skip to content

Under the CCPA, a food-delivery app user with an open refund dispute asks for deletion — what must the business delete, keep and pass on?

level: seniorimportance: must knowfreq 50%

answer

  1. exceptions are data-by-data
  2. reasonably necessary to keep
  3. delete the rest
  4. notify downstream recipients
  5. explain any denial in detail

basics

~20 s

Under Civil Code 1798.105, the business keeps only what the open dispute or a legal obligation reasonably needs, deletes the rest, uses kept data for nothing else, and notifies service providers, contractors and third parties it sold or shared to.

solid answer

~50 s

Civil Code `1798.105(a)` gives a right to delete personal information the business collected from the consumer, and `1798.105(d)` lists when a business need not comply because keeping the data is **reasonably necessary**: completing the transaction or performing the contract (`(d)(1)`), security and integrity (`(d)(2)`), complying with a legal obligation (`(d)(8)`) and others. An open refund dispute keeps the disputed order, payment reference and support thread under `(d)(1)`; it does not keep saved addresses, favourites or the marketing profile. The CCPA regulations make the partial denial concrete (11 CCR 7022(f)): explain the basis in detail, delete what no exception covers, use retained data only for the exception's purpose, and instruct service providers and contractors likewise. Under `1798.105(c)(1)` the business also notifies service providers and contractors, and third parties it sold or shared to, unless impossible or disproportionate.

go deeper

for a junior

Recall that the right to delete has listed exceptions in 1798.105(d), such as completing a transaction or meeting a legal obligation, and that other data must still go.

for a middle

Explain 'reasonably necessary': each exception covers the data it needs, and the business must notify service providers, contractors and third parties it sold or shared to.

for a senior

Walk a partial denial through 11 CCR 7022(f): detailed explanation, delete the rest, purpose-bound retention, instructions downstream, and the backup deferral in 7022(d).

for a principal

Design deletion as a data-scoped workflow with exception tags and expiry, so kept records are released automatically when the dispute or legal duty ends.

## The right and its reach Under the CCPA as amended by the CPRA, Civil Code `1798.105(a)` gives a consumer the right to request that a business delete 'any personal information about the consumer which the business has collected from the consumer'. On a verifiable request, `1798.105(c)(1)` requires the business to: 1. **Delete** the consumer's personal information from its records; 2. **Notify service providers and contractors** to delete it from theirs; 3. **Notify all third parties** to whom it sold or shared the information to delete it, unless this proves impossible or involves disproportionate effort. 11 CCR 7022(b)(1) says what deletion means: permanently and completely **erasing** from existing systems (backups and archives excepted, see below), **deidentifying**, or **aggregating**. ## The exceptions in 1798.105(d) A business, service provider or contractor need not comply to the extent it is **reasonably necessary** to keep the personal information to: - (1) complete the transaction, fulfil a warranty or recall, provide a good or service the consumer requested or reasonably anticipates, or otherwise perform a contract with the consumer; - (2) help ensure security and integrity, to the extent reasonably necessary and proportionate; - (3) debug errors that impair existing intended functionality; - (4) exercise or protect free speech or another legal right; - (5) comply with the California Electronic Communications Privacy Act; - (6) engage in qualifying public or peer-reviewed research, with informed consent, where deletion would seriously impair it; - (7) enable solely internal uses reasonably aligned with the consumer's expectations; - (8) comply with a legal obligation. The words that matter are **'reasonably necessary'**. Each exception covers the data it needs, not the account. ## Applying it to the refund dispute | Data | Exception | Outcome | |---|---|---| | The disputed order, its payment reference and the refund thread | `(d)(1)` completing the transaction and the contract | Keep, only for resolving the dispute | | Order records a tax or accounting law requires to be kept | `(d)(8)` legal obligation | Keep, only for that obligation | | Saved delivery addresses, favourite restaurants, marketing preferences | None | Delete | | Behavioural profile used for personalised promotions | None | Delete | Once the dispute closes, the need that justified keeping the dispute data is gone, so the exception no longer covers it. ## How a partial denial must be handled 11 CCR 7022(f) turns the exception into a procedure. A business that denies a request in whole or in part must: 1. Give the consumer a **detailed explanation** of the basis, including any conflicting law, CCPA exception, or facts showing impossibility or disproportionate effort; 2. **Delete** the personal information not subject to the exception; 3. **Not use** the retained information for any purpose other than the exception's; 4. **Instruct** service providers and contractors to do the same. It must also tell the consumer whether it complied and that it keeps a record of the request (7022(e)); `1798.105(c)(2)` allows a confidential record of deletion requests, for example so that the data is not sold again. ## Downstream and backups - **Service providers and contractors** cooperate and delete, and pass the request on to their own service providers and contractors (`1798.105(c)(3)`, 7022(c)). - **Third parties** that bought or received the data by sharing are notified; claiming impossibility needs a detailed, factual explanation (7022(b)(3)). - **Backups and archives** need not be purged at once: under 7022(d), deletion on archived or backup systems may wait until that system is restored to an active system or is next accessed or used for a sale, disclosure or commercial purpose. ## What interviewers listen for That the candidate treats exceptions as **data-scoped and purpose-bound**, deletes everything else now, restricts the use of what stays, propagates the request, and can explain a denial in terms the regulation accepts.

  • Can the app keep the user's email address because it might want to send her a win-back offer later?
    No. Civil Code 1798.105(d) excuses deletion only where keeping the data is reasonably necessary for a listed purpose. A future marketing campaign is not one; the internal-uses exception in (d)(7) needs uses reasonably aligned with the consumer's expectations, and someone who has asked to be deleted is unlikely to expect win-back marketing.
  • Must a service provider delete the data if the consumer asks it directly?
    Not when it holds the data in its role as a service provider or contractor to the business. Civil Code 1798.105(c)(3) says it need not comply with a request submitted directly to it in that role; it acts on the business's direction and must cooperate with the business's response.

saying these in an interview costs you the question

  • Refuses the whole deletion request because one exception covers some data
  • Keeps retained data and continues using it for marketing
  • Deletes only its own copy and never tells service providers or contractors
  • Says every backup must be purged immediately on each deletion request
  • Answers a partial denial with a bare 'we cannot delete your data'