California Privacy Law Delete Data in 2026: What the Right to Delete Actually Covers
If you are searching for california privacy law delete data on August 11, 2026, the practical question is not just whether California gives people a deletion right. It does. The more useful question is what that right actually reaches, what a business still may keep, how fast the response has to come back, and how the new state-run data broker workflow changes the picture in 2026.
That framing matters because California now has two related but different deletion tracks. Under the CCPA, a consumer can ask a covered business to delete personal information the business collected from the consumer. In parallel, California’s newer Delete Act powers DROP, a state-hosted mechanism that lets California residents send one deletion request to active data brokers. As of August 1, 2026, data brokers must begin retrieving and processing those DROP requests.
If you want the broader California baseline first, start with our guides to California consumer privacy, California data privacy protection act, and consent for data collection. This article is narrower. It is the operational answer to the keyword california privacy law delete data as it stands today.

What the California right to delete actually covers
The core deletion right is still anchored in California Civil Code section 1798.105.
That section says a consumer can request that a business delete personal information about the consumer that the business collected from the consumer. It also says that, after receiving a verifiable consumer request, the business must delete that information from its own records, tell service providers and contractors to delete it from their records, and notify third parties to whom the business sold or shared the personal information to delete it too, unless that would be impossible or involve disproportionate effort.
That is the first important clarification for anyone searching california privacy law delete data:
- the right is real;
- it is broader than deleting one row from one app;
- but it is not unlimited across every possible data source and exemption.
California’s privacy agencies also still summarize the consumer-facing rule in plain language. The CPPA FAQ says the right to delete lets consumers request that businesses delete personal information they collected from the consumer and tell their service providers to do the same, while noting that some exceptions apply.
What businesses may still keep after a deletion request
The most common mistake in delete-right content is pretending a valid request always means total erasure everywhere.
It does not.
Section 1798.105(d) still lists exceptions that allow a business, service provider, or contractor to keep personal information when retention is reasonably necessary for specific purposes. The most practical ones to remember are:
- completing the transaction, providing a requested good or service, honoring certain warranties or recalls, or performing a contract;
- helping ensure security and integrity;
- debugging existing functionality;
- exercising free-speech or other legal rights;
- certain scientific, historical, or statistical research with consent;
- certain internal uses aligned with the consumer’s expectations and the context in which the information was provided; and
- complying with a legal obligation.
The CPPA FAQ also points to common denial reasons consumers will actually encounter in production:
- the business cannot verify identity;
- the information was not collected directly from the consumer;
- the information falls within an exception;
- or the information is outside the CCPA because it is publicly available or otherwise exempt.
That is why the phrase california privacy law delete data needs a scope check. The right is powerful, but it is not a blanket rule that every copy of every data point disappears instantly on demand.
How a business has to accept delete requests
California’s rules are still specific here.
Under section 1798.130, businesses generally must make available two or more designated methods for submitting deletion, correction, and know requests, including at minimum a toll-free telephone number. If the business has a website, it must also make the website available for those requests. A business that operates exclusively online and has a direct relationship with the consumer only needs to provide an email address for these requests.
The CPPA FAQ repeats the same practical rule and tells consumers to use the designated request methods listed in the privacy policy, not just whatever support mailbox happens to be easiest to find.
That matters because California enforcement examples still show request-method failures as a recurring problem. The Attorney General’s published CCPA case examples include companies that failed to provide accessible request methods, gave incorrect instructions for delete requests, omitted authorized-agent instructions, or left consumers with broken or incomplete request paths.
For teams implementing this, the immediate review questions are:
- Are the delete-request methods easy to find in the privacy policy?
- Do they actually work?
- Do they cover authorized agents where required?
- Do they route into a response workflow that can verify identity and track the deadline?
Those basics still matter as much as any advanced privacy tooling.
How fast the response has to happen
The statutory response clock is still one of the clearest parts of the California workflow.
Section 1798.130(a)(2) says the business must disclose, correct, or delete the information within 45 days of receiving a verifiable consumer request. The business can extend once by another 45 days when reasonably necessary if it notifies the consumer within the first 45-day period.
