Your GDPR and CCPA rights, explained
Privacy laws give you tools: ask what a company holds, demand deletion, and opt out of sale or sharing. You do not need to be a lawyer to use them.
GDPR-style rights (access and erasure)
If you are covered by the GDPR or similar rules, you can typically request a copy of personal data a company holds about you, ask for correction, and request deletion when the law allows. Companies must respond within set timelines.
Be specific: name the account email, approximate dates, and what you want (export vs delete). Keep a copy of what you send and when.
CCPA/CPRA: know, delete, and opt out
California residents (and people covered by similar US state laws) can ask what categories of data are collected, request deletion, and opt out of sale or sharing of personal information — including via global privacy control signals where supported.
“Sale” and “sharing” often include ad-tech arrangements, not only a spreadsheet sold for cash. Opt-out links and Do Not Sell pages exist for a reason — use them.
Make requests easier to send
Ready-made access, delete, and opt-out letters save time and keep the language clear. Send from the email tied to the account when possible, and follow up if the deadline passes.
Blocking new tracking and exercising rights work together: one reduces future collection; the other cleans up the past.
Ready to put this into practice? Continue with a short next step — no hard sell.
PrivyDeck privacy rightsAlso see Help center, How we protect you, and Plans.