The obligations attach to the data, not to the software. A spreadsheet of leads carries exactly the same duties as a six-figure platform: the same deletion rights, the same retention limit, the same requirement to have told people what you were doing when you collected it.

The difference is that the platform can usually show what happened and the spreadsheet cannot. That asymmetry is the actual argument for a system, and it is a better one than the feature comparison.

What follows is the short list of things that are now expected of any company holding US customer records, whatever it holds them in.

Locations in which customer records accumulate in a company without a central systemThe locations in which customer records accumulate within a company that has not adopted a central customer relationship management system, each of which constitutes a place a deletion request must reach and a place a right to know request must be answered from. The definition of personal information triggering these obligations is broad, the definition applied to the mandatory website privacy policy expressly including a first and last name, a home or other physical address, an email address, a telephone number, a social security number and any other identifier permitting the physical or online contacting of a specific individual, so that a work email address is personal information and business to business collection is not outside scope. Records accumulate first in the nominal list, being the spreadsheet or contact tool the company regards as its database. They accumulate second in the shared inbox, where enquiries, replies and attachments persist indefinitely. Third in calendar invitations, which retain names and email addresses of everybody invited. Fourth in scheduling tools, which store booking records with contact details and notes. Fifth in exported spreadsheets kept locally by individuals, which are outside every system and every backup policy. Sixth in phone contact synchronisation, where business contacts are replicated to personal devices. Seventh in analytics, advertising and email platforms which received the record through integrations. The practical consequence is that the ability to honour a deletion request depends on knowing this list rather than on the sophistication of any single system, so a company aware that its data occupies six locations can comply while a company operating an expensive platform alongside three unrecorded copies cannot. A diagnostic question identifies the unrecorded copies quickly, namely asking what would actually have to be searched if a person requested everything held about them, an exercise which typically surfaces two or three locations nobody had counted.Where the records actually areThe one you think ofThe spreadsheet or contact toolyou call the database.One location. The one that getsupdated when somebody asks.The ones you forgetThe shared inboxCalendar invitationsThe scheduling toolAn export on somebody’s laptopContact sync on a phoneAnd a work email address is personal informationThe definition includes “an e-mail address” and “any other identifier that permits … contacting of a specific individual.”The test that finds the shadow copies: what would you actually have to search if somebody asked what you hold?The honest answer usually names two or three places nobody had counted.
The list is longer than the database. Every one of these is a place a deletion request has to reach. Source : Method, over the deletion and right-to-know provisions (2026)

Deletion is not a row you remove

The right to delete looks simple until you read what it obliges you to do beyond your own file.

The right itself. A consumer “shall have the right to request that a business delete any personal information about the consumer which the business has collected from the consumer.”

And the three-part obligation it triggers. On a verifiable request, the business must “delete the consumer’s personal information from its records, notify any service providers or contractors to delete the consumer’s personal information from their records, and notify all third parties to whom the business has sold or shared the personal information to delete the consumer’s personal information.”

With one qualifier. “Unless this proves impossible or involves disproportionate effort.” That is a real limit, and it is not a general excuse.

Which is where the spreadsheet starts to hurt. To notify service providers you have to know which ones hold the record. If a lead flowed into an email tool, an ads platform, a scheduling tool and a shared inbox, deletion means four notifications, and nobody wrote down that it happened.

Two neighbouring rights come with the same problem. The right to know covers “the categories of personal information it has collected”, “the categories of sources”, and the “business or commercial purpose for collecting, selling, or sharing” it. The right to correct covers inaccurate information. Both require you to know where a record lives.

And a separate federal rule constrains one specific list. An address belonging to someone who opted out of your email may not be sold, leased, exchanged or transferred. Your suppression list is an obligation, not an asset, and it has to survive every migration you ever do.

