How to delete personal data for GDPR & CCPA compliance


 

Deleting a customer’s personal data under GDPR or CCPA means erasing it everywhere it’s stored — not just the primary database, but replicas, backups, caches, search indexes, logs, and every third-party tool that touched it — usually within 30 to 45 days of the request.

This guide covers what a genuine deletion request requires, what GDPR (Article 17) and CCPA (§1798.105) actually oblige you to do, where copies of personal data typically hide, and why backups and derived data (like AI/ML models trained on that data) make full erasure harder than a simple DELETE statement.

What counts as a