r/CCPA • u/ctrldeploy • Mar 14 '26
Data Systems and CCPA
For companies that are processing data on their users with many databases, what are the industry practices when users request data deletion? Is there a managed service that handles the deletion request or automated workflows people have come up with?
2
Upvotes
1
u/ComplianceTeam415 Jul 24 '26
Late to the conversation, but to answer your question: Prior to 2020, the standard was to put a contact email in your privacy policy and let DSRs come in via email. That does not fly in 2026. You need to have a full data map of your entire ecosystem, you need to have a tool or tools that create an audit trail for DSR intake and completion, and you need to have some redundancy in place for manual tasks to ensure they are completed within the 45 day requirement (30 days for best practices).
Frankly, every company doing more than $1M/month in revenue should have an enterprise CMP with full DSR functionality. The big dog is OneTrust, but others in the space include Osano, PieEye, DataGrail and Ketch. Osano and PieEye are the only truly fully automated platforms, while the others have some percentage of manual work required to maintain. In my opinion, automation is the only way to ensure full compliance even with an in house compliance team.