The three obligations triggered by a single customer deletion requestThe obligations triggered by a single verifiable consumer deletion request, only one of which concerns the business’s own records. The first obligation is to delete the consumer’s personal information from the business’s own records. The second is to notify any service providers or contractors holding that information to delete it from their records. The third is to notify all third parties to whom the business has sold or shared the personal information to delete it from theirs. All three are subject to a single qualifier, namely unless doing so proves impossible or involves disproportionate effort, which operates as a genuine limit rather than as a general exemption. The practical difficulty this creates for a company without a central system is that discharging the second and third obligations requires knowing which downstream systems received the record, so that a lead which flowed into an email marketing tool, an advertising platform, a scheduling tool and a shared inbox generates four separate notification duties, none of which will have been recorded as performed. Two adjacent rights create the same dependency on knowing where records live. The right to know obliges the business to disclose the categories of personal information collected about the consumer, the categories of sources from which it was collected, and the business or commercial purpose for collecting, selling or sharing it. The right to correct obliges the business to correct inaccurate personal information it maintains, taking into account the nature of the information and the purposes of processing. A separate federal obligation constrains one particular list, since federal commercial email law makes it unlawful to sell, lease, exchange or otherwise transfer the electronic mail address of a person who has submitted an opt out request, which means a suppression list constitutes a standing obligation that must survive every system migration rather than a marketing asset.One request, three obligations1. Your own records”Delete the consumer’s personalinformation from its records.”The easy one.2. Service providers”Notify any service providers orcontractors to delete” it too.Requires knowing who holds it.3. Third parties”Notify all third parties to whomthe business has sold or shared” it.Requires a record of sharing.All three qualified by one clause: “unless this proves impossible or involves disproportionate effort.” A real limit,not a general excuse, and not available to a company that simply never kept track.Which is the real argument for a systemNot features. The ability to answer “where did this record go, and did we tell them” without reconstructing it.And one list you may never tradeAddresses that opted out may not be sold, leased, exchanged or transferred. Suppression is a duty, not an asset.
Three obligations, only one of which is in your own file. The others require knowing where the record went. Source : California Civil Code 1798.105 and 1798.110 (2026)

You are now expected to have decided how long you keep things

This is the newest of these obligations and the one companies most often discover only when writing a notice.

The disclosure requirement. At or before collection, a business must state “the length of time the business intends to retain each category of personal information, including sensitive personal information, or if that is not possible, the criteria used to determine that period.”

With a substantive limit attached to it. A business “shall not retain a consumer’s personal information … for each disclosed purpose for which the personal information was collected for longer than is reasonably necessary for that disclosed purpose.”

And a proportionality rule over the whole activity. Collection, use, retention and sharing “shall be reasonably necessary and proportionate to achieve the purposes for which the personal information was collected or processed.”

The children’s rule converges on the same point. Information “may not be retained indefinitely”, and the operator “must establish, implement, and maintain a written data retention policy” setting out purposes, business need and “a timeframe for deletion”, published in the notice.

Which makes a written retention decision an artefact rather than an intention. Two separate regimes now expect one to exist and to be published.

And “until they ask us to delete it” is not an answer. It expresses no period. A workable answer looks like a rule: three years from last meaningful contact, then deletion, with an exception for records under a contractual or legal hold.

One practical benefit worth noting. A retention rule shrinks every other obligation. Fewer records means fewer deletion notifications, less exposure in a breach, and a smaller answer to a right-to-know request.

Data retention obligations across two regimes and the form a compliant retention answer takesThe data retention obligations imposed by two separate United States privacy regimes and the form a compliant answer takes. Under California consumer privacy law, a business must inform consumers at or before the point of collection of the length of time it intends to retain each category of personal information, including sensitive personal information, or where that is not possible the criteria used to determine that period. A substantive limit accompanies the disclosure requirement, providing that a business shall not retain personal information for each disclosed purpose for which it was collected for longer than is reasonably necessary for that disclosed purpose. A proportionality rule applies over the whole activity, requiring that a business’s collection, use, retention and sharing of personal information be reasonably necessary and proportionate to achieve the purposes for which it was collected or processed, or another disclosed and compatible purpose. Under the amended children’s online privacy rule, personal information collected online from a child may be retained only for as long as reasonably necessary to fulfil the specific purposes for which it was collected, may not be retained indefinitely, must be deleted using reasonable measures once no longer reasonably necessary, and the operator must at minimum establish, implement and maintain a written data retention policy setting out the purposes of collection, the business need for retention and a timeframe for deletion, which must be provided in the notice on the website or service. The consequence is that a written and published retention decision has become an expected artefact rather than an internal intention. A statement that information is kept until the person asks for its deletion expresses no period and does not satisfy either regime, whereas a rule such as retention for three years from last meaningful contact followed by deletion, subject to an exception for records under contractual or legal hold, does. A retention rule additionally reduces every other obligation, since fewer retained records produce fewer deletion notifications, smaller breach exposure and a shorter response to a right to know request.Two regimes, the same expectationDisclose it”The length of time the business intends toretain each category … or if that is notpossible, the criteria used to determinethat period.”And observe itNo retention “longer than is reasonablynecessary for that disclosed purpose.”And for children’s data: “may not beretained indefinitely.”Not an answer”Until you ask us to delete it.”It expresses no period at all.An answer”Three years from last meaningful contact,then deleted, except records under acontractual or legal hold.”And the reason to want one beyond complianceA retention rule shrinks every other obligation: fewer deletion notifications, less breach exposure, and a shorteranswer when somebody asks what you hold about them.
Both regimes want a period or a rule producing one. An intention to delete eventually is not either. Source : California Civil Code 1798.100(a)(3) and (c), and 16 CFR 312.10 (2025)

