Privacy GuideJuly 16, 202611 min read

How to Write a Data Deletion Request Letter (With Templates)

PT

By PrivacyOn Team

Privacy Research & Removal Operations

How to Write a Data Deletion Request Letter (With Templates)

Don't want to do this by hand? We remove your info from 100+ broker sites automatically.

A data deletion request letter is a formal written request asking a company to delete your personal data under laws like CCPA, GDPR, or a state privacy statute. It must identify you, cite the specific law, name the data to delete, set the legal deadline (30-45 days), and go out via certified mail or documented email so you have a paper trail if you need to escalate.

When You Need a Formal Letter

A formal data deletion request letter is appropriate in several situations:

  • The company has no online opt-out form: Some data brokers and businesses only accept requests via email or postal mail.
  • The online form did not work: You submitted a request through their website but your data is still listed weeks or months later.
  • The company ignored your initial request: You received no response within the legally required timeframe.
  • You want a paper trail: A formal letter, especially one sent via certified mail, creates documented evidence that you made the request -- which is critical if you need to escalate to a regulator.
  • You are exercising rights under a specific privacy law: Citing the applicable statute makes it clear that the business has a legal obligation to respond.

Which 2026 Privacy Law Applies to You

The legal basis for your request depends on where you live and, in some cases, where the business is located. Twenty U.S. states now have comprehensive consumer privacy laws in force as of mid-2026. Here are the major statutes you can cite:

  • CCPA/CPRA (California): California Consumer Privacy Act, Section 1798.105 -- right to delete personal information.
  • VCDPA (Virginia): Virginia Consumer Data Protection Act -- right to delete personal data.
  • CPA (Colorado): Colorado Privacy Act -- right to delete personal data.
  • CTDPA (Connecticut): Connecticut Data Privacy Act -- right to delete personal data.
  • TDPSA (Texas): Texas Data Privacy and Security Act -- effective July 2024, right to delete personal data.
  • UCPA (Utah): Utah Consumer Privacy Act -- right to delete personal data.
  • OCPA (Oregon): Oregon Consumer Privacy Act -- effective July 2024, right to delete.
  • MCDPA (Montana): Montana Consumer Data Privacy Act -- effective October 2024.
  • TIPA (Tennessee), Iowa, Delaware, New Hampshire, New Jersey: All effective in 2025 with right-to-delete provisions.
  • RIDTPPA (Rhode Island), Indiana, Kentucky, Maryland, Minnesota: Effective January 1, 2026 or later in 2026, right to delete personal data.
  • GDPR (European Union/UK): Article 17 -- right to erasure. Applies to EU/UK residents or when an EU/UK-based company processes your data.

If your state does not have a comprehensive privacy law yet, you can still cite the federal Fair Credit Reporting Act (FCRA) if the company qualifies as a consumer reporting agency, or reference the company's own privacy policy, which often includes commitments to honor deletion requests.

Key Elements of an Effective Letter

Your data deletion request letter should include these essential components:

1. Identify Yourself -- But Do Not Over-Share

Provide enough information for the company to locate your records, but do not hand over more data than necessary. Typically, your full name, email address, and mailing address are sufficient. Never include your Social Security number unless the company specifically requires it to process your request, and even then, consider whether you trust the company with that information.

2. Cite the Applicable Law

Explicitly name the law under which you are making your request and reference the specific section. For example:

  • "Pursuant to Section 1798.105 of the California Consumer Privacy Act (CCPA)"
  • "Under Article 17 of the General Data Protection Regulation (GDPR)"
  • "In accordance with the Virginia Consumer Data Protection Act (VCDPA)"

Citing the specific law signals that you know your rights and understand the company's legal obligations. Vague requests without legal citations are much easier for companies to ignore.

3. Specify What You Want Deleted

Be clear about what data you want removed. You can request deletion of all personal data the company holds about you, or you can target specific categories such as your home address, phone number, or financial information. The more specific your request, the harder it is for the company to claim confusion about what you are asking for.

4. Set a Deadline

Reference the legally mandated response timeframe. Most state privacy laws require a response within 30 to 45 days:

  • CCPA/CPRA: 45 days, with a possible 45-day extension.
  • VCDPA, CPA, CTDPA, TDPSA: 45 days, with a possible 45-day extension.
  • GDPR: 30 days (one month), with a possible 60-day extension for complex requests.
  • RIDTPPA: 45 days, with a possible 45-day extension.

5. State the Consequences of Non-Compliance

Politely but clearly note that failure to comply may result in a complaint to the appropriate regulatory authority. This is not a threat -- it is a statement of fact about your rights under the law.

Sample Data Deletion Request Letter (2026)

[Your Name]
[Your Address]
[Your Email]
[Date]

[Company Name]
Privacy Department / Data Protection Officer
[Company Address]

Dear Privacy Team,

I am writing to request the deletion of all personal data your company holds about me, pursuant to [Section 1798.105 of the California Consumer Privacy Act / Article 17 of the GDPR / applicable state law].

My identifying information for locating my records:
Full Name: [Your Name]
Email Address: [Your Email]
Mailing Address: [Your Address]

Please delete all personal data associated with me, including but not limited to my name, address, phone number, email address, and any other personally identifiable information in your systems. Please also confirm in writing when the deletion is complete, and instruct any third parties to whom you have sold or shared my data to do the same.

Under [applicable law], you are required to respond to this request within [30/45] days. If you are unable to fulfill this request, please provide a written explanation of the legal basis for your refusal.

If I do not receive a satisfactory response within the required timeframe, I intend to file a complaint with [the California Privacy Protection Agency / my state Attorney General / the relevant supervisory authority].

Thank you for your prompt attention to this matter.

