Skip to content
RiskTemplates · The Daily Brief Sunday, October 4, 2026
Wire SEC v. Meyer Global: The $46,020 Capital Call That Allegedly Wiped Out a Nearly $3 Million SpaceX Stake SEP 30

Feature Data Privacy

Your Customer Wants Their Data Deleted. Federal Law Says You Can't. Here's How to Navigate the Conflict.

CCPA, Virginia VCDPA, and 18 other state privacy laws give consumers the right to demand deletion of their data. Federal banking and securities laws require you to keep most of it for 3 to 7 years. Here is what financial institutions must do when these obligations collide.

By Rebecca Leung · October 3, 2026 ·
Table of Contents

TL;DR

  • 19 states have comprehensive privacy laws in effect; every one includes a right to deletion with exceptions for legal obligations
  • Financial institutions face mandatory federal retention requirements — BSA (5 years), FCRA (7 years), SEC 17a-4 (3-6 years), RESPA (3 years) — that make full deletion legally impossible for many records
  • The “legal obligation” exception is real but specific: you must cite the actual regulation, state the expiration date, and prove the retained data is used only for compliance purposes
  • Partial deletion is not optional: data not covered by a specific legal retention obligation must still be deleted when a consumer requests it
  • Boilerplate denials citing “regulatory requirements” without specifics aren’t compliant under California, Colorado, Virginia, or Connecticut frameworks

A consumer submits a CCPA deletion request to their mortgage servicer. They want everything deleted — loan application records, payment history, the appraisal, all of it. The servicer’s compliance team looks at the request and knows immediately that full deletion isn’t possible: RESPA requires mortgage origination records to be retained for three years, the Bank Secrecy Act has its own requirements, and their secondary market investor agreement has retention provisions on top of that.

So they send back a form response: “Regulatory requirements prevent us from honoring your deletion request.”

That response is non-compliant. And if the consumer files a complaint with the California AG, the servicer is going to have to explain exactly which regulation requires retention of exactly which records — and demonstrate that they actually deleted the data they weren’t required to keep.

This is the collision that financial institutions operating in states with privacy laws are navigating in 2026. The good news: the legal framework actually works if you execute it correctly. The problem is that most financial institutions are either refusing all deletion requests with boilerplate language or deleting records they were legally required to keep.


The Conflict in Plain English

Privacy law deletion rights and federal financial records retention mandates pull in opposite directions. The laws don’t fully resolve this conflict — they leave a gap for institutional judgment, documentation, and process.

State privacy laws give consumers the right to request deletion of their personal information. CCPA and CPRA cover all businesses meeting California’s thresholds, including most financial institutions operating in the state. Nineteen other states have similar frameworks, with Virginia, Colorado, Connecticut, Texas, and Nevada among the most actively enforced.

Federal banking and securities laws require specific records to be retained for specific periods. These retention obligations exist for specific regulatory purposes: AML investigations, credit reporting accuracy, audit trails, investor protection. They are not suggestions.

The resolution: every major state privacy law includes an exception to deletion rights for records necessary to comply with a legal obligation. Federal records retention mandates qualify. But the exception has conditions. It is not a blanket refusal — it is a use-specific retention authorization with a defined scope and a defined endpoint.


What Financial Institutions Are Actually Required to Retain

Before you can respond to a deletion request, you need to know your mandatory retention landscape. The major categories:

Bank Secrecy Act / Anti-Money Laundering
Under 31 CFR Part 1020 and related FinCEN rules, banks must retain records of cash transactions above $10,000 for five years. Currency transaction reports (CTRs) must be retained for five years from the date filed. Suspicious activity reports (SARs) must be retained for five years from the date filed — and the records supporting the SAR decision must be retained for the same period. Customer identification program records must be retained for five years after the account is closed.

Fair Credit Reporting Act
Consumer reporting agencies must retain a consumer’s complete file for seven years on most negative items, ten years for bankruptcies. Adverse action notices — the records documenting the specific reasons a credit decision was adverse — must be retained under Regulation B (ECOA) for 25 months after the action was communicated to the consumer.

Exchange Act and Securities Recordkeeping
Under Exchange Act Rule 17a-4, broker-dealers must retain records of customer orders, trade confirmations, and account records for at least three years (six years for some categories), with the first two years in an easily accessible location. The Investment Advisers Act requires investment advisers to retain most client records for five years. These are hard legal obligations, not soft guidance.

RESPA and TILA
Under RESPA, lenders must retain mortgage origination records for three years. Under Regulation Z (TILA), lenders must retain loan origination records for two years after the later of the transaction closing date or when the action taken was communicated to the consumer.

