Layer27 is now part of Katalyst.

Read the announcement
Layer27, a Katalyst Company

Blog

The Right to Be Forgotten: What U.S. Businesses Must Know About Data Deletion Obligations in 2026

State privacy laws are creating real legal obligations to delete customer data on request. Here's what your business must do to comply — before regulators come knocking.

June 15, 2026Layer27
Data SecurityComplianceBusiness StrategyIT Strategy
The Right to Be Forgotten: What U.S. Businesses Must Know About Data Deletion Obligations in 2026

When a customer emails your business and says, "Delete everything you have on me," what actually happens next?

For most organizations, the honest answer is uncomfortable: someone forwards the email to IT, IT isn't sure what systems to check, legal hasn't written a policy, and nobody is confident the data ever gets fully removed. A week later, the email is buried, and life moves on.

That response — or lack of one — is becoming a serious legal liability.

The "right to be forgotten," or more precisely the right to deletion, is no longer a European concept that American businesses can safely ignore. A growing patchwork of U.S. state privacy laws now grants consumers the explicit right to demand that businesses erase their personal information. And as of 2026, those laws cover a significant portion of the U.S. population — with enforcement actions and fines to match.

This post will walk you through what the right to deletion actually requires, which laws apply to your business, the technical realities of honoring deletion requests, and what a realistic compliance program looks like in 2026.


Why "Right to Deletion" Is Having Its Moment in 2026

The concept originates with the European Union's General Data Protection Regulation (GDPR), which has included robust erasure rights since 2018. But U.S. privacy law has been catching up quickly — and the pace accelerated dramatically in 2024 and 2025.

As of mid-2026, 19 states have enacted comprehensive consumer privacy laws, most of which include a right to deletion. California, Colorado, Connecticut, Virginia, Texas, Florida, Oregon, Montana, and others all have laws on the books. Several more are in active legislative sessions. The American Privacy Rights Act (APRA), a proposed federal baseline privacy law, stalled in Congress but has renewed momentum heading into late 2026 — and it includes deletion rights with significant teeth.

Enforcement is no longer theoretical:

  • The California Privacy Protection Agency (CPPA) has issued over $20 million in fines since 2023, with several cases specifically involving failures to honor deletion requests.
  • The Texas Data Privacy and Security Act (TDPSA), which took effect in July 2024, has already seen its first enforcement actions from the state Attorney General.
  • The FTC has increasingly framed data retention and deletion failures as unfair or deceptive trade practices, using its Section 5 authority to pursue companies that retain data longer than stated in their privacy policies.

The days of treating deletion requests as a nuisance are over. They are now a compliance obligation with real consequences.


What "Right to Deletion" Actually Requires

Before you can build a compliant process, you need to understand what these laws actually require — because the details vary more than most people realize.

The Core Obligation

At its simplest, the right to deletion allows a consumer to request that a business delete their personal information. The business must:

  1. Confirm whether it holds the consumer's data
  2. Delete the data from its own systems
  3. Instruct service providers and contractors to delete the same data
  4. Respond to the consumer within a defined timeframe (typically 45–60 days, with extension options)

What Data Must Be Deleted?

This is where it gets complicated. "Personal information" under most state laws is defined broadly. It typically includes:

  • Name, address, email, phone number
  • Purchase history and browsing behavior
  • Geolocation data
  • Biometric identifiers
  • IP addresses and device identifiers
  • Inferences drawn from any of the above

That last one catches many businesses off guard. If your CRM has a field that says "likely high-income based on zip code and purchase history," that inference is personal information and may be subject to deletion.

Exceptions That Matter

No deletion right is absolute. Common exceptions include:

  • Data needed to complete a transaction the consumer initiated
  • Data required for legal obligations (e.g., tax records, regulatory recordkeeping)
  • Data necessary to detect and prevent fraud or security incidents
  • Data protected by freedom of expression or public interest considerations
  • Data retained under contractual obligations with the consumer

The challenge is that most businesses can't articulate which data falls under which exception — because they don't have a clear map of what they hold or why they're holding it.


The Technical Problem Nobody Wants to Talk About

Here's the part that keeps IT professionals up at night: actually deleting data is hard.

Modern businesses don't store data in one place. A single customer record might live in:

  • A CRM (Salesforce, HubSpot, or similar)
  • A marketing automation platform (Mailchimp, Klaviyo, Marketo)
  • An e-commerce platform (Shopify, WooCommerce)
  • An ERP or accounting system
  • A customer support ticketing system (Zendesk, Freshdesk)
  • Email archives
  • Analytics platforms (Google Analytics, Mixpanel)
  • Data warehouses or business intelligence tools
  • Cloud storage (SharePoint, Google Drive, Dropbox)
  • Backups

That last one is the real complication. When a customer requests deletion and you remove their record from your CRM, their data still exists in last night's backup. And the backup from last week. And the quarterly archive you stored offsite. Under most state laws, you're still required to delete or quarantine that data.

