A spreadsheet carries the same obligations as a platform. Deletion has to reach your vendors, and you now have to have decided how long you keep things.
The obligations attach to the data, not to the software. A spreadsheet of leads carries exactly the same duties as a six-figure platform: the same deletion rights, the same retention limit, the same requirement to have told people what you were doing when you collected it.
The difference is that the platform can usually show what happened and the spreadsheet cannot. That asymmetry is the actual argument for a system, and it is a better one than the feature comparison.
What follows is the short list of things that are now expected of any company holding US customer records, whatever it holds them in.
The right to delete looks simple until you read what it obliges you to do beyond your own file.
The right itself. A consumer “shall have the right to request that a business delete any personal information about the consumer which the business has collected from the consumer.”
And the three-part obligation it triggers. On a verifiable request, the business must “delete the consumer’s personal information from its records, notify any service providers or contractors to delete the consumer’s personal information from their records, and notify all third parties to whom the business has sold or shared the personal information to delete the consumer’s personal information.”
With one qualifier. “Unless this proves impossible or involves disproportionate effort.” That is a real limit, and it is not a general excuse.
Which is where the spreadsheet starts to hurt. To notify service providers you have to know which ones hold the record. If a lead flowed into an email tool, an ads platform, a scheduling tool and a shared inbox, deletion means four notifications, and nobody wrote down that it happened.
Two neighbouring rights come with the same problem. The right to know covers “the categories of personal information it has collected”, “the categories of sources”, and the “business or commercial purpose for collecting, selling, or sharing” it. The right to correct covers inaccurate information. Both require you to know where a record lives.
And a separate federal rule constrains one specific list. An address belonging to someone who opted out of your email may not be sold, leased, exchanged or transferred. Your suppression list is an obligation, not an asset, and it has to survive every migration you ever do.
You are now expected to have decided how long you keep things
This is the newest of these obligations and the one companies most often discover only when writing a notice.
The disclosure requirement. At or before collection, a business must state “the length of time the business intends to retain each category of personal information, including sensitive personal information, or if that is not possible, the criteria used to determine that period.”
With a substantive limit attached to it. A business “shall not retain a consumer’s personal information … for each disclosed purpose for which the personal information was collected for longer than is reasonably necessary for that disclosed purpose.”
And a proportionality rule over the whole activity. Collection, use, retention and sharing “shall be reasonably necessary and proportionate to achieve the purposes for which the personal information was collected or processed.”
The children’s rule converges on the same point. Information “may not be retained indefinitely”, and the operator “must establish, implement, and maintain a written data retention policy” setting out purposes, business need and “a timeframe for deletion”, published in the notice.
Which makes a written retention decision an artefact rather than an intention. Two separate regimes now expect one to exist and to be published.
And “until they ask us to delete it” is not an answer. It expresses no period. A workable answer looks like a rule: three years from last meaningful contact, then deletion, with an exception for records under a contractual or legal hold.
One practical benefit worth noting. A retention rule shrinks every other obligation. Fewer records means fewer deletion notifications, less exposure in a breach, and a smaller answer to a right-to-know request.
Before any of this is actionable, two definitional points decide how much of your data is in scope.
A work email address is personal information. The definition used for the mandatory privacy policy expressly includes “an e-mail address”, alongside a name, a physical address, a telephone number, and “any other identifier that permits the physical or online contacting of a specific individual.” B2B does not remove data from scope.
And your records live in more places than your list. The shared inbox, the calendar invitations, the notes in a scheduling tool, the exported spreadsheet somebody kept on a laptop, the contact sync in a phone. Each is a record you are responsible for and none of them is in the tool you think of as the database.
Which is why the map matters more than the system. A company that knows its data lives in six places can honour a deletion request. A company with an expensive platform and three shadow copies cannot. The map is also what falls between suppliers, since the form belongs to whoever built the site and the tags to whoever runs the ads, which is one argument for keeping the site, the campaigns and the measurement under a single owner.
One test that finds the shadow copies fast. Ask what would have to be searched if somebody asked what you hold about them. The honest answer usually names two or three places nobody had counted.
You have to identify the person making a request, and you can be penalised for asking too hard. Both failures have been enforced.
Asking too much is a violation. A 2025 decision fined a company $632,500, in part over an excessive verification requirement imposed before consumers could exercise “the right to opt-out of sale or sharing”, along with an asymmetric interface.
Because an opt-out is not an access request. Stopping the sharing of a browser’s data does not require you to establish who the person is. Demanding an account login and a document scan before honouring it inverts the burden.
Failing to process is also a violation. Another 2025 decision fined a company $345,178 for “a failure to process consumer requests to opt out of the sale or sharing of personal information for 40 days”, caused by a misconfigured privacy portal.
And a tool does not carry the responsibility for you. The enforcement division’s summary: “Businesses should scrutinize their privacy management solutions to ensure they comply with the law and work as intended, because the buck stops with the businesses that use them. Using a consent management platform doesn’t get you off the hook for compliance.”
Which suggests a simple internal split. Verify identity for requests that reveal or change data: access, correction, deletion. Do not verify for requests that only reduce processing: opt-outs and unsubscribes. Just honour those.
What this means before you buy anything
None of the above requires a platform. It requires four artefacts, and a spreadsheet company can hold all four.
A map of where records go. One page listing every tool that receives customer data: email, ads, scheduling, support, analytics, invoicing. This is what makes deletion notifications possible and it takes an hour to write.
A retention rule. One sentence with a number and an exception, published in your notice, applied on a recurring date.
A request log. Date received, what was asked, what you did, which vendors you notified, date closed. Five columns. This is the artefact that a platform would give you free and that you otherwise have to keep by hand.
A suppression list that outlives your tools. Held outside any single vendor, carried into every migration, never traded.
And one rule about what you collect in the first place. Every field on your form becomes a category you must disclose, retain against a period, produce on request and delete on demand. A form that collects a phone number nobody will call has created four obligations to support one unused column.
Which is the honest argument for a system, when the time comes. Not that it does marketing. That it can answer, on a Tuesday, where a record went and what you did about it.
Write the destination map first. One page, every tool that has ever received a customer record. It costs an hour and it is the prerequisite for every other obligation on this list.
Then decide a retention period out loud, put it in your notice at collection, and set a recurring date to apply it. The decision is more valuable than the number, and any defensible number beats none.
Split your request handling in two: verify identity where a request reveals or changes data, and do not verify where it only stops processing. Both halves of that have been enforced, in opposite directions.
And before adding a field to a form, ask what it obliges you to do for the next three years. Most B2B forms collect two or three fields nobody uses, and each one is a standing commitment.
Yes. The obligations attach to the personal information, not to the software holding it. A shared spreadsheet and an enterprise platform carry the same duties, and only one of them has an audit trail.
Does deleting a record mean deleting it from my tools too?
Yes. The statute requires notifying service providers and contractors to delete it, and notifying all third parties to whom you sold or shared it, unless that proves impossible or involves disproportionate effort.
How long can I keep a lead that never converted?
As long as is reasonably necessary for the purpose you disclosed, and no longer. You also have to have stated that period, or the criteria producing it, at the point you collected the data.
Can I ask someone to verify their identity before opting out?
Be careful. A regulator fined a company $632,500 in part over an excessive verification requirement imposed before consumers could exercise the right to opt out.