Your data retention and privacy rights come down to two things you can do: ask a company what personal information it holds about you, and, in most cases, tell it to delete that information. Those rights sit in the EU’s General Data Protection Regulation and in more than 20 U.S. state privacy laws, led by California’s Consumer Privacy Act. There is no single federal U.S. privacy statute covering every kind of personal data, so which rules protect you depends on where you live, what company you’re dealing with, and what kind of record is at stake.
The underlying principle is the same across these laws. Companies are supposed to keep personal information only as long as they actually need it for the purpose they collected it. Everything below flows from that idea.
Your Right to Know What a Company Has on You
Start here. You cannot make a sensible deletion request without first seeing what a company is actually holding.
Under the GDPR, you can get confirmation of whether your data is being processed, a copy of that data, and information about why it’s being processed, what categories are involved, who it’s been shared with, and how long the company plans to store it.1General Data Protection Regulation (GDPR). Art. 15 GDPR – Right of Access by the Data Subject
Under California’s law and similar state statutes, you can ask a business to disclose the categories and specific pieces of personal information it has collected, where it came from, why it was collected, and which third parties have received it. You can make these requests up to twice a year at no cost.2State of California – Department of Justice – Office of the Attorney General. California Consumer Privacy Act (CCPA)
California law also requires businesses to state in their privacy policy how long they intend to keep each category of personal information, or the criteria they use to decide.3California Legislative Information. California Civil Code 1798.100 Reading that section of the policy is a fast way to see what timeline the company has committed to publicly.
Your Right to Have Data Deleted
The right to erasure, sometimes called the right to be forgotten, lets you ask an organization to delete personal data it holds about you. Under the GDPR, it applies when the data is no longer necessary for the original purpose, when you withdraw the consent the processing was based on and no other legal basis exists, or when the data was processed unlawfully.4General Data Protection Regulation (GDPR). Art. 17 GDPR – Right to Erasure
State privacy laws in the U.S. give you a similar right. Once a business receives a verified deletion request, it generally must delete the personal information it holds and instruct its service providers to do the same.
Response deadlines depend on which law governs. The GDPR gives organizations one month from receipt of your request to act, with a possible two-month extension for complex or high-volume requests; if the company extends, it has to tell you within that first month.5General Data Protection Regulation (GDPR). Art. 12 GDPR – Transparent Information, Communication Under California’s law and most other state privacy statutes, businesses have 45 calendar days to respond, with a possible additional 45-day extension.2State of California – Department of Justice – Office of the Attorney General. California Consumer Privacy Act (CCPA)
When a Company Can Legally Refuse
Deletion is not absolute. Both the GDPR and state laws let companies keep data in specific circumstances, and knowing these upfront saves you from misreading a refusal.
Under the GDPR, a company can decline to delete when the data is needed for:
- Compliance with a legal obligation under EU or member state law.
- Exercising the right of freedom of expression and information.
- Reasons of public interest in the area of public health.
- Public interest archiving, scientific research, or historical research where deletion would seriously impair those objectives.
- Establishing, exercising, or defending legal claims.4General Data Protection Regulation (GDPR). Art. 17 GDPR – Right to Erasure
U.S. state privacy laws include broadly similar exceptions and add a few. A business can typically keep data needed to complete a transaction you asked for, detect security incidents, debug errors, comply with a legal obligation, or support internal uses reasonably aligned with your expectations given your relationship. The security-incident exception matters in practice: if a company is actively investigating a breach, it may keep affected records as part of that response even after you’ve asked for deletion.
Retention Minimums That Override Deletion
Even when a general privacy law would let you delete, sector rules sometimes require a company to hold specific records for a fixed minimum period. If your request touches one of these categories, the company can lawfully keep the underlying records until the retention clock runs out.
Tax and Financial Records
The IRS generally requires records supporting a tax return to be kept for three years from the filing date. That extends to six years only if you failed to report income exceeding 25% of the gross income shown on the return.6Internal Revenue Service. How Long Should I Keep Records Businesses subject to anti-money laundering rules face a separate five-year minimum under the Bank Secrecy Act covering most transaction records, suspicious activity reports, and customer identification documentation.7FFIEC BSA/AML. Appendix P – BSA Record Retention Requirements
Medical Records
HIPAA does not set a retention period for patient medical records; state law controls that, and periods vary. What HIPAA does require is that covered entities keep their own privacy policies, procedures, and certain written communications for six years from creation or from the date last in effect, whichever is later.8eCFR. 45 CFR 164.530 – Administrative Requirements9U.S. Department of Health and Human Services. Does the HIPAA Privacy Rule Require Covered Entities to Keep Patients Medical Records for Any Period of Time If a provider tells you it can’t delete your medical file because of HIPAA, the real reason is state law.