What "Deletion" Actually Means Technically

True deletion is not the same as deactivating an account or flagging a record as "inactive." Compliant deletion typically means:

  • Logical deletion: Removing the record and ensuring it cannot be queried or surfaced in normal operations
  • Cryptographic erasure: Encrypting the data with a key that is then destroyed, rendering it unrecoverable — particularly useful for backups
  • Physical deletion: Overwriting or destroying storage media, applicable to decommissioned hardware

For most businesses, cryptographic erasure is the most practical approach for handling personal data in backup environments. This is one reason why well-architected Backup-as-a-Service (BaaS) solutions — like Layer27's — are increasingly designed with privacy compliance in mind, including the ability to tag, isolate, and manage data at the record level rather than treating every backup as a monolithic blob.


Why Your Current Processes Probably Won't Cut It

Let's be direct: most mid-market businesses are not ready for this.

The Data Mapping Problem

You cannot delete data you can't find. Before you can honor deletion requests, you need a data inventory — a documented map of what personal information you collect, where it lives, why you hold it, who has access to it, and how long you retain it.

Most organizations don't have this. According to the 2025 IAPP Privacy Tech Vendor Report, fewer than 40% of businesses subject to U.S. state privacy laws have completed a comprehensive data mapping exercise. Without it, deletion requests become a manual scramble through dozens of systems with no guarantee of completeness.

The Vendor Chain Problem

Your deletion obligation doesn't stop at your own systems. Under California's CPPA regulations, for example, you must pass deletion requests downstream to every service provider, contractor, and third party that received the consumer's data from you. That means your email marketing platform, your analytics vendor, your CDP, your data broker relationships — all of them.

Do you know every vendor that has received customer personal information? Do you have contractual language requiring them to honor deletion requests? If you answered "not really" to either question, you have a compliance gap.

The Verification Problem

Privacy laws require you to verify that a deletion request comes from the actual consumer — or their authorized agent — before acting on it. But verification processes have their own privacy risks. Asking for too much identifying information to verify identity can itself be a privacy violation.

The CPPA has issued specific guidance on this tension: your verification process must be reasonably calibrated to the sensitivity of the request and must not require consumers to create an account or provide more information than necessary.


Building a Deletion Rights Compliance Program

Here's a practical framework for getting your organization to a defensible compliance posture.

Step 1: Complete a Data Inventory and Classification Exercise

Map every data flow in your organization. Know what personal data you collect, where it goes, how long you keep it, and on what legal basis you hold it. This exercise is foundational — you cannot complete steps 2 through 5 without it.

Layer27's Compliance practice helps organizations build and maintain these data inventories as part of broader privacy program development. It's detailed, unglamorous work, but it's the bedrock of everything else.

Step 2: Build a Deletion Request Intake Process

You need a designated channel for deletion requests — typically a privacy request form on your website, a dedicated email address (privacy@yourdomain.com), or both. Your intake process should:

  • Log every request with a timestamp
  • Send an automated acknowledgment to the requester
  • Trigger an internal workflow with a defined owner and deadline
  • Track the request through to completion

This is a process and technology problem. Most organizations need to implement purpose-built privacy request management tools (OneTrust, TrustArc, and Osano are common options) rather than managing this via email and spreadsheets.

Step 3: Establish Identity Verification Standards

Work with legal counsel to define appropriate verification standards for your industry and data sensitivity. Document the process so it's applied consistently. Critically, make sure your verification process doesn't create new privacy violations in the process of confirming old ones.

Step 4: Execute Deletion Across All Systems — Including Backups

This is the hardest technical step. Your IT team (or a partner like Layer27) needs to build a deletion execution checklist that covers every system in your data map. For primary systems, you'll automate wherever possible. For backups, you'll likely implement cryptographic erasure or establish documented processes for quarantining data that has been requested for deletion from active systems.

If your backup architecture doesn't support this today, that's a conversation worth having with your IT partner. Layer27's Backup-as-a-Service (BaaS) and Disaster Recovery-as-a-Service (DRaaS) platforms can be configured to support privacy-compliant data lifecycle management — a capability that's quickly moving from "nice to have" to "table stakes" for compliance-minded organizations.

