How to Write a Privacy-Rights Opt-Out Request (CCPA & GDPR)
A practical anatomy of a CCPA or GDPR deletion request: identify the broker, state the right, provide match data, limit verification, and track follow-up.
Not all requests give a broker enough information to locate the right record. A concise request that identifies the listing, states the right you are exercising, and keeps a record of the exchange is easier to evaluate. Whether a law applies, what verification is reasonable, and whether an exception applies depend on the person, broker, and jurisdiction.
Key Takeaways
- A specific, written request is easier for a broker to match to the right record than a vague request.
- Include only the identifiers needed to locate the listing; avoid sending sensitive documents unless the broker explains why they are required.
- Name the privacy right you are exercising when it applies to you, but do not claim a law that does not apply.
- Keep a copy of the request, any verification exchange, and the broker's response.
- A statutory response period is not a promise of deletion; check the applicable regulator's guidance before escalating.
Four Elements of a Clear Request
1. The Subject Line
Make the purpose clear.
- *Less specific: "Remove my info"
- *Clearer: "Privacy request: deletion or opt-out for [your name]"
Use the broker's published privacy contact or form where available. Do not assume a particular subject line controls how a broker routes your request.
2. The Verification Data
Provide enough to identify the record, but not enough to create a new one.
Tired of dealing with data exposure?
Your personal data is likely on 545 data brokers. Use OfflistMe to generate pre-filled opt-out emails for all of them in one go.
- *Include: Full Name, City/State, Record URL (if found), email address on the listing.
- *Exclude: SSN, Driver's License number, Full DOB, financial account numbers.
The goal is to match the record that exists, not to prove identity by handing over sensitive documents. A broker may request reasonable verification under applicable law; an email address associated with a listing may help, but is not universally sufficient.
3. The Legal Citation
If a privacy law applies to you, name it accurately. Clear language helps, but a citation neither guarantees a result nor removes a broker's ability to apply lawful verification or exemptions.
- CCPA: *"I am exercising my right under California Civil Code § 1798.105(a) to request deletion of all personal information you have collected about me."*
- GDPR: *"I am exercising my Right to Erasure under Article 17 of the General Data Protection Regulation."*
- VCDPA: *"I am exercising my right to deletion under Virginia Code § 59.1-578(A)(3)."*
4. The "Do Not Sell" Declaration
For US brokers, an opt-out of sale or sharing can be separate from a deletion request. Ask for the actions you want, and use the broker's published process when it distinguishes them.
- "I strictly withhold consent for the sale, sharing, or transfer of my personal information under California Civil Code § 1798.120(a)."*
A Complete Opt-Out Email Template
Use this template verbatim, substituting your information in the bracketed fields:
To: privacy@[broker].com
Subject: Privacy request: deletion and opt-out
Attn: Privacy Compliance Officer
I am requesting deletion of personal information associated with me, where applicable, and an opt-out of sale or sharing where your process provides one.
Full Name: [Your Full Name]
City/State: [City, State]
Email: [Your Email]
Record URL (if known): [paste URL]
Legal Basis:
- If you process data of California residents: California Civil Code § 1798.105(a) (CCPA/CPRA)
- If you process data of EU/UK residents: GDPR Article 17 (Right to Erasure)
- If you process data of Virginia residents: Virginia Code § 59.1-578(A)(3) (VCDPA)
Requested Actions:
- Delete all personal information you hold about me.
2.
Do not sell, share, license, or transfer my personal information (Cal. 120).
3.
Please confirm receipt and explain any verification, exception, or next step required by your privacy process.
If an applicable privacy law sets a response period, please process this request within that period or explain why it does not apply.
