Sometimes. If you live in one of the 20 U.S. states with a comprehensive privacy law — or in the EU or UK — you have a legal right to demand deletion, and the company must respond within 45 days. But that right comes with broad exemptions. A company can lawfully refuse when it needs your data to finish a transaction, fight fraud, or satisfy its own legal obligations.
The Short Answer: It Depends on Three Things
Whether you can actually force deletion turns on three questions, in this order:
- Where do you live? Deletion rights in the United States are granted by state, not federally. If your state has no comprehensive privacy law, most companies can simply say no.
- Is the company covered? Every state law has revenue or volume thresholds, plus entity-level exemptions for banks, hospitals, nonprofits, and government agencies.
- Does an exemption apply to that specific data? Even a covered company can keep records it needs for fraud prevention, legal compliance, security, or an active contract with you.
Get all three answers in your favor and the company must delete. Miss any one and your request becomes a polite ask rather than an enforceable demand.
Where You Have a Real Right to Delete
United States: 20 States and Counting
As of 2026, roughly 20 states have comprehensive consumer privacy laws that include a right to delete personal data — among them California, Virginia, Colorado, Connecticut, Utah, Texas, Oregon, Montana, Delaware, Iowa, Nebraska, New Hampshire, New Jersey, Tennessee, Minnesota, Maryland, Indiana, Kentucky and Rhode Island. The mechanics are broadly similar:
- You submit a verifiable consumer request — the company is allowed to confirm you are who you say you are before deleting anything.
- The company has 45 days to respond, extendable once by another 45 days with written notice. Ninety days is the practical outer limit.
- The company must pass your request down the chain to the service providers and vendors it shared your data with.
- You cannot be charged, and you cannot be penalized with worse pricing or service for exercising the right.
EU and UK: The Strongest Version
Under GDPR Article 17 — the "right to erasure," commonly called the right to be forgotten — you can demand deletion when the data is no longer necessary, when you withdraw the consent it was based on, when you object and no overriding legitimate interest exists, or when it was processed unlawfully. The response deadline is one month, extendable to three for complex requests. Enforcement has teeth: data protection authorities can fine up to 4% of global annual turnover.
No Federal U.S. Deletion Right Exists Yet
There is still no general federal law giving Americans a right to delete their data. Bills introduced in 2026, including the SECURE Data Act and the GUARD Financial Data Act, would create data-broker registration and portability requirements — but until something passes, your zip code determines your rights. Sector laws (HIPAA for health records, FCRA for credit files, GLBA for financial accounts) grant correction and access rights but generally not deletion.
The Seven Reasons a Company Can Legally Say No
These exemptions appear, with small variations, in nearly every state privacy law. A company that cites one of them is usually on solid ground:
- Completing a transaction. They can keep what they need to deliver the product, honor a warranty, or finish a service you requested.
- An ongoing relationship. If you still have an active account, subscription, or contract, the data supporting it stays.
- Legal obligations. Tax records, employment files, and regulated financial records carry statutory retention periods that override your request.
- Fraud and security. Companies may retain data to detect security incidents, investigate fraud, and prosecute those responsible — this is the exemption most often invoked.
- Internal uses you would reasonably expect. A narrow category, but real, covering uses aligned with the context in which you provided the data.
- Free speech and public interest. Journalism, public records, and lawful publication are generally protected. This is why a news article about you does not have to come down.
- Exempt entities and data types. Data covered by HIPAA, GLBA, FCRA, FERPA or the Driver's Privacy Protection Act is typically carved out of state privacy laws entirely.
Deletion Does Not Always Mean Erasure
Most state laws let a company satisfy a deletion request by de-identifying or aggregating the data instead of destroying it, and nearly all allow retention in backup and archive systems until those systems cycle on their normal schedule. A compliant "we deleted your data" can still mean a copy sits in a backup tape for another six months. That is legal.
Skip the manual work
PrivacyOn removes your personal information from 100+ data broker sites and keeps it removed — automatically.
Start your free scan★★★★★ 4.8/5 · Trusted by thousands of families
How to Make a Request That Is Hard to Refuse
Vague requests get vague answers. A request that names the law, the data, and the deadline gets routed to someone who handles compliance:
- Find the right channel. Look for "Do Not Sell or Share My Personal Information" or "Privacy Rights" in the site footer, or the privacy contact in the privacy policy. Using the official channel starts the statutory clock.