Step 5: Issue Downstream Deletion Requests to Your Vendors

Review your vendor contracts to confirm they include data processing agreements (DPAs) with deletion obligations. For vendors that don't have formal DPAs in place, get them signed. Then build a process for issuing deletion requests to each vendor within the required response window.

If you manage SaaS platforms across your organization — and most businesses do — Layer27's Co-Managed IT practice can help inventory your vendor relationships and ensure contracts are structured to support privacy compliance.

Step 6: Document Everything

When a regulatory inquiry arrives, documentation is your defense. Maintain records of every deletion request received, every action taken, every vendor notified, and every exception applied with the legal justification for it. Regulators don't just want to know that you completed a deletion — they want to know that you have a repeatable, auditable process for doing so.


What About Employee Data?

One area that catches many organizations flat-footed: employee personal data is also subject to deletion rights in some states.

California's CPRA, for example, extended meaningful privacy rights to employees — including, in some circumstances, deletion rights for certain categories of employment-related data. This is an evolving area of law, and the exceptions for employment data are broader than for consumer data. But the trend is clear: workforce data is increasingly in scope, and organizations need HR, legal, and IT working together to address it.


The Business Case Beyond Compliance

If the regulatory risk doesn't motivate action on its own, consider the business case:

Customer trust is a competitive differentiator. A 2025 Cisco Consumer Privacy Survey found that 81% of consumers said they would stop purchasing from a company that misused their data. Demonstrating that you have real deletion capabilities — not just a checkbox — is a meaningful trust signal.

Data minimization reduces your breach exposure. Every record you delete is one fewer record an attacker can steal. There is a direct relationship between disciplined data lifecycle management and reduced breach severity. This is a principle we explored in depth in our post on data minimization as a security strategy, and deletion rights enforcement is the natural extension of that discipline.

Litigation exposure decreases. Many state privacy laws include private rights of action — meaning individual consumers can sue you, not just regulators. California's CPRA allows consumers to sue for data breaches involving certain categories of sensitive personal information. Keeping data longer than necessary, and in breach-prone systems, multiplies that exposure.


What Happens If You Don't Comply?

The penalty structures vary by state, but the numbers are significant:

  • California: Up to $2,500 per unintentional violation, $7,500 per intentional violation — and with thousands of consumers potentially affected by a single policy failure, these fines compound rapidly
  • Texas: Up to $7,500 per violation per day
  • Florida: Up to $50,000 for violations involving sensitive personal data
  • FTC enforcement: Unlimited in theory, with the FTC able to seek consumer redress and disgorgement of profits

Beyond fines, there is the reputational damage of a public enforcement action, the cost of regulatory investigation response, and the litigation risk in states with private rights of action.


Getting Started Without Getting Overwhelmed

If this feels like a lot, that's because it is. But you don't have to build a comprehensive privacy compliance program overnight.

The practical starting point is a gap assessment: understand where you stand today against the laws that apply to your business, identify your three to five highest-risk gaps, and build a prioritized roadmap. Layer27's Compliance team works with organizations across industries to do exactly this — translating legal requirements into actionable IT and operational changes.

From there, investments in the right infrastructure — purpose-built backup architectures, well-governed cloud environments through Infrastructure Pro or Cloud Services, and security monitoring through our 24x7 SOC — create the technical foundation for sustainable compliance.

And don't overlook the human element. Your customer service team, sales team, and HR staff are all likely to encounter deletion requests before your legal or IT teams do. Security Awareness Training extended to privacy topics ensures that employees know how to recognize a deletion request and route it correctly — rather than forwarding it into a black hole.


The Bottom Line

The right to be forgotten is no longer a concept reserved for EU regulators and multinational enterprises. It's a real, enforceable obligation affecting U.S. businesses of every size — and the complexity of honoring it properly should not be underestimated.

The businesses that will navigate this well are the ones that treat deletion rights as an operational process, not a one-time legal exercise. That means data mapping, technical infrastructure, vendor governance, employee training, and documented procedures working together as a system.

The businesses that ignore it are building a liability that will eventually find them.


Ready to Assess Your Data Deletion Readiness?

Layer27 helps U.S. businesses build privacy compliance programs that are technically sound, legally defensible, and operationally sustainable. Whether you need a gap assessment against applicable state privacy laws, help designing a deletion request workflow, or the infrastructure to support data lifecycle management at scale, we're ready to help.

Contact Layer27 today to schedule a privacy compliance assessment.

Ready to transform your IT?

Get a free consultation and discover how Layer27 can help your business thrive with proactive IT management, advanced cybersecurity, and scalable cloud solutions.