Data Deletion Request Letter Generator

Write a legally worded request to delete, access or stop the sale of your data, with the deadline and a follow-up letter.

The letter is written in your browser and your name, email and details are never sent to us. The tracker saves only company names, dates and statuses, in this browser and in your account if you are signed in.

Most people know companies hold too much data about them. Far fewer know that in many places the law gives you the right to make a company delete it, show you what it holds, or stop selling it, and that the company has a fixed number of days to answer. The hard part is writing a request that cites the right law, asks for the right things, and cannot be brushed off as a customer service ticket.

This generator writes that letter for you. Choose where you live and what you want, add the company and the details it holds about you, and you get a complete letter that cites the correct law and articles or sections, the exact deadline the company must meet, the regulator to complain to if it does not, and a follow-up letter ready for the day the deadline passes. It covers the GDPR in the EU, the UK GDPR, the CCPA in California, eighteen other US state privacy laws, the Australian Privacy Act, PIPEDA in Canada and Quebec's Law 25.

Every letter is honest about what the law actually allows. Where a right is narrower than people assume, such as deletion in Australia or data you did not provide in Iowa and Utah, the tool tells you before you send it.

How it works

  1. Choose where you live. The law that protects you usually depends on your location, not where the company is based, so a Californian can use the CCPA against a company in another state.
  2. Tick what you want: deletion, a copy of your data, an end to selling and marketing, or a correction. You can combine them in one letter.
  3. For GDPR and UK GDPR erasure, pick the reason that fits. The letter then cites the matching ground in Article 17, which is harder for a company to dispute than a general request.
  4. Enter the company's name, its privacy email if you have it, and the name, email and other identifiers the company already holds, such as a username or a people-search listing URL.
  5. The letter is assembled in your browser from wording written for each law, with the correct article or section for every request, a request for written confirmation, and a line asking the company to request only the identification it truly needs.
  6. The deadline is calculated from the date you send it, using one calendar month for the GDPR, 45 days for the CCPA and most state laws, 90 days for Iowa, and 30 days for Australia, Canada and Quebec.
  7. Copy the letter, open it in your email app, or download it. Then add it to your tracker, which flags the request when the deadline passes and gives you the follow-up letter.

Reading your results

  • They must reply by shows the date the legal deadline falls, counted from the day you send the letter. If you post it, add a few days for delivery.
  • The extension note explains how much longer the company can legally take and what it must tell you to use that time. A company that goes quiet without explaining a delay has missed the deadline.
  • Your letter is the complete text to send. The numbered requests each cite their own legal basis, so a company cannot answer one part and ignore the rest without saying why.
  • Warnings are the honest limits of your request under that law, such as records a company can keep for tax purposes, business size thresholds, or rights your state does not include.
  • How to send it so it counts lists the steps that avoid the most common delays, starting with sending from the email address the company already knows.
  • The regulator line names the body that takes complaints when a company ignores or refuses a valid request, with a link to its complaint page where one exists.
  • The follow-up letter restates your original request, the date it was sent and the deadline that passed, and gives the company seven days before you escalate.
  • The request tracker lists every letter you mark as sent, with its deadline and status. Overdue requests are highlighted with a one click copy of the follow-up letter.

How this fits into the real world

Data protection rights are routinely used and routinely ignored. Companies receive deletion and access requests every day, but a request that arrives as a vague complaint through a support chat is easy to close without action. A written request that names the law and the deadline goes to the privacy or legal team, starts a clock the company is accountable for, and creates the paper trail a regulator will ask to see.

People-search sites and data brokers are the most common target. In California, the Delete Act created the Delete Request and Opt-out Platform, known as DROP, which since January 2026 has let residents send one deletion request to every registered data broker, and brokers have had to start processing those requests from August 2026. Residents of other states and countries still write to brokers one at a time, and an emailed request citing the law is often the fallback when an opt-out form is broken or demands more ID than it should.

