Privacy Tools

The Right to Be Forgotten Isn't One Law — Here's How to Actually Use Yours (2026)

GDPR, CCPA, UK GDPR, and a growing list of state laws all offer some version of a deletion right, each with different deadlines. Here's how to write a request that actually cites the right one.

📅 Aug 9, 2026·⏱️ 6 min read·✍️ Cikal Studio Labs
🗑️

"Right to be forgotten" is a category, not one law

The phrase gets used loosely to describe several distinct legal rights that share a common goal — requiring a company to delete your personal data on request — but differ meaningfully in scope, exceptions, and how quickly a company must respond. Sending a vague "please delete my data" email, with no legal citation, gives a company far more room to delay or partially comply than a request that names the specific right you're exercising.

The major versions, and what they actually require

  • GDPR Article 17 (EU). The original "right to erasure," generally requiring a response within one month, extendable by two further months for complex requests. It includes several defined exceptions (legal obligations, freedom of expression, public interest archiving).
  • UK GDPR. Mirrors the EU version closely post-Brexit, with the same one-month baseline response window, enforced by the UK's Information Commissioner's Office.
  • CCPA/CPRA (California). Provides a deletion right with a generally required 45-day response window, extendable by another 45 days, and includes its own set of business exceptions.
  • Other U.S. state privacy laws. Most of the 20 states with comprehensive privacy laws in effect as of 2026 include some deletion right, though exact deadlines and scope vary by state statute.

Why naming third-party deletion matters

A company deleting your data from its own primary systems doesn't automatically mean data it shared with advertising partners, analytics providers, or other processors gets deleted too. A well-formed deletion request explicitly asks for confirmation that data shared with third parties has also been deleted, or that a deletion request has been passed along to them — closing a gap many companies otherwise leave unaddressed by default.

Why asking for a legal basis on refusal matters

Every version of this right includes legitimate exceptions — data a company must retain for tax records, active legal disputes, or fraud prevention, for example. A request that asks the company to state their specific legal basis for any partial refusal makes it harder for a company to simply decline without justification, and gives you something concrete to escalate to a regulator if the stated basis doesn't hold up.

What to do if a company doesn't respond in time

Missing the legally required response window is itself a violation you can escalate. In the EU and UK, this means filing a complaint with your national data protection authority or the ICO. In the U.S., depending on your state, this typically means a complaint to your state attorney general's consumer protection office. Keeping a dated copy of your original request is what makes that escalation possible.

A written request beats an informal one every time

Even where a company would eventually comply with an informal request, a formal one that cites the specific applicable law creates a paper trail with a clear deadline attached — turning "I asked nicely" into "I made a legally cognizable request on this date, requiring a response by this date."

Frequently Asked Questions

Is the 'right to be forgotten' the same everywhere?

No — it's a family of related but distinct rights. GDPR Article 17 in the EU, UK GDPR, CCPA/CPRA in California, and various U.S. state privacy laws each define their own scope, exceptions, and required response timeframe. Citing the specific law that applies to your situation gives your request more legal weight than a generic deletion ask.

How long does a company have to respond to a deletion request?

It depends on the law. GDPR and UK GDPR generally require a response within one month, extendable by two further months for complex requests. CCPA/CPRA in California generally requires a response within 45 days, extendable by another 45 days. Other U.S. state laws vary by statute.

Does deleting my data from a company's own systems mean it's deleted everywhere?

Not automatically. A company may have shared your data with third-party processors, advertising partners, or analytics providers who retain their own copies unless specifically asked to delete it too. A well-formed deletion request should explicitly ask for confirmation that any data shared with third parties has also been deleted.

What can I do if a company ignores my deletion request or misses the deadline?

Missing the legally required response window is itself something you can escalate. In the EU/UK, that means filing a complaint with your national data protection authority or the ICO. In the U.S., it typically means a complaint to your state attorney general's consumer protection office, depending on the applicable law.

Is there a tool that generates a deletion request for my specific jurisdiction?

Yes — the Right to Be Forgotten Request Generator builds a properly formatted request citing GDPR, CCPA/CPRA, UK GDPR, other U.S. state law, or Canada's PIPEDA, automatically including the response deadline that law requires and language asking about third-party data deletion.