Data Rights & Account Deletion

You’ve probably seen the “Delete my account” link buried somewhere in settings and assumed it works like emptying a trash bin. It doesn’t. That button tries to move your data through a thicket of systems, vendors, legal carve-outs, fraud controls, backups, and analytics identifiers. On the other side are real rights you can use—access, export (a.k.a. portability), deletion, and opt-out signals—but they only deliver if you ask for the right thing, in the right way, and keep evidence while the clock runs. This guide is a deep, practical walkthrough of those rights in the U.S. (with occasional international contrasts), how companies actually implement them, and where requests stall. Along the way, I’ll translate the law into plain language, explain complex terms, and show you how to turn a one-line “please delete” into a documented, end-to-end outcome.

The map of your rights (U.S. first, EU for contrast)

In the United States, privacy rights are a patchwork. California’s CCPA/CPRA gives you rights to know, access, delete, correct, and opt-out of the “sale” or “sharing” of your personal information, with deadlines and verification rules. In California, a business generally has 45 days to respond, with a possible 45-day extension if it tells you within the first 45 days; responses must come in a “readily usable” format that you can transmit to another entity. (FindLaw Codes, California Privacy Protection Agency, Sidley Austin)

Colorado’s law is similar on paper—45 days plus a 45-day extension—and adds a strong “universal opt-out” requirement that forces businesses to honor a browser-level signal (Global Privacy Control) for targeted ads and sales. Virginia, Colorado, and other newer state laws also give you a formal right to appeal if a company refuses your request; Virginia’s statute sets a 60-day deadline to resolve that appeal. (thesedonaconference.org, Colorado Attorney General, Virginia Law)

Financial and health data have their own federal regimes. Gramm-Leach-Bliley (GLBA) focuses on notice and limited opt-outs rather than a general right to delete. HIPAA gives you a powerful right of access to your medical records within 30 days, but not a generic right to “erase” them. That’s why your healthcare portal feels different from a shopping app. (Federal Trade Commission, Legal Information Institute, AIHC)

For contrast, the European Union’s GDPR centralizes these rights: Article 15 (access), Article 20 (portability), and Article 17 (erasure). The default response time is one month (extendable by two in complex cases under Article 12(3)). U.S. services with EU users must honor those rights for those users. (GDPR)

What “access” really means—and why it’s your leverage

An access request isn’t just “send me my data.” Under California and the GDPR, you’re entitled to categories and specific pieces of data, sources, recipients, how long it’s kept, and the purposes of processing. Think of it as your audit log. If a company sends you only a PDF “report,” you can push for actual data in a usable format; California requires “readily usable,” while the GDPR says “commonly used, machine-readable.” In practical terms, CSV/JSON beats screenshots. If you’re in health care, HIPAA’s access rule is explicit: the covered entity must provide what it keeps in your “designated record set” regardless of age or location of storage, and it has 30 days to act. That’s one of the fastest clocks in U.S. privacy. (Sidley Austin, GDPR, HHS.gov)

Two pro moves make access requests pay off. First, identify the account identifiers the company uses (email variants, phone numbers, device IDs) so its search is complete. Second, ask for “a copy of my personal data and a list of all third parties to whom you disclosed it in the past 12 months.” California’s transparency provisions and CPPA regulations support disclosures about sources and recipients. If the export shows vendors you don’t recognize, you’ve just mapped where to send follow-on deletion requests. (California Department of Justice)

Export and portability—download vs. “direct transfer”

“Export,” “download,” and “portability” get used interchangeably, but the legal standards differ. California’s “readily usable” format is meant to let you transmit the data to another entity without hindrance; the GDPR goes further and contemplates direct controller-to-controller transfer “where technically feasible.” If the service offers only a human-readable PDF, it may satisfy disclosure but not portability. Ask for structured files (CSV/JSON) for data tables like transactions or activity logs. That format choice determines whether your data is practically reusable. (Sidley Austin, GDPR)

Deletion vs. deactivation vs. suppression—words that make or break outcomes

Deletion under California means removing your personal information from active systems and instructing service providers and contractors to do the same, subject to enumerated exceptions (think legal obligations, security, debugging, or uses reasonably aligned with your expectations). If a business denies deletion, it should cite the exception; you can demand partial deletion of non-exempt fields. (Justia, consumerprivacyact.com)

Deactivation often just means the account can’t log in; the records live on. Unless you see a deletion confirmation aligned to the statutory language—and the company has told its vendors—it’s not the same right. California regulations spell out how businesses must process delete requests and the 45-day + 45-day timeline. (California Privacy Protection Agency)

Suppression (or “put beyond use”) is the compromise for tricky data stores: the record persists in an archive or backup but is quarantined from production use. UK regulators have long acknowledged “put beyond use” as a practical step when immediate physical deletion from backups is disproportionate. French CNIL, likewise, expects backup erasure plans or guarantees that data in backups won’t be restored to production. If a service cites “backups” to stall your request indefinitely, you can press for a suppression guarantee and a future-dated purge on the next backup rotation.