Children Under 13
The Children’s Online Privacy Protection Act imposes stricter limits on websites and apps that collect information from children under 13. Operators may retain a child’s personal information only for as long as reasonably necessary for the purpose it was collected, must maintain a written retention policy specifying purposes and deletion timeframes, and may not retain the information indefinitely. When it is no longer needed, it must be deleted using reasonable security measures.10eCFR. 16 CFR 312.10
Employment Records
Federal employment rules require employers to keep personnel and employment records for at least one year, measured from the termination date if the employee was involuntarily terminated. Payroll records carry a three-year minimum under both the Age Discrimination in Employment Act and the Fair Labor Standards Act. Records explaining wage differences between employees of opposite sexes must be kept for at least two years.11U.S. Equal Employment Opportunity Commission. Recordkeeping Requirements
How to Actually Submit a Request
The mechanics vary a little by company, but the pattern is consistent.
Businesses covered by privacy laws must offer at least two ways to receive consumer requests, typically a toll-free number and a web form or email address. These channels are often separate from general customer service, so check the company’s privacy policy for the correct method rather than calling the main support line.2State of California – Department of Justice – Office of the Attorney General. California Consumer Privacy Act (CCPA)
Expect identity verification. The company will ask you to confirm your name, email address, and possibly other account details before acting, so someone else cannot access or delete your data. You should not have to open a new account to submit a request, though the company can route you through an existing one.
Save what you send and what comes back. Note the date of your submission. Keep any acknowledgment, any request for verification, and any final response. That record is what a regulator or court will look at if the company misses its deadline or refuses without a valid reason.
If the Company Ignores You or Refuses Without Cause
Under the GDPR, you can lodge a complaint with the supervisory authority in the EU member state where the violation occurred.1General Data Protection Regulation (GDPR). Art. 15 GDPR – Right of Access by the Data Subject In the United States, you can file a complaint with your state attorney general or, for businesses under FTC jurisdiction, with the Federal Trade Commission.
Watch for companies that make deletion harder than it needs to be. The FTC has flagged design tactics such as making users navigate a maze of screens to cancel, burying opt-outs in dense terms of service, and using confusing layouts that discourage follow-through. If a company makes it unreasonably difficult to find or complete a deletion request, that conduct itself can draw enforcement action.
A Shortcut for California Residents Dealing with Data Brokers
Data brokers collect and sell personal information from public records, online activity, and purchase histories, often without your knowledge, and sending deletion requests to each one individually is a heavy lift. California has built a centralized option: the Delete Request and Opt-out Platform, which lets consumers send a single deletion request to over 500 registered data brokers at once.12California Privacy Protection Agency. About DROP and the Delete Act Starting August 1, 2026, brokers must process these requests within 90 days and continue deleting on a rolling 45-day cycle after that.13California Privacy Protection Agency. Delete Request and Opt-out Platform (DROP)
The tool is currently limited to California residents. Outside California, deletion requests to data brokers have to go one at a time.
What Companies Face for Getting It Wrong
The penalties behind these rights give them real weight, and they apply both to keeping data longer than allowed and to refusing valid deletion requests.
GDPR fines run on two tiers. Less severe violations can reach €10 million or 2% of a company’s total global annual turnover, whichever is higher. For the most serious violations, including breaches of the core processing principles like storage limitation, fines can reach €20 million or 4% of global annual turnover.14General Data Protection Regulation (GDPR). Fines / Penalties These are ceilings, not defaults.
In the United States, enforcement is split. The Federal Trade Commission can bring actions for unfair or deceptive privacy practices, with civil penalties reaching up to $53,088 per violation as of 2026.15Federal Trade Commission. FTC Reminds Data Brokers of Their Obligations to Comply with PADFAA State attorneys general enforce their own privacy statutes. Under California’s law, civil penalties run from roughly $2,500 per unintentional violation to approximately $7,500 per intentional violation, and individual consumers can bring civil action for data breaches caused by a business’s failure to maintain reasonable security, with statutory damages of $100 to $750 per consumer per incident.