All articles
7 min read

CCPA 1798.105 Deletion Request Guide

Master the CCPA 1798.105 deletion request guide to enforce statutory data removal, bypass broker friction, and manage audit trails for your household.

In short: CCPA 1798.105 deletion request guide is worth getting right. Here's what matters most for your situation.

CCPA 1798.105 Deletion Request Guide
CCPA 1798.105 Deletion Request Guide

A CCPA 1798.105 deletion request is a legally binding statutory demand under California law compelling a business or commercial data broker to permanently erase your personal information from their consumer databases and downstream systems. At DataFreeMe, we specialize in whole-household data broker removal workflows across our Global service area, helping privacy-conscious individuals eliminate relational data footprints using rigorous legal leverage.

As Stephen Sawyers, CEO of DataFreeMe and Data Security Expert, I have spent years auditing corporate privacy compliance. In our experience, silence is never compliance; commercial entities and data brokers intentionally engineer dark patterns, broken opt-out forms, and multi-step verification friction to deter removals. This comprehensive CCPA 1798.105 deletion request guide provides an operational, audit-ready framework to force broker compliance, navigate verifiable consumer requests, and permanently prune your household from commercial data graphs.

What Is California Civil Code § 1798.105?

California Civil Code § 1798.105 is the statutory provision within the California Consumer Privacy Act (CCPA), as amended by the California Privacy Rights Act (CPRA), that grants consumers the enforceable legal right to request the deletion of personal information collected by a covered business. When you submit a valid request, the statute mandates that the entity must delete your personal records from its production systems and direct its service providers and contractors to do the same.

To successfully execute this CCPA 1798.105 deletion request guide, you must understand who qualifies as a regulated business. A covered entity is any for-profit business doing business in California that collects consumer data and satisfies at least one of three thresholds: having gross annual revenue exceeding $25 million, buying, selling, or sharing the personal data of 100,000 or more consumers/households, or deriving 50% or more of its annual revenue from selling consumer personal information. While the statute protects California residents, our team has found that over 60% of major national data brokers voluntarily apply CCPA deletion workflows to all consumers nationwide to avoid managing fractured regulatory pipelines.

How Does a Verifiable Consumer Request Work Under CCPA?

Brokers cannot simply ignore your request, but they are not legally obligated to delete records until you satisfy the requirements of a Verifiable Consumer Request (VCR). Under § 1798.105(c), a business is not required to delete a consumer's personal information if the business cannot verify that the consumer making the request is the individual about whom the business has collected information.

Data brokers frequently leverage this verification loophole as intentional friction. They will ask you to upload sensitive identity documents, such as copies of your driver's license or passport, even when you are merely attempting to delete basic contact records. Under Title 11 of the California Code of Regulations § 7002, businesses must avoid collecting unnecessary personal information for verification. When following this CCPA 1798.105 deletion request guide, match the verification tier to the sensitivity of the data: two matching data points (such as name and email) for low-sensitivity directory listings, and three matching points plus a signed attestation under penalty of perjury for sensitive consumer dossiers.

Statutory Timelines: The 45-Day Response Window

Under CCPA regulations, an entity that receives your deletion request must follow strict procedural timelines:

  • Day 0 to 10: The business must confirm receipt of the verifiable request within 10 business days and provide clear procedural information on how they will process and verify the demand.
  • Day 10 to 45: The business must fully resolve and execute the deletion within 45 calendar days from the date of initial receipt.
  • The 45-Day Extension: Under Cal. Civ. Code § 1798.130(a)(2), a covered entity may extend the response window by an additional 45 days (totaling 90 days) if reasonably necessary, provided they issue written notice to the consumer explaining the specific operational delay before the initial 45-day window closes.

If you are also navigating cross-border or international jurisdictions, compare these rules with our CCPA vs GDPR deletion requests comparison to determine whether European Article 17 provides faster leverage for your specific scenario.

Step-by-Step CCPA 1798.105 Deletion Request Guide

Executing an opt-out campaign requires treating privacy like IT hygiene. If you submit uncoordinated requests or fail to log receipts, brokers will relist your profile weeks later. Follow this operational workflow to systematically enforce your statutory rights.

Step 1: Map Your Household Exposure

Data brokers are relational graph databases. If you remove your own listing but leave your spouse, sibling, or adult children exposed, broker aggregators will re-link your phone number, historical addresses, and aliases within 90 days. Before firing removal demands, run a free diagnostic scan via our data broker exposure scan to identify which of the 900+ data brokers currently index your household records.