A realistic expectation: deletion takes time to propagate through analytics, logs, caches, and processors. California recognizes “disproportionate effort” in some edge cases, but companies can’t rely on their own poor processes to refuse your request. That clause is not a blank check. (California Privacy Protection Agency)

The trap doors: legal holds, fraud flags, and mandatory retention

Even the best deletion request runs into law-driven stops. Banks must keep certain records for five years under the Bank Secrecy Act/anti-money-laundering rules. Payment card environments often retain security logs for at least a year under PCI DSS 4.0. Healthcare entities may need to keep clinical records under state rules even if HIPAA lets you access them. When a company says “we can’t delete X for legal reasons,” this is what they mean; the requirement should be specific and documented, and non-essential fields should still be removed or masked. (Federal Trade Commission, Protecting Student Privacy)

Another trap is the fraud and chargeback stack. Merchants and payment processors frequently keep device fingerprints or risk scores to prevent abuse; those data elements may be retained under security exceptions while marketing profiles get purged. Your leverage is to separate categories: “Delete my marketing and personalization data; suppress my identifiers from being used for advertising; retain only what is strictly necessary for fraud and legal obligations.”

Verification, authorized agents, and avoiding the “prove it’s you” dead-end

Reasonable verification is required so companies don’t hand your data to impostors. California’s CPPA rules detail how verification works for account-holders and non-account-holders and how authorized agents can act for you. The key is proportionality: the company shouldn’t demand more sensitive data than it already maintains just to verify you, and it must publish a method that ordinary users can actually complete. If you hit a wall, cite the CPPA verification sections and ask what specific data points they are matching against; give them only those. (California Privacy Protection Agency)

Authorized agents—lawyers, privacy services, even a family member—can submit on your behalf in California if you provide written permission or a power of attorney. Companies may still need to verify you, but they cannot refuse agents categorically. (California Privacy Protection Agency)

The clock: timelines, extensions, and your right to appeal

Under California, the business has 45 days to respond and can extend once for 45 more days with notice and reason, for a hard cap of 90. Under the GDPR, controllers have one month, extendable by two for complexity. Virginia and Colorado mirror the 45-day window and add a formal appeal right if a controller denies or ignores you; Virginia’s statute forces a written decision on appeal within 60 days and must tell you how to contact the Attorney General if it still refuses. Colorado’s rules also require clear disclosures and documentation of authentication efforts. Put those clocks in your calendar when you send a request. (Sidley Austin, GDPR, Virginia Law, Colorado Secretary of State)

Global Privacy Control and “frictionless” opt-outs

Deletion is not your only move. If you don’t want to be tracked in the first place, enable Global Privacy Control (GPC) in your browser. California requires businesses to treat an opt-out preference signal like GPC as a valid, user-enabled request to stop selling or sharing your data; Colorado’s Attorney General has formally recognized GPC as the first and currently only valid Universal Opt-Out Mechanism, effective July 1, 2024. If a site says “we don’t recognize that,” they’re behind the law in two major states. (Legal Information Institute, Colorado Attorney General)

The Sephora case in 2022 made this real. California’s Attorney General announced a $1.2M settlement partly because the company failed to honor GPC. That enforcement wave kicked off broader compliance. If your GPC-enabled browser is ignored, reference that action in your complaint. (California Department of Justice)

Data brokers and California’s “Delete Act” one-stop

Even if you delete at a retailer, your data may live on at data brokers—companies you’ve never interacted with that trade in personal information. California moved the broker registry from the AG to the CPPA and passed the Delete Act, which requires a central, one-click deletion mechanism across registered brokers by January 1, 2026. Brokers must check and process those requests on a 45-day cycle and instruct their service providers to delete, with limited exceptions mirrored from CCPA. Keep an eye on that CPPA portal; it will become a high-leverage tool for Californians. (BCLP)

Vermont also has a data broker registry and opt-out rules, but California’s unified delete mechanism is the most aggressive. If you live elsewhere, you can still use California brokers’ tools—they often act nationwide—but your legal leverage is strongest if you’re a California resident.

