← Back to Blog
Compliance & Legal2026-09-27·Digital Footprint Health Team

Privacy Deletion Request Letter Template: Choosing Between GDPR and CCPA

GDPRCCPAright to erasuredata privacy law

Most people think of the right to deletion as that button buried in a platform settings page. The button works, but it only covers what you posted yourself. Screenshots that got reposted, profiles assembled about you by data brokers, and search results still serving cached copies all sit outside its reach. For those, you send a letter.

Writing the letter is the easy part. The hard part is picking the right legal basis, because the same demand framed under GDPR and under CCPA produces different deadlines, different obligations and different grounds for refusal. Here is how the two paths diverge, with templates you can copy directly.

What actually separates the two paths

Which one applies depends on where the data controller sits and where your request falls, not on where you live.

DimensionGDPR (EU/EEA)CCPA / CPRA (California)
Core provisionArticle 17, right to erasureSection 1798.105, consumer right to delete
Who it bindsControllers processing EU personal data, regardless of company domicileFor-profit entities meeting revenue or data-volume thresholds
DeadlineOne month in principle, extendable to three for complexity45 days after a verifiable request, extendable by another 45
Identity checkController must take reasonable steps to confirm identityMust go through a verifiable consumer request process
Common refusalsFreedom of expression, legal obligation, public-interest archivingCompleting a transaction, security incidents, internal lawful use
CostFree, reasonable fee allowed for manifestly unfounded requestsFree, up to twice per 12-month period

A workable order of operations: check whether the company has EU operations or targets EU users. If yes, lead with GDPR. If it only operates in the US and clears the CCPA thresholds, lead with CCPA. If neither applies, you are down to platform policy and reputational pressure, which is a different playbook entirely.

Material to gather before you send anything

Requests get rejected over unverified identity far more often than over a misstated legal basis. Assemble this first and attach it in one pass.

  • Verifiable identity document. The name page of a passport or licence, plus issuing authority if asked. Mask the middle digits of any document number.
  • Account and email list. Every email you registered with, including old ones. Broker profiles frequently hang off an address you stopped using years ago.
  • Specific URLs. List each page or record you want removed, with the date you first saw it. A blanket "delete everything about me" usually comes back for resubmission.
  • Legal basis and section numbers. Cite which limb of GDPR Article 17(1) applies, or CCPA 1798.105(a).
  • A durable reply address. Not a work address you may lose access to.

If you are also cleaning up an X account, the archive request and the deletion request have an ordering problem. Get it backwards and both slow down. Archive first, then request erasure covers why.

The general template

This version keeps both legal frames open. Replace the bracketed parts. The tone is deliberately restrained, because emotional language gives a processor a reason to set the request aside.

[Date]

To: [controller's legal or privacy officer address, not support]

Subject: Personal data deletion request / [your name] / [legal basis]

Dear Sir or Madam,

I am [name], resident in [country/state]. I request that you delete the following personal data relating to me:

[Item 1: page URL or record identifier]
[Item 2]
[Item 3]

I make this request under [GDPR Article 17(1) / CCPA 1798.105(a)].

Identity verification material is attached: [document type].

Please confirm receipt in writing and inform me of the outcome within the statutory period. If further information is required, reach me at [email].

[Name]
[Postal address, optional]

Three details carry more weight than they look. Addressing the privacy officer rather than support cuts weeks off the average response. Sending minimal identity evidence is both a data-minimisation habit and self-protection. The line asking for written confirmation is where any later complaint starts, because your mail server timestamps it and the recipient's assurances do not.

Additions for a GDPR request

Two extra paragraphs belong in a GDPR letter. The first states the notification duty: if erasure is refused, the controller must explain why and tell you about your right to lodge a complaint with a supervisory authority and to seek a judicial remedy. The second addresses search engines specifically. The Court of Justice has treated the right as requiring de-referencing for particular queries rather than removal of the source page, which means the site hosting the original needs its own request.

The platform-level mechanics, including the point where free-expression arguments typically get raised, are walked through in how GDPR deletion requests work on X.

