Write a legally worded request to delete, access or stop the sale of your data, with the deadline and a follow-up letter.
The letter is written in your browser and your name, email and details are never sent to us. The tracker saves only company names, dates and statuses, in this browser and in your account if you are signed in.
Most people know companies hold too much data about them. Far fewer know that in many places the law gives you the right to make a company delete it, show you what it holds, or stop selling it, and that the company has a fixed number of days to answer. The hard part is writing a request that cites the right law, asks for the right things, and cannot be brushed off as a customer service ticket.
This generator writes that letter for you. Choose where you live and what you want, add the company and the details it holds about you, and you get a complete letter that cites the correct law and articles or sections, the exact deadline the company must meet, the regulator to complain to if it does not, and a follow-up letter ready for the day the deadline passes. It covers the GDPR in the EU, the UK GDPR, the CCPA in California, eighteen other US state privacy laws, the Australian Privacy Act, PIPEDA in Canada and Quebec's Law 25.
Every letter is honest about what the law actually allows. Where a right is narrower than people assume, such as deletion in Australia or data you did not provide in Iowa and Utah, the tool tells you before you send it.
Data protection rights are routinely used and routinely ignored. Companies receive deletion and access requests every day, but a request that arrives as a vague complaint through a support chat is easy to close without action. A written request that names the law and the deadline goes to the privacy or legal team, starts a clock the company is accountable for, and creates the paper trail a regulator will ask to see.
People-search sites and data brokers are the most common target. In California, the Delete Act created the Delete Request and Opt-out Platform, known as DROP, which since January 2026 has let residents send one deletion request to every registered data broker, and brokers have had to start processing those requests from August 2026. Residents of other states and countries still write to brokers one at a time, and an emailed request citing the law is often the fallback when an opt-out form is broken or demands more ID than it should.
Access requests are a powerful first step. Under the GDPR, the CCPA and PIPEDA you can ask a company what it holds, where it got it and who it shared it with. The answer often reveals the broker or partner that sold your details, which tells you where to send the next deletion request.
The rules are not the same everywhere, and knowing the difference saves wasted effort. Australia has no general right to erasure yet, so a deletion request relies on the rule that organisations must destroy information they no longer need. Utah and Iowa only require deletion of data you gave the company yourself. Most US state laws only apply to larger businesses. A letter that asks for what the law actually allows is far more likely to be honoured.
In many places, yes. The GDPR in the EU and the UK GDPR give a right to erasure under Article 17. California residents have a right to delete under the CCPA, and most other US states with a comprehensive privacy law give a similar right. In Australia and Canada there is no standalone right to erasure yet, but organisations must destroy or anonymise information they no longer need, and you can withdraw consent or ask for access and correction.
Under the GDPR and UK GDPR, one calendar month, extendable by two further months for complex requests if the company tells you why. Under the CCPA, 45 calendar days, extendable once by 45 days, with confirmation of receipt within 10 business days. Most other US state laws allow 45 days, and Iowa allows 90. Australian organisations should respond within a reasonable period, usually no more than 30 days, and Canadian organisations must answer access requests within 30 days.
You do not have to explain yourself at length, but erasure applies when one of the grounds in Article 17(1) is met, such as the data no longer being needed, withdrawing consent, or objecting to processing. Citing the ground that fits your situation makes the request harder to refuse, which is why the generator asks you to choose one.
Not upfront. Send the request from the email address the company already has, and include identifiers it already holds, such as a username or account number. A company may ask for more if it has reasonable doubt about who you are, but it should ask only for what is necessary. If a people-search site demands a government ID, ask why and consider covering the ID number and photo.
Send the follow-up letter, which gives seven days and says you will escalate. If there is still no answer, complain to the regulator: the ICO in the UK, your national data protection authority in the EU, the California Privacy Protection Agency or your state Attorney General in the US, the OAIC in Australia, or the Privacy Commissioner of Canada. Include copies of your request and follow-up.
No. Closing an account often just deactivates it, and the company may keep your data for years. A deletion request asks for the data itself to be erased and for anyone the company shared it with to be told. Close the account first if you want, then send the request.
Deletion removes the data the company holds. Opting out, such as a Do Not Sell or Share request under the CCPA or a direct marketing objection under the GDPR, stops the company selling your data or using it for marketing but lets it keep the data. You can ask for both in one letter.