Children’s and students’ data—special lanes

If your child is under 13, COPPA gives you the right to review and delete their data collected online by a “covered operator.” Schools are a special case: FERPA centers on access and amendment rather than deletion, but it does give you strong rights to review and correct education records. When a service refuses a child’s deletion by citing “we have parental consent on file,” respond by exercising COPPA’s parental review/deletion right explicitly. (California Department of Justice, Legal Information Institute)

Platform rules that help you find the switch

Two platform policies matter even before the law kicks in. Apple’s App Store Review Guideline 5.1.1 now requires apps that let you create an account to also offer an in-app way to delete it. Google Play’s policy similarly forces developers to provide an in-app and web-accessible deletion path and to explain what gets deleted and what persists. If you’re hunting for the control, start in-app; these rules pressure developers to surface it. (Apple Developer)

Controllers, processors, service providers—why vendor chains slow you down

Under the GDPR, the company that decides “why and how” data is processed is the controller; vendors that act only on its behalf are processors. California’s equivalents are business and service provider/contractor. When you send a deletion request to the brand, it must relay it to its service providers and contractors. If a vendor keeps emailing you after the brand claims to have deleted your data, ask the brand to identify that vendor and confirm downstream deletion—then contact the vendor directly with your evidence. The definitions matter because they determine who must act and who can claim an exemption. (Federal Trade Commission, Protecting Student Privacy)

Backups, archives, and the “we’ll get to it later” problem

Backups are the most common stall. Regulators get that live deletion from immutable backups can be disproportionate, but they expect guardrails: quarantine the data, don’t restore it to production, and erase it on the normal backup rotation. France’s CNIL says controllers must either delete in backups or ensure data from backups is never returned to production. If a company won’t commit to that, ask for written confirmation that your data is “put beyond use” and the date when the backup cycle will purge it. If there’s a litigation hold, ask them to isolate your records from marketing or product use until the hold lifts.

Building a clean, end-to-end playbook (what to say, what to keep)

Start with identity. List the emails, phone numbers, and usernames you’ve used with the service. If you have an account, submit your request while logged in; if not, use the published privacy address or web form and ask what data points they need to verify you under the CPPA verification rules, emphasizing proportionality. State precisely what you want: a machine-readable access export; deletion of non-exempt personal information; and instructions relayed to service providers and contractors. Reference the legal clock (“I understand you have 45 days to respond; please confirm receipt and timing”). Ask for a suppression guarantee for backups and archives.

As the days pass, keep a ledger of dates, ticket numbers, and what they promised. If they extend, they owe you notice and a reason within the first 45 days in California. If they deny or ignore you, invoke your appeal right (Virginia/Colorado and many other states), ask for a human review, and save the appeal response. If they still refuse, your complaint goes to the state regulator: CPPA/AG in California, AG in Colorado and Virginia, or to a Data Protection Authority if you’re in the EU. Each submission lands harder with a neat evidence pack: your original request, their acknowledgments, policy citations, and a list of data you still see in the product that contradicts their “we deleted” claim. (California Privacy Protection Agency, Virginia Law)

International notes (short and targeted)

If you’re an EU resident, the GDPR’s portability right goes beyond a simple download and can require direct transfer, which is useful when switching services. If you’re in the U.S. using an EU-based service, the company may still apply GDPR to you as a matter of product policy. Conversely, if you’re a U.S. resident in a U.S. service, don’t assume “right to be forgotten” exists—state law defines the scope and exceptions. (GDPR)

When they say “no”: reading refusals and pushing back

Refusals typically cite exceptions: legal obligations, security incidents, debugging, or “internal uses reasonably aligned with expectations.” Those can be legitimate—but they’re narrow. If a company refuses to delete data used for advertising by claiming a broad “internal use,” ask them to explain why targeted ads are “reasonably aligned” with your expectations based on their privacy notice at the time of collection. If they refuse access because verification failed, ask them to specify the data points required and to use an alternative channel consistent with CPPA’s verification rules; they must document why authentication failed. In Colorado and Virginia, press the appeal button and force a written rationale under the statutory timeline. (SixFifty, Colorado Secretary of State)

Bottom line

Data rights work when you make them specific, time-bound, and documented. Ask for a proper export, use that export to guide deletion downstream, force recognition of your opt-out signals, and don’t let “backups” or “legal obligations” swallow your whole request. Keep the tone factual, track the clock, and escalate with evidence. That’s how a one-line privacy request turns into a real purge.

Glossary (plain-English, with quick notes)

Access (Right of Access). Your right to see what a company holds about you and how it uses it. In California, the response must be within 45 days (extendable once); under HIPAA it’s 30 days for medical records; under the GDPR it’s one month. Access is leverage because it reveals vendors and categories for targeted deletion. (Sidley Austin, Legal Information Institute)

Portability (Export). Getting your data in a structured, commonly used, machine-readable format you can reuse or move. California says “readily usable;” the GDPR contemplates direct transfers between companies where feasible. CSV/JSON is the gold standard. (Sidley Austin, GDPR)

Deletion (Erasure). Removing your personal information from active systems and telling service providers to do the same, subject to carve-outs (legal obligations, security, debugging, etc.). Backups may be quarantined and purged on rotation rather than wiped instantly. (Justia)

Deactivation. Closing the account without deleting the underlying data. It’s not the same as legal deletion; ask explicitly for deletion and backup suppression.

