I’m trying to understand how data privacy rights vary by region, including GDPR protections, U.S. state privacy laws, and areas where legal gaps remain. I need help figuring out which rules apply and what options people have when their data isn’t fully protected.
Don’t assume a “Delete my account” button means the company must erase every copy of your data. Deletion rights have exceptions for legal records, fraud prevention, security, and other required retention, and they may not pull back information already disclosed to third parties.
GDPR generally gives people in the EU or EEA the strongest baseline: access, correction, deletion, restriction, portability, objection to certain processing, and protections involving solely automated decisions. U.S. state laws are more uneven. Depending on your state and whether the business meets coverage thresholds, you may have rights to access, correct, delete, and obtain data, plus opt out of sales, targeted advertising, or certain profiling. California adds rights involving sharing and sensitive personal information. Most state laws rely on government enforcement, so you usually cannot sue over an ordinary unanswered privacy request. (edpb.europa.eu)
The practical approach is to identify your residency, the type of data, and who holds it. Send a written request that lists each right separately, save the confirmation, and note the response deadline. If the company refuses, use any required appeal process, then complain to the relevant data protection authority, state attorney general, state privacy agency, or the FTC. The gaps tend to involve exempt small businesses, nonprofits, employment data, publicly available information, and data covered by industry-specific rules. Health data is a good example: HIPAA covers certain providers and partners, but many consumer health apps fall outside HIPAA even though other FTC or state rules may still apply.
If the company cannot verify that the account is yours, your request may stall before any privacy right gets considered. Use the email address tied to the account and the company’s official request form when possible. Avoid sending a full driver’s license by default. If identification is genuinely needed, ask what fields are required and redact the rest.
I slightly disagree with sending every possible request at once. A focused request such as “give me the personal data associated with this email and explain the categories of third parties receiving it” is harder to brush off as vague or excessive. Once you see what exists, you can make a better deletion, correction, or opt-out request. GDPR coverage depends on the organization’s connection to the EEA and whether it targets or monitors people there, not simply on EU citizenship. State rights usually depend on residency, whether the company is covered, and whether you are acting as a consumer rather than as an employee or in another exempt role. (edpb.europa.eu)
@rocketthinker3831 is right about keeping a paper trail. Save the exact request, verification messages, denial reason, and appeal. Authentication is a real requirement, but it can become a convenient bottleneck. If a company demands far more sensitive information than it already has, ask for another verification method rather than creating a fresh privacy risk just to exercise a privacy right.
Start by matching your residence to the company’s privacy notice, then check whether the company and the type of data are actually covered. That second step matters because U.S. state laws commonly exclude certain small businesses, employee records, health data already regulated elsewhere, or organizations such as nonprofits. GDPR is broader in some ways and includes access, correction, erasure, restriction, portability, objection, and protections around certain automated decisions.
The biggest practical difference is enforcement. Under GDPR, you can complain to the relevant data protection authority if the organization refuses or mishandles a request. State laws may provide access, deletion, correction, portability, and opt-outs from sales, targeted advertising, or profiling, but the exact package varies. Appeals are available in some states. In many cases, though, you cannot personally sue over an ordinary request denial and must complain to the state regulator.
Deletion is where expectations often go wrong. It rarely means every trace disappears immediately. A company may retain transaction records for taxes, fraud prevention, legal claims, security, or other statutory duties, and backups may age out later. Ask the company to identify what it deleted, what it retained, why it retained it, and whether retained data has been blocked from marketing or unrelated use. That answer usually exposes the real gap between having a right on paper and getting a useful result.
Do not fake an EU location or pick California from a dropdown and assume privacy rights magically appear. GDPR coverage depends on the organization’s establishment or whether it offers goods or services to, or monitors, people in the EEA. U.S. state rights usually follow actual residency and the law’s coverage rules. A company may voluntarily offer the same request process worldwide, but its privacy notice is not proof that every listed right legally applies to you. (edpb.europa.eu)
Pay attention to the capacity in which the company has your data. The same person can be a consumer, employee, contractor, patient, or business contact, with different rules applying to each record. Yes, the law enjoys putting people into boxes almost as much as companies enjoy finding exemptions. If a retailer denies your consumer request because the information came from an employment application, that may be legitimate. If it lumps your shopping account into that denial, push back and ask it to separate the records and explain each exemption.
I agree with @techchizkid that a focused request is often easier to manage, but clever wording cannot rescue a request when the business is outside the law. Before debating deletion, ask what identifiers it uses to link records, where the information came from, what purposes it serves, and which categories of outsiders receive it. That can expose duplicate profiles under an old email, phone number, advertising ID, or previous address. Then send the correction, deletion, or opt-out request using those identifiers. “Delete everything about me” sounds satisfying, but it gives a company plenty of room to return a canned answer about records it supposedly could not locate.
For online advertising, a browser-based opt-out signal can save some form-filling. Global Privacy Control must be honored for certain sale, sharing, or targeted-advertising opt-outs under laws including California and Colorado. It is not a universal invisibility cloak, does not create an access or deletion request, and may need to be enabled on every browser or device you use. California residents now have another unusually practical option: the state’s DROP system sends a single deletion and opt-out request to registered data brokers. Brokers began processing those requests on August 1, 2026, but it still covers registered brokers and non-exempt matching data, not every company that has ever seen your name.
Keep the rejection language, not merely the rejection email. “We cannot verify you,” “we are exempt,” “we do not sell data,” and “we retained it for legal purposes” are four different problems. Ask which law, exemption, data category, and processing activity supports the answer. Companies are much less comfortable with specific follow-up questions than with clicking the “request closed” button and hoping you wander off.
Expect a successful deletion request to be temporary if you keep using the service. It can remove existing records without preventing fresh login, device, purchase, location, or cookie data from being collected the next time you return. Account closure, data deletion, consent withdrawal, and advertising opt-outs are separate actions.
Decide what result you actually want. If you still need the account, correction and processing limits may be more useful than deletion that breaks features. If you are leaving, request deletion and closure, disconnect app permissions, clear stored site data, and keep any applicable opt-out signal enabled. Otherwise the company may truthfully say it deleted your profile while quietly building a new one from your next visit.
Small correction to the ‘you usually can’t sue’ line that keeps coming up: California is the exception people forget. Under the CCPA you do have a private right of action, but only for certain data breaches involving specific unencrypted personal info, not for a company ignoring your access or deletion request. So the ‘no lawsuit’ advice is right for ordinary requests and wrong for breach cases. Worth keeping straight because it changes whether a lawyer is even interested.
The other thing nobody put a number on is timing. GDPR gives the company about a month to respond, extendable in complex cases. Most US state laws land around 45 days with a possible extension. The catch is that the clock often does not start until they verify you, which loops back to the authentication bottleneck @techchizkid mentioned. That means a company can drag verification, then start the 45 days, and you are looking at months before you even get to an appeal. Diary the dates yourself, because they will not remind you.
I mostly agree with @quantumlab that enforcement is the real difference, but I’d set expectations lower on the complaint step. Filing with a state AG or the FTC is not like reporting a broken product and getting a fix. Individual complaints mostly feed pattern-spotting. You rarely get a personal resolution out of it. It matters in bulk, not for your one stalled request. If you actually need a result, a clear, documented appeal to the company is usually more productive than a regulator complaint, at least first.
My practical take: decide upfront if you want leverage or just closure. If you want closure, follow the steps everyone above listed and move on. If you want leverage, the strongest positions are a breach in a state with a private right of action, or a company that clearly targets EEA users and is fumbling a GDPR request in front of an active regulator. Everything else is a paperwork grind where persistence matters more than the specific right you cite.