[Your Full Name]
[Date]
Vague vs Specific Opt-Out Request
| Element | Weak (Often Ignored) | Strong (Legally Compliant) |
|---|---|---|
| Subject line | "Please remove my data" | "Privacy request: deletion or opt-out for [name]" |
| Identity proof | "My name is John" | Full name, city/state, email on file, record URL |
| Legal citation | "I have privacy rights" | "California Civil Code § 1798.105(a)" or "GDPR Article 17" |
| Opt-out declaration | Not included | Explicit: "Do not sell my personal information, § 1798.120" |
| Documentation | No saved record | Saved request, response, and verification notes |
State-by-State Legal Citations
Use the statute that matches your residency and circumstances. If you are unsure, use the broker's published privacy process and review the regulator's official guidance.
- *California (CCPA/CPRA): "California Civil Code § 1798.105(a). Right to Deletion" and "§ 1798.120(a). Right to Opt Out of Sale"
- *EU/UK (GDPR): "General Data Protection Regulation, Article 17. Right to Erasure ('Right to be Forgotten')"
- *Virginia (VCDPA): "Virginia Consumer Data Protection Act, Va. Code § 59.1-578(A)(3)"
- *Colorado (CPA): "Colorado Privacy Act, C.R.S. § 6-1-1306(1)(c)"
- *Connecticut (CTDPA): "Connecticut Data Privacy Act, Conn. Gen. Stat. § 4-48(b)(3)"
- *Texas (TDPSA): "Texas Data Privacy and Security Act, Tex. Bus. & Com. Code § 541.051(c)"
If you are not covered by one of these laws, do not claim coverage. Use the broker's published opt-out process and consider contacting the privacy regulator in your jurisdiction for guidance.
What to Do When Brokers Don't Respond
Step 1: Follow up at the applicable deadline. Check the broker's privacy notice and the regulator's current guidance before calculating a deadline. Send a concise follow-up that references the original request.
Step 2: FTC complaint. File at reportfraud.FTC.gov. Select "Identity Theft/Privacy" → "Data Broker." The FTC uses complaint volume to prioritize investigations. A filed complaint also creates a timestamped record useful in later escalation.
Step 3: State AG complaint. If you are in a covered state:
- California: oag.ca.gov/privacy (CPPA enforcement)
- Virginia: oag.state.va.us
- Colorado: coag.gov
Step 4: Private right of action. California CCPA § 1798.150 creates a private right of action for security breaches involving your data. For general non-compliance, CPPA enforcement is the primary mechanism. New Jersey's Daniel's Law (for covered professionals) and GDPR (for EU residents) provide stronger private rights.
Step 5: Small claims court. In some states, consumer protection statutes allow small claims filings for statutory damages from willful non-compliance. This is rarely worth it for a single broker but is effective when patterns of non-compliance exist.
Frequently Asked Questions
Q: Do I need a lawyer to send an opt-out request?
A: No. Individuals can use a broker's published privacy process directly. A lawyer may be appropriate for a complex dispute or litigation. This template is general information, not legal advice.
Q: What if the broker says it cannot find my record?
A: This sometimes happens with records indexed under a different name variation. Reply with alternate name formats (maiden name, common misspellings) and ask them to confirm a comprehensive search. Under CCPA, they must make a "reasonable effort" to locate the record.
Q: Can I send one email to all brokers or do I need individual emails?
A: Individual emails with the specific broker's name in the body are more effective, they signal a human wrote them and they clear spam filters better. OfflistMe generates per-broker emails with correct recipient addresses pre-filled.
Q: Does citing GDPR work for US residents?
A: Many brokers honor GDPR-cited requests globally because maintaining two separate response pipelines is operationally complex. It is not a legal entitlement for US residents, but in practice it often works. Always cite your home-state statute first.
Q: What's the difference between deletion and opt-out?
A: Deletion removes the record from the broker's database. Opt-out of sale stops the broker from selling your data to third parties, but they may still keep a suppressed record internally. For people-search sites, deletion is what you want. For marketing data brokers (Acxiom, Oracle), opt-out of sale is the primary lever.
Use a clear template, then verify the broker's current process.
Prepare privacy-rights request drafts for 500+ brokers →
What Makes a Request Easier to Evaluate
There is no magic wording that guarantees a broker will delete a record. A well-documented request is still useful because it identifies the record, states what you are asking for, and preserves a record for any appropriate follow-up.