Additions for a CCPA request

Two traps sit in the CCPA route. First, the definition of "sale" is broad enough that handing data to an ad network can count, which means you can stack the right to opt out of sale on top of deletion. Second, verification often routes through an existing account authentication channel; decline to cooperate and you never reach the status of a verifiable request. If a reply says your identity could not be confirmed, treat it as an interim step and resubmit with the requested material. How far global privacy laws reach compares the state-level thresholds, which is useful for a quick self-check.

What happens after it goes out

The usual sequence: an automated acknowledgement within 24 to 72 hours, a human confirmation in one to two weeks possibly bundled with a verification request, then the statutory window. GDPR means one month, extendable to three. CCPA means 45 days, extendable by another 45. If the window closes with no reply, you can escalate, either to a national data protection authority in the EU, all of which run online complaint forms, or to the California Attorney General.

One boundary is worth setting expectations around. A deletion request generally does not reach backup systems and logs. Controllers will often retain a copy under a legal-obligation or internal-use exemption, which is not by itself a violation. What you can insist on is that the retained copy is not put back to the commercial purpose that prompted the request.

Where you cannot fix it with a letter

Some of what follows you around is not held by any controller you can name. Cached copies on third-party scrapers, screenshots in group chats, and text quoted inside someone else's post all sit outside every statutory framework described above. A realistic plan handles those by lowering their prominence rather than by removing them: publish current, accurate material about yourself so the stale item loses ranking, and keep the items you can control clean. Treating the letter as complete coverage leads to disappointment, and treating it as one layer of several is closer to how it actually works.

Deciding which items are worth the effort is the practical bottleneck. A list of a few thousand posts is not something you triage by reading. That triage is what the free check does.

Keeping a record of what you sent

The part that quietly decides whether a request succeeds is documentation. Save the sent message as a PDF rather than trusting your mail client's search, because the copy you can produce months later is the one that matters. Keep one plain text file listing each recipient, the date sent, the legal basis cited, the statutory deadline you calculated, and what came back. When a controller goes silent, that file turns a scattered inbox into a timeline you can attach to a complaint without reconstructing anything.

Two habits make the log worth keeping. Note the deadline you computed at the moment of sending, since recalculating later invites argument about when the clock started. And log refusals verbatim, including the exemption clause cited, because patterns across several refusals are what supervisory authorities act on. A single complaint about one company rarely moves; three showing the same boilerplate rejection language from the same processor gets read differently.

About digital-footprint-health.shop

digital-footprint-health.shop covers the step before the letter: seeing what you actually hold. Drop your X data archive into the check on the homepage and the tool parses every post on your own machine, surfacing phone numbers, emails, addresses, locations and sensitive topics with a 0-100 health score and a ranked risk list. Nothing is uploaded. The check is free and read-only; cleanup scope and cost sit on the pricing page, and the method write-ups are collected in the blog index.

Frequently Asked Questions

Does the request have to go by registered mail?

No. Email is valid under both GDPR and CCPA. What matters is being able to prove when it arrived and what it said, so turn on delivery confirmation and ask for written acknowledgement in the body. If nothing comes back, a registered letter plus the postal receipt gives you a second, stronger record.

They say the data is deleted. How do I verify that?

Two steps. Ask them to describe the scope, including what happened to backups and logs. Then re-run the search for that item two to four weeks later to see whether it still surfaces. Search indexes lag, so a result showing up in the short term is not automatically a breach.

Can I cite both GDPR and CCPA in one letter?

Yes, but rank them. State the primary basis in the body, then add a line saying you also make the request under the other regime where applicable. That stops a controller from closing the whole request by claiming the regime does not apply, while keeping the deadline arithmetic unambiguous.

What if the request is refused?

You have options. Under GDPR, demand the formal refusal reasoning, then complain to the data protection authority in your country, which is normally free to do. Under CCPA, report to the California Attorney General. Neither route needs a lawyer, but both depend on keeping the full email chain as evidence.

Check your own X/Twitter footprint

Free on-device scan. Your archive never leaves your computer.

Start Free Check

Related Reads

Published on 2026-09-27. Last updated 2026-09-27.