Suppression / “Put beyond use.” Preventing data from being used in production while it persists in archives or backups until those systems age out. Regulators accept this with guardrails.

Controller / Processor (Business / Service Provider). The controller/business decides why/how data is used; the processor/service provider acts on its instructions. Your requests to the brand should flow downstream to its vendors. (Federal Trade Commission, Protecting Student Privacy)

Global Privacy Control (GPC). A browser signal that tells sites to stop selling/sharing your data. Mandatory to honor in California and recognized as the official universal opt-out in Colorado as of July 1, 2024. (Legal Information Institute, Colorado Attorney General)

Appeal (Virginia/Colorado). A formal second look if your request is denied. Virginia requires a written decision within 60 days, with directions to the AG if refusal stands; Colorado sets similar obligations. Use it. (Virginia Law, thesedonaconference.org)

HIPAA Right of Access. Specific to medical records: the provider must give you access within 30 days; it’s about access, not deletion. (Legal Information Institute)

Delete Act (California). A forthcoming, one-stop portal (by Jan 1, 2026) to send a single deletion request to all registered data brokers; brokers must check and process on a 45-day cycle. (BCLP)

Sources & further reading (open-access)

  • California Privacy Protection Agency, CCPA Regulations (effective Jan. 2, 2024). The official rules on timelines, verification, deletion handling, and opt-out preference signals. https://cppa.ca.gov/regulations/pdf/cppa_regs.pdf (California Privacy Protection Agency)
  • California Civil Code § 1798.130 and § 1798.105. Statutory deadlines, “readily usable” format, and deletion scope/exceptions. https://codes.findlaw.com/ca/civil-code/civ-sect-1798-130/ and https://law.justia.com/codes/california/code-civ/division-3/part-4/title-1-81-5/section-1798-105/ (FindLaw Codes, Justia)
  • California Department of Justice, CCPA Overview. Consumer-facing explanations and pointers to exceptions. https://oag.ca.gov/privacy/ccpa (California Department of Justice)
  • Colorado Department of Law, Universal Opt-Out Mechanism list. GPC recognized as the first valid UOOM; obligations effective July 1, 2024. https://coag.gov/uoom/ (Colorado Attorney General)
  • Colorado Privacy Act rules and guidance on response timelines and appeals. https://www.sos.state.co.us/CCR/GenerateRulePdf.do?fileName=4+CCR+904-3 and overview: https://trustarc.com/resource/colorado-privacy-act-guide/ (Colorado Secretary of State, TrustArc)
  • Virginia’s Consumer Data Protection Act (appeals within 60 days). https://law.lis.virginia.gov/vacode/title59.1/chapter53/section59.1-577/ and AG summary: https://www.oag.state.va.us/consumer-protection/files/tips-and-info/Virginia-Consumer-Data-Protection-Act-Summary-2-2-23.pdf (Virginia Law, Virginia Attorney General's Office)
  • California AG press release, Sephora settlement—failure to honor Global Privacy Control. https://oag.ca.gov/news/press-releases/attorney-general-bonta-announces-settlement-sephora-part-ongoing-enforcement (California Department of Justice)
  • California Privacy Protection Agency, Delete Act / Data Broker registry. https://cppa.ca.gov/enforcement/priors.html and overview: https://www.bclplaw.com/en-US/events-insights-news/the-delete-act-a-first-of-its-kind-data-broker-law.html (BCLP)
  • GDPR text (English), Articles 12, 15, 17, 20 (access, timelines, erasure, portability). https://gdpr-info.eu/art-15-gdpr/ (GDPR)
  • HHS/OCR, HIPAA Right of Access. https://www.law.cornell.edu/cfr/text/45/164.524 and HHS FAQs: https://www.hhs.gov/hipaa/for-professionals/faq/right-to-access-and-research/index.html (Legal Information Institute, HHS.gov)
  • PCI DSS & AML/BSA retention context (illustrative). See PCI DSS 4.0 resources at https://www.pcisecuritystandards.org and BSA five-year recordkeeping summaries. (Federal Trade Commission, Protecting Student Privacy)
  • CNIL (France), Right to Erasure—handling deletion in backups and archives. https://www.cnil.fr/en/right-erasure-or-right-be-forgotten
  • Apple App Store Review Guidelines 5.1.1 and Google Play Account Deletion policy. https://developer.apple.com/app-store/review/guidelines/ and https://support.google.com/googleplay/android-developer/answer/13387467?hl=en (Apple Developer)

Note: Links above go to official texts or authoritative explainers so readers can verify details and cite them in complaints or appeals. If you want, I can turn this into a printable checklist and request letter template tailored to your brand voice.