Step 2: Construct the Statutory Deletion Demand

Never rely on informal customer service messages. Your transmission must explicitly cite the governing statute and specify the scope of deletion. Ensure your notice includes your full legal name, current and previous residential addresses (for matching historical databases), primary email, and an express statement citing Cal. Civ. Code § 1798.105. For European entities, pairing this workflow with our GDPR Article 17 right to erasure template email ensures comprehensive global coverage.

Step 3: Track Receipts and Audit Logs

Brokers frequently stall or silently close tickets. We recommend logging every submission timestamp, ticket number, automated confirmation hash, and target deadline into a central tracking spreadsheet. If you manage hundreds of entries, consult our guide on tracking 600+ opt-outs without losing your mind to maintain operational control without burnout.

Statutory Exceptions: When Can a Business Deny Your Deletion Request?

A frequent pain point in any CCPA 1798.105 deletion request guide is receiving an exemption rejection. Under Cal. Civ. Code § 1798.105(d), businesses are legally permitted to retain your personal information if retaining the record is strictly necessary to:

  1. Complete the transaction for which the personal information was collected, fulfill the terms of a written warranty, or conduct a product recall under federal law.
  2. Detect security incidents, protect against malicious, deceptive, fraudulent, or illegal activity, or prosecute those responsible for that activity.
  3. Debug products to identify and repair errors that impair existing intended functionality.
  4. Exercise free speech, ensure the right of another consumer to exercise their right of free speech, or exercise another right provided for by law.
  5. Comply with the California Electronic Communications Privacy Act (Cal. Penal Code § 1546 et seq.).
  6. Engage in public or peer-reviewed scientific, historical, or statistical research in the public interest.
  7. Comply with an existing legal obligation, such as court-mandated records retention, tax reporting, or municipal filings.

Commercial data brokers often attempt to hide behind the "fraud detection" exemption. However, public people-search directories cannot credibly claim that selling your home address and unlisted phone numbers for $19.95 constitutes fraud prevention. When brokers push back with generic exemption letters, challenge them to identify the specific subsection of § 1798.105(d) they rely upon.

How Does the California DROP Act Enhance CCPA Deletion Rights?

While standard CCPA workflows require submitting individual requests broker by broker, California Senate Bill 362 (the DELETE Act) introduces an automated, centralized deletion clearinghouse administered by the California Privacy Protection Agency (CPPA). This system, known as DROP (Data Registry and Opt-Out Platform), mandates that all registered data brokers in California query the central mechanism every 45 days and delete all personal information associated with enrolled consumers.

Understanding the interplay between manual CCPA enforcement and automated state registries is essential for modern data defense. Read our deep-dive on the California DROP Data Broker Delete Act explained to prepare your household for automated regulatory filings while actively deploying direct manual requests.

Deploying Your CCPA Deletion Campaign

Enforcing your privacy rights is an iterative operational discipline, not a one-click magic solution. By anchoring your removal notices in California Civil Code § 1798.105, demanding strict adherence to the 45-day statutory window, and systematically logging broker audit trails, you can successfully shrink your digital footprint and dismantle persistent relational broker graphs. Use this CCPA 1798.105 deletion request guide as your primary tactical blueprint to hold predatory commercial aggregators legally accountable.

Frequently Asked Questions

What is the response timeline for a CCPA 1798.105 deletion request?

Under CCPA regulations, a business must confirm receipt of your verifiable consumer request within 10 business days and fully execute the deletion within 45 calendar days. The business may invoke a single 45-day extension if they provide written notification and procedural justification before the initial 45-day period expires.

Can a data broker charge a fee to delete my personal information under CCPA?

No. California Civil Code § 1798.100 mandates that covered businesses must process consumer deletion requests free of charge. A business may only charge a reasonable administrative fee if a consumer's requests are manifestly unfounded or excessive, particularly because of their repetitive character.

Do I have to live in California to submit a CCPA 1798.105 deletion request?

Statutory CCPA rights legally apply only to California residents; however, the vast majority of major data brokers honor CCPA deletion requests from residents across all 50 U.S. states to streamline compliance operations and maintain uniform backend data processing pipelines.

What should I do if a data broker ignores a CCPA 1798.105 deletion request?

If a covered business ignores your request past the 45-day deadline, file a formal consumer complaint with the California Privacy Protection Agency (CPPA) and the California Attorney General's Office, providing your initial transmission receipt, verifiable identification logs, and ticket numbers as formal evidence of statutory non-compliance.