Under the CCPA, a food-delivery app user with an open refund dispute asks for deletion — what must the business delete, keep and pass on?
answer
- exceptions are data-by-data
- reasonably necessary to keep
- delete the rest
- notify downstream recipients
- explain any denial in detail
basics
~20 sUnder Civil Code 1798.105, the business keeps only what the open dispute or a legal obligation reasonably needs, deletes the rest, uses kept data for nothing else, and notifies service providers, contractors and third parties it sold or shared to.
solid answer
~50 sCivil Code `1798.105(a)` gives a right to delete personal information the business collected from the consumer, and `1798.105(d)` lists when a business need not comply because keeping the data is **reasonably necessary**: completing the transaction or performing the contract (`(d)(1)`), security and integrity (`(d)(2)`), complying with a legal obligation (`(d)(8)`) and others. An open refund dispute keeps the disputed order, payment reference and support thread under `(d)(1)`; it does not keep saved addresses, favourites or the marketing profile. The CCPA regulations make the partial denial concrete (11 CCR 7022(f)): explain the basis in detail, delete what no exception covers, use retained data only for the exception's purpose, and instruct service providers and contractors likewise. Under `1798.105(c)(1)` the business also notifies service providers and contractors, and third parties it sold or shared to, unless impossible or disproportionate.
go deeper
Recall that the right to delete has listed exceptions in 1798.105(d), such as completing a transaction or meeting a legal obligation, and that other data must still go.
Explain 'reasonably necessary': each exception covers the data it needs, and the business must notify service providers, contractors and third parties it sold or shared to.
Walk a partial denial through 11 CCR 7022(f): detailed explanation, delete the rest, purpose-bound retention, instructions downstream, and the backup deferral in 7022(d).
Design deletion as a data-scoped workflow with exception tags and expiry, so kept records are released automatically when the dispute or legal duty ends.
## The right and its reach Under the CCPA as amended by the CPRA, Civil Code `1798.105(a)` gives a consumer the right to request that a business delete 'any personal information about the consumer which the business has collected from the consumer'. On a verifiable request, `1798.105(c)(1)` requires the business to: 1. **Delete** the consumer's personal information from its records; 2. **Notify service providers and contractors** to delete it from theirs; 3. **Notify all third parties** to whom it sold or shared the information to delete it, unless this proves impossible or involves disproportionate effort. 11 CCR 7022(b)(1) says what deletion means: permanently and completely **erasing** from existing systems (backups and archives excepted, see below), **deidentifying**, or **aggregating**. ## The exceptions in 1798.105(d) A business, service provider or contractor need not comply to the extent it is **reasonably necessary** to keep the personal information to: - (1) complete the transaction, fulfil a warranty or recall, provide a good or service the consumer requested or reasonably anticipates, or otherwise perform a contract with the consumer; - (2) help ensure security and integrity, to the extent reasonably necessary and proportionate; - (3) debug errors that impair existing intended functionality; - (4) exercise or protect free speech or another legal right; - (5) comply with the California Electronic Communications Privacy Act; - (6) engage in qualifying public or peer-reviewed research, with informed consent, where deletion would seriously impair it; - (7) enable solely internal uses reasonably aligned with the consumer's expectations; - (8) comply with a legal obligation. The words that matter are **'reasonably necessary'**. Each exception covers the data it needs, not the account. ## Applying it to the refund dispute | Data | Exception | Outcome | |---|---|---| | The disputed order, its payment reference and the refund thread | `(d)(1)` completing the transaction and the contract | Keep, only for resolving the dispute | | Order records a tax or accounting law requires to be kept | `(d)(8)` legal obligation | Keep, only for that obligation | | Saved delivery addresses, favourite restaurants, marketing preferences | None | Delete | | Behavioural profile used for personalised promotions | None | Delete | Once the dispute closes, the need that justified keeping the dispute data is gone, so the exception no longer covers it. ## How a partial denial must be handled 11 CCR 7022(f) turns the exception into a procedure. A business that denies a request in whole or in part must: 1. Give the consumer a **detailed explanation** of the basis, including any conflicting law, CCPA exception, or facts showing impossibility or disproportionate effort; 2. **Delete** the personal information not subject to the exception; 3. **Not use** the retained information for any purpose other than the exception's; 4. **Instruct** service providers and contractors to do the same. It must also tell the consumer whether it complied and that it keeps a record of the request (7022(e)); `1798.105(c)(2)` allows a confidential record of deletion requests, for example so that the data is not sold again. ## Downstream and backups - **Service providers and contractors** cooperate and delete, and pass the request on to their own service providers and contractors (`1798.105(c)(3)`, 7022(c)). - **Third parties** that bought or received the data by sharing are notified; claiming impossibility needs a detailed, factual explanation (7022(b)(3)). - **Backups and archives** need not be purged at once: under 7022(d), deletion on archived or backup systems may wait until that system is restored to an active system or is next accessed or used for a sale, disclosure or commercial purpose. ## What interviewers listen for That the candidate treats exceptions as **data-scoped and purpose-bound**, deletes everything else now, restricts the use of what stays, propagates the request, and can explain a denial in terms the regulation accepts.
- Can the app keep the user's email address because it might want to send her a win-back offer later?No. Civil Code 1798.105(d) excuses deletion only where keeping the data is reasonably necessary for a listed purpose. A future marketing campaign is not one; the internal-uses exception in (d)(7) needs uses reasonably aligned with the consumer's expectations, and someone who has asked to be deleted is unlikely to expect win-back marketing.
- Must a service provider delete the data if the consumer asks it directly?Not when it holds the data in its role as a service provider or contractor to the business. Civil Code 1798.105(c)(3) says it need not comply with a request submitted directly to it in that role; it acts on the business's direction and must cooperate with the business's response.
saying these in an interview costs you the question
- Refuses the whole deletion request because one exception covers some data
- Keeps retained data and continues using it for marketing
- Deletes only its own copy and never tells service providers or contractors
- Says every backup must be purged immediately on each deletion request
- Answers a partial denial with a bare 'we cannot delete your data'