How to Write a Privacy-Rights Opt-Out Request (Source-Aware Guide)
Source-aware guide to privacy requests: identify the listing, use the provider's current route, cite only applicable law, minimize verification, and preserve follow-up evidence.
Not all requests give a broker enough information to locate the right record. A concise request that identifies the listing, states the right you are exercising, and keeps a record of the exchange is easier to evaluate. Whether a law applies, what verification is reasonable, and whether an exception applies depend on the person, broker, and jurisdiction.
Key Takeaways
- A specific, written request is easier for a broker to match to the right record than a vague request.
- Include only the identifiers needed to locate the listing; avoid sending sensitive documents unless the broker explains why they are required.
- Name the privacy right you are exercising when it applies to you, but do not claim a law that does not apply.
- Keep a copy of the request, any verification exchange, and the broker's response.
- A statutory response period is not a promise of deletion; check the applicable regulator's guidance before escalating.
Four Elements of a Clear Request
1. The Subject Line
Make the purpose clear.
- *Less specific: "Remove my info"
- *Clearer: "Privacy request: deletion or opt-out for [your name]"
Use the broker's published privacy contact or form where available. Do not assume a particular subject line controls how a broker routes your request.
2. The Verification Data
Provide enough to identify the record, but not enough to create a new one.
Exercise your statutory data deletion rights
Review source-aware privacy-rights request drafts directly in your browser. Send or submit each request yourself after checking the provider route and applicable law.
- *Include: Full Name, City/State, Record URL (if found), email address on the listing.
- *Exclude: SSN, Driver's License number, Full DOB, financial account numbers.
The goal is to match the record that exists, not to prove identity by handing over sensitive documents. A broker may request reasonable verification under applicable law; an email address associated with a listing may help, but is not universally sufficient.
3. The Legal Citation
If a privacy law applies to you, name it accurately. Clear language helps, but a citation neither guarantees a result nor removes a broker's ability to apply lawful verification or exemptions.
- CCPA: *"I am exercising my right under California Civil Code § 1798.105(a) to request deletion of personal information about me that your business collected, subject to applicable exceptions."*
- GDPR: *"I am exercising my right to erasure under Article 17 of the General Data Protection Regulation, subject to applicable conditions."*
- VCDPA: *"I am exercising my right to deletion under Virginia Code § 59.1-577(A)(3), subject to applicable conditions and exemptions."*
4. The "Do Not Sell" Declaration
For US brokers, an opt-out of sale or sharing can be separate from a deletion request. Ask for the actions you want, and use the broker's published process when it distinguishes them.
- "I direct you not to sell or share my personal information under California Civil Code § 1798.120(a), if that right applies to me."*
A Complete Opt-Out Email Template
Use this template verbatim, substituting your information in the bracketed fields:
To: [provider's published privacy address or form]
Subject: Privacy request: deletion and opt-out
Attn: Privacy Compliance Officer
I am requesting deletion of personal information associated with me, where applicable, and an opt-out of sale or sharing where your process provides one.
Full Name: [Your Full Name]
City/State: [City, State]
Email: [Your Email]
Record URL (if known): [paste URL]
Legal Basis:
- If a verified privacy law applies to me: [insert the current statute and request type]
- Otherwise: please process this request under your current published privacy route
Requested Actions:
- Delete personal information about me to the extent required by applicable law and your current privacy process, and explain any exception or retained minimum data.
- Do not sell or share my personal information where an applicable opt-out right and your current process support that request.
3.
Please confirm receipt and explain any verification, exception, or next step required by your privacy process.
If an applicable privacy law sets a response period, please respond within that period or explain any applicable extension, exception, or reason it does not apply.
[Your Full Name]
[Date]
Vague vs Specific Opt-Out Request
| Element | Weak (Less useful) | Stronger (Clearer, not a compliance guarantee) |
|---|---|---|
| Subject line | "Please remove my data" | "Privacy request: deletion or opt-out for [name]" |
| Identity proof | "My name is John" | Name, location, email on file, and record URL when safe and relevant |
| Legal citation | "I have privacy rights" | The current statute and request type that actually apply |
| Opt-out declaration | Not included | Explicit: "Do not sell my personal information, § 1798.120" |
| Documentation | No saved record | Saved request, response, and verification notes |
State-by-State Legal Citations
Use the statute that matches your residency and circumstances. If you are unsure, use the broker's published privacy process and review the regulator's official guidance.
