For U.S. consumers in 2026, the best first move usually isn't a paid privacy product. Start smaller: identify what a company collected, decide which law or policy applies, and choose the outcome you want. Access, deletion, correction, and opt-outs are separate requests, and they don't all follow the same path.
California residents may have rights under the California Consumer Privacy Act, as amended by the California Privacy Rights Act, when the business is covered. Outside California, rights, deadlines, and complaint routes vary by state. Browser signals, account settings, and credit tools can help, but each solves a different problem.
Four facts that shape your request
Most disputes come down to four points:
- Where you live. State privacy law usually follows your residence, not where a website is hosted.
- Whether the business is covered. A company may be subject to a state privacy law only if it meets that law's thresholds or other requirements.
- What kind of information is involved. Shopping records, ad profiles, health data, financial records, and employment files can trigger different rules.
- What you want the company to do. Reading your file, fixing it, deleting it, and stopping targeted advertising are distinct actions.
A privacy policy explains how a company says it handles information. It doesn't automatically hand every visitor every right mentioned on the page. Likewise, a form built for European users doesn't prove GDPR rights apply to a U.S. customer.
Before you contact anyone, save a copy of the privacy policy. Note the email address, phone number, app, website, or store tied to your account. If the policy names data brokers or advertising partners, check whether those companies run their own opt-out processes.
California rights under CCPA and CPRA
California's Attorney General CCPA guidance is the place to check current instructions. Depending on the business and the request, California consumers may be able to:
- Ask what personal information a business collects, uses, sells, or shares.
- Get access to certain personal information and details about where it came from and why it was used.
- Request deletion, subject to exceptions.
- Correct inaccurate personal information.
- Opt out of sale or sharing of personal information.
- Limit some uses and disclosures of sensitive personal information.
- Receive equal service when exercising privacy rights.
These rights are not a universal delete button. A business may keep some records for security, legal compliance, accounting, transaction completion, or other permitted reasons. It may also need to verify you before releasing sensitive account information. Don't email a driver's license, Social Security number, or other identity document unless the company gives you a secure official channel and explains why it needs that document.
For many CCPA access, deletion, and correction requests, the usual response period is 45 days, with an extension where permitted. Different request types can have different handling rules, so check the company's instructions and current official guidance.
If you opt out of sale or sharing, the business must wait at least 12 months before asking you to opt back in, according to the California Attorney General's guidance.
What Global Privacy Control can and cannot do
Global Privacy Control, or GPC, is a browser or extension setting that sends an opt-out preference to participating websites. In appropriate situations, California consumers can use a user-enabled GPC signal as an opt-out request. The official GPC site explains how to turn it on.
GPC is useful when you visit many sites, but it has limits:
- It generally tells a site you want to opt out. It doesn't erase information already collected.
- It doesn't close an account or cancel a subscription.
- It may miss offline purchases, data held under a separate account, or sites outside covered jurisdictions.
- A website may still require a separate process for access, correction, or deletion.
After you enable GPC, open a site's privacy choices page and check whether the signal is recognized. If it isn't, take a screenshot and submit a direct opt-out request through the company's official privacy page.
How to send a request that won't get stalled
Use the same basic process for access, correction, deletion, or opt-out requests:
- Find the official channel. Look in the privacy policy, account settings, or a "Do Not Sell or Share My Personal Information" link. Don't send sensitive information through an ad or an unfamiliar form.
- Name the request. Say whether you want access, correction, deletion, or an opt-out. A vague message that mixes several demands is easier to misroute.
- Provide only what's needed to locate your account. An account email, phone number, order number, or customer ID may be enough. Ask what verification is required before sending anything more sensitive.
- Set the scope. Specify account data, marketing profile, mobile app data, or a particular transaction.
- Keep proof. Save the date, confirmation number, screenshots, messages, and any response.
- Check the answer. Look for a response to each part of the request and an explanation for any refusal or retained data.
A short message you can adapt:
I am requesting [access to, correction of, deletion of, or an opt-out from the sale or sharing of] personal information associated with [account email, phone number, or customer ID]. Please confirm the scope of this request, tell me what verification is required through a secure channel, and provide the applicable response deadline. Please explain any information you cannot provide or delete.
If you're not a California resident, replace the CCPA language with the privacy law or company policy that applies where you live. Don't claim a California right that may not apply in your state.
