Why a Casual Request Doesn't Work
Emailing customer support and asking them to "please delete my account and data" is one of the least effective ways to get a company to actually comply. Support teams triage vague requests as low priority, and without a specific legal citation or deadline, there's nothing forcing a response within any particular timeframe. A properly worded request โ citing the exact statute that grants you the right, and the exact deadline the company is legally bound to โ changes the conversation entirely.
GDPR: The Right to Erasure
If you're in the EU or UK, or the company processes data belonging to EU/UK residents, your request should cite Article 17 of the General Data Protection Regulation (Regulation (EU) 2016/679) โ commonly known as the "right to be forgotten." Article 17 requires erasure when, among other grounds: the data is no longer necessary for its original purpose, you withdraw consent and there's no other legal basis for processing, you object to the processing, or the data was processed unlawfully.
Critically, Article 12(3) requires the controller to respond "without undue delay and in any event within one month of receipt of the request" โ in practice, a 30-day deadline. If the request is complex, they can extend by up to two further months, but they must tell you within the original month and explain why.
CCPA: The Right to Delete
If you're a California resident, your request should cite Cal. Civ. Code ยง1798.105, the CCPA's (as amended by the CPRA) "right to delete." Once a business receives a verifiable request, Cal. Civ. Code ยง1798.130(a)(2) gives them 45 days to respond, with one additional 45-day extension allowed if they notify you within the initial window. The CCPA also requires the business to direct any service providers or contractors it shared your data with to delete it as well.
Outside the EU/UK and California
Not every jurisdiction has a statute as specific as GDPR or CCPA. A generic request still works โ frame it as a clear, good-faith privacy request, note that you're withdrawing any consent previously given, and set a reasonable (though not legally binding) 30-day expectation for a written response. Many companies will honor a clearly worded request regardless of jurisdiction, especially if they operate any GDPR-compliant infrastructure globally.
What a Strong Request Should Include
- Your identity and contact details โ enough for them to locate your account and respond to you.
- The exact legal basis โ the specific article or code section, not just "privacy law."
- A clear scope โ all personal data associated with your account, not just "some" of it.
- A specific deadline โ calculated from the date of the letter, not left open-ended.
- A request for third-party confirmation โ ask whether your data was shared with others, and whether they've been instructed to delete it too.
If They Don't Respond in Time
Under GDPR, you can file a complaint with your national Data Protection Authority (in the UK, the ICO) if a controller misses the deadline or refuses without valid grounds. Under CCPA, you can report non-compliance to the California Privacy Protection Agency or the Attorney General's office. Keep a copy of your original letter and any correspondence โ it's the evidence that starts the clock and proves you followed the correct legal process.
The Takeaway
The difference between a request that gets ignored and one that gets a compliant response within a legal deadline usually comes down to specificity: the right statute, the right deadline, and a clearly scoped ask. Once you have the letter right, sending it to the next company takes minutes, not hours.