- *California (CCPA/CPRA): "California Civil Code § 1798.105(a). Right to Deletion" and "§ 1798.120(a). Right to Opt Out of Sale or Sharing"
- *EU/UK (GDPR): "General Data Protection Regulation, Article 17. Right to Erasure ('Right to be Forgotten')"
- *Virginia (VCDPA): "Virginia Consumer Data Protection Act, Va. Code § 59.1-577(A)(3)"
- *Colorado (CPA): "Colorado Privacy Act, C.R.S. § 6-1-1306(1)(d)"
- *Connecticut (CTDPA): "Connecticut Data Privacy Act, Conn. Gen. Stat. § 42-518(a)(3)"
- *Texas (TDPSA): "Texas Data Privacy and Security Act, Tex. Bus. & Com. Code § 541.051(b)(3)"
If you are not covered by one of these laws, do not claim coverage. Use the broker's published opt-out process and consider contacting the privacy regulator in your jurisdiction for guidance.
What to Do When Brokers Don't Respond
Step 1: Follow up at the applicable deadline. Check the broker's privacy notice and the regulator's current guidance before calculating a deadline. Send a concise follow-up that references the original request.
Step 2: Regulator complaint. Use the regulator or complaint route that covers the provider, residence, and issue. The FTC's ReportFraud.gov accepts reports about scams and bad business practices, but a complaint is not a guaranteed investigation or personal remedy.
Step 3: State complaint. If a state privacy agency or attorney general route applies, use its current official form. For California, the CPPA complaint form explains that the agency enforces the CCPA but does not act as the consumer's attorney. Colorado publishes current CPA guidance.
Step 4: Legal advice. A private claim, regulator referral, or court remedy depends on the applicable law, facts, harm, deadline, and jurisdiction. Do not state that a general privacy request creates damages or a private right of action without qualified advice.
Step 5: Consider qualified legal advice. A court claim or other remedy depends on the applicable law, facts, available forum, deadlines, and jurisdiction. Do not assume that a privacy request creates statutory damages, a private right of action, or a small-claims remedy.
Frequently Asked Questions
Q: Do I need a lawyer to send an opt-out request?
A: No. Individuals can use a broker's published privacy process directly. A lawyer may be appropriate for a complex dispute or litigation. This template is general information, not legal advice.
Q: What if the broker says it cannot find my record?
A: This sometimes happens with records indexed under a different name variation. Reply with alternate name formats only when safe and necessary, and ask the provider to explain its matching and verification process. Do not assume a particular statute requires a specific search without checking the current law.
Q: Can I send one email to all brokers or do I need individual emails?
A: Use the provider's published route and follow its required format. Separate requests can make provider-specific records easier to track, but there is no general rule that individual emails are more effective or clear spam filters better. OfflistMe prepares separate broker-specific drafts using current catalog records; review the recipient and route before sending.
Q: Does citing GDPR work for US residents?
A: A provider may accept a voluntary request from outside the GDPR's scope, but a citation does not create a legal entitlement for a U.S. resident. Identify the law that applies to your residence, provider, data, and request before citing it.
Q: What's the difference between deletion and opt-out?
A: If a provider grants deletion, it may remove or de-identify the record within the scope it controls; an opt-out may instead limit sale or sharing while allowing retention for permitted purposes. Read the provider's response and applicable law. A people-search source, marketing provider, public record, and search result may require different actions.
Use a clear template, then verify the broker's current process.
Prepare privacy-rights request drafts for 1,000+ brokers →
What Makes a Request Easier to Evaluate
There is no magic wording that guarantees a broker will delete a record. A well-documented request is still useful because it identifies the record, states what you are asking for, and preserves a record for any appropriate follow-up.
It can start a statutory process. If a privacy law applies and the request is verifiable, that law may set a response period. The process can include verification, extensions, or exceptions, and the final response is not proof that every copy of a record is gone.
