Skip to main content

Someone asked me to delete their data. What do I have to do?

Last reviewed
2026-09-16

Treat it as a formal request from the moment it arrived, whatever channel it came through and whatever words it used. Verify who is asking, delete across everywhere you hold their information rather than just the obvious system, and respond within the statutory window, which is 45 days in California and generally one month under the GDPR.

The longer version

A request does not have to cite a statute or use a form. An email saying please remove my details is a request, and the deadline runs from when it arrived rather than from when somebody noticed it.

Verification is required and has to be proportionate. You need reasonable confidence the person is who they say they are, without demanding more information than the request itself justifies.

Deletion means everywhere you hold it: the website, the CRM, the mailing list, the spreadsheet on somebody’s desktop, and anything passed to a processor. Exemptions exist in most statutes, for example where you must keep a record for tax or to complete a transaction, and those are judgement calls worth checking.

What to do

  1. Record the date it arrived. That is the start of the clock and the first thing anybody will ask about.
  2. Verify the requester proportionately.
  3. List every place you hold information about that person, including anything given to a third party.
  4. Delete, log what was deleted, and respond within the deadline saying what was done.
  5. If you are relying on an exemption to refuse any part, say so and say why.

The obligation behind this

Sources

  1. California Consumer Privacy Act (CCPA)California Office of the Attorney General

WebSpark describes obligations and evidences what a site does. It does not provide legal advice, and this page is not a substitute for a lawyer who knows your business.