--
title: "Privacy Deletion Request Letter Template: Choosing Between GDPR and CCPA"
description: "A platform delete button only covers what you posted yourself. Reposts, broker profiles and search caches need a formal request. Two versions of the letter, one under GDPR and one under CCPA, plus the material to gather first and what the 30-day clock actually covers."
tags: ["privacy", "gdpr", "security", "legal"]
canonical_url: https://digital-footprint-health.shop/blog/privacy-deletion-request-letter-template
A delete button covers what you posted. It does nothing about a profile a data broker assembled out of public records, or a search result still handing out a cached copy of a page you removed two years ago. Those need a letter.
The awkward part is not the wording. It is choosing a legal basis, because the identical demand sent under GDPR and sent under CCPA produces different clocks, different duties on the recipient, and different excuses they can reach for when refusing.
Two regimes, one slot in the mailbox
Which one you lead with depends on where the company operates and whether your request falls inside the regime's scope. Your own location matters less than most guides suggest.
| Dimension | GDPR (EU/EEA) | CCPA / CPRA (California) |
|---|---|---|
| Core provision | Article 17, right to erasure | Section 1798.105, right to delete |
| Who it binds | Controllers processing EU personal data, wherever the company sits | For-profit entities above revenue or data-volume thresholds |
| Deadline | One month in principle, three for complex cases | 45 days after a verifiable request, up to 90 |
| Identity check | Reasonable steps to confirm who is asking | Verifiable consumer request process |
| Standard refusals | Freedom of expression, legal obligation, public-interest archiving | Completing a transaction, security incidents, internal lawful use |
| Cost | Free, fee allowed for manifestly unfounded requests | Free, up to twice per 12-month window |
A practical order of operations. Check whether the company has EU operations or actively targets EU users. If it does, lead with GDPR. If it only operates in the US and clears the CCPA thresholds, lead with CCPA. If neither lands, you are down to platform policy and public pressure, which is a different game with a different set of levers.
Gather this before you send anything
Requests die over identity verification far more often than over a wrong legal citation. Put the file together in one pass instead of dribbling documents across three replies.
- A name page from a passport or driving licence. Add issuing authority if they ask.
- The email address the account was registered under, or a screenshot of the account page.
- The exact URLs, handles and record identifiers you want removed. Copy them, do not paraphrase them.
- A short timeline if the data appeared more than once. Two line entries are enough.
Attach these to the first message. The clock on the response period usually starts when a request is verifiable, and an unverifiable request does not start it at all.
The GDPR version
To: [controller name], Data Protection Officer
Subject: Data subject erasure request under Article 17 GDPR
I am exercising my right to erasure under Article 17 of Regulation (EU) 2016/679.
Data concerned: [URLs / handles / record IDs]
Basis: [Art. 17(1)(a) withdrawn consent / (c) no longer necessary / (d) unlawful processing]
Identity: [name, registered email, ID reference]
Please confirm within one month, as required by Article 12(3), which of the following you have done: erased the data, restricted processing pending a decision, or declined with a documented justification.
If you rely on an exemption under Article 17(3), identify the specific provision and the facts supporting it.
If you have shared this data with processors or third parties, tell me who received it so I can follow up with them directly.
Two sentences in that letter do most of the work. Asking which provision of Article 17(3) they are relying on removes the option of an unexplained refusal. Asking for the recipient list turns a single request into a trail you can act on.
The CCPA version
To: [business name], Privacy Team
Subject: Verifiable consumer request to delete, Cal. Civ. Code 1798.105
I am a California consumer submitting a verifiable request to delete personal information under the CCPA as amended by the CPRA.
Categories to delete: [identifiers / commercial information / internet activity]
Record locators: [URLs / handles / account identifiers]
Please confirm receipt within 10 business days and complete the request within 45 days, or notify me of an extension under section 1798.130(a)(2).
State which categories you deleted, and which you retained under an exception in section 1798.105(d), with the exception cited.
Direct your service providers and contractors to delete the same information, as required by section 1798.105(c)(3).
The 10 business day acknowledgement is easy to forget and useful precisely because it is mechanical. If it does not arrive, you already have a procedural failure to point at, separate from the substance of the request.
What the clock really covers
The deadline applies to the request, not to the internet. Two things sit outside it and are worth understanding before you start checking.
Backups and logs often fall under a retention exception even where the live record must go. Search engine caches follow their own refresh schedule, which can run weeks. So a search result reappearing three days after you deleted the source is expected behaviour, not a breach. That does not make it permanent, and it does not obligate anyone to hurry the index along either.
Keep the entire thread. A record of what you asked, when they answered, and what they promised is the file you want if the request escalates to a supervisory authority or the California Attorney General. Both routes are free, and neither requires a lawyer.
Top comments (0)