Data Deletion Request: Rights, Refusals, and Response Times

A data deletion request is a formal demand that a company permanently erase the personal information it holds about you. Whether the company must honor it, how quickly, and what it can lawfully keep depends on which privacy law covers your situation: the EU’s General Data Protection Regulation, one of roughly 20 U.S. state privacy statutes, or the federal Children’s Online Privacy Protection Act for data about kids under 13. The mechanics are similar across regimes. You identify yourself, list the data you want removed, and submit the request through the company’s designated channel. From there the clock starts, and the company must either delete the data or point to a specific legal reason it cannot.

Who Has the Right to Demand Deletion

The strongest and most established deletion right sits in Article 17 of the GDPR, which covers anyone whose data is processed by organizations operating within the European Economic Area. It requires companies to erase personal data when it is no longer needed for its original purpose, when you withdraw consent, or when the data was collected unlawfully.1GDPR.eu. General Data Protection Regulation – Art. 17 GDPR Right to Erasure (Right to Be Forgotten)

The United States has no comprehensive federal privacy law giving adults a general right to deletion. Roughly 20 states have filled the gap with their own consumer privacy statutes, most of which include a deletion right for residents. These laws share a structure: a verified request goes to a covered business, the business responds within a set window, and the state attorney general enforces violations. If you live in a state without a comprehensive privacy law, your leverage depends on whether the company happens to be covered by another state’s law that applies to you, whether federal law like COPPA reaches the data, or whether the company honors deletion requests as a matter of policy.

What Data You Can Ask to Have Deleted

Privacy laws define “personal information” broadly, and the categories reach well past the obvious identifiers. Most comprehensive statutes cover your name, email, and Social Security number, but also biometric data such as fingerprints or facial recognition profiles, geolocation records, browsing and search history, purchase records, audio and visual recordings, employment information, and inferences a company has drawn about your preferences or behavior from other data points. That last category matters. The marketing profile a company has built about you from your activity is itself personal data you can ask to have deleted.

The practical implication is in how you word the request. Asking a company to “delete my account” may leave behavioral profiles, advertising identifiers, or analytics logs untouched, because the company treats those as separate from the user account. Naming the categories forces a more thorough sweep.

Preparing and Submitting the Request

Before you send anything, gather the identifiers the company will use to match you to its records. At a minimum, that means your account username, the email address on file, and secondary details like your phone number or mailing address. Some companies require a copy of government-issued identification for requests involving sensitive records. Having this ready avoids back-and-forth that can drag out the process.

Most companies publish their procedure in a privacy policy or a dedicated data rights portal, usually linked from the footer of the homepage. Look for “privacy settings,” “your data rights,” or “submit a request.” Larger companies increasingly run automated portals with dropdown menus for request types. Smaller ones may list an email address for a privacy contact. If you still have an active account, check the settings dashboard first, because some platforms let you initiate deletion directly there.

When you fill in the form or write the request, list the categories you want removed rather than saying “delete everything.” Account information, browsing history, transaction records, marketing profiles, location data, and behavioral or advertising tags are all fair to itemize. Keep a copy of what you submit, along with the date. That record is what you’ll rely on if you need to follow up or file a complaint.

For companies subject to the GDPR, any clear written request is legally sufficient. You do not have to use a particular form, cite the article number, or route the message to a special department. Once the company receives a clear request, the obligation is on them.

Electronic submissions usually generate an automated reference number that serves as your tracking ID. If no confirmation arrives within a few business days, follow up. A missing confirmation can mean the request never entered the company’s queue.

How Long the Company Has to Respond

Under the GDPR, companies must respond within one month. If the request is complex or the company is processing high volumes, it can extend the deadline by two additional months, but only if it notifies you of the extension within the initial month.2European Data Protection Board. Respect Individuals Rights A company that considers a request “manifestly unfounded or excessive” may charge a reasonable fee or refuse, but it carries the burden of proving that characterization.

Most U.S. state privacy laws give businesses 45 days to respond to a verified deletion request, with the option to extend by another 45 days if the business tells you about the delay. The outer limit in most states is 90 days from submission. In that window you should receive at least an acknowledgment and, later, a confirmation of completion or an explanation of any denial.

Missing these deadlines carries enforcement risk for the company. State attorneys general can pursue civil penalties that vary by jurisdiction but can reach several thousand dollars per individual violation. Note your submission date and the applicable deadline, and send a written follow-up the day after the deadline passes if you haven’t heard back.

When a Company Can Legally Refuse

A deletion request is not an absolute override. Both the GDPR and U.S. state privacy laws recognize categories of data a company can keep despite your objection.

