Privacy guide · 11 min read

How to Make a Company Delete Your Data

Erasure and objection are different rights, and for marketing only one of them can be argued with. What to send, what deadline applies, what comes back.

YeyMail Team ·

Somebody has your email address who should not, and this time you know who. Perhaps an address you gave to one company started receiving mail from somewhere else. Perhaps the company told you itself, in a breach notification. Perhaps you signed up years ago and have regretted it since. Either way you have a name, and you want your data gone.

Getting the name is a separate problem, and the method that works has to be in place before the leak rather than after it. This post picks up where that one stops. It is the step that guide ends on and never explains: how you turn a company's name into a deletion that actually happens.

This is general information and not legal advice. It covers the UK and EU position in most detail, because those rules are the best documented by the regulators, with a shorter and more honest note on the United States. Every rule below comes from a regulator's guidance or from the legislation.

The right you use matters more than the wording

Most guides treat this as one thing and call it a deletion request. It is two different rights, and choosing the wrong one is the commonest way a perfectly reasonable request gets refused.

The first is erasure, at Article 17 of the GDPR and its UK equivalent. The ICO states plainly that the right is not absolute and only applies in certain circumstances: where the data is no longer necessary for the purpose it was collected for, where you withdraw consent and there is no other lawful basis, where you have objected and there is no overriding legitimate interest, where the data is processed for direct marketing and you object, where the processing was unlawful, where the company has a legal obligation to erase, or where the data was collected from a child for an online service.

The second is the right to object, at Article 21. For most purposes an objection is not absolute either. You have to give reasons based on your particular situation, and the company may weigh them against its own compelling legitimate grounds. But for direct marketing the ICO's guidance to organisations is unambiguous: this is an absolute right and there are no exemptions or grounds on which a company may refuse. Its public page says the same from your side, that organisations cannot refuse an objection to marketing targeted at you.

That is the whole lever. Erasure arrives with a published list of grounds on which a company may lawfully decline. A direct marketing objection arrives with none of those. The ICO's guidance to organisations says in terms that there are no exemptions or grounds to refuse it. The one route left open is the one that applies to any rights request: a company can still refuse if it can show the request is manifestly unfounded or excessive. If what you want is for the marketing to stop, object first and ask for erasure second, because the objection is the half of the request there is no argument against.

SituationRight to useCan they refuse?Realistic outcome
Marketing email you never asked forObject, direct marketingNot on the meritsMail stops, you stay on a suppression list
A signup you regretErasure, consent withdrawnSometimesAccount gone, minus what they must keep
Data held after a breach noticeErasure, on a ground that still has to applySometimesIf a ground applies: live records deleted, backups put beyond use
Ad targeting on legitimate interestsObject, with your reasonsYes, if their grounds override yoursVaries, so make them state the grounds

Sending it

In the UK and the EU there is no special form and no portal you are obliged to use. California works the other way: send the request through one of the business's designated methods, which its privacy policy has to set out. The ICO is explicit that the law does not specify how to make a valid request, that it can go to any part of the organisation, and that it need not quote Article 17 or use the phrase request for erasure. A request can be made verbally, but the ICO's own advice is to follow it up in writing, because that gives you proof of what you asked for. Keep the sent copy.

Say which right you are exercising and what data you mean. If you are objecting to something other than marketing, give your reasons, because the company is entitled to weigh them. If you are objecting to marketing, you need no reason at all.

The company may ask you to prove who you are, where it has genuine doubts, but only so far as is necessary and proportionate. That has a practical consequence: where identity information is requested, the clock starts when they receive it, not when you first wrote.

The deadline is one calendar month, counted from the day the request arrives to the corresponding date in the following month. It can be extended by a further two months where the request is complex or where you have made several, but the company must tell you inside the first month and explain why. A refusal is still a response and is still owed within the same month, with reasons and with your right to complain to a supervisory authority.

There is normally no fee. The ICO's position is that in most cases a company cannot charge for an erasure request or an objection. The exception is a request judged manifestly unfounded or excessive, where it may instead charge a reasonable fee based on the administrative cost, or refuse, and must tell you which.

A request you can adapt

Dear [company], I am writing to exercise two rights under data protection law. First, I object to the use of my personal data for direct marketing. Second, I ask you to erase the personal data you hold about me. Third, if you have disclosed my data to anyone else, please tell me who the recipients were. My account is in the name [name], at [email address]. Please confirm in writing within one calendar month what you have done, and if you are keeping any of my data, say which data and on what ground.

