulfillment time, effort, error, and costs.

Key Takeaway

  • CCPA enforcement will likely have a significant financial impact for organizations  that fail to comply
  • Organizations have been fined billions of dollars due to non-compliance with GDPR and studies show that this could be the case under the CCPA as well.
  • The CCPA gives consumers the right to request deletion of any and all information related to them (apart from the 7 exceptions discussed above).
  • Organizations will have 45 days to fulfill this request in order to avoid fines and penalties.
  • Adopting modern, purpose-built privacy management solutions that leverage automation to complete data service requests helps organizations reduce time, effort, and costs.

Next Steps

Securiti is the pioneer in deploying artificial intelligence and robotic automation for privacy compliance. Judged “Most Innovative Startup 2020” by RSA, Securiti offers organizations with a solution that will help them automate their entire privacy compliance ecosystem, including right to deletion requests. Schedule a live demo today and see for yourself how Securiti can get your business ready for compliance with CCPA.


Frequently Asked Questions (FAQs)

The right to delete in the California Consumer Privacy Act (CCPA) allows consumers to request that a business delete their personal information which the business has collected from the consumers. Businesses must fulfill these requests unless the exception applies.

While CCPA grants consumers the right to delete their personal information, exceptions exist. Businesses are not required to delete personal information if it's necessary for various purposes, such as completing a transaction for which the personal information was collected, ensuring the security and integrity of the personal information of consumers , or complying with legal obligations.

Under CCPA, businesses are required to delete a consumer's personal information upon a verifiable request unless an exception applies. Businesses are required to delete the consumer's personal information from their records, instruct their service providers and contractors to do the same, and inform third parties to whom the businesses have shared or sold the personal information to delete the personal information of consumers. However, businesses are not required to delete the personal information if it is impossible or requires a disproportionate effort.

CCPA grants several rights to California consumers, including the right to know what personal information is collected, the right to request deletion of personal information, the right to opt-out of the sale of personal information, and protection from discrimination for exercising these rights.

Starting January 1, 2028, the Delete Act will require data brokers to have an independent audit every three years to check compliance. Until then, Californians can ask individual brokers to delete their data.

Analyze this article with AI

Prompts open in third-party AI tools.
Join Our Newsletter

Get all the latest information, law updates and more delivered to your inbox


Share

More Stories that May Interest You

Take a
Product Tour

See how easy it is to manage privacy compliance with robotic automation.

Videos
View More
Rehan Jalil, Veeam on Agent Commander : theCUBE + NYSE Wired: Cyber Security Leaders
Following Veeam’s acquisition of Securiti, the launch of Agent Commander marks an important step toward helping enterprises adopt AI agents with greater confidence. In...
View More
Mitigating OWASP Top 10 for LLM Applications 2025
Generative AI (GenAI) has transformed how enterprises operate, scale, and grow. There’s an AI application for every purpose, from increasing employee productivity to streamlining...
View More
Top 6 DSPM Use Cases
With the advent of Generative AI (GenAI), data has become more dynamic. New data is generated faster than ever, transmitted to various systems, applications,...
View More
Colorado Privacy Act (CPA)
What is the Colorado Privacy Act? The CPA is a comprehensive privacy law signed on July 7, 2021. It established new standards for personal...
View More
Securiti for Copilot in SaaS
Accelerate Copilot Adoption Securely & Confidently Organizations are eager to adopt Microsoft 365 Copilot for increased productivity and efficiency. However, security concerns like data...
View More
Top 10 Considerations for Safely Using Unstructured Data with GenAI
A staggering 90% of an organization's data is unstructured. This data is rapidly being used to fuel GenAI applications like chatbots and AI search....
View More
Gencore AI: Building Safe, Enterprise-grade AI Systems in Minutes
As enterprises adopt generative AI, data and AI teams face numerous hurdles: securely connecting unstructured and structured data sources, maintaining proper controls and governance,...
View More
Navigating CPRA: Key Insights for Businesses
What is CPRA? The California Privacy Rights Act (CPRA) is California's state legislation aimed at protecting residents' digital privacy. It became effective on January...
View More
Navigating the Shift: Transitioning to PCI DSS v4.0
What is PCI DSS? PCI DSS (Payment Card Industry Data Security Standard) is a set of security standards to ensure safe processing, storage, and...
View More
Securing Data+AI : Playbook for Trust, Risk, and Security Management (TRiSM)
AI's growing security risks have 48% of global CISOs alarmed. Join this keynote to learn about a practical playbook for enabling AI Trust, Risk,...