Under GDPR Article 17(3), the recognized grounds are data necessary for freedom of expression and information (journalism, academic or artistic purposes), data the company must keep to comply with EU or member state law (including tax and employment records), data needed for public health interests, data required for scientific, historical, or statistical archiving where deletion would seriously impair the work, and data needed to establish, exercise, or defend legal claims.1GDPR.eu. General Data Protection Regulation – Art. 17 GDPR Right to Erasure (Right to Be Forgotten)

U.S. state laws contain similar carve-outs. The most common cover data needed to complete a pending transaction, fulfill an existing contract such as an active subscription or unpaid balance, detect security incidents, meet legal recordkeeping requirements, or defend against legal claims. A company that denies your request must explain in writing why and identify the specific legal basis. If the explanation is vague or doesn’t map to a recognized exemption, that refusal is worth challenging.

Many state laws give you a formal right to appeal a denial. The appeal process typically mirrors the original request, and the company usually has 45 days to reconsider. If the appeal is also denied, the company must provide contact information for the state attorney general’s office so you can escalate.

What “Deleted” Means for Backups

Even after a company confirms deletion from its active systems, your data almost certainly still exists in backup and disaster recovery copies. Backups are not designed for surgical removal of individual records, and this is where most people’s expectations run into technical reality.

The GDPR does not explicitly exempt backups. European regulators have taken a pragmatic line: data lingering in backups is acceptable temporarily provided the company puts it “beyond use.” The company cannot access or use the backed-up data operationally, must delete it when the backup is next refreshed or overwritten on a documented schedule, and must be transparent with you about the timeline. Backup cycles run from about 30 days to several months depending on the infrastructure.

U.S. state laws handle backups less explicitly, but the practical result is similar. If a company later restores a backup that contains records you had deleted, it must re-delete them. When you receive a deletion confirmation, the useful question is whether it covers backup and archival systems or only the active database. If the answer is unclear, push for specifics.

Deleting a Child’s Data Under COPPA

COPPA applies nationwide, regardless of state law. It covers websites and online services directed at children under 13, as well as general-audience services that knowingly collect personal information from children in that age group.

Under COPPA, parents can direct an operator to delete their child’s personal information at any time. The operator must comply and must also give parents the ability to refuse any further collection or use of the child’s data going forward.3eCFR. 16 CFR 312.6 – Right of Parent to Review Personal Information Provided by a Child One practical consequence: an operator that deletes a child’s data and loses parental consent may terminate the service, so expect account closure if the service needs personal data to function.

COPPA also limits how long operators can hold children’s data. An operator can retain it only as long as reasonably necessary for the purpose it was collected, and must maintain a written retention policy spelling out why the data is collected, the business need for keeping it, and the timeframe for deletion.4eCFR. 16 CFR Part 312 – Childrens Online Privacy Protection Rule If a children’s service cannot point you to a written policy or explain how long it keeps your child’s data, that is worth reporting to the FTC.

Data Brokers You’ve Never Heard Of

Companies you have accounts with are the easy target. Data brokers are harder. They collect and sell personal information about you without any direct relationship, pulling from public records, purchase histories, social media, and other sources to build profiles they sell on. You may never have heard of most of the brokers holding your data.

In states whose privacy laws cover data brokers, you can submit deletion requests the same way you would to any other business. The problem is scale. Hundreds of brokers may hold information about you, and contacting each individually is a significant undertaking. Some states have started requiring data brokers to register with a state authority, and at least one is building a centralized platform that will let consumers send a single deletion request to all registered brokers at once, with processing requirements beginning in mid-to-late 2026.

Verifying Deletion and Filing Complaints

A deletion confirmation email is a start, not proof. Data sometimes lingers in analytics platforms, third-party integrations, or archives even after the company confirms the active database is clean. The most effective verification is a follow-up access request, sometimes called a data subject access request, submitted a few weeks after you receive the deletion confirmation. If the company responds that it holds no personal data about you, that’s strong evidence the deletion was thorough. If it returns data that should have been erased, you now have documentation of non-compliance.

When a company ignores your request, misses the deadline, or gives an inadequate response, your enforcement path depends on which law applies. GDPR complaints go to the data protection authority in the relevant EU member state. In the U.S., the typical route is a complaint to your state attorney general’s consumer protection division. The FTC handles COPPA violations and deceptive privacy practices. Filing a complaint doesn’t guarantee an individual resolution, but agencies prioritize enforcement based on complaint volume, so reports matter even when they feel abstract.

Keep the full paper trail: the original request, the confirmation or reference number, any company responses, and any follow-up access requests. If the matter escalates, that documentation is the foundation of your case.