It preserves evidence. An email with a statutory citation creates a timestamped record. If you later contact a regulator or lawyer, you can show when the request was submitted, what process or deadline you relied on, and what response you received. That record can help describe the issue, but it does not by itself establish a legal violation or entitlement.
It makes follow-up more concrete. A broker can still say it cannot locate a record or ask for reasonable verification. A request that records the profile URL, identifiers supplied, date sent, and the applicable process gives you a practical basis to clarify or escalate.
One nuance worth understanding: a state law does not automatically apply just because a broker is national. Use the law that applies to your residency and the broker's activities, and avoid making jurisdictional claims you cannot support.
How to Document Your Opt-Out Requests for Legal Use
Most people submit opt-out requests and forget about them. A dated evidence trail can make follow-up clearer and may support a regulator complaint or other advice, but it does not by itself establish a legal violation or entitlement.
Step 1: Create a dedicated folder in your email client labeled "Data Broker Opt-Outs." Move every sent opt-out email and every confirmation you receive into this folder. Date-stamp the folder entries. This creates a searchable archive.
Step 2: Record the broker profile before submitting the request. Before you email the opt-out, capture only the minimum information needed to document the listing: the profile URL, relevant fields, and the date (use your computer's date display in the screenshot if possible). Redact unrelated personal information before storing or sharing the file. Filename format: [broker-name]-profile-[YYYY-MM-DD].png. This is your "before" evidence.
Step 3: Log the request in a spreadsheet. Maintain a simple log with columns: Broker Name, Date Submitted, Email Address Used, Law or provider process relied on, Confirmation Received (Y/N), Date Confirmation Received, Deletion or suppression observed (Y/N). A small log makes the next check and any escalation easier.
Step 4: Record the provider's response and later state. When a broker sends a deletion confirmation email, save it alongside the before-record. If the profile later returns a 404 or an empty search result, record that result, but do not treat it as proof that every copy has been deleted from every system.
Step 5: Record the applicable follow-up date. When you submit to each provider, record the provider-stated timeframe or the verified statutory deadline that applies to your request. If the profile is still live or there is no response, preserve the evidence before using the regulator or appeal route that covers the issue.
The time required varies with the number of providers and evidence. For safety-sensitive situations, preserve records in a way that does not expose your location or create a new risk, and consider qualified legal or victim-support advice.
Drafting Enforceable First-Party Requests
Under CCPA, GDPR, and other privacy laws, a first-party request may carry specific rights and response rules when the law and facts fit. Clear wording helps the provider evaluate the request, but a citation does not force compliance when the law, scope, verification, or exception does not apply.
Key Elements of an Enforceable Request:
- Statutory Citations: Cite the specific law that applies to your residency (e.g., California Civil Code § 1798.105 for CCPA, or Tex. Bus. & Com. Code § 541.051(b)(3) for a TDPSA deletion request).
- Clear Identifiers: Provide the exact name variations, email addresses, and phone numbers associated with the profile. Do not provide sensitive files like SSNs or passport scans unless the provider explains why they are necessary and the applicable process requires them.
- Explicit Instruction: Use a clear, scoped directive such as: "I request deletion or suppression of personal information associated with this profile under the privacy rights that apply to me. Please explain any exemption or verification requirement."
- Documentation Trail: Keep a record of the submission date, route, evidence supplied, and any auto-response emails. The applicable response deadline, extension rules, appeal route, and complaint authority vary by law and provider, so verify those details before escalating.
Related Guides
- Complete Data Broker Opt-Out Guide
- How to Request Data Removal from the Internet
- The Authorized Agent Loophole in Data Broker Opt-Outs
- California Data Broker Opt-Out: Your CCPA Rights
- Does Opting Out Guarantee Data Removal?
Primary legal sources
Use the current official text and regulator guidance before relying on a citation; amendments, scope, verification rules, exceptions, and response periods can change.
Understand your privacy rights
Where a privacy right is relevant, these plain-English explainers show what each law covers and what to verify before making a request.
Related Data Broker Removal Guides
Take back your privacy today
Review provider-specific routes, prepare your requests locally, and send or submit each one yourself.
Review Provider RoutesFree to review provider routes · Optional one-time unlock from $9.00 · No subscription
