GDPR Erasure Requests: How to Ask a Company to Delete Your Data

A genuinely strong right, with limits worth knowing before you rely on it.


If you're in the EU or UK, you can require most organisations to delete the personal data they hold on you, free, with a one-month response deadline. It's one of the strongest privacy rights available anywhere and it applies to data brokers as much as to anyone else. It also has real exceptions — legal obligations, ongoing contracts, and legal claims can all defeat a request — so it's a strong tool rather than a universal one.

What the right actually is

The right to erasure — often called the right to be forgotten — lets you ask an organisation to delete personal data about you. It's free, and they must respond within one month, extendable by a further two for complex requests.

You don't need to justify it in most cases. Where their basis for holding the data is consent or legitimate interests, withdrawing consent or objecting is generally enough.

How to make one

  1. Find the right contact. The privacy policy names a data protection officer or privacy contact. Use that rather than general support, which often doesn't route these correctly.
  2. Say what you're doing. State plainly that you are making a request for erasure of your personal data under the GDPR (or UK GDPR). Naming it matters — it starts the clock and creates an obligation.
  3. Identify yourself just enough to let them find your records. Name, the email address you used, and any account reference. No more.
  4. Ask them to confirm what was deleted and to tell anyone they shared it with.
  5. Record the date. The one-month clock runs from receipt.
The identity-verification trap

They may verify who you are before acting, which is legitimate — they mustn't delete the wrong person's records. But requests for a government ID to erase a record containing only your name and email are disproportionate.

Give the minimum needed to match what they hold. If a data broker asks for far more than they display, that itself is worth questioning. The same trap in broker opt-outs

When they can refuse

  • Legal obligation. Financial and tax records have statutory retention periods. Your bank cannot delete your transaction history on request.
  • Contract performance. An active service needs the data to deliver it.
  • Legal claims. Data needed to establish or defend a claim can be retained.
  • Freedom of expression, and journalistic or archival purposes.
  • Public interest tasks and certain public-health or research purposes.

A partial refusal is common and often correct: they delete the marketing profile and keep the invoices. They must explain which and why.

If they ignore you

Complain to your supervisory authority — the ICO in the UK, your national data protection authority in the EU. It's free, and regulators do act on patterns of non-response. Include the date of your original request and any reply.

Using it against data brokers

This is where it's most useful, because brokers rarely have a lasting legal basis to keep your data once you object. There's no central portal, so it's one request per broker — free, effective, and tedious.

Work from a list of brokers actually showing your data rather than a generic top-100 list. Where this sits among the free routes

The limit worth knowing

Erasure is retrospective. It removes records that exist; it does nothing about what you disclose next week, and brokers continuously re-ingest from public records nobody can be deleted from — so a deleted record can reappear from a source you never dealt with. Why

Which is why it pairs with prevention rather than replacing it. The two halves

Give every service its own address

Don't SPAM Me puts unlimited aliases on a domain you own. Any address at that domain starts working the first time mail arrives, and when spam turns up you know exactly which company leaked it. The software is free; you bring the domain, or register one during setup.

Get started — free

Keep reading