If the company ignores or denies you
Send one written follow-up. Include the original request date, confirmation number, and the unresolved part. Ask the company to identify the legal or policy reason for the denial and whether you can appeal.
For California matters, start with the California Attorney General's CCPA information. If you live elsewhere, look for the privacy complaint or consumer-protection page of your state attorney general or designated privacy regulator.
A private lawsuit is not the same thing as a regulator complaint. The California Attorney General says that, before suing over a CCPA violation, a consumer must provide written notice identifying the alleged violations and allow 30 days for the business to respond in writing that it has cured them and will not repeat them. That is a specific pre-suit requirement for situations where a private action is available, not a universal deadline for every privacy complaint.
Reduce the data companies collect in the first place
You can lower future exposure even when deletion isn't available:
- Leave optional profile fields blank when the service doesn't need them.
- Review app permissions and turn off contacts, location, microphone, or photo access when a feature doesn't require it.
- Switch off personalized advertising and marketing messages in account settings.
- Use a unique password for each important account and enable multifactor authentication.
- Close old accounts and remove access from apps you no longer use.
- Look for a separate data-sharing or advertising preference center.
- Don't post account numbers, identification documents, travel plans, or security-question answers publicly.
- Think twice before using quizzes, loyalty programs, free apps, or services that ask for information unrelated to their main function.
A privacy setting usually changes future collection or use. It doesn't necessarily remove records already held by the company or its service providers.
What to do after a data breach
A breach notice should tell you what happened, which information was affected, and what the company is doing. The FTC's data breach response guide is written for businesses, but it shows the kind of information consumers should expect, including a clear description of the compromise and response steps.
Do this:
- Save the notice. Record the company, date, affected service, and data categories.
- Verify independently. Go to the company's official website or call a number from a statement, bill, or account page. Don't click an unexpected email link.
- Change affected passwords. Change the password anywhere you reused it, and turn on multifactor authentication.
- Watch financial accounts. Contact your bank or card issuer through its official number if you see an unfamiliar transaction.
- Consider a credit freeze. If Social Security numbers or other credit-related information were exposed, a freeze can help stop new accounts from being opened in your name.
- Check your credit reports. Look for accounts or inquiries you don't recognize.
- Be careful with follow-up offers. Breaches can lead to convincing phishing messages, even when the original company is legitimate.
The FTC says credit freezes are free and can be placed with Equifax, Experian, and TransUnion. A freeze stays in place until you ask the bureaus to remove it. The FTC's credit freeze and fraud alert guidance explains the difference and links to the bureaus.
A credit freeze protects access to your credit file. It doesn't delete exposed information, fix a breached company's systems, or stop every type of account takeover.
Privacy tools and their limits
| Tool or setting | What it helps with | What it cannot guarantee |
|---|---|---|
| Global Privacy Control | Sends an opt-out preference to participating websites | Deletion of existing data or coverage on every site |
| Account privacy settings | Reduces optional sharing, marketing, or personalization | A legally enforceable deletion or access response |
| Password manager and multifactor authentication | Reduces account takeover risk | Removal of data already held by a company |
| Credit freeze | Helps block new credit opened in your name | Protection from all fraud or misuse outside credit |
| Company privacy request portal | Routes an access, correction, deletion, or opt-out request | Approval of a request when an exception applies |
Privacy-management services may help organize requests, but they don't create rights that your state law or the company's policy doesn't provide. You still need to check the recipient, scope, verification process, and response.
Common questions
Can I make any company delete all my information?
Not necessarily. The answer depends on your state, the business, the data involved, and legal or operational exceptions. Ask what the company retained and why.
Does turning on GPC delete my data?
No. GPC is an opt-out preference signal. Use the company's direct access or deletion process for information already collected.
Does CCPA apply to every website that serves California visitors?
No. The CCPA applies to California consumers and businesses that meet the law's coverage requirements. A site's availability in California alone doesn't establish coverage.
Should I send my Social Security number to verify a request?
Only through a secure, official process when it's genuinely required. Start by asking whether the company can verify you with less sensitive information.
What should I do if I live outside California?
Check your state's official privacy and consumer-protection resources, then review the company's privacy policy for its request process. State rights and deadlines aren't uniform.
Pick one company, save its privacy policy, enable GPC if it fits your situation, and submit one clearly documented request through the official channel.