Feature Data Privacy
Your Customer Wants Their Data Deleted. Federal Law Says You Can't. Here's How to Navigate the Conflict.
CCPA, Virginia VCDPA, and 18 other state privacy laws give consumers the right to demand deletion of their data. Federal banking and securities laws require you to keep most of it for 3 to 7 years. Here is what financial institutions must do when these obligations collide.
Table of Contents
TL;DR
- 19 states have comprehensive privacy laws in effect; every one includes a right to deletion with exceptions for legal obligations
- Financial institutions face mandatory federal retention requirements — BSA (5 years), FCRA (7 years), SEC 17a-4 (3-6 years), RESPA (3 years) — that make full deletion legally impossible for many records
- The “legal obligation” exception is real but specific: you must cite the actual regulation, state the expiration date, and prove the retained data is used only for compliance purposes
- Partial deletion is not optional: data not covered by a specific legal retention obligation must still be deleted when a consumer requests it
- Boilerplate denials citing “regulatory requirements” without specifics aren’t compliant under California, Colorado, Virginia, or Connecticut frameworks
A consumer submits a CCPA deletion request to their mortgage servicer. They want everything deleted — loan application records, payment history, the appraisal, all of it. The servicer’s compliance team looks at the request and knows immediately that full deletion isn’t possible: RESPA requires mortgage origination records to be retained for three years, the Bank Secrecy Act has its own requirements, and their secondary market investor agreement has retention provisions on top of that.
So they send back a form response: “Regulatory requirements prevent us from honoring your deletion request.”
That response is non-compliant. And if the consumer files a complaint with the California AG, the servicer is going to have to explain exactly which regulation requires retention of exactly which records — and demonstrate that they actually deleted the data they weren’t required to keep.
This is the collision that financial institutions operating in states with privacy laws are navigating in 2026. The good news: the legal framework actually works if you execute it correctly. The problem is that most financial institutions are either refusing all deletion requests with boilerplate language or deleting records they were legally required to keep.
The Conflict in Plain English
Privacy law deletion rights and federal financial records retention mandates pull in opposite directions. The laws don’t fully resolve this conflict — they leave a gap for institutional judgment, documentation, and process.
State privacy laws give consumers the right to request deletion of their personal information. CCPA and CPRA cover all businesses meeting California’s thresholds, including most financial institutions operating in the state. Nineteen other states have similar frameworks, with Virginia, Colorado, Connecticut, Texas, and Nevada among the most actively enforced.
Federal banking and securities laws require specific records to be retained for specific periods. These retention obligations exist for specific regulatory purposes: AML investigations, credit reporting accuracy, audit trails, investor protection. They are not suggestions.
The resolution: every major state privacy law includes an exception to deletion rights for records necessary to comply with a legal obligation. Federal records retention mandates qualify. But the exception has conditions. It is not a blanket refusal — it is a use-specific retention authorization with a defined scope and a defined endpoint.
What Financial Institutions Are Actually Required to Retain
Before you can respond to a deletion request, you need to know your mandatory retention landscape. The major categories:
Bank Secrecy Act / Anti-Money Laundering
Under 31 CFR Part 1020 and related FinCEN rules, banks must retain records of cash transactions above $10,000 for five years. Currency transaction reports (CTRs) must be retained for five years from the date filed. Suspicious activity reports (SARs) must be retained for five years from the date filed — and the records supporting the SAR decision must be retained for the same period. Customer identification program records must be retained for five years after the account is closed.
Fair Credit Reporting Act
Consumer reporting agencies must retain a consumer’s complete file for seven years on most negative items, ten years for bankruptcies. Adverse action notices — the records documenting the specific reasons a credit decision was adverse — must be retained under Regulation B (ECOA) for 25 months after the action was communicated to the consumer.
Exchange Act and Securities Recordkeeping
Under Exchange Act Rule 17a-4, broker-dealers must retain records of customer orders, trade confirmations, and account records for at least three years (six years for some categories), with the first two years in an easily accessible location. The Investment Advisers Act requires investment advisers to retain most client records for five years. These are hard legal obligations, not soft guidance.
