Outbound Wiki

Article

Deleting Data: Reinforcing Data Subjects' Rights

jipel.law.nyu.edu

Open at publisher

Quoted on this wiki

Every place a page here uses this source, in the order the words come in it.

  1. Furthermore, if the data broker possesses data from people in the European Union, the data broker should comply with the General Data Protection Regulation (GDPR), which empowers data subjects to request the removal of their personal data. California Senate Bill 362, signed into law on October 10, 2023, required the California Privacy Protection Agency (CPPA) to establish an accessible deletion mechanism by January 1, 2026. Also known as the Delete Act, this bill applies to all California “data brokers,” which are businesses that knowingly collect and sell to third parties the personal information of a consumer with whom they do not have a direct relationship. The Delete Act mandates that the deletion mechanism must enable individuals to submit a single verifiable consumer request requiring all data brokers to delete any personal information related to the consumer, including data held by any associated service providers or contractors.

    In GDPR territorial scope

  2. The Delete Act significantly strengthens the accountability of data brokers by imposing increased penalties, and requiring CPPA to create a centralized mechanism that shifts the burden from consumers to data brokers. Starting August 1, 2026, consumers will not only be able to submit deletion requests through a single interface, but data brokers will also be required to access this deletion system at least once every 45 days to process requests. With stricter enforcement and penalties, data brokers must implement notification systems and monitoring protocols to ensure compliance. Data brokers often collect personal information indirectly, through third-party sources rather than from consumers. For consumers, ex post remedies are costly and burdensome due to an absence of contracts, evidentiary challenges and uncertainties, and limited recoverable damages. Moreover, consumers typically lack any direct legal relationship with the entities that hold or process their data, making it nearly impossible to submit individual deletion requests to each relevant party.

    In Lead source provenance

  3. California Senate Bill 362, signed into law on October 10, 2023, required the California Privacy Protection Agency (CPPA) to establish an accessible deletion mechanism by January 1, 2026. Also known as the Delete Act, this bill applies to all California “data brokers,” which are businesses that knowingly collect and sell to third parties the personal information of a consumer with whom they do not have a direct relationship. The Delete Act mandates that the deletion mechanism must enable individuals to submit a single verifiable consumer request requiring all data brokers to delete any personal information related to the consumer, including data held by any associated service providers or contractors. With stricter enforcement and penalties, data brokers must implement notification systems and monitoring protocols to ensure compliance. This act seeks to balance the risks and benefits that exist between consumers and data brokers. Data brokers often collect personal information indirectly, through third-party sources rather than from consumers. During data processing, consumers are exposed to potential risks, such as misuse, or leakage of their personal data, often not knowing when or how their data was collected. While consumers bear most of the potential risks, data brokers and associated service providers or contractors reap the economic benefits of processing this data.

    In Outbound data vendors

  4. However, in practice, many data brokers simply ignore opt-out requests and do not offer an opt-out option. California Senate Bill 362, signed into law on October 10, 2023, required the California Privacy Protection Agency (CPPA) to establish an accessible deletion mechanism by January 1, 2026. Also known as the Delete Act, this bill applies to all California “data brokers,” which are businesses that knowingly collect and sell to third parties the personal information of a consumer with whom they do not have a direct relationship. The Delete Act mandates that the deletion mechanism must enable individuals to submit a single verifiable consumer request requiring all data brokers to delete any personal information related to the consumer, including data held by any associated service providers or contractors.

    In Outbound data vendors

  5. For consumers, ex post remedies are costly and burdensome due to an absence of contracts, evidentiary challenges and uncertainties, and limited recoverable damages. Moreover, consumers typically lack any direct legal relationship with the entities that hold or process their data, making it nearly impossible to submit individual deletion requests to each relevant party. However, when personal data is resold or transferred to third parties, consumers often lack awareness of which entities hold their information. Chinese authorities have begun to play a more active role. On February 19, 2025, the Cyberspace Administration of China (CAC) announced penalties for 78 mobile apps that failed to properly cancel user accounts within the specified timeframe, requiring them to implement corrective measures. Subsequently, on March 28, 2025, the CAC in coordination with other agencies, launched a campaign titled “Special Actions for Personal Information Protection in 2025,” which emphasized the need for companies to implement reliable mechanisms for personal data deletion and account cancellation. While these initiatives demonstrate progress, governmental regulatory enforcement in China primarily remains focused on punishing unlawful conduct by data controllers rather than ensuring that individual deletion requests are fulfilled. As a result, litigation remains the primary channel through which consumers in China can enforce their deletion rights.

    In Prospecting transparency notices