The CPPA FAQ adds the more consumer-friendly operational detail: businesses must confirm receipt within 10 business days and must substantively respond within 45 calendar days, with one extension up to 90 days total if the consumer is notified.
So if your real search intent behind california privacy law delete data is, How long can they take?, the working answer in 2026 is:
- acknowledgement within 10 business days; and
- substantive response within 45 calendar days, extendable once to 90 total when properly noticed.
The new 2026 twist: DROP for data brokers
This is the part that changed the most recently.
California’s laws and regulations page now lists both the current CCPA and the Delete Act materials as effective in 2026, and California’s privacy site explains that DROP is the state’s accessible deletion mechanism for data brokers. Through DROP, a California resident can submit one deletion request to active data brokers instead of chasing each broker individually.
California’s privacy site describes DROP as the first platform of its kind and says it allows consumers to request deletion from over 600 data brokers in one request. The site’s current how-it-works page says residents first verify California residency, then create a profile with the data brokers can use for matching, and data brokers begin processing requests starting in August 2026.
The CPPA’s November 2025 announcement approving the Delete Act regulations added the operational details that matter now:
- the regulations took effect January 1, 2026;
- consumers could begin using DROP in January 2026;
- starting August 1, 2026, data brokers must access DROP at least every 45 days to retrieve and process deletion requests;
- if a consumer’s information matches the broker’s records, the broker must delete all associated personal data, including inferences, unless a legal exemption applies; and
- the broker must report request status in DROP within 45 days of retrieving the request.
That makes today’s california privacy law delete data question materially different from the same search a year ago. The consumer deletion conversation is no longer only about direct requests to first-party businesses. California also now has a live mechanism for registered data brokers.

What businesses should recheck right now
If I were auditing a delete-right workflow this week, I would review it in this order:
- Confirm whether the company is handling first-party CCPA delete requests, data broker obligations, or both.
- Check that the privacy policy clearly explains how consumers can submit deletion requests.
- Test every designated request method, including website forms, phone routing, or the online-only email path.
- Confirm the verification step is reasonable and does not create unnecessary friction.
- Map which systems, service providers, contractors, and shared third parties must receive deletion instructions.
- Document the exceptions the company may rely on and tie them to real retention reasons, not vague blanket language.
- Check deadline handling for the 10-business-day acknowledgement and 45-day substantive response.
- If the organization is a data broker, confirm the DROP retrieval and reporting workflow now that the August 1, 2026 processing date has passed.
That review sequence is much more useful than arguing in the abstract about whether California has a deletion right. The answer to that part is settled. The execution details are where businesses still fail.
Bottom line
The keyword california privacy law delete data points to a real and active right in 2026, but the right works through defined channels and defined limits.
For ordinary covered businesses, the core rule is still the CCPA delete workflow: accept requests through designated methods, verify the request, delete covered personal information collected from the consumer, pass deletion downstream where required, and respond on time unless an exception applies. For data brokers, California now also has a live statewide mechanism through DROP, with processing requirements that began on August 1, 2026.
If your process still treats deletion as a manual inbox task, hides request methods in a hard-to-find policy, or has no clear downstream deletion map, it is overdue for a recheck.
Sources
- California Legislative Information: Civil Code section 1798.105
- California Legislative Information: Civil Code section 1798.130
- California Privacy Protection Agency: Frequently Asked Questions
- California Privacy Protection Agency: Laws and regulations
- California Privacy Protection Agency: About DROP and the Delete Act
- California Privacy Protection Agency: How DROP works
- California Privacy Protection Agency: Information for Data Brokers
- California Privacy Protection Agency: California Approves Delete Act Regulations
- California Department of Justice: California Consumer Privacy Act
- California Department of Justice: CCPA Enforcement Case Examples
- California Department of Justice: Attorney General Bonta Reminds Californians to DELETE Their Data Using New Tool
This post was updated on August 11, 2026 using current official California law, regulator, and government materials available at publication time.