Access requests are a powerful first step. Under the GDPR, the CCPA and PIPEDA you can ask a company what it holds, where it got it and who it shared it with. The answer often reveals the broker or partner that sold your details, which tells you where to send the next deletion request.

The rules are not the same everywhere, and knowing the difference saves wasted effort. Australia has no general right to erasure yet, so a deletion request relies on the rule that organisations must destroy information they no longer need. Utah and Iowa only require deletion of data you gave the company yourself. Most US state laws only apply to larger businesses. A letter that asks for what the law actually allows is far more likely to be honoured.

Who this is for

  • Anyone who closed an account and wants the company to delete what it still holds.
  • People removing themselves from people-search sites when the opt-out form fails or does not exist.
  • Anyone who wants to know what a company holds about them and who it sold or shared it with.
  • People receiving marketing from a company they never signed up with, who want it stopped and want to know the source.
  • Anyone whose data was exposed in a breach and wants the company to stop keeping more than it needs.

What this tool cannot tell you

  • This is not legal advice. The letters are written to match each law as it stood in September 2026, but laws and regulator guidance change, and your situation may involve exemptions a general letter cannot account for.
  • A company can lawfully refuse or partly refuse. Records needed for tax, fraud prevention, legal claims or ongoing contracts can usually be kept, and the company should tell you what it kept and why.
  • US state laws only cover businesses above size or data volume thresholds, and the Australian Privacy Act exempts most businesses with an annual turnover of 3 million dollars or less.
  • Deletion only covers the company you write to. Copies already sold or shared elsewhere need their own requests, although several laws require the company to pass your request on.
  • The tool does not send the letter or monitor replies for you. You send it, and you update the tracker when the company responds.

Frequently asked questions

Can I ask a company to delete my personal data?

In many places, yes. The GDPR in the EU and the UK GDPR give a right to erasure under Article 17. California residents have a right to delete under the CCPA, and most other US states with a comprehensive privacy law give a similar right. In Australia and Canada there is no standalone right to erasure yet, but organisations must destroy or anonymise information they no longer need, and you can withdraw consent or ask for access and correction.

How long does a company have to respond to a deletion request?

Under the GDPR and UK GDPR, one calendar month, extendable by two further months for complex requests if the company tells you why. Under the CCPA, 45 calendar days, extendable once by 45 days, with confirmation of receipt within 10 business days. Most other US state laws allow 45 days, and Iowa allows 90. Australian organisations should respond within a reasonable period, usually no more than 30 days, and Canadian organisations must answer access requests within 30 days.

Do I need to give a reason for a GDPR erasure request?

You do not have to explain yourself at length, but erasure applies when one of the grounds in Article 17(1) is met, such as the data no longer being needed, withdrawing consent, or objecting to processing. Citing the ground that fits your situation makes the request harder to refuse, which is why the generator asks you to choose one.

Should I send ID with my request?

Not upfront. Send the request from the email address the company already has, and include identifiers it already holds, such as a username or account number. A company may ask for more if it has reasonable doubt about who you are, but it should ask only for what is necessary. If a people-search site demands a government ID, ask why and consider covering the ID number and photo.

What can I do if a company ignores my request?

Send the follow-up letter, which gives seven days and says you will escalate. If there is still no answer, complain to the regulator: the ICO in the UK, your national data protection authority in the EU, the California Privacy Protection Agency or your state Attorney General in the US, the OAIC in Australia, or the Privacy Commissioner of Canada. Include copies of your request and follow-up.

Is a deletion request the same as closing my account?

No. Closing an account often just deactivates it, and the company may keep your data for years. A deletion request asks for the data itself to be erased and for anyone the company shared it with to be told. Close the account first if you want, then send the request.

What is the difference between a deletion request and opting out?

Deletion removes the data the company holds. Opting out, such as a Do Not Sell or Share request under the CCPA or a direct marketing objection under the GDPR, stops the company selling your data or using it for marketing but lets it keep the data. You can ask for both in one letter.

Related tools

Guides that go with this tool