IAPP Privacy. Security. Risk. 2025

SAN DIEGO

28-31 October

Back to conference agenda

Navigating Data Deletion: Frameworks, Protocols, and CA's Evolving Deletion Laws

Friday, 31 Oct.

15:45 - 16:45 EDT

Intermediate level

BREAKOUT SESSIONPRIVACYENFORCEMENTPRIVACY ENGINEERINGREGULATORY GUIDANCEU.S. STATE REGULATIONLAW AND REGULATION
Download the presentation slides

Rowena Lam, Senior Director of Product, Privacy and Data, IAB Tech Lab
Julie Rubash, CIPP/US, General Counsel and Chief Privacy Officer, Sourcepoint
Houman Saberi, Industry Relations and Operations Lead, Consumer Reports Innovation Lab


As data deletion requests grow under global privacy laws, organizations must adopt scalable solutions to remain compliant. This session explores technical approaches to managing deletion requests, including standardized frameworks, open-source protocols, and streamlined workflows to improve privacy operations. With California’s Data Broker Registry and Delete Act reshaping requirements, this panel will examine the evolving regulatory landscape and its business impact. Attendees will gain practical insights into overcoming privacy engineering implementation challenges, leveraging scalable solutions, and building consumer trust. Whether refining workflows, starting from scratch, or preparing for California’s new mandates, this session provides the tools to confidently navigate the complexities of data deletion.

What you will learn: 

  • Understand data deletion standardized frameworks and open-source protocols.
  • Gain insights into California’s privacy requirements for data deletion and impact for businesses categorized as data brokers.
  • Learn how to address technical and organizational challenges in meeting deletion request obligations while ensuring privacy operations are efficient.