The right to know requires businesses to disclose what personal information they collect, share, or sell, including who receives it. The right to delete requires that a valid request trigger removal of the relevant data, including action by third parties, service providers, and contractors. One is transparency, the other is removal.
Transparency versus erasure under CPRA
The right to know is a disclosure right. It lets a consumer ask what personal information a business collects, shares, or sells, and who receives it. The right to delete is a removal right. It asks the business to act on a valid request and delete covered data, including where the data has been shared with third parties, service providers, or contractors.
That difference matters because the two rights operate on different outcomes. Right to know improves visibility into data handling, while right to delete changes the data state itself. In practice, businesses often need different internal workflows, verification steps, and downstream coordination for each request type.
A useful way to think about it is that one right answers “what do you have and where did it go?”, while the other answers “remove it where the law requires.” That means a company can satisfy a knowledge request without deleting anything, and it can also have deletion obligations that reach beyond its own system boundary.
How the two rights differ in practice
Right to know requests are usually about inventory, disclosure, and traceability. The business must be able to locate personal information, identify categories, and explain sharing or sale relationships in a way that is understandable to the consumer. The control challenge is completeness: if you cannot find the data or map where it flows, you cannot answer accurately.
Right to delete requests are usually about execution and propagation. The business has to remove the personal information it holds and also make sure covered downstream recipients receive and act on the deletion request where required. The control challenge is not just finding the data, but ensuring it actually disappears from the relevant operational, backup, and third-party paths within the limits of the law.
Because of that, the delete right is often more operationally demanding than the know right. A company may be able to explain its data practices before it can reliably purge those records across all connected systems, which is why deletion workflows need stronger ownership and exception handling than disclosure workflows.
What businesses should verify before treating either request as complete
For right to know, the key verification point is whether the response reflects the full scope of personal information the business actually handles. That includes confirming that upstream collection sources, adtech, analytics, CRM, and outsourced processing channels are included in the response logic, not just the most obvious internal database.
For right to delete, the key verification point is whether the deletion request has been carried through every system that is legally and operationally in scope. If third parties, service providers, or contractors keep a copy under the business relationship, the business needs a process to confirm that the deletion instruction was sent, tracked, and completed or formally excepted.
In both cases, the common failure mode is partial coverage. A request can look resolved at the ticket level while the underlying data remains in logs, shared services, exports, or vendor-held datasets. That is why request handling should be measured by evidence of completion, not by the fact that a form was submitted or an email was sent.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
NIST SP 800-53 Rev 5 and NIST CSF 2.0 set the technical controls, while GDPR and ISO/IEC 27001:2022 define the regulatory obligations.
| Framework | Control / Reference | Relevance |
|---|---|---|
| GDPR | Data subject rights | CPRA rights to know/delete mirror core privacy-rights handling concepts. |
| Recommendation — Map consumer request handling to rights-disclosure and deletion workflows with auditable completion evidence. | ||
| NIST SP 800-53 Rev 5 | AU-11 — Audit Record Retention | Deletion and disclosure workflows depend on retaining evidence of request handling without overretaining personal data. |
| Recommendation — Retain request-handling evidence separately from consumer data and document deletion completion. | ||
| ISO/IEC 27001:2022 | A.5.34 — Privacy and protection of PII | The topic concerns handling personal information rights and deletion obligations in a governed privacy process. |
| Recommendation — Define privacy request handling, escalation, and verification controls for personal information. | ||
| NIST CSF 2.0 | GV.OC-03 — Legal and regulatory requirements are understood and inform cybersecurity risk management | Consumer privacy rights under CPRA shape how data is disclosed, deleted, and evidenced. |
| Recommendation — Embed CPRA request handling into governance and operational control definitions. | ||
Practitioner Guidance
What to prioritise: Treat right to know and right to delete as separate operational workflows, not as one generic privacy request. Right to know needs data discovery and response accuracy; right to delete needs deletion orchestration and downstream confirmation.
What to verify: Check that your process can distinguish between data that must be disclosed, data that must be deleted, and data that is excepted from deletion. The highest-risk gap is assuming a single response template or a single records search is enough for both rights.
What good looks like: The know workflow produces a complete and explainable disclosure, while the delete workflow produces traceable evidence that the request reached every required holder of the data and was acted on where required.
Practitioner takeaway: The right to know is about visibility into data handling, but the right to delete is about enforcing removal across the business and its processors, so deletion controls need stronger operational proof than disclosure controls.
Related resources from NHI Mgmt Group
- What is the difference between attack surface management and NHI governance?
- What is the difference between reviewing human access and reviewing NHIs?
- What is the difference between role-based access and API key governance for NHI security?
- What is the difference between human IAM controls and NHI governance?