What counts as a record, and where it is

Before any of this is actionable, two definitional points decide how much of your data is in scope.

A work email address is personal information. The definition used for the mandatory privacy policy expressly includes “an e-mail address”, alongside a name, a physical address, a telephone number, and “any other identifier that permits the physical or online contacting of a specific individual.” B2B does not remove data from scope.

And your records live in more places than your list. The shared inbox, the calendar invitations, the notes in a scheduling tool, the exported spreadsheet somebody kept on a laptop, the contact sync in a phone. Each is a record you are responsible for and none of them is in the tool you think of as the database.

Which is why the map matters more than the system. A company that knows its data lives in six places can honour a deletion request. A company with an expensive platform and three shadow copies cannot. The map is also what falls between suppliers, since the form belongs to whoever built the site and the tags to whoever runs the ads, which is one argument for keeping the site, the campaigns and the measurement under a single owner.

One test that finds the shadow copies fast. Ask what would have to be searched if somebody asked what you hold about them. The honest answer usually names two or three places nobody had counted.

When identity verification is required for a privacy request and when demanding it creates liabilityThe division between privacy requests for which identity verification is appropriate and those for which demanding verification has itself been treated as a violation, both directions having been the subject of enforcement decisions in 2025. Requests that reveal or change personal data, namely access requests seeking disclosure of what a business holds, correction requests seeking amendment of inaccurate information, and deletion requests seeking removal of records, justify verification of the requester’s identity, since honouring an unverified request of this kind would itself disclose or destroy another person’s data. Requests that only reduce processing, namely opting out of the sale or sharing of personal information and unsubscribing from commercial messages, do not require the business to establish who the requester is, since stopping the sharing of a browser’s data does not turn on the identity of the person operating that browser, and demanding an account login or identity documentation before honouring such a request inverts the burden. Enforcement has run in both directions. One decision in March 2025 imposed a fine of six hundred and thirty two thousand five hundred dollars in part over an excessive verification requirement imposed before consumers could exercise the right to opt out of sale or sharing, together with an asymmetric interface and deficient advertising technology contracts. A second decision in May 2025 imposed a fine of three hundred and forty five thousand one hundred and seventy eight dollars where the business failed to oversee and properly configure the technical infrastructure of its privacy portal, resulting in a failure to process consumer opt out requests for forty days, and where identity verification was imposed before an opt out. The regulator’s enforcement division summarised the position by stating that businesses should scrutinise their privacy management solutions to ensure they comply with the law and work as intended, because responsibility rests with the businesses that use them, and that using a consent management platform does not relieve a business of compliance.Verify here. Do not verify there.Verify: requests that reveal or change dataAccess: what do you hold about meCorrection: this information is wrongDeletion: remove my recordsHonouring these unverified would expose or destroy someone else’s data.Do not verify: requests that only stop thingsOpt out of sale or sharingUnsubscribe from emailDemanding a login and a document scan here has been fined.Asking too much$632,500, in part over excessive verificationbefore an opt-out.Doing too little$345,178, for failing to process opt-outsfor 40 days.And the sentence to put above whichever tool you use”Businesses should scrutinize their privacy management solutions to ensure they comply with the law and work asintended, because the buck stops with the businesses that use them.”
Requests that reveal or change data need identity. Requests that only stop processing do not, and demanding it has been fined. Source : California Privacy Protection Agency enforcement decisions, 2025 (2025)

Verification is a trap in both directions

You have to identify the person making a request, and you can be penalised for asking too hard. Both failures have been enforced.

Asking too much is a violation. A 2025 decision fined a company $632,500, in part over an excessive verification requirement imposed before consumers could exercise “the right to opt-out of sale or sharing”, along with an asymmetric interface.

Because an opt-out is not an access request. Stopping the sharing of a browser’s data does not require you to establish who the person is. Demanding an account login and a document scan before honouring it inverts the burden.