RESPA and TILA
Under RESPA, lenders must retain mortgage origination records for three years. Under Regulation Z (TILA), lenders must retain loan origination records for two years after the later of the transaction closing date or when the action taken was communicated to the consumer.
Regulation E
Institutions must retain electronic fund transfer records for two years. This covers most payment transaction records.
What the “Legal Obligation” Exception Actually Requires
California’s CPRA — the most comprehensive framework in the country — allows businesses to deny deletion requests when compliance “is reasonably necessary to comply with a legal obligation.” Colorado CPA, Virginia VCDPA, and Connecticut CTDPA use similar language.
But the CPRA adds a condition that most financial institutions miss: data retained under the legal obligation exception may only be used for the purpose of that legal obligation. You cannot retain BSA-required transaction records and then run them through a customer analytics model. You cannot retain Reg B adverse action documentation and then use it to build a marketing segmentation profile. The exception authorizes retention; it does not authorize continued use.
What a compliant response to a deletion request you cannot fully honor looks like:
- Acknowledge receipt within 10 days (CCPA requirement)
- Identify which data you are retaining and under what legal obligation
- Cite the specific regulation (e.g., “31 CFR § 1020.220 requires us to retain this transaction record for five years from the date of the transaction, which was [date]; our retention obligation expires on [date]”)
- Confirm the retained data will not be used for any purpose other than satisfying the specified legal obligation
- Confirm that data not subject to a specific legal retention obligation is being deleted
- Provide a timeline for deletion of the retained records when the legal obligation expires
That last item — confirming partial deletion — is where most institutions fall short. They deny the full request without deleting anything, when the obligation only protects specific record categories.
The Partial Deletion Problem
The legal obligation exception covers records required by a specific law or regulation. It does not cover:
- Marketing and advertising data linked to a consumer
- Behavioral tracking data (website analytics, session replay, cookies)
- Preferences and consent records tied to marketing (as opposed to legal compliance)
- Data you collected beyond what any specific legal requirement necessitated
- Data where the retention obligation has already expired
A mortgage servicer who receives a deletion request cannot delete the RESPA-required origination records. But they must delete the consumer’s email marketing preferences, their website browsing history, their suppression list status (once that purpose is served), and any other consumer data not covered by a specific legal retention obligation.
Financial institutions consistently under-implement partial deletion. The FTC’s enforcement pattern and state AG enforcement activity both show that treating all consumer data as subject to one undifferentiated regulatory hold is not a defensible position. You need a records map — a documented inventory of what consumer data you hold, what category it falls into, and what specific legal obligation (if any) requires its retention.
What Regulators Actually Examine
When a California AG investigator reviews a consumer complaint about a failed deletion request, they are looking for three things:
- Did you respond within the required timeframe?
- Did you cite a specific legal basis — not just generic regulatory language?
- Did you delete the data you weren’t legally required to retain?
The FTC, in its evolving privacy enforcement posture, is looking at the same questions for non-bank financial institutions. The 2026 enforcement trend — state enforcement taking center stage — means that the “we’re a financial institution and therefore exempt” framing is increasingly inadequate. State privacy law deletion rights apply to financial institutions with limited, specific exceptions. Those exceptions require documentation.
The connection to your broader compliance program: the records retention schedule you built for internal audit purposes is now also your deletion response documentation. If you can’t point to a record category, the specific regulation requiring its retention, and the retention period end date, you can’t invoke the legal obligation exception properly.
So What?
If you’re receiving state privacy law deletion requests and your response process isn’t distinguishing between legally-required records and everything else, the action steps are:
Map your data to your retention schedule. For each category of consumer data your institution holds, document: what legal obligation (if any) requires its retention, the specific regulation citation, the retention period, and the data store where it lives. This map is your response infrastructure.
