If you want a company to remove your personal information, there isn't one U.S. form that erases it everywhere. The next step depends on who holds the data, where you live, and whether you need deletion, an opt-out, account closure, or help after a breach.
California residents can send data-broker deletion requests through the California Delete Request and Opt-out Platform (DROP). Other consumers generally have to use each company's own privacy process and check the rights available in their state.
This is general consumer information, not legal advice. Privacy rights and exceptions vary.
Decide what you want the company to do
These requests are related, but they don't do the same job:
| Your goal | Request to make | What it usually does not guarantee |
|---|---|---|
| Remove personal information | A deletion request | Removal from other companies' databases, public records, or data already copied elsewhere |
| Stop certain data sharing | An opt-out of sale or sharing | Deletion of information the company is allowed to retain |
| Close an account | An account-closure request | Immediate removal of records needed for transactions, fraud prevention, or other permitted purposes |
| Respond to a breach | A security and breach-response request | Automatic deletion, compensation, or a universal response deadline |
Unsubscribing from marketing email only changes one communications channel. Clearing browser cookies removes information from your device, not necessarily what a company already stored on its servers. Say exactly which outcome you want.
You may need more than one request. A loyalty-program member might ask a business to delete an old profile but keep a current account. Someone who still uses an app might choose an opt-out instead of account closure. A retailer can hold purchase records, an advertising partner can hold an identifier, and a data broker can hold contact information from another source. One request doesn't automatically reach all of them.
What rule controls your request?
State privacy law
The United States does not have one general deletion process covering every business. State laws can differ in who is covered, which rights are available, how identity is verified, and what exceptions apply.
California's CCPA gives qualifying consumers rights that include requesting to know what information a business holds, requesting deletion, and opting out of certain sales or sharing. The EPIC CCPA overview includes sample request language and links to related California resources.
Living in a state with a privacy law doesn't automatically mean every organization must delete every record. The business may not be covered, or an exception may apply.
The company's privacy process
Even where a specific legal right is uncertain, a company may still offer account deletion or privacy controls. Look for:
- Privacy center or privacy choices
- Delete account or close account
- Submit a privacy request
- Do Not Sell or Share My Personal Information
- A privacy email address or web form
- Instructions for former customers
Use the company's official website or app. Don't enter identity documents into a link from an unexpected email or text message.
A data broker's process
A data broker is different from a retailer, social network, bank, or app where you created an account. Removing information from one retailer does not necessarily remove a broker's copy. You'll usually need separate requests unless a state-operated platform covers the broker.
California residents: use CCPA rights and DROP carefully
Start with the business that collected your information. Ask for deletion if you want the data removed. Ask to opt out of sale or sharing if you want to limit specified uses while keeping an account or service.
DROP is built for deletion requests to data brokers, not as a general account-deletion form for every company. Before you submit, the platform requires you to verify that you are a California resident as defined in section 17014 of Title 18 of the California Code of Regulations, as that section read on September 1, 2017. If the verification providers can't confirm your status, the platform says you may request a review of the residency classification under section 7622 of Title 11 of the California Code of Regulations.
Beginning August 1, 2026, data brokers must process DROP deletion requests at least once every 45 days. That cadence is not a promise that every record will disappear within 45 days. Keep the submission confirmation and check the status of any request that remains unresolved.
You may still need to contact an online service, employer, health provider, financial institution, or retailer directly.
How to submit a deletion request
1. Identify the data holder
Make a short list of the places most likely to hold your information:
- Retailers and delivery services
- Social media, dating, gaming, and messaging apps
- Former subscription services
- Advertising or loyalty programs
- Property, people-search, or other data brokers
- Businesses named in a privacy notice or breach letter
Search each official website for its privacy policy and request channel. Use the same email address or phone number connected to the account when you can, because that helps the company locate the correct records.
2. State the request clearly
Say whether you want deletion, an opt-out, access to your information, or more than one action. Include only the identifiers needed to locate your account, such as:
- Name used on the account
- Email address
- Phone number
- Username or customer number
- Mailing address, if it is associated with the account
A request can be concise:
I am requesting deletion of the personal information associated with this account: [email address or username]. I am a resident of [state]. Please confirm what was deleted. If you retain any information, please identify the category retained and the reason it could not be deleted. I also request an opt-out of the sale or sharing of my personal information where that right applies.
