If a business receives a deletion request, but is required by foreign law to retain the data, can it deny the request without violating the CCPA?

BCLP
Contact

Likely, yes.

A consumer’s right to deletion is subject to a number of exceptions.  One of these exceptions is to “comply with a legal obligation.”1 Thus, where retaining personal information of a consumer is necessary to comply with a legal obligation, the business is not required to honor the data subject request.  The CCPA does not identify, restrict, or qualify the type of legal obligation that triggers the exception.  Thus, it is likely, though not certain, that a requirement to maintain personal data under foreign law would trigger the exception, such that a business would not be obligated to delete the personal data subject to the foreign law.  

This is in marked contrast to GDPR’s relationship with United States law.  The GDPR states that a company does not have to honor a request to be forgotten if the processing is necessary for “compliance with a legal obligation which requires processing by Union or Member State law to which the controller is subject.” Many companies assume that they can use this exception if they are required by United States law to retain data.  Unfortunately, the Article 29 Working party (now the European Data Protection Board) - an influential, independent advisory body to the European Commission on data protection matters that was chiefly comprised of representatives from each Member State’s supervisory authority – has implied that United States law cannot justify ongoing processing.

For more information and resources about the CCPA visit http://www.CCPA-info.com. 


This article is part of a multi-part series published by BCLP to help companies understand and implement the General Data Protection Regulation, the California Consumer Privacy Act and other privacy statutes.  You can find more information on the CCPA in BCLP’s California Consumer Privacy Act Practical Guide, and more information about the GDPR in the American Bar Association’s The EU GDPR: Answers to the Most Frequently Asked Questions

1. CCPA, Section 1798.105(d)(8). 

[View source.]

Written by:

BCLP
Contact
more
less

PUBLISH YOUR CONTENT ON JD SUPRA NOW

  • Increased visibility
  • Actionable analytics
  • Ongoing guidance

BCLP on:

Reporters on Deadline

"My best business intelligence, in one easy email…"

Your first step to building a free, personalized, morning email brief covering pertinent authors and topics on JD Supra:
*By using the service, you signify your acceptance of JD Supra's Privacy Policy.
Custom Email Digest
- hide
- hide