For U.S. consumers in 2026, the best first move usually isn't a paid privacy product. Start smaller: identify what a company collected, decide which law or policy applies, and choose the outcome you want. Access, deletion, correction, and opt-outs are separate requests, and they don't all follow the same path.

California residents may have rights under the California Consumer Privacy Act, as amended by the California Privacy Rights Act, when the business is covered. Outside California, rights, deadlines, and complaint routes vary by state. Browser signals, account settings, and credit tools can help, but each solves a different problem.

Four facts that shape your request

Most disputes come down to four points:

A privacy policy explains how a company says it handles information. It doesn't automatically hand every visitor every right mentioned on the page. Likewise, a form built for European users doesn't prove GDPR rights apply to a U.S. customer.

Before you contact anyone, save a copy of the privacy policy. Note the email address, phone number, app, website, or store tied to your account. If the policy names data brokers or advertising partners, check whether those companies run their own opt-out processes.

California rights under CCPA and CPRA

California's Attorney General CCPA guidance is the place to check current instructions. Depending on the business and the request, California consumers may be able to:

These rights are not a universal delete button. A business may keep some records for security, legal compliance, accounting, transaction completion, or other permitted reasons. It may also need to verify you before releasing sensitive account information. Don't email a driver's license, Social Security number, or other identity document unless the company gives you a secure official channel and explains why it needs that document.

For many CCPA access, deletion, and correction requests, the usual response period is 45 days, with an extension where permitted. Different request types can have different handling rules, so check the company's instructions and current official guidance.

If you opt out of sale or sharing, the business must wait at least 12 months before asking you to opt back in, according to the California Attorney General's guidance.

What Global Privacy Control can and cannot do

Global Privacy Control, or GPC, is a browser or extension setting that sends an opt-out preference to participating websites. In appropriate situations, California consumers can use a user-enabled GPC signal as an opt-out request. The official GPC site explains how to turn it on.

GPC is useful when you visit many sites, but it has limits:

After you enable GPC, open a site's privacy choices page and check whether the signal is recognized. If it isn't, take a screenshot and submit a direct opt-out request through the company's official privacy page.

How to send a request that won't get stalled

Use the same basic process for access, correction, deletion, or opt-out requests:

  1. Find the official channel. Look in the privacy policy, account settings, or a "Do Not Sell or Share My Personal Information" link. Don't send sensitive information through an ad or an unfamiliar form.
  2. Name the request. Say whether you want access, correction, deletion, or an opt-out. A vague message that mixes several demands is easier to misroute.
  3. Provide only what's needed to locate your account. An account email, phone number, order number, or customer ID may be enough. Ask what verification is required before sending anything more sensitive.
  4. Set the scope. Specify account data, marketing profile, mobile app data, or a particular transaction.
  5. Keep proof. Save the date, confirmation number, screenshots, messages, and any response.
  6. Check the answer. Look for a response to each part of the request and an explanation for any refusal or retained data.

A short message you can adapt:

I am requesting [access to, correction of, deletion of, or an opt-out from the sale or sharing of] personal information associated with [account email, phone number, or customer ID]. Please confirm the scope of this request, tell me what verification is required through a secure channel, and provide the applicable response deadline. Please explain any information you cannot provide or delete.

If you're not a California resident, replace the CCPA language with the privacy law or company policy that applies where you live. Don't claim a California right that may not apply in your state.

If the company ignores or denies you

Send one written follow-up. Include the original request date, confirmation number, and the unresolved part. Ask the company to identify the legal or policy reason for the denial and whether you can appeal.

For California matters, start with the California Attorney General's CCPA information. If you live elsewhere, look for the privacy complaint or consumer-protection page of your state attorney general or designated privacy regulator.

A private lawsuit is not the same thing as a regulator complaint. The California Attorney General says that, before suing over a CCPA violation, a consumer must provide written notice identifying the alleged violations and allow 30 days for the business to respond in writing that it has cured them and will not repeat them. That is a specific pre-suit requirement for situations where a private action is available, not a universal deadline for every privacy complaint.

Reduce the data companies collect in the first place

You can lower future exposure even when deletion isn't available:

A privacy setting usually changes future collection or use. It doesn't necessarily remove records already held by the company or its service providers.

What to do after a data breach

A breach notice should tell you what happened, which information was affected, and what the company is doing. The FTC's data breach response guide is written for businesses, but it shows the kind of information consumers should expect, including a clear description of the compromise and response steps.

Do this:

  1. Save the notice. Record the company, date, affected service, and data categories.
  2. Verify independently. Go to the company's official website or call a number from a statement, bill, or account page. Don't click an unexpected email link.
  3. Change affected passwords. Change the password anywhere you reused it, and turn on multifactor authentication.
  4. Watch financial accounts. Contact your bank or card issuer through its official number if you see an unfamiliar transaction.
  5. Consider a credit freeze. If Social Security numbers or other credit-related information were exposed, a freeze can help stop new accounts from being opened in your name.
  6. Check your credit reports. Look for accounts or inquiries you don't recognize.
  7. Be careful with follow-up offers. Breaches can lead to convincing phishing messages, even when the original company is legitimate.

The FTC says credit freezes are free and can be placed with Equifax, Experian, and TransUnion. A freeze stays in place until you ask the bureaus to remove it. The FTC's credit freeze and fraud alert guidance explains the difference and links to the bureaus.

A credit freeze protects access to your credit file. It doesn't delete exposed information, fix a breached company's systems, or stop every type of account takeover.

Privacy tools and their limits

Tool or setting What it helps with What it cannot guarantee
Global Privacy Control Sends an opt-out preference to participating websites Deletion of existing data or coverage on every site
Account privacy settings Reduces optional sharing, marketing, or personalization A legally enforceable deletion or access response
Password manager and multifactor authentication Reduces account takeover risk Removal of data already held by a company
Credit freeze Helps block new credit opened in your name Protection from all fraud or misuse outside credit
Company privacy request portal Routes an access, correction, deletion, or opt-out request Approval of a request when an exception applies

Privacy-management services may help organize requests, but they don't create rights that your state law or the company's policy doesn't provide. You still need to check the recipient, scope, verification process, and response.

Common questions

Can I make any company delete all my information?
Not necessarily. The answer depends on your state, the business, the data involved, and legal or operational exceptions. Ask what the company retained and why.

Does turning on GPC delete my data?
No. GPC is an opt-out preference signal. Use the company's direct access or deletion process for information already collected.

Does CCPA apply to every website that serves California visitors?
No. The CCPA applies to California consumers and businesses that meet the law's coverage requirements. A site's availability in California alone doesn't establish coverage.

Should I send my Social Security number to verify a request?
Only through a secure, official process when it's genuinely required. Start by asking whether the company can verify you with less sensitive information.

What should I do if I live outside California?
Check your state's official privacy and consumer-protection resources, then review the company's privacy policy for its request process. State rights and deadlines aren't uniform.

Pick one company, save its privacy policy, enable GPC if it fits your situation, and submit one clearly documented request through the official channel.