Failing to process is also a violation. Another 2025 decision fined a company $345,178 for “a failure to process consumer requests to opt out of the sale or sharing of personal information for 40 days”, caused by a misconfigured privacy portal.

And a tool does not carry the responsibility for you. The enforcement division’s summary: “Businesses should scrutinize their privacy management solutions to ensure they comply with the law and work as intended, because the buck stops with the businesses that use them. Using a consent management platform doesn’t get you off the hook for compliance.”

Which suggests a simple internal split. Verify identity for requests that reveal or change data: access, correction, deletion. Do not verify for requests that only reduce processing: opt-outs and unsubscribes. Just honour those.

What this means before you buy anything

None of the above requires a platform. It requires four artefacts, and a spreadsheet company can hold all four.

A map of where records go. One page listing every tool that receives customer data: email, ads, scheduling, support, analytics, invoicing. This is what makes deletion notifications possible and it takes an hour to write.

A retention rule. One sentence with a number and an exception, published in your notice, applied on a recurring date.

A request log. Date received, what was asked, what you did, which vendors you notified, date closed. Five columns. This is the artefact that a platform would give you free and that you otherwise have to keep by hand.

A suppression list that outlives your tools. Held outside any single vendor, carried into every migration, never traded.

And one rule about what you collect in the first place. Every field on your form becomes a category you must disclose, retain against a period, produce on request and delete on demand. A form that collects a phone number nobody will call has created four obligations to support one unused column.

Which is the honest argument for a system, when the time comes. Not that it does marketing. That it can answer, on a Tuesday, where a record went and what you did about it.

Four documentary artefacts satisfying customer data obligations without a dedicated platformFour documentary artefacts that allow a company without a customer relationship management platform to satisfy its obligations concerning customer records, each of which can be maintained in a spreadsheet. The first is a map of destinations, being a single page listing every tool that receives customer data, including email marketing, advertising platforms, scheduling, customer support, analytics and invoicing, which is the prerequisite for discharging the obligation to notify service providers and third parties following a deletion request and which takes approximately one hour to compile. The second is a retention rule, being one sentence containing a period and an exception, published in the notice at collection and applied on a recurring date, which satisfies both the disclosure obligation and the substantive limit on retaining information longer than reasonably necessary. The third is a request log containing five columns recording the date a request was received, what was requested, what action was taken, which vendors were notified and the date the matter was closed, this being the artefact a platform would supply automatically and which must otherwise be maintained manually. The fourth is a suppression list held outside any single vendor system, carried through every migration and never sold, leased, exchanged or transferred, since federal commercial email law prohibits transferring the address of a person who has opted out. A governing principle applies upstream of all four, namely that every field collected on a form becomes a category that must be disclosed at collection, retained against a stated period, produced upon a right to know request and deleted upon a deletion request, so that collecting a telephone number nobody will call creates four ongoing obligations in support of one unused column. The resulting argument for eventually adopting a system is not its marketing functionality but its ability to answer, without reconstruction, where a given record was sent and what was done about it.Four artefacts, no purchase required1. A map of destinationsEvery tool that receives customer data: email,ads, scheduling, support, analytics, invoicing.2. A retention ruleOne sentence with a number and an exception,published, and applied on a recurring date.3. A request logReceived, asked, done, vendors notified, closed.Five columns.4. A suppression listHeld outside any one vendor, carried throughevery migration, never traded.And the rule that sits upstream of all fourEvery form field becomes a category to disclose, retain, produce and delete. A phone number nobody calls is fourobligations in support of one unused column.The argument for a system is not features. It is answering, on a Tuesday, where a record went and what you did.
A map, a rule, a log and a list. All four fit in a spreadsheet, and all four are what an audit would ask for. Source : Method, over the California deletion, retention and opt-out provisions and enforcement decisions (2026)

What to do with this

Write the destination map first. One page, every tool that has ever received a customer record. It costs an hour and it is the prerequisite for every other obligation on this list.

Then decide a retention period out loud, put it in your notice at collection, and set a recurring date to apply it. The decision is more valuable than the number, and any defensible number beats none.

Split your request handling in two: verify identity where a request reveals or changes data, and do not verify where it only stops processing. Both halves of that have been enforced, in opposite directions.

And before adding a field to a form, ask what it obliges you to do for the next three years. Most B2B forms collect two or three fields nobody uses, and each one is a standing commitment.

The adjacent pieces are consent on lead capture forms and what US law requires on a B2B website.