Your Privacy Rights
How to File a CCPA Deletion Request (Step by Step)
The short version
A CCPA deletion request is a message you send to a company, not to the state. Find the request channel in its privacy policy, say you are a California resident exercising your right to delete, and give only enough detail to be found in its records. The business then has 10 business days to confirm receipt and 45 calendar days to respond, extendable once to 90. It can refuse under a short list of legal exceptions, but it has to tell you which one. For data brokers, California's DROP platform is the faster route.
What a CCPA deletion request actually does
A CCPA deletion request is a formal instruction to a company to erase the personal information it collected from you, and to pass that instruction on to its service providers and contractors. There is no government form to fill in. You send it to the business, and the law puts that business on a clock.
The right comes from California Civil Code section 1798.105(a): "A consumer shall have the right to request that a business delete any personal information about the consumer which the business has collected from the consumer."
One detail worth knowing before you start: "delete" is broader than it sounds. Under the CCPA regulations, a business can comply by permanently erasing the data from its active systems, by deidentifying it, or by aggregating it. All three count. Backup and archive copies can lag behind until those systems are next restored or used.
Who can file one, and against whom
The right belongs to California residents. It applies to for-profit businesses that do business in California and meet at least one size threshold, so a small local shop is usually outside it. If you are not in California, the mechanics below still help, but the legal deadline will not.
The California Attorney General lists the thresholds as: gross annual revenue of over $25 million; selling personal data of 100,000 or more California residents; or deriving 50% or more of annual revenue from selling California residents' personal information.
Not in California? Our guide on what to do if you are outside California covers the routes that still work, and our state-by-state deletion rights breakdown shows where your own state has caught up.
The limit that catches most people out
Read section 1798.105(a) again and the words "collected from the consumer" do a lot of work. The delete right is strongest against companies you dealt with directly. It is much weaker against a company that bought your file from somebody else, which is exactly how the data-broker industry operates.
The California Privacy Protection Agency lists "if the information wasn't collected directly from the consumer" among the reasons a business may deny a deletion request. That is not a loophole a broker invented - it is in the design of the statute.
This gap is precisely why California passed a second law aimed at brokers. Our plain-English explainer on the California Delete Act covers what that added.
Step one: find the company's request channel
Start in the privacy policy. The CPPA's guidance is blunt about it: review the business's privacy policy, which must include instructions on how you can submit your request. Do not email a general support address and hope. Use the channel the company designated, because that is the one its compliance clock is wired to.
Businesses have to designate at least two methods for submitting requests - for example a toll-free number, an email address, a website form, or a hard copy form. A business that operates exclusively online and has a direct relationship with you only needs to provide an email address.
In practice, look for footer links labelled "Your Privacy Choices", "Privacy Rights", "Do Not Sell or Share My Personal Information", or a privacy request portal linked from the policy itself.
Step two: what to put in the request
Keep it short and specific. You do not need a lawyer, a legal template, or any particular magic wording. State that you are a California resident, that you are exercising your right to delete under the CCPA, and give the business enough identifying detail to find you in its records - and no more than that.
A workable request includes:
- Your full name, and the email address, phone number, or account username you used with that company.
- A one-line statement: you are a California resident exercising your right to delete under the CCPA.
- A request that they also notify their service providers, contractors, and any third parties they sold or shared your data with.
- A request for written confirmation of what was deleted.
Then save a dated copy of exactly what you sent, and screenshot any confirmation screen. If you ever escalate, that record is the whole case.
Step three: verification, without over-sharing
Expect an identity check. Businesses are required to verify that the person asking for deletion is really the consumer the data is about, and if they cannot verify you, the regulations allow them to deny the request. That much is legitimate. What is not legitimate is using verification as a wall.
In March 2025 the CPPA fined American Honda Motor Co. $632,500. Among the allegations: "requiring Californians to verify themselves and provide excessive personal information to exercise certain privacy rights" and "making it difficult for Californians to authorize other individuals or organizations (known as 'authorized agents') to exercise their privacy rights."
The rule of thumb: hand over the identifiers the company already holds on you. If a service that knows you only by an email address demands a photo of your driver's licence, that is worth questioning rather than complying with reflexively.
Step four: the clock the business is on
Once your request lands, two deadlines start running. Knowing them turns a vague wait into a checkable one, and a missed deadline is itself a reportable fact. Note the date you filed, then diary the two dates below.
| Stage | Deadline | What it means |
|---|---|---|
| Confirm receipt | 10 business days | An acknowledgement that your request arrived, not a decision |
| Substantive response | 45 calendar days | The actual answer: deleted, partly deleted, or denied with reasons |
| Extension | +45 days (90 total) | Allowed once, and only if the business notifies you it is taking it |
Source: California Privacy Protection Agency CCPA FAQ and California Attorney General CCPA guidance.
Silence past 45 days without an extension notice is not a grey area. It is the single clearest thing you can point to when you escalate.
