Data Deletion Request Form Template
Accept data subject deletion requests with a structured form that captures identity verification, scope of deletion, sub-processor propagation requirements, and the 30-day response clock. Built for GDPR Article 17, LGPD Article 18 §VI, CCPA/CPRA, UK GDPR, and the patchwork of US state privacy laws (Virginia, Colorado, Connecticut, Utah, Texas, Oregon, Montana, Iowa, Tennessee).
Data Deletion Request Form Template
Live preview — try the fields below.
No fields to preview.
Who this template is for
Data deletion requests — also known as 'right to be forgotten' under GDPR Article 17, 'right to delete' under California CCPA/CPRA, and 'eliminação dos dados pessoais' under Brazilian LGPD Article 18 §VI — are one of the most consequential privacy workflows a business has. The clock starts the moment the request lands in your inbox (30 days under GDPR, LGPD, and most US state laws; CCPA gives 45 days extendable once). Missing the deadline is a published enforcement action — the AEPD (Spain), CNIL (France), Garante (Italy), and ICO (UK) all publish DPA enforcement decisions monthly, and the ANPD (Brazil) has been actively fining since 2023. This template structures the request itself — identity verification (proportionate but mandatory), the scope of deletion the requester is asking for (account-only, marketing-only, all data including backups), the legal basis the controller relied on (consent, contract, legitimate interest), and the exceptions that may apply (legal retention obligation, freedom of expression, public interest, scientific research). It is the structured intake your DPO, privacy team, or outside privacy counsel actually wants — not the email inbox where requests get lost between Slack notifications, and not the $50K/year OneTrust DSAR Automation module that most companies outgrow into rather than buy on day one.
From request to documented deletion in one compliance-grade flow
Data subject submits the deletion request with their identity (full name, account email, optional account ID or username), the scope of deletion they are requesting (full account closure with all personal data, marketing data only, specific data categories, support tickets only — the GDPR Article 12 transparency principle requires you to honor the requester's stated scope unless an exception applies), and the legal basis they cite if they know it (often they do not, and the controller is expected to identify the basis). Identity verification follows: for low-risk requests (closing a free newsletter signup), email verification via a one-time link is sufficient; for medium-risk requests (closing a paying account with billing history), the form requires the requester to send the request from the account email and confirms via the existing account login or a secondary verification (SMS, government ID last-4); for high-risk requests (healthcare data, financial data, employment records), the form requires a proportionate identity proof such as a redacted government ID upload or notarized declaration. The form captures the request timestamp (which starts the response clock — 30 days under GDPR Art. 12(3), LGPD Art. 19, and most US state privacy laws; 45 days under CCPA Cal. Civ. Code § 1798.130(a)(2)), routes to the DPO or designated privacy contact, and creates a tracked record in your privacy management system. The controller's processing of the request: (1) verify identity is sufficient for the data sensitivity; (2) identify all systems and processors holding the personal data (CRM, marketing platform, analytics, support ticketing, payment processor, email service provider, backups); (3) apply legal exceptions where they exist (GDPR Art. 17(3) carve-outs: freedom of expression, legal obligation to retain, public interest, scientific or historical research, legal claims; LGPD Art. 16 retention exceptions; CCPA Cal. Civ. Code § 1798.105(d) exceptions); (4) propagate the deletion to sub-processors per GDPR Art. 17(2) — your DPA with each sub-processor should already require them to act on these requests, and the form's export captures the propagation checklist; (5) deliver the deletion confirmation to the data subject with the date, the systems where deletion was applied, the systems where retention exceptions applied (with the legal basis cited), and the timestamp. The audit trail — submitted, verified, propagated, completed — is the documentation a DPA inquiry, an ANPD investigation, or a class-action plaintiff will request.
What's included
Every field exists because some privacy team has been burned by its absence — usually during the regulator inquiry that came 18 months after a request was mishandled, or during the audit where the DPO had to reconstruct what was deleted, when, and by whom from Slack screenshots and Jira tickets.
Businesses using data deletion request forms
SaaS and consumer apps with EU/UK/Brazil users
Any SaaS or app with users in the EU/EEA, UK, or Brazil has a hard legal obligation to accept and process erasure requests within 30 days. The form replaces the support-ticket inbox approach where requests get triaged like feature questions and miss the legal deadline. For US-based SaaS with California users (which is most US SaaS), CCPA/CPRA imposes the same workflow with a 45-day deadline. Pairs with your privacy policy's 'how to exercise your rights' section as the linked-to form.
