Privacy rights requests are formal, legally protected tools that let you access, correct, delete, or restrict how organizations use your personal data. Under the California Consumer Privacy Act (CCPA), businesses must respond within a set statutory deadline. Similarly, the General Data Protection Regulation (GDPR) mandates a response within a defined time frame. Both laws require organizations to verify your identity before acting on any request, and both allow limited extensions when requests are complex or voluminous.
The core rights covered by these requests include:
- Right to access: See what personal data a company holds about you
- Right to correction: Fix inaccurate or incomplete records
- Right to deletion: Ask a company to erase your data
- Right to opt out: Stop the sale or sharing of your personal information
- Right to restrict processing: Limit how your data is used in specific circumstances
- Right to data portability: Receive your data in a machine-readable format (primarily a GDPR right)
Identity verification is mandatory. Companies must confirm you are who you claim to be before releasing or deleting data, which protects everyone from unauthorized disclosures.
Why you should submit a privacy rights request
Most people have no idea how much data companies hold about them. Submitting a data privacy request is one of the few direct ways to find out and do something about it.
Here are the main reasons to exercise your rights:
- Regain control over your data: You can see exactly what a company knows about you and decide whether that use is acceptable.
- Stop unwanted marketing: Opting out of data sales cuts off the pipeline that feeds targeted advertising and unsolicited outreach.
- Fix inaccurate records: Incorrect data can affect credit decisions, insurance rates, and even employment background checks. A correction request forces the company to update it.
- Limit data broker exposure: Data brokers collect and sell your information without any direct relationship with you. Submitting deletion requests to them reduces your digital footprint.
- Exercise legal rights under the CCPA: California residents have some of the strongest user privacy rights in the country, and using them is the only way to make those rights real.
- Prevent unauthorized data sharing: Once you submit a request, the business must also notify any service providers or third parties it has shared your data with.
- Build a paper trail: Documented requests create a record you can use if a company fails to comply, supporting formal complaints or legal action.
The practical impact compounds quickly. A single deletion request to a data broker can remove your profile from their database and stop future sales of that data to advertisers, insurers, and other buyers.
Who must comply with privacy requests in the US
Not every business in the United States is legally required to honor privacy information requests. The rules depend on which state law applies and whether the company meets specific thresholds.
Under the CCPA, a business must comply if it meets at least one of these criteria:
- Annual gross revenues exceed $25 million
- Buys, sells, receives, or shares the personal information of 100,000 or more consumers or households per year
- Derives 50% or more of annual revenues from selling consumers’ personal information
Data brokers are a special category. California requires data brokers to register with the California Privacy Protection Agency and honor deletion and opt-out requests. These are companies you may never have directly interacted with, yet they collect and sell detailed profiles about you.
Beyond California: Several other states, including Virginia, Colorado, Connecticut, and Texas, have enacted their own privacy laws with similar compliance requirements. Many large platforms voluntarily extend CCPA-style rights to all US residents, not just Californians, because managing state-by-state variations is operationally complex.
GDPR applicability for US residents: The GDPR applies to organizations established in the European Union or those that target EU residents. If you are a US resident with no EU connection, GDPR rights generally do not apply to you directly. However, many global companies apply GDPR-equivalent standards worldwide as a baseline.
One important nuance: even covered businesses are not required to honor requests for de-identified data, aggregated data, or information protected as a trade secret. Knowing this scope helps you frame requests that are more likely to get a complete response.
How to submit a privacy rights request step by step
The process is more straightforward than most people expect. Here is how to do it effectively.
Step 1: Find the company’s privacy policy
Look for a “Privacy Policy” link, usually in the footer or header of a website. California-regulated businesses are also required to post a “Do Not Sell or Share My Personal Information” link or a “Your CA Privacy Choices” option. That page will tell you exactly how to submit a request.
Step 2: Choose your submission method
Companies typically offer three channels:
- Web form: The fastest option for most people. Many companies use automated privacy dashboards that process requests faster than manual review.
- Email: Send a written request to the privacy contact listed in the policy, usually something like privacy@company.com.
- Toll-free phone number: Required for CCPA-covered businesses. Useful if you prefer not to submit anything in writing.
Step 3: Provide identifying information
You only need to supply what the company genuinely needs to locate your records and confirm your identity. Typical requirements include your name, email address, and account information if you have one. Some companies may ask you to answer security questions or click a verification link. Government-issued ID is sometimes requested for sensitive data categories.

What you should not have to provide: Social security numbers, financial account numbers, or any information unrelated to confirming who you are. If a company demands excessive verification, that itself may be grounds for a complaint.
Step 4: Wait for the response
Under the CCPA, businesses have 45 days to respond, with a possible extension. Under GDPR, the deadline is 30 days, and extensions are allowed for complex or voluminous requests. The company may contact you during that window if it needs clarification.
Step 5: Escalate if the request is ignored or denied
If a business ignores your request or you believe it did not follow the law, you can file a complaint with the California Privacy Protection Agency. Before going that route, try contacting the company’s Data Protection Officer or Privacy Officer directly. That step often resolves issues faster than a formal complaint.
Pro Tip: Save a screenshot or email confirmation of every request you submit, including the date, method, and any confirmation number. That record is your primary evidence if you ever need to escalate.
What rights do you actually have under US privacy laws?
The CCPA and its amendment, the California Privacy Rights Act (CPRA), give California residents a specific set of rights. Here is what each one covers in practice.
Right to know
You can ask a business to disclose the categories and specific pieces of personal information it has collected about you, the sources of that data, the business or commercial purpose for collecting it, and the third parties it has shared it with. This right covers data collected in the 12 months before your request.