What actually happens next

Partial compliance is the normal outcome, and it is not always the company being difficult. The account gets closed, the marketing stops, and something remains: an invoice they must keep for tax purposes, a record in a backup not yet overwritten, or, most confusingly of all, your email address.

That last one deserves explaining, because it looks exactly like obstruction and usually is not. The ICO's guidance to organisations is that an objection to direct marketing does not automatically mean they need to erase your personal data, and that in most cases suppressing your details will be preferable. Suppression, in the regulator's words, involves retaining just enough information about you to ensure that your preference not to receive direct marketing is respected in future.

Its public page puts the same point from your side. Organisations can keep your name on a suppression list even after you have objected, so that they can comply with your request and not mistakenly market to you again. Consider what full deletion of your address would mean. The company would hold no record of you at all, so the next time your address arrived on a purchased list there would be nothing to check it against and no way to know you had asked them to stop. The suppression record is not the company defying your objection. It is the mechanism by which the objection keeps working.

One under-used part of the request is worth adding. If the company has disclosed your data to others, it must inform each recipient of the erasure unless that proves impossible or involves disproportionate effort, and if you ask, it must tell you who those recipients were. Ask. It is the only lawful route you have to the next name in the chain.

When they can lawfully say no

Erasure has real exemptions, and the actual categories are worth knowing rather than a paraphrase. Under Article 17(3) the right does not apply where processing is necessary for exercising the right of freedom of expression and information, for compliance with a legal obligation, for the performance of a task carried out in the public interest or in the exercise of official authority, for archiving in the public interest or for scientific, historical or statistical research where erasure would seriously impair it, or for the establishment, exercise or defence of legal claims. Two further exceptions cover special category data held for public health reasons and for medical or social care purposes under professional secrecy.

A company may also refuse a request it considers manifestly unfounded or excessive, and the bar is high. The first covers requests made with no genuine intention to exercise the right, or made to harass. The second covers requests repeating earlier ones, though raising the same issue twice is not automatically excessive, particularly where the first attempt was handled badly.

If they refuse, or say nothing at all

The ICO asks you to complain to the organisation first and give it the chance to resolve the matter. In the UK, the Data (Use and Access) Act 2025 requires organisations to acknowledge a data protection complaint within 30 days, counted from the day after they receive it, to keep you updated on progress, and to provide an outcome without an unjustifiable or excessive delay. The 30 days is an acknowledgement clock only: the law sets no fixed time limit for the outcome itself.

If that goes nowhere you can complain to the ICO, and it is worth being realistic. Its complaints page states that cases needing closer examination are currently being assigned to case officers within 40 weeks of submission, and that the ICO cannot award compensation even where it finds the law has been broken. The likeliest useful outcome is that it tells the organisation to do more work on your case.

In the EU the escalation route is similar and mostly only the address differs, but the 30-day acknowledgement duty above is a UK rule with no EU-wide equivalent. You complain to your own national supervisory authority, and the European Data Protection Board publishes the current list for every member state. The underlying rights are the same everywhere, with national procedure on top. Both routes leave the courts open, and the ICO's own sensible advice is to take independent legal advice first.

The United States, honestly

None of the rights above apply in the United States. Deletion rights there are created state by state, under statutes like California's, so what you can ask for depends on where you live. This section covers California only, because it is the state whose own regulators publish the detail.

California is the best-documented example. The Attorney General's guidance says you can request that businesses delete personal information they collected from you. A business must offer at least two methods for submitting a request, though an online-only business need only offer an email address, and you cannot be made to create an account in order to ask. The state privacy agency adds that a business must confirm receipt within 10 business days and respond substantively within 45 calendar days, extendable by a further 45 if it notifies you.

The exceptions look familiar: completing a transaction or providing a service you asked for, security purposes, legal compliance and legal claims, and categories the law excludes such as publicly available information and certain medical and credit reporting data. There is no Californian equivalent of the absolute marketing objection. The nearest thing is a separate right, to stop a business selling or sharing your personal information.

The honest ceiling

Everything above works against a company you can name and reach. That is narrower than it sounds.

Deleting your data from a company does not un-leak it. If the address was sold on before your request arrived, the buyer holds a copy your request does not touch, because you did not send it to them and you have no idea who they are. If it appeared in a breach dump, that dump has been copied, mirrored and traded, and no request reaches a file already sitting on somebody's hard drive. The broker three hops downstream will never hear from you, for the simple reason that you will never learn its name.