Spotlight Talks

Spotlight 50:52
From Data to Deployment: Safeguarding Enterprise AI with Security and Governance
Watch Now View
Spotlight 11:29
Not Hype — Dye & Durham’s Analytics Head Shows What AI at Work Really Looks Like
Not Hype — Dye & Durham’s Analytics Head Shows What AI at Work Really Looks Like
Watch Now View
Spotlight 11:18
Rewiring Real Estate Finance — How Walker & Dunlop Is Giving Its $135B Portfolio a Data-First Refresh
Watch Now View
Spotlight 13:38
Accelerating Miracles — How Sanofi is Embedding AI to Significantly Reduce Drug Development Timelines
Sanofi Thumbnail
Watch Now View
Spotlight 10:35
There’s Been a Material Shift in the Data Center of Gravity
Watch Now View
Spotlight 14:21
AI Governance Is Much More than Technology Risk Mitigation
AI Governance Is Much More than Technology Risk Mitigation
Watch Now View
Spotlight 12:!3
You Can’t Build Pipelines, Warehouses, or AI Platforms Without Business Knowledge
Watch Now View
Spotlight 47:42
Cybersecurity – Where Leaders are Buying, Building, and Partnering
Rehan Jalil
Watch Now View
Spotlight 27:29
Building Safe AI with Databricks and Gencore
Rehan Jalil
Watch Now View
Spotlight 46:02
Building Safe Enterprise AI: A Practical Roadmap
Watch Now View
Latest
View More
Introducing Agent Commander
The promise of AI Agents is staggering— intelligent systems that make decisions, use tools, automate complex workflows act as force multipliers for every knowledge...
Risk Silos: The Biggest AI Problem Boards Aren’t Talking About View More
Risk Silos: The Biggest AI Problem Boards Aren’t Talking About
Boards are tuned in to the AI conversation, but there’s a blind spot many organizations still haven’t named: risk silos. Everyone agrees AI governance...
Largest Fine In CCPA History_ What The Latest CCPA Enforcement Action Teaches Businesses View More
Largest Fine In CCPA History: What The Latest CCPA Enforcement Action Teaches Businesses
Businesses can take some vital lessons from the recent biggest enforcement action in CCPA history. Securiti’s blog covers all the important details to know.
View More
AI & HIPAA: What It Means and How to Automate Compliance
Explore how the Health Insurance Portability and Accountability Act (HIPAA) applies to Artificial Intelligence (AI) in securing Protected Health Information (PHI). Learn how to...
California’s Delete Request and Opt-out Platform (DROP) and the Delete Act View More
California’s Delete Request and Opt-out Platform (DROP) and the Delete Act
Understand California’s DROP platform and the Delete Act, including compliance timelines, the 45-day cycle, broker obligations, and how to operationalize compliance.
Building A Secure AI Foundation For Financial Services View More
Building A Secure AI Foundation For Financial Services
Access the whitepaper and discover how financial institutions eliminate Shadow AI, enforce real-time AI policies, and secure sensitive data with a unified DataAI control...
Emerging AI Security Trends For 2026 View More
Emerging AI Security Trends For 2026
Securiti’s latest infographic provides security leaders with a walkthrough of all the emerging AI security trends for 2026 to help them assess and plan...
Safe AI, Accelerated: View More
Safe AI, Accelerated: Securing Data & AI Across the Lifecycle
Securiti’s latest infographic dives into the issue organizations face when scaling their AI projects safely, and how best they can address those challenges.
View More
Take the Data Risk Out of AI
Learn how to prepare enterprise data for safe Gemini Enterprise adoption with upstream governance, sensitive data discovery, and pre-index policy controls.
View More
Navigating HITRUST: A Guide to Certification
Securiti's eBook is a practical guide to HITRUST certification, covering everything from choosing i1 vs r2 and scope systems to managing CAPs & planning...
What's
New