"Delete" is a right, not a guarantee — and both GDPR and CCPA build real exceptions into it.
Sometimes, yes, and it's legal. Both the EU/UK's GDPR right to erasure (Article 17) and California's CCPA deletion right come with specific, named exceptions built into the law itself — not loopholes companies invented. Common legitimate reasons include an active legal obligation (tax records, for example), fraud and security investigations, defending against a legal claim, and completing a transaction you already started. Deleting your account triggers a real right, but it isn't an instruction that erases every trace of you everywhere, instantly.
Article 17(3) lists when a company can refuse or limit an erasure request, even when you've asked directly:
A company relying on one of these has to tell you which one applies — a vague "we can't delete that" isn't a sufficient answer under the law.
California's law lists a similar, separately-worded set of exceptions, including data a business needs to:
| What happens | Is this normal? |
|---|---|
| Your profile disappears immediately, but billing/transaction records are kept for a set retention period | Yes — this is the legal-obligation exception at work, typically tied to tax or accounting law retention periods |
| Your data is removed from active systems but persists briefly in backups until they're overwritten | Yes — GDPR guidance generally accepts this as long as backups aren't actively used and are purged on a normal cycle |
| The company simply says no with no explanation of which exception applies | No — this isn't a valid response under either law |
| Data is kept indefinitely "in case we need it later" with no specific legal basis named | No — this doesn't fit any of the recognized exceptions |
Use Kibbo's Privacy & Data tools to draft a formal erasure request citing the exact legal right that applies to you.
Explore Privacy & Data tools →