The duty to inform other controllers is real but bounded. It covers recipients the company disclosed the data to, subject to impossibility and disproportionate effort, and reasonable steps where the data was made public online. It does not reconstruct the chain for you.

So treat this for what it is. It reduces the number of live copies sitting inside companies you can name, it stops those companies marketing to you for good, and it produces a written record you can escalate. It is maintenance rather than a remedy. And it depends entirely on attribution, because without a name there is nobody to write to. That is why working out which company leaked your address is the prerequisite rather than the optional extra.

Making the next one easier

The hard part of all this was never the letter. It was knowing who to send it to, and being able to show that they had your address. Both are decided long before the request, by how you hand the address out. A distinct address per company turns an unwanted message into evidence with a name attached, and makes a suppression list something you can verify, because you will notice at once if that address starts receiving mail again.

Save the message with its headers, note the date you sent the request, and put the one-month date in the calendar. If you have to escalate, that timeline is most of the case. As for the copies already in circulation, that is a separate job and a question of containment rather than deletion.

The YeyMail takeaway
The address that makes the request possible

YeyMail gives every company its own forwarding address, which is what makes a request like this possible at all. When mail arrives at an address only one company ever had, the company is named and the evidence is the message itself. The activity view keeps per-alias delivery events for 90 days, so you can check whether the mail really stopped after they told you it had. If it did not, the kill switch refuses further mail at SMTP time, so the sender gets a rejection rather than having the message accepted and quietly dropped. It is never paywalled and it keeps working after you cancel. Starter is $0.99 a month or $9.48 a year and Plus is $4.99 a month or $47.88 a year, and there is a free 7-day trial with no card, giving you the Starter feature set with lighter limits. We are not lawyers, and nothing above is legal advice.

Start free — one alias per signup7-day trial · No credit card

Sources

Common questions

Do I have to use a specific form to request deletion?

In the UK and the EU, no. The ICO states that data protection law does not specify how to make a valid request, that it can be made verbally or in writing, and that it can go to any part of an organisation rather than a named contact. It does not have to quote Article 17 or use the phrase request for erasure. Writing is still better, because the ICO's own advice is to follow up any verbal request in writing so you have proof of what you asked for. California is the exception: the Attorney General's guidance tells you to submit a deletion request through one of the business's designated methods, listed in its privacy policy.

How long does a company have to reply?

One calendar month in the UK and EU, counted from the day the request arrives to the corresponding date in the following month. It can be extended by a further two months where the request is complex or where you have made a number of requests, but the company must tell you within the first month and explain why. In California, a business must confirm receipt within 10 business days and respond substantively within 45 calendar days, extendable by another 45 days with notice.

Why does a company keep my email address after I ask them to delete it?

Usually because you objected to marketing rather than only asking for erasure. The ICO's guidance says that in most cases suppression is preferable to erasure in that situation, and suppression means retaining just enough information about you to ensure your preference not to receive direct marketing is respected in future. If the company held nothing at all, it would have no way to recognise your address the next time it arrived on a purchased list.

Can a company charge me a fee?

In most cases no. The ICO's position is that a company cannot normally charge for either an erasure request or an objection. The one exception is a request the company judges manifestly unfounded or excessive, where it may charge a reasonable fee based on the administrative cost of complying, or refuse outright. Either way it has to tell you and justify the decision.

What can I do if they ignore me?

Complain to the organisation first, since the ICO asks you to give it a chance to resolve the matter. In the UK, organisations must acknowledge a data protection complaint within 30 days and provide an outcome without unjustifiable or excessive delay; that specific deadline is a UK rule and does not apply across the EU. If that fails, complain to the ICO in the UK, or to your national supervisory authority in the EU. Be realistic about timing: the ICO says cases needing closer examination are currently being assigned to case officers within 40 weeks of submission, and it cannot award compensation.

Does deleting my data from a company fix a leak?

No. A request binds only the company you send it to. A copy sold on before your request arrived, or one circulating in a breach dump, is untouched by it, and you will usually never learn the name of the broker holding it. The process reduces the number of live copies at companies you can name, which is worth doing, but it is not a remedy for a leak that has already happened.

Keep reading

Privacy guide
How to Find Out Which Company Leaked Your Email
Breach response
Your Email Was Leaked: The Complete What-Now Checklist
Guide
How to Stop Spam Emails (Filters Aren't Enough)