Perils of living in Massachusetts. I hope similar laws pass federally in the United States.
That being said, I’ve been on the other side of GDPR. Getting ready for GDPR around 2017 was so much work. We initially had a lengthy confluence runbook with all the places data had to be deleted from. It took a while to automate. Painful, but it’s the right thing to do.
RE: OP
I’m pretty sure this is in violation of both GDPR/CCPA
IANAL, but I agree. In my past companies, when a GDPR deletion request comes, we follow through and delete the data. We might ask users to verify their identity but that’s about it. It should be 2-3 emails back and forth.
Thanks for all the great memories and moments RIF. We will miss you!