Don't claim to live in California or another state if you don't. Residency can affect eligibility, and DROP specifically verifies California residency.
3. Verify your identity safely
A company may need to confirm that the requester controls the account. Complete verification through the official privacy page or support channel, not through an unverified message.
Provide the minimum information necessary. If a business asks for an identity document, check why it is needed and whether irrelevant details can be redacted. Don't send a full Social Security number, complete bank details, or account passwords in an ordinary email.
4. Save proof of submission
Keep:
- A copy of the request
- The date and time submitted
- The web address or email used
- Confirmation and case numbers
- Screenshots of the privacy policy or request page
- Any identity-verification instructions
- The company's response
A simple spreadsheet can track the business, request type, submission date, deadline stated by the company, and follow-up date.
5. Review a partial approval carefully
A response may say that some information was deleted while other information was retained. Ask:
- Which categories were deleted?
- Which categories remain?
- Why was each retained category excluded?
- Was the opt-out processed separately?
- Was information shared with service providers or other recipients?
- Is there an appeal or review process?
- Do you need to contact an affiliated company separately?
A refusal isn't automatically unlawful, but a vague answer doesn't tell you enough to decide what to do next. Ask for a written explanation.
What limits should you expect?
Deletion rights commonly have limits. A business may say it must retain some information because of an exception, a transaction, fraud or security concerns, or another legal obligation. The exact rules depend on the applicable law and the type of record.
Ask the company to separate information it deleted from information it retained. If it refers to an exception, request the general category and explanation rather than sending more sensitive information than necessary.
Also keep these boundaries in mind:
- Closing an account may not erase records from a separate billing or support system.
- Deleting a profile may not remove information held by a data broker.
- Removing data from a company's system may not remove copies already downloaded or republished by others.
- An opt-out may limit future uses without erasing historical information.
- A request to a data broker doesn't necessarily change what the original business retains.
- If you need evidence for a complaint or fraud claim, save it before closing the account.
If the company ignores or denies your request
Follow this order:
- Check the response date and scope. Make sure the company addressed deletion, opt-out, or access separately if you asked for more than one action.
- Send a written follow-up. Include the case number, original submission date, and the specific part that remains unresolved.
- Ask about appeal. Some companies provide an internal review process, especially for privacy requests.
- Gather supporting records. Save screenshots, emails, account pages, privacy notices, and the company's explanation.
- Use the appropriate state complaint route. The agency depends on your state and the issue.
California consumers can submit a complaint to CalPrivacy. Its guidance recommends contacting the business first and including the business name, dates, what happened, which privacy rights may have been violated, and supporting material such as screenshots or emails. CalPrivacy says you may choose whether to provide contact information, and it isn't required to take action on every complaint.
A complaint creates a record. It isn't a guarantee that an agency will order deletion. Don't include unnecessary passwords, full payment numbers, or other sensitive information in supporting documents.
If your concern is a data breach
A breach and a deletion request require different first steps. If an account may have been compromised, protect it before trying to close it:
- Change the affected password and any reused password.
- Turn on multi-factor authentication.
- Review account activity, recovery email addresses, and connected devices.
- Contact your bank or card issuer through a verified number if financial information may be involved.
- Save the breach notice and ask what information was affected, when the incident occurred, and what protections the company is offering.
- Consider a fraud alert or credit freeze if highly sensitive identity information was exposed.
The FTC's data breach response guide is written for businesses. It recommends mobilizing a response team, using forensic experts, consulting legal counsel, and clearly describing what is known. It does not create a consumer deletion deadline or promise payment after every breach.
Don't delete a compromised account before saving the notice, transaction history, and relevant messages. You may need those records for your bank, an identity-theft report, or a privacy complaint.
Start with one company that holds the most sensitive information, such as an old financial, health, shopping, or identity-related account. Use an official request channel, send a precise deletion or opt-out request, save the confirmation, and use that record for the next data holder.