Regulation E
Institutions must retain electronic fund transfer records for two years. This covers most payment transaction records.


California’s CPRA — the most comprehensive framework in the country — allows businesses to deny deletion requests when compliance “is reasonably necessary to comply with a legal obligation.” Colorado CPA, Virginia VCDPA, and Connecticut CTDPA use similar language.

But the CPRA adds a condition that most financial institutions miss: data retained under the legal obligation exception may only be used for the purpose of that legal obligation. You cannot retain BSA-required transaction records and then run them through a customer analytics model. You cannot retain Reg B adverse action documentation and then use it to build a marketing segmentation profile. The exception authorizes retention; it does not authorize continued use.

What a compliant response to a deletion request you cannot fully honor looks like:

  1. Acknowledge receipt within 10 days (CCPA requirement)
  2. Identify which data you are retaining and under what legal obligation
  3. Cite the specific regulation (e.g., “31 CFR § 1020.220 requires us to retain this transaction record for five years from the date of the transaction, which was [date]; our retention obligation expires on [date]”)
  4. Confirm the retained data will not be used for any purpose other than satisfying the specified legal obligation
  5. Confirm that data not subject to a specific legal retention obligation is being deleted
  6. Provide a timeline for deletion of the retained records when the legal obligation expires

That last item — confirming partial deletion — is where most institutions fall short. They deny the full request without deleting anything, when the obligation only protects specific record categories.


The Partial Deletion Problem

The legal obligation exception covers records required by a specific law or regulation. It does not cover:

  • Marketing and advertising data linked to a consumer
  • Behavioral tracking data (website analytics, session replay, cookies)
  • Preferences and consent records tied to marketing (as opposed to legal compliance)
  • Data you collected beyond what any specific legal requirement necessitated
  • Data where the retention obligation has already expired

A mortgage servicer who receives a deletion request cannot delete the RESPA-required origination records. But they must delete the consumer’s email marketing preferences, their website browsing history, their suppression list status (once that purpose is served), and any other consumer data not covered by a specific legal retention obligation.

Financial institutions consistently under-implement partial deletion. The FTC’s enforcement pattern and state AG enforcement activity both show that treating all consumer data as subject to one undifferentiated regulatory hold is not a defensible position. You need a records map — a documented inventory of what consumer data you hold, what category it falls into, and what specific legal obligation (if any) requires its retention.


What Regulators Actually Examine

When a California AG investigator reviews a consumer complaint about a failed deletion request, they are looking for three things:

  1. Did you respond within the required timeframe?
  2. Did you cite a specific legal basis — not just generic regulatory language?
  3. Did you delete the data you weren’t legally required to retain?

The FTC, in its evolving privacy enforcement posture, is looking at the same questions for non-bank financial institutions. The 2026 enforcement trend — state enforcement taking center stage — means that the “we’re a financial institution and therefore exempt” framing is increasingly inadequate. State privacy law deletion rights apply to financial institutions with limited, specific exceptions. Those exceptions require documentation.

The connection to your broader compliance program: the records retention schedule you built for internal audit purposes is now also your deletion response documentation. If you can’t point to a record category, the specific regulation requiring its retention, and the retention period end date, you can’t invoke the legal obligation exception properly.


So What?

If you’re receiving state privacy law deletion requests and your response process isn’t distinguishing between legally-required records and everything else, the action steps are:

Map your data to your retention schedule. For each category of consumer data your institution holds, document: what legal obligation (if any) requires its retention, the specific regulation citation, the retention period, and the data store where it lives. This map is your response infrastructure.

Build a tiered response template. Template one: full deletion confirmation. Template two: partial deletion with specific legal citations for retained records. Neither template should be “we can’t comply for regulatory reasons.”

Train intake teams on the clock. The 45-day clock starts at submission. Your website form, your secure message portal, your call center — all must timestamp deletion requests on receipt and route them to compliance within 24 hours.

Audit your cookie and tracking data. Marketing cookies, session replay tools, behavioral analytics, and advertising pixels linked to consumer identities are unlikely to qualify for legal retention exceptions. They should be deleted when a consumer requests it.

Document every response. Date of request, date of acknowledgment, data deleted, data retained with citation, date the retained data will be deleted.

The intersection of state privacy deletion rights and federal records retention isn’t going away — it will get more complex as more states activate. The Data Privacy Compliance Kit includes deletion request response templates built for financial institution retention conflicts, a records retention schedule aligned to BSA, FCRA, SEC 17a-4, and key state frameworks, and a consumer request log designed for regulatory examination. If you’re working through your Q4 privacy compliance checklist, the Q4 2026 compliance deadline guide includes state privacy law enforcement deadlines alongside the regulatory action items you already know about.