- Name your law. Write "I am a California resident exercising my right to delete under the CCPA as amended by the CPRA" — or your state's equivalent, or GDPR Article 17.
- Be specific about scope. Ask for deletion of all personal information they hold, and explicitly include data shared with service providers and third parties.
- Verify promptly. Companies are allowed to request identity verification, and many requests die because the consumer ignored the verification email. Answer it — but do not send a photo of your ID unless the data at issue genuinely warrants that level of proof.
- State the deadline. "I expect a substantive response within 45 days as required by statute."
- Keep everything. Save the submission confirmation, the timestamps, and every reply. Documentation is what makes a complaint credible.
What to Do When a Company Refuses
You have escalation options, and they cost nothing:
- Ask them to cite the exemption. Most state laws require the company to explain a denial. A refusal that names no legal basis is a weak refusal.
- Appeal. Virginia, Colorado, Connecticut and most newer state laws give you a statutory right to appeal a denial, and the company must respond to the appeal in writing.
- File with your state attorney general. In most states the AG is the enforcement authority, and complaints are free to file online. California adds the California Privacy Protection Agency.
- Complain to the FTC. Deceptive privacy promises — a company that publishes a deletion policy and then ignores it — are an FTC enforcement matter under Section 5.
- EU and UK residents: file with your national data protection authority, which can investigate and fine.
Data Brokers Are the Exception Worth Knowing
Data brokers are the category where deletion rights actually bite hardest, because they have the fewest exemptions to hide behind. They have no transaction with you to complete, no contract to service, and no ongoing relationship to protect — so the usual refusals do not apply.
California residents get the strongest tool in the country here. The Delete Request and Opt-out Platform (DROP), run by the California Privacy Protection Agency, lets you file one verified request that reaches every data broker registered with the state. Since August 1, 2026, registered brokers have been required to check DROP and process deletion requests on a recurring 45-day cycle. It is free, and it covers hundreds of companies in a single submission.
Everyone else has to go broker by broker — and there are hundreds, each with its own form, its own verification email, and its own habit of re-listing you 30 to 90 days later when it re-imports public records. That is not a one-time project; it is a standing chore.
PrivacyOn handles it for you: continuous removal across 100+ data broker and people-search sites, automatic re-filing when your data reappears, 24/7 dark web monitoring for leaked credentials, and family plans covering up to 5 people from $8.33/month. Start with a free scan to see which brokers are publishing your name, address and phone right now.
Frequently Asked Questions
Can I force any company to delete my data?
No. You can force deletion only when a law covers both you and the company, and no exemption applies to the specific data. In the U.S. that means living in one of roughly 20 states with a comprehensive privacy law, and dealing with a business that meets that law's revenue or data-volume threshold. Outside those conditions, deletion is a courtesy the company may decline.
How long does a company have to respond to a deletion request?
Most U.S. state laws give 45 days, extendable once by another 45 with notice, for a 90-day outer limit. Under GDPR the deadline is one month, extendable to three months for complex or numerous requests. The clock starts when you submit through the company's designated privacy channel, not when you email a random support address.
What are the most common legal reasons a deletion request is denied?
Fraud prevention and security, statutory record-retention obligations such as tax and employment records, an active contract or account, and completing a transaction you requested. Free-speech and public-records carve-outs explain why news coverage and court records generally stay up. A denial should cite a specific basis — if it does not, push back and ask which exemption applies.
Does deleting my data remove me from Google search results?
Not by itself. Getting a company to delete your record removes it at the source, but Google may still show a cached result until it recrawls. Submit a removal through Google's Results About You tool for phone numbers, addresses and emails to suppress the listing in Search while the source page drops out of the index.
Do data brokers have to honor deletion requests?
In covered states, yes — and brokers have fewer exemptions available than ordinary businesses, because they have no transaction or contract with you to protect. The practical problem is not the law but the volume: hundreds of brokers, each with its own form, each re-importing public records every 30 to 90 days and re-listing you. Compliance is per-request, not permanent.
Is there a faster way than filing hundreds of individual requests?
For Californians, yes: DROP reaches every state-registered broker in one verified submission. For everyone else, an automated removal service is the realistic option. PrivacyOn files and re-files removals across 100+ broker and people-search sites, verifies the confirmation emails, monitors for re-listings, and adds dark web monitoring — from $8.33/month, with family plans for up to 5 people and a free scan before you commit.