Step five: reading the response and its exceptions
A denial is not automatically bad faith. Section 1798.105(d) sets out specific situations where a business does not have to delete, and some of them are reasonable. The test is not whether they said no - it is whether they told you which exception they are relying on.
The listed exceptions cover things like completing a transaction or contract you asked for, ensuring security and integrity, debugging existing functionality, exercising free speech, complying with the California Electronic Communications Privacy Act, certain research with your informed consent, internal uses reasonably aligned with your expectations, and complying with a legal obligation.
The procedural protection matters as much as the list. Under the CCPA regulations, a business that denies a request wholly or partly must "provide to the consumer a detailed explanation of the basis for the denial" and must still "delete the consumer's personal information that is not subject to the exception." A flat "we are unable to delete your data" with no reason attached is not a compliant answer.
If they ignore you or stonewall
You have two escalation routes: the California Privacy Protection Agency and the California Attorney General. Be realistic about what each does. The CPPA says plainly that it "does not represent individual consumers and cannot act as your attorney" - your complaint shapes enforcement priorities rather than forcing your particular deletion.
That is not the same as nothing. The agency's 2025 decisions show what those patterns turn into:
| Company | Date | Fine | Core allegation |
|---|---|---|---|
| American Honda Motor Co. | March 12, 2025 | $632,500 | Excessive verification, asymmetric privacy choices, obstructing authorized agents |
| Todd Snyder, Inc. | May 6, 2025 | $345,178 | Opt-out requests unprocessed for 40 days; demanded more information than necessary |
| Tractor Supply Company | September 30, 2025 | $1,350,000 | No effective opt-out mechanism; privacy policy and job-applicant notice failures |
Source: California Privacy Protection Agency enforcement announcements, 2025.
The statutory ceiling is per violation, not per company. The CPPA's inflation adjustment effective January 1, 2025 set administrative fines at "not more than $2,663 for each violation or $7,988 for each intentional violation." Our guide to where to file a privacy complaint walks through both routes.
For data brokers, use DROP instead
Filing requests one at a time makes sense for a company you actually have a relationship with. It is a bad fit for the hundreds of data brokers that never dealt with you and hold your file anyway. California built a separate route for exactly that problem, and it costs nothing to use.
DROP - the Delete Request and Opt-out Platform, run by the CPPA - lets a California resident submit one deletion request that reaches over 500 registered data brokers at once. Consumer sign-ups have been live since January 2026, and from August 1, 2026 registered brokers must process those requests, checking the platform at least every 45 days.
Our step-by-step California DROP guide covers signing up. If you are outside California, the per-broker opt-out guides are the equivalent work done manually.
Know who has your data before you write
A free exposure scan shows which data brokers are likely to list you and whether your email turns up in known breaches. No account, nothing stored.
Frequently asked questions
Do I have to live in California to file a CCPA deletion request?
Yes. The CCPA gives its rights to California residents. If you live elsewhere, check whether your own state has a deletion right, and use each company's or data broker's own opt-out process in the meantime.
How long does a business have to respond to a CCPA deletion request?
The California Privacy Protection Agency says businesses must confirm receipt of your request within 10 business days and substantively respond within 45 calendar days. They may extend that by another 45 days, for 90 days total, if they notify you.
Does it cost anything to file a CCPA deletion request?
No. Exercising your CCPA rights is free, and a business cannot discriminate against you for using them. You also do not need a lawyer or a paid service to send one.
Can a business legally refuse to delete my data?
Yes, in defined cases. Civil Code section 1798.105(d) lists exceptions such as completing a transaction, security and integrity, debugging, free speech, certain research, internal uses aligned with your expectations, and complying with a legal obligation. It must tell you which one applies.
What if a company got my data from someone else rather than from me?
That is the main gap in the delete right. Section 1798.105(a) covers personal information a business collected from the consumer, and the CPPA lists information not collected directly from you among the reasons a request may be denied. For data brokers, California's DROP platform is the better route.
Do I need a formal legal letter or a specific template?
No. There is no required wording. A short message stating that you are a California resident exercising your CCPA right to delete, sent through the company's designated request channel, is enough. Keep a dated copy of what you sent.
What happens if a business just ignores my request?
You can complain to the California Privacy Protection Agency or the California Attorney General. Be realistic: the CPPA states that it does not represent individual consumers and cannot act as your attorney, so a complaint feeds enforcement priorities rather than forcing your specific deletion.
Does a CCPA deletion request cover data brokers too?
Not well, because brokers rarely collect from you directly. California built a separate route: DROP, the free state-run Delete Request and Opt-out Platform, sends one deletion request to every registered data broker at once.
Sources: California Civil Code section 1798.105; California Attorney General CCPA guidance (oag.ca.gov/privacy/ccpa); California Privacy Protection Agency CCPA FAQ, complaint guidance, and 2025 enforcement announcements (Honda, Todd Snyder, Tractor Supply); CCPA regulations, 11 CCR section 7022 (Requests to Delete).