Sources: CCPA/CPRA legal obligation exception analysis | State privacy law enforcement 2026 | FTC Safeguards Rule enforcement 2026 | US privacy fines and class action risk 2026 | Chapman and Cutler: California Consumer Privacy Rules and Financial Institutions

◆ Need the working template?

Start with the source guide.

These answer-first guides summarize the required fields, evidence, and implementation steps behind the templates practitioners search for.

◆ Immaterial Findings · Weekly

Sharp risk & compliance insights. No fluff.

◆ FAQ

Frequently asked questions.

Can a financial institution ever fully comply with a CCPA deletion request?
Sometimes, partially. Financial institutions cannot delete records they are legally required to retain — BSA transaction records (5 years), FCRA consumer report data (7 years for negative items), SEC 17a-4 brokerage records (3-6 years), and RESPA mortgage origination records (3 years) all qualify as legal obligations under CCPA and most state privacy law deletion exceptions. However, data that doesn't fall under a specific legal retention obligation — analytics cookies, marketing preferences, behavioral tracking data — must still be deleted when a consumer requests it. The error most financial institutions make is treating 'legal obligation' as a blanket exemption that covers everything.
What does the CCPA 'legal obligation' exception actually require us to do?
The CCPA and CPRA legal obligation exception allows you to retain data that is necessary to comply with a specific legal or regulatory requirement. To use it correctly, you must: (1) identify the specific law or regulation requiring retention, (2) state when that retention obligation expires, (3) confirm that the retained data will only be used for the legal compliance purpose — not for marketing, analytics, or any other use, and (4) delete data not subject to a specific legal obligation. A generic statement that 'regulatory requirements prevent deletion' doesn't satisfy the exception. Your response must cite the specific obligation.
What happens if we respond to a deletion request by saying we can't delete the data?
You must still respond within 45 days under CCPA (extendable to 90 with notice). A compliant denial must: acknowledge the specific data subject to a legal retention hold, cite the specific regulation requiring retention, state when the obligation expires, confirm the data won't be used for any non-compliance purpose, and confirm that any data NOT subject to a legal obligation will be deleted. Boilerplate refusals — 'regulatory requirements prevent us from complying' — are not compliant and have been cited in California AG investigations. A poorly documented denial may result in a formal inquiry requiring you to prove the specific legal basis.
How long does the 45-day clock actually run, and where does it start?
Under California CCPA/CPRA, the response clock starts when the consumer submits a verifiable consumer request — not when your compliance team receives it internally. The initial acknowledgment must happen within 10 days. The substantive response (delete or deny with legal basis) must happen within 45 days, extendable to 90 with written notice during the initial 45 days. Colorado CPA: 45 days, extendable to 90. Virginia VCDPA: 45 days, extendable to 90. Connecticut CTDPA: 45 days, extendable to 90. The clock starts at submission, so your intake process — the website form, the email address, the call center script — needs to timestamp every request the moment it arrives.
Does this apply to both bank and non-bank financial institutions?
Yes, with different regulatory frameworks. Bank and credit union consumer data falls under CCPA and state privacy law deletion rights, though the GLBA entity-level exemption in some states may limit the scope. Non-bank financial institutions — fintechs, mortgage servicers, payday lenders, auto dealers offering financing — are subject to both FTC Safeguards Rule obligations and state privacy law deletion rights. The BSA, FCRA, and other federal records retention requirements apply to any institution subject to those laws, regardless of charter type. For federally chartered banks, the OCC overlay also applies.
What records should we delete when we can't delete everything?
When you receive a deletion request and some records are legally required to be retained, you must still delete everything that isn't protected by a specific legal obligation. This typically includes: marketing and advertising preference data, behavioral tracking and analytics data, cookies and session replay data, suppression list data once its purpose has been served, and any data collected beyond what the specific legal obligation required. The partial deletion obligation is real and enforceable. Retaining data beyond your legal requirements — even data that never needed to exist in the first place — doesn't get legal protection just because you have a legitimate retention reason for other records.
Rebecca Leung

Author

Rebecca Leung

Rebecca Leung has 8+ years of risk and compliance experience across first and second line roles at commercial banks, asset managers, and fintechs. Former management consultant advising financial institutions on risk strategy. Founder of RiskTemplates.

◆ Related framework

Data Privacy Compliance Kit

Which of the 23 state privacy laws apply to your fintech after GLBA, plus the GLBA checklist, request tracker, assessments and vendor terms to comply.

Immaterial Findings · Newsletter

The brief, in your inbox.

Enforcement of the week, a framework breakdown, and the prompts that are actually worth running. Delivered to your inbox. Free.