Sincerely,
[Your Name]

How to Send Your Letter

The method of delivery matters for creating a verifiable paper trail:

  • Certified mail with return receipt: The gold standard. Proof of delivery, a stamped receipt, and a signed green card if you need to escalate. Costs about $4-$8 in 2026 -- money well spent for high-stakes requests.
  • Email with read receipt: Faster than postal mail and acceptable for most requests. Save the sent email along with any delivery confirmations, and CC yourself so the message lives in two mailboxes.
  • Online privacy request portals: If the company offers one, use it -- but also send a follow-up email or letter referencing your submission with the date and confirmation number.

Regardless of the method, always keep copies of everything you send and receive. Save screenshots of online submissions, confirmation emails, and postal receipts in a dedicated folder.

Skip the manual work

PrivacyOn removes your personal information from 100+ data broker sites and keeps it removed — automatically.

Start your free scan

★★★★★ 4.8/5 · Trusted by thousands of families

Following Up on Your Request

Track the deadline from the date your letter was received, not the date you sent it. If you have not received a response by the deadline:

  1. Send a follow-up letter or email referencing your original request, the date it was sent, and the legal deadline that has passed.
  2. Check whether your data has actually been removed by searching for yourself on the site or requesting a copy of any remaining data.
  3. Document the company's failure to respond -- this documentation is critical for regulatory complaints.

When to Escalate

If a company ignores your request or denies it without a valid legal basis, you have escalation options:

  • California Privacy Protection Agency (CPPA): California's dedicated privacy regulator has aggressively enforced CCPA/CPRA since taking over from the AG. File at cppa.ca.gov.
  • Your state Attorney General: Most state privacy laws are enforced by the AG's office. File a complaint through their website and include copies of all your correspondence.
  • File a complaint with the FTC: The Federal Trade Commission handles complaints about unfair or deceptive business practices, including data privacy violations. File at reportfraud.ftc.gov.
  • File with a data protection authority (GDPR): If you are in the EU or UK, file with your national data protection authority. The UK's ICO and Ireland's DPC are especially active.
  • Consult a privacy attorney: For persistent violations involving sensitive data, legal counsel may be worthwhile. California's CCPA allows statutory damages of $100-$750 per consumer per incident in the event of a data breach.

Do Not Threaten Litigation Unless You Mean It

Vague threats of lawsuits in a deletion request letter can undermine your credibility and may cause the company to route your request to their legal department, which often slows down the process rather than speeding it up. Stick to referencing the specific law and the regulatory complaint process. That is usually enough to get results.

Let PrivacyOn Handle It Automatically

Writing, sending, tracking, and following up on data deletion requests across dozens of data brokers is a major time commitment. And even when you succeed, many brokers re-list your data within months, requiring you to start the process all over again.

PrivacyOn automates the entire data removal process. PrivacyOn submits opt-out and deletion requests to over 100 data broker sites on your behalf, tracks responses, follows up on ignored requests, and continuously monitors for re-listings. Family plans cover up to five people. Instead of spending hours drafting letters and tracking deadlines, you can let PrivacyOn handle it -- starting at just $8.33 per month. Start with a free scan to see where your data appears.

Frequently Asked Questions

Do I need to send a data deletion request letter by certified mail?

Not always. Email is legally sufficient in most jurisdictions, and many companies offer online portals that satisfy the same purpose. Certified mail is worth the $4-$8 in three cases: the company has ignored an earlier email, you plan to file a regulatory complaint if they refuse, or the request involves sensitive data (medical, financial) where a paper trail is important.

How long does a company have to respond to a data deletion request?

Under most U.S. state privacy laws (CCPA, VCDPA, CPA, CTDPA, TDPSA, OCPA), the response deadline is 45 days, with a possible 45-day extension for complex requests. Under the GDPR, the deadline is 30 days (one month), extendable to 90 days. The clock starts the day the company receives your request, not the day you send it.

What can I do if a company ignores my deletion request?

Send one follow-up citing the missed deadline, then escalate. In California, file with the California Privacy Protection Agency (CPPA) at cppa.ca.gov. In other states, file with your Attorney General. For GDPR violations, file with your national data protection authority. Include copies of your original request, delivery receipts, and any responses (or lack thereof).

Can I use a data deletion request letter if my state does not have a privacy law?

Yes, though it carries less legal weight. Cite the company's own published privacy policy (which almost always includes deletion commitments), and reference the FTC's authority under Section 5 of the FTC Act to enforce unfair or deceptive practices. Many companies honor requests from any U.S. resident to avoid regulatory scrutiny, even without a state law on your side.

Should I include my Social Security number in a deletion request?

No -- unless the company specifically requires it to locate your records and you trust them with it. Most identity-verification steps only need your name, email, and mailing address. Handing over an SSN to a data broker who already has too much information about you is exactly the kind of over-sharing that fuels the problem.

Does PrivacyOn send deletion request letters for me?

Yes. PrivacyOn submits legally-worded opt-out and deletion requests to 100+ data brokers on your behalf, using each broker's preferred channel (portal, email, or certified letter where required). PrivacyOn tracks responses, follows up on ignored requests, and re-submits when brokers relist your data -- for $8.33/month with family coverage for up to five people.

PT
PrivacyOn Team

Privacy Research & Removal Operations

Operates removal across 100+ data broker sitesGuides verified against live opt-out processesContent reviewed and updated continuously

The team that operates PrivacyOn's data-removal service — publishing opt-out guides and privacy research based on handling real removal requests every day.

Your info is on 100+ broker sites. Take it down.

Let PrivacyOn automatically remove your personal information from data broker sites and keep it removed.

★★★★★ 4.8/5 · Trusted by thousands of families