EnglishEspañol

How to Submit a Data Deletion Request (2026)

Independently fact-checked against primary sources (last audited August 14, 2026). · Reviewed by the RecordingLaw editorial team. · Law checked current as of August 14, 2026. · 9 primary sources cited on this page. How we verify our legal content

How to Submit a Data Deletion Request (2026)

Frequently Asked Questions

Can I submit a data deletion request to any company, or only certain ones?

Your deletion right only applies if a law covers both you (based on where you live) and the specific business. CCPA covers California residents dealing with for-profit businesses above certain size thresholds (annual revenue above $26.625 million, data on 100,000-plus consumers, or 50 percent of revenue from selling data). The EU GDPR covers anyone in the EU regardless of company size, and the UK GDPR mirrors it for UK residents. Virginia, Colorado, Connecticut, and Texas have similar state laws. If none of these laws apply, the company has no legal obligation to delete your data, though many companies honor voluntary requests.

How long does the company have to respond to my deletion request?

Under CCPA: 45 calendar days, with one possible 45-day extension for a 90-day maximum. The company must notify you within the first 45 days if it is using the extension. Under Virginia VCDPA and Colorado CPA: the same 45-plus-45-day schedule. Under GDPR: one calendar month, extendable by two additional months for complex or numerous requests. The company must notify you within the first month if it is extending the deadline. All responses must be free of charge.

What information do I need to include in a deletion request?

Include your full legal name, the email address or username on file with the company, a clear statement invoking your deletion right and the specific statute (for example, Cal. Civ. Code § 1798.105(a) or GDPR Article 17), and any account or order numbers that help the company locate your records. Do not include sensitive identifiers beyond what the company specifically requests for verification. Businesses may only use your verification information for identity verification and nothing else.

Can someone else submit a deletion request on my behalf?

Yes. Under CCPA you may designate an authorized agent (a person or a California-registered business entity) to submit the request on your behalf. The company may require written proof of your authorization and may ask you to verify your identity directly with the business rather than through the agent. Virginia, Colorado, and Connecticut have similar authorized-agent rules. For elderly relatives, people with disabilities, or privacy attorneys filing for clients, the authorized agent pathway is the standard approach.

What happens if the company ignores my deletion request?

Failing to respond within the statutory deadline is a violation of the applicable law. In California, file a complaint with the California Privacy Protection Agency at cppa.ca.gov or the Attorney General at oag.ca.gov. Fines can reach $7,500 per intentional violation. In Virginia, use the internal appeal process and then contact the Virginia AG. Under GDPR, lodge a complaint with your national data protection authority. GDPR fines can reach EUR 20 million or 4 percent of global annual revenue. There is no private right of action for deletion refusals under CCPA or VCDPA; the remedy is a regulator complaint.

Is the GDPR right to be forgotten the same as the CCPA right to delete?

They are similar in purpose but differ in scope, grounds, and timelines. GDPR Article 17 has six grounds for erasure (including withdrawal of consent and objection to processing) and applies to all controllers regardless of size. CCPA Section 1798.105 applies only to covered businesses above size thresholds and lists eight specific exceptions. GDPR's response deadline is one month; CCPA's is 45 days. Both are free, and both require the controller to cascade the deletion to service providers, processors, and third parties who received the data.

Will deleting my data affect my account or services?

Possibly. If the company needs your data to maintain your account, complete an ongoing service, or fulfill a contract, it may be exempt from deleting certain records under Cal. Civ. Code § 1798.105(d)(1). However, it cannot punish you for submitting a deletion request. Under CCPA Section 1798.125, businesses cannot deny service, charge higher prices, or provide a lower level of service solely because you exercised your privacy rights. Submitting a request should never trigger retaliatory treatment.

What can a business do with my data after I submit a deletion request but before it responds?

Once a verified deletion request is received, the business should not be using your personal data for new purposes. While it technically has up to 45 days (or longer with an extension) to complete the deletion, it cannot use that window to re-sell your data or expand its processing. It may retain a minimal internal record that a request was received (necessary to honor the deletion and prevent future sales), but that record cannot be used for any other commercial purpose under CCPA regulations.

Updates

Corrected the deletion deadline for California data brokers responding through the DROP platform to 45 days (the statute sets 45, not 90), repointed the Colorado response-timeline citation to the subsection that actually contains it, and clarified that UK residents are covered by the UK GDPR rather than the EU regulation.

Corrected the authorized-agent regulatory citations to the current CCPA regulations, updated the CCPA revenue threshold to the CPI-adjusted figure, and refreshed the DROP registered-broker count.

Independently fact-checked against the cited primary sources; governing law re-checked for recent changes

Governing law re-checked for recent changes

Reviewed and approved by an editor

Sources and References

  1. Cal. Civ. Code § 1798.105: Right to Delete Personal Information (CCPA/CPRA)(leginfo.legislature.ca.gov).gov
  2. California AG: CCPA Consumer Rights Overview(oag.ca.gov).gov
  3. California Privacy Protection Agency: DROP Platform(privacy.ca.gov).gov
  4. GDPR Art. 17: Right to Erasure (Right to be Forgotten), Regulation (EU) 2016/679(eur-lex.europa.eu).gov
  5. GDPR Art. 12: Transparent Information and Response Timelines, Regulation (EU) 2016/679(eur-lex.europa.eu).gov
  6. Va. Code Ann. § 59.1-577: VCDPA Consumer Rights Including Deletion(law.lis.virginia.gov).gov
  7. Colorado SB 21-190: Colorado Privacy Act (CPA), C.R.S. § 6-1-1306(leg.colorado.gov).gov
  8. Cal. Code Regs. tit. 11, §§ 7001(d), 7060-7063: Authorized Agents and Identity Verification(cppa.ca.gov).gov
  9. California Privacy Protection Agency: Enforcement and Complaint Filing(cppa.ca.gov).gov
  10. Cal. Civ. Code § 1798.99.86: Accessible Deletion Mechanism (DROP) and 45-Day Data Broker Deletion Deadline(leginfo.legislature.ca.gov)
  11. Data Protection Act 2018 § 3: Definitions of the UK GDPR and the EU GDPR(legislation.gov.uk)
Share: