Account deletion policy

We work for a company that builds and maintains apps for our clients and we had a few questions regarding the new account deletion policy that comes into fruition at the end of June 2022.

We have tried to raise this directly with Apple but with no response as of yet. Do any of you know the answers to the following:

  • Does providing the user with an email address to request that their account and data be deleted suffice in 'deleting' their account? We have a few apps that the data is managed by the client and not by us (the app developers), so it is more difficult to remove from our side. For example, we have a client that allow users to create accounts within the app, but the data is stored by them and used across multiple platforms (such as health records), so if we were to allow the user to delete this data entirely, it may cause issues on other platforms. We were wondering if it’s possible that these users send an email in app asking for their account to be removed and we just anonymise the data JUST for the app and continue to store their health record. 

  • Do we need to offer the option of deleting the account if their account is technically created off app and they only have to enter a OTP to be able to access said account? In this example, the user still sees the option to 'Sign up' but they can't do so unless their phone number is already in the database. 

  • Do we need to offer the option of deleting the account if their account is created using social logins (Apple/Google/Facebook etc)? 

  • Do we need to offer the option of deleting the account if users are only able to sign in to the app? Aka, they do not create the account on the app, but elsewhere on a website? 

  • Do we need to offer the option of deleting the account if it isn't technically made on the app, but in an embedded link that leads to the client's website? 

  • Do we need to offer the option of deleting data if we don’t have an account for a user, but store identifiers so we can map users, but don’t retain any personal information about the user?

Any help will be greatly appreciated, thank you.