Welcome to Zuora Product Documentation

Explore our rich library of product information

Scrub or delete personal data

Learn how to scrub or delete personal data in Zuora.

Zuora makes available different options to perform data deletion. You can follow the steps to scrub certain personalized data related to an individual. In this context, scrubbing data means the data is permanently anonymized.

Zuora does not advise that any or all of the steps below are required for deletion under applicable privacy laws. You choose whether to export any data you want to retain or archive for business purposes and which methods you want to deploy for deletion. If you have questions about what data you need to delete when you receive a request from an individual subscriber, consult your legal counsel for guidance.

After the data is deleted or scrubbed, it cannot be recovered. If you change your mind about the deletion, Zuora is not responsible for retrieving or restoring data which you have deleted or scrubbed.

After you delete or scrub personal data, you no longer have access to the personal data. In addition, functionality that relies on scrubbed fields may no longer operate.

Note: Certain fields, such as CRM Account ID, may be used for the integration with other systems. Scrubbing these fields may impact integration. If you want other systems to receive the data, do not scrub these fields.
  1. To scrub payment methods associated with an individual, use the REST API operation, Scrub a payment method
  2. Scrub the following Account fields:
    • Account Name

    • Account Number (If an account has posted invoices, closed accounting periods, journalized transactions, the Account Number field cannot be scrubbed.)

    • CRM Account ID

    • PO Number

    • Tax Exempt Certificate ID

    • VAT ID

    • Any custom fields that contain personal data

  3. Scrub the Contact fields below.

    You can use use the Scrub a contact API operation to scrub the sensitive data of a specific contact. You can also change the values of these fields.

    • First Name

    • Last Name

    • Personal Email

    • Address fields, including Address 1, Address 2, and so on

    • Phone fields, including Home Phone, Mobile Phone, and so on

  4. Remove the billing documents:
    1. For existing billing documents, use the REST API operation Create a job to hard delete billing document files, to start the deletion of billing documents for specific accounts. You can use the REST API operation Retrieve a job of hard deleting billing document files to check the status of the deletion.
    2. Optionally, if you want to get billing document files with scrubbed account and contact data, regenerate the billing document files for invoices, credit memos, and debit memos.
  5. Scrub payments by changing the Reference ID field for each transaction using the Update API operation.

    You can only update the Reference ID for external payments. Currently, it is not possible to change the Reference ID field for electronic payments or refunds.

  6. Remove the email and call-out notification history using the REST API operation Delete notification histories for an account.
  7. Optional: Use the REST API operation Delete to remove the Export objects.

    Export objects correspond to data source exports. This step is optional because each exported file is only available for 7 days.

  8. To delete any other objects, use the REST API operation Delete.