It can start a statutory process. If a privacy law applies and the request is verifiable, that law may set a response period. The process can include verification, extensions, or exceptions, and the final response is not proof that every copy of a record is gone.
It creates enforceable documentation. An email with a statutory citation creates a timestamped legal record. If you later file an FTC complaint or state AG referral, you can show: request submitted on date X, statutory deadline was date Y, response received (or not) on date Z. This paper trail is what distinguishes a legitimate complaint from a speculative one.
It makes follow-up more concrete. A broker can still say it cannot locate a record or ask for reasonable verification. A request that records the profile URL, identifiers supplied, date sent, and the applicable process gives you a practical basis to clarify or escalate.
One nuance worth understanding: a state law does not automatically apply just because a broker is national. Use the law that applies to your residency and the broker's activities, and avoid making jurisdictional claims you cannot support.
How to Document Your Opt-Out Requests for Legal Use
Most people submit opt-out requests and forget about them. This is a mistake. Proper documentation transforms your opt-out emails from requests into a legal record that can support FTC complaints, state AG referrals, and in rare cases, litigation.
Step 1: Create a dedicated folder in your email client labeled "Data Broker Opt-Outs." Move every sent opt-out email and every confirmation you receive into this folder. Date-stamp the folder entries. This creates a searchable archive.
Step 2: Screenshot the broker profile before submitting the request. Before you email the opt-out, take a screenshot showing: the URL of the profile, the information displayed (address, phone, relatives), and the date (use your computer's date display in the screenshot if possible). Filename format: [broker-name]-profile-[YYYY-MM-DD].png. This is your "before" evidence.
Step 3: Log the request in a spreadsheet. Maintain a simple log with columns: Broker Name, Date Submitted, Email Address Used, Statutory Citation Used, Confirmation Received (Y/N), Date Confirmation Received, Deletion Confirmed (Y/N). A 15-row spreadsheet covering your Tier 1 brokers takes ten minutes to create and becomes invaluable if you need to escalate.
Step 4: Screenshot the deletion confirmation. When a broker sends a deletion confirmation email, screenshot it and save it alongside the before-screenshot. When the profile is gone, screenshot the 404 or empty search result. This is your "after" evidence.
Step 5: Note the 45-day deadline explicitly. When you submit to each broker, add a calendar reminder 46 days out labeled "Check [broker] compliance." If the profile is still live or you have received no response on day 46, your documentation is already ready to support a CPPA or FTC complaint.
This documentation process adds roughly 5 minutes per broker. For a typical 15-broker Tier 1 pass, that is 75 minutes of extra time that creates a comprehensive legal record. For survivors of stalking or domestic violence who may need this documentation for court proceedings, it is essential.
Drafting Enforceable First-Party Requests
Under CCPA, GDPR, and other modern privacy laws, first-party deletion requests submitted by consumers carry specific legal deadlines and obligations. Writing a request with the correct citations is essential to force compliance.
Key Elements of an Enforceable Request:
- Statutory Citations: Cite the specific law that applies to your residency (e.g., California Civil Code § 1798.105 for CCPA, or Tex. Bus. & Com. Code § 541.051 for TDPSA).
- Clear Identifiers: Provide the exact name variations, email addresses, and phone numbers associated with the profile. Do not provide sensitive files like SSNs or passport scans unless legally required.
- Explicit Instruction: Use clear directives: "I request the permanent erasure of all personal information and the suppression of future data collection."
- Documentation Trail: Keep a record of the submission date and any auto-response emails. If the broker does not process the request within the statutory window (typically 45 days), this record is the evidence needed to file a complaint with your state attorney general.
Related Guides
Understand your privacy rights
Every removal request cites a specific statute. These plain-English explainers show what each law covers and how enforcement actually works.
Related Data Broker Removal Guides
Take back your privacy today
Remove your personal information from data brokers and platforms in seconds.
Remove Your Personal Data NowFrom $9.00 one-time · 545 data brokers · No subscription