Right to delete
You can request that a business delete your personal information. The business must also direct its service providers to delete the same data. Exceptions exist: companies can retain data they need to complete a transaction, detect security incidents, comply with legal obligations, or exercise free speech rights.
Right to correct
If a business holds inaccurate personal information about you, you can ask it to correct the record. The CPRA added this right, bringing California closer to the GDPR’s rectification standard.
Right to opt out of sale or sharing
You can tell a business to stop selling or sharing your personal information with third parties for cross-context behavioral advertising. This right applies even if you previously consented to data sharing.
The Delete Request and Opt-out Platform (DROP)
The California Privacy Protection Agency runs a free tool called DROP that lets you submit a single request to delete your data across all data brokers registered with the agency. Without DROP, you would need to contact hundreds of data brokers individually. DROP is available to all California residents at no cost and is one of the most practical tools available for reducing your data broker exposure.
Costs and fees
The first copy of your personal data is free under both CCPA and GDPR. Additional copies may carry a reasonable administrative fee. Businesses cannot charge you for submitting a deletion or opt-out request.
CCPA vs. GDPR: key differences
| Feature | CCPA (California) | GDPR (European Union) |
|---|---|---|
| Response deadline | 45 days (CCPA, extensions allowed for complex requests) | 30 days (GDPR, extensions allowed for complex requests) |
| Right to portability | Limited | Full |
| Right to restrict processing | Not explicit | Yes |
| Applies to | California residents | EU residents / EU-targeting orgs |
| Cost for first access request | Free | Free |
| Enforcement body | California Privacy Protection Agency | National Data Protection Authorities |
For a deeper look at how these frameworks affect analytics and marketing data, the privacy compliance guide from Trackingplan covers the operational side in detail.
Best practices for documenting and following up on privacy requests
Submitting a request is only half the job. How you document and follow up determines whether you can enforce your rights if something goes wrong.

Be specific about what you are requesting
The right of access is designed to let you verify that data processing is lawful, not to extract every internal document a company has ever created. Specify the data categories you want: purchase history, location data, email records, or inferred attributes. Broad, unfocused requests invite equally broad responses that are hard to act on, and they can slow down processing.
Document every step
Record the following for each request you submit:
- Date of submission
- Submission method (web form, email, phone)
- Confirmation number or email receipt
- Name of the company and the specific right exercised
- Any follow-up communications and their dates
Thorough documentation of this kind is what turns a denied or ignored request into a viable complaint with a regulatory agency.
Provide minimal but sufficient verification
Match the verification information you provide to what the company actually needs. If you have an account, your login credentials are usually enough. Avoid volunteering sensitive identifiers like your full social security number unless the company can clearly justify why it needs them. Disproportionate verification demands are a recognized problem, and regulators take complaints about them seriously.
Follow up before escalating
If the deadline passes without a response, contact the company’s Data Protection Officer or Privacy Officer first. A direct follow-up often resolves the issue without regulatory involvement. If that fails, file a formal complaint with the California Privacy Protection Agency or the relevant state authority.
Pro Tip: When building a complaint file, include your original request, any confirmation receipts, follow-up emails, and a timeline showing the missed deadline. Regulatory agencies move faster when the evidence is organized and complete.
Recognize and push back on excessive demands
Companies sometimes ask for more information than they need, either to delay compliance or out of genuine confusion about the rules. If a company asks for your social security number to process a simple access request, that is disproportionate. You can push back in writing, citing the proportionality standard, and note that you will file a complaint if the demand is not withdrawn.
For marketing teams managing the other side of this process, Trackingplan’s data subject access request guide explains how organizations should handle incoming requests to stay compliant.
Key Takeaways
Privacy rights requests give individuals direct, legally enforceable control over personal data, with CCPA requiring a 45-day response and GDPR requiring 30 days.
| Point | Details |
|---|---|
| Response deadlines | CCPA requires a response within 45 days; GDPR requires 30 days, and both allow extensions for complex or voluminous requests. |
| California’s DROP tool | The California Privacy Protection Agency’s free DROP platform lets you delete data from all registered data brokers with a single request. |
| Verification limits | Companies can only ask for information proportionate to confirming your identity; excessive demands are grounds for a complaint. |
| Documentation matters | Recording the date, method, and confirmation of every request is the foundation of any enforcement action if a company fails to comply. |
| First request is free | Both CCPA and GDPR require businesses to provide the first copy of your personal data at no charge. |
FAQ
What is a privacy rights request?
A privacy rights request is a formal, legally protected submission asking an organization to access, correct, delete, or restrict the use of your personal data. Laws like the CCPA and GDPR give individuals the right to make these requests, and covered businesses must respond within set deadlines.
What are examples of privacy rights?
Under the CCPA and GDPR, your rights include the right to know what data a company holds, the right to delete it, the right to correct inaccurate records, and the right to opt out of the sale or sharing of your personal information.
Can you request to see your personal information?
Yes. Both the CCPA and GDPR give you the right to access the personal data a company holds about you, including the categories of data, its sources, and who it has been shared with. The first copy is free, and the company must respond within 45 days under CCPA or 30 days under GDPR, with extensions allowed for complex or voluminous requests.
How do you ask a platform like Meta to delete your data?
Find the platform’s privacy policy or settings page and look for a data deletion option. Submit a deletion request through the web form or privacy email listed there. Meta and similar platforms are subject to CCPA if they meet the revenue or data volume thresholds, so California residents can also file a complaint with the California Privacy Protection Agency if the request is ignored.
What happens if a company ignores your privacy request?
If a company misses the response deadline, contact its Data Protection Officer or Privacy Officer directly as a first step. If that does not resolve the issue, file a formal complaint with the California Privacy Protection Agency or your state’s relevant regulatory body. Clear documentation of your original request and follow-up attempts is essential to support that complaint.











