Blog

CCPA/CPRA: How to Demand Deletion of Your Personal Data in California

September 17, 2026 · 9 min

Updated on September 2, 2026

California's privacy law is the most powerful consumer data tool in the United States. You can demand deletion, demand disclosure of what was collected and sold, and opt out of sale or sharing — and businesses have 45 days to comply. This guide explains exactly how to file a request, what they can refuse, and the escalation path when they stall.

What CCPA and CPRA give you

The California Consumer Privacy Act, expanded by the California Privacy Rights Act, applies to businesses meeting revenue or data-volume thresholds — which covers essentially every major data broker, retailer, adtech company and people-search site operating in the US market.

  • Right to know: what personal information a business collected, where it came from, why, and who it was shared with.
  • Right to delete: demand deletion of personal information the business collected from you, subject to narrow exceptions.
  • Right to correct: fix inaccurate personal information.
  • Right to opt out of sale or sharing: stop your data being sold or used for cross-context behavioural advertising.
  • Right to limit use of sensitive personal information: restrict use of data like precise location, health or biometric information.
  • Right to non-discrimination: a business cannot punish you for exercising these rights.

Who can file — and the residency question

Formally, the CCPA protects California residents. In practice, most large data brokers and people-search sites apply the same deletion workflow to all US residents, because maintaining separate processes for fifty states is more expensive than just complying everywhere.

This means it is always worth filing, even if you live elsewhere in the US. It costs nothing but your time, and many businesses will process it rather than argue about jurisdiction.

How to file a request that gets processed

Businesses must provide at least two methods — typically a web form and a toll-free number. A request that gets ignored is usually one that was vague or unverifiable.

  • Use the business's dedicated privacy request page, not general customer support. Search "[company] CCPA request" or check the footer for "Do Not Sell or Share My Personal Information".
  • State explicitly which rights you are exercising: deletion, disclosure, and opt-out of sale or sharing. Ask for all three.
  • Provide enough identifying information to be matched, but no more than necessary. Businesses may request verification, but cannot demand excessive documentation.
  • Keep a dated copy of everything you submit. The clock on their 45-day deadline starts when you submit, not when they acknowledge.
  • Use an authorised agent or a written authorisation if you are filing on someone else's behalf — the law permits it, with proof.
Start by finding out what shows up about you Request your free diagnosis: we analyse your case and tell you what can be done, with no commitment. Request free diagnosis

What they can legitimately refuse

There are real exceptions, and knowing them stops you wasting time on requests that cannot succeed.

  • Information needed to complete a transaction or provide a service you requested.
  • Data used for security, fraud prevention or to prosecute those responsible for illegal activity.
  • Information required to comply with a legal obligation or exercise legal claims.
  • Internal uses reasonably aligned with your expectations, in some contexts.
  • Publicly available government records — which is precisely why people-search sites argue they are exempt, though this is contested for aggregated profiles.

When they refuse or stall

If a business misses the 45-day deadline (extendable once by another 45 days with notice), ignores the request, or gives a blanket refusal, you have escalation routes that cost nothing.

  • Send a written follow-up citing the CCPA sections and the missed deadline, and state your intent to complain.
  • File a complaint with the California Privacy Protection Agency (CPPA), which now has its own enforcement authority and rulemaking power.
  • File with the California Attorney General, which has brought enforcement actions and issues fines per violation.
  • Document everything. Patterns of non-compliance across multiple businesses are what turn individual complaints into enforcement.

The limit of what a request can achieve

A deletion request removes your data from a business's systems. It does not remove copies already sold to third parties before your request, and it does not stop a new business from collecting the same information later.

That is why reputation cleanup in the US is rarely one request. It is a combination: deletion demands against the businesses that hold your data, delisting requests against Google for what remains indexed, and ongoing monitoring because the underlying public records keep regenerating profiles. Prioritising what is actually searchable — not what you assume is out there — is what makes the effort pay off.

Frequently asked questions

How long does a CCPA deletion request take?
Businesses must respond within 45 days. They may extend once by a further 45 days if they notify you. If the deadline passes without a response, you can complain to the California Privacy Protection Agency or the Attorney General.
Can I file a CCPA request if I do not live in California?
Formally the CCPA protects California residents, but most large data brokers apply the same process to all US residents because it is cheaper than maintaining state-by-state workflows. It is always worth submitting.
Do I need a lawyer to file?
No. The process is designed to be self-service: a web form or phone line, a verification step, and a 45-day deadline the business must meet. A lawyer becomes relevant only if you pursue damages after a breach.
Does a deletion request remove me from Google?
No. It removes your data from the business's systems. Google may still link to pages hosted elsewhere, which requires a separate delisting request through Google's own tools.
What is the difference between CCPA and CPRA?
The CCPA was the original 2018 law. The CPRA amended it, effective 2023, adding rights to correct data, limit use of sensitive information, and creating the California Privacy Protection Agency with enforcement powers.
Request free diagnosis

Keep reading