Build a tiered response template. Template one: full deletion confirmation. Template two: partial deletion with specific legal citations for retained records. Neither template should be “we can’t comply for regulatory reasons.”
Train intake teams on the clock. The 45-day clock starts at submission. Your website form, your secure message portal, your call center — all must timestamp deletion requests on receipt and route them to compliance within 24 hours.
Audit your cookie and tracking data. Marketing cookies, session replay tools, behavioral analytics, and advertising pixels linked to consumer identities are unlikely to qualify for legal retention exceptions. They should be deleted when a consumer requests it.
Document every response. Date of request, date of acknowledgment, data deleted, data retained with citation, date the retained data will be deleted.
The intersection of state privacy deletion rights and federal records retention isn’t going away — it will get more complex as more states activate. The Data Privacy Compliance Kit includes deletion request response templates built for financial institution retention conflicts, a records retention schedule aligned to BSA, FCRA, SEC 17a-4, and key state frameworks, and a consumer request log designed for regulatory examination. If you’re working through your Q4 privacy compliance checklist, the Q4 2026 compliance deadline guide includes state privacy law enforcement deadlines alongside the regulatory action items you already know about.
Sources: CCPA/CPRA legal obligation exception analysis | State privacy law enforcement 2026 | FTC Safeguards Rule enforcement 2026 | US privacy fines and class action risk 2026 | Chapman and Cutler: California Consumer Privacy Rules and Financial Institutions
◆ Need the working template?
Start with the source guide.
These answer-first guides summarize the required fields, evidence, and implementation steps behind the templates practitioners search for.
◆ Related template
Data Privacy Compliance Kit
Which of the 23 state privacy laws apply to your fintech after GLBA, plus the GLBA checklist, request tracker, assessments and vendor terms to comply.
◆ Immaterial Findings · Weekly
Sharp risk & compliance insights. No fluff.
◆ FAQ
Frequently asked questions.
Can a financial institution ever fully comply with a CCPA deletion request?
What does the CCPA 'legal obligation' exception actually require us to do?
What happens if we respond to a deletion request by saying we can't delete the data?
How long does the 45-day clock actually run, and where does it start?
Does this apply to both bank and non-bank financial institutions?
What records should we delete when we can't delete everything?
Author
Rebecca Leung
Rebecca Leung has 8+ years of risk and compliance experience across first and second line roles at commercial banks, asset managers, and fintechs. Former management consultant advising financial institutions on risk strategy. Founder of RiskTemplates.
◆ Related framework
Data Privacy Compliance Kit
Which of the 23 state privacy laws apply to your fintech after GLBA, plus the GLBA checklist, request tracker, assessments and vendor terms to comply.
◆ Keep reading
Related posts.
Data Privacy
CFPB's Section 1033 Rewrite Is at OIRA. What the Two Key Substantive Changes Mean for Banks, Fintechs, and Data Aggregators.
The CFPB sent its Section 1033 reconsideration NPRM to OIRA on August 6, 2026. Two proposed changes — allowing data access fees and tightening the 'authorized representative' standard — would reshape how open banking works in the U.S. Here's what each change means for your compliance program.
Sep 28, 2026
Data Privacy
Your Analytics Stack Is a GLBA Time Bomb. The Class Action Wave Targeting Financial Institutions That Use Meta Pixel Has Arrived.
TaxAct just paid Connecticut $275K for sharing taxpayer data via Meta Pixel. Class actions against banks and fintechs using third-party tracking scripts are surging. Here's what the GLBA exposure actually looks like — and what your tag governance program needs.
Sep 25, 2026
Data Privacy
California Just Fined GM $12.75 Million for Selling Driver Data Without Consent. Your Financial Data Practices Face the Same Scrutiny.
The $12.75M GM/OnStar CCPA settlement makes data minimization and purpose limitation enforcement reality. Here's what fintech and financial services compliance teams need to do about consumer behavioral data sales and sharing.
Sep 22, 2026