E-commerce and DTC brands
Customer deletion requests in e-commerce are complicated by the transaction history retention obligation under tax law (US: IRC retention rules typically 3-7 years; Spain: Art. 30 Código de Comercio 6 years for accounting records, Ley General Tributaria 4 years for tax; Brazil: 5 years for fiscal records under Lei 8.137/90). The form's exception-handling lets you delete the marketing profile, account credentials, and personal-data-not-tied-to-transactions while retaining anonymized transaction records for the tax retention period — the lawful middle path under GDPR Art. 17(3)(b) and equivalents.
Healthcare practices and digital health apps
Healthcare data has its own retention rules that often override pure-privacy deletion requests. US HIPAA does not include a right to deletion — only a right to amend and a right to access — but CCPA and state laws apply to health-data-holding entities that are not covered entities (digital health, wellness apps, mental-health apps). EU GDPR Art. 9 sensitive data (health) has stricter conditions, and member-state law often imposes minimum retention periods (Spain: 5 years from last clinical entry under Ley 41/2002 historia clínica; Brazil: 20 years for medical records under CFM Resolução 1.821/2007). The form captures the data type and surfaces the applicable retention exception.
HR and employment-data controllers
Employee-data deletion has the most complex exception map — payroll records must be retained for the statute of limitations on wage claims (varies by jurisdiction, typically 3-7 years), tax records under federal/state/national obligations, OSHA injury records (5 years US), Spanish work-time records (4 years under RDL 8/2019), Brazilian eSocial records (varies by event, 5+ years), and pension records (often 10+ years or for life of the obligation). The form distinguishes between former-employee-initiated deletion of preferences/marketing-data (immediately actionable) and full employee-record deletion (only after retention periods expire).
Marketing agencies and email service providers
Service providers and processors under GDPR Art. 28 / LGPD Art. 39 / CCPA service-provider definition have a derived obligation to action deletion requests on behalf of their client controllers. The form distinguishes between requests received directly from data subjects (route back to the controller) and requests received from controllers asking the processor to delete the subject's data (process immediately and confirm completion). For agencies running campaigns on Klaviyo, Mailchimp, Brevo, ActiveCampaign, Constant Contact, HubSpot, Marketo, the form generates the processor-to-controller confirmation that the DPA requires.
Public sector, education, and grant-funded research
Public-sector controllers have additional exception grounds under GDPR Art. 17(3) — public interest, official authority, and (in some member states) freedom-of-information obligations. Research data benefits from the Art. 89 research exception with appropriate safeguards. For Brazilian public-sector controllers, LGPD Art. 23 specifies the public-power processing regime with additional ANPD oversight. The form's exception fields capture the specific public-interest or research basis cited, which is the documentation auditors and ombudsmen actually inspect.
Tailor it to your privacy program
Every privacy program has its own routing, retention, and verification rules. Configure the identity verification tier based on data sensitivity — email-link verification for newsletter-only data, account-login verification for SaaS accounts, government-ID upload for high-risk financial or health data (with the redaction guidance prominent so requesters do not over-share). Set the scope-of-deletion options to match your data categories — many companies separate 'account closure' from 'marketing data only' from 'full erasure including backups' because each has different operational implications and timeline. Configure the response SLA per regulation — 30 days under GDPR Art. 12(3) and LGPD Art. 19, 45 days under CCPA Cal. Civ. Code § 1798.130(a)(2), 25 working days under UK GDPR — and the form auto-tracks the clock from submission. Add the legal-exception checklist your DPO uses: GDPR Art. 17(3) carve-outs (freedom of expression, legal obligation, public interest, research, legal claims); LGPD Art. 16 retention exceptions; CCPA exceptions including the 'transaction completion' and 'security' carve-outs; sectoral retention rules from your industry (financial: FINRA 4511 for broker-dealers, SOX 404 for issuers; healthcare: state-specific medical record retention; tax: IRS 7-year guidance and equivalent national rules). Integrate with your privacy management platform — OneTrust DSAR Automation, TrustArc, Securiti, BigID, Transcend, DataGrail, Osano, WireWheel, Ethyca for full enterprise DSR workflow; or Termly, Cookiebot Privacy Center, Iubenda, SafeLab LGPD (Brazil), Yzr (Spain) for SMB privacy. For agencies and B2B service providers, add the 'processor passthrough' option that flags requests for routing back to the originating controller. For multi-locale operations, the form captures the requester's claimed jurisdiction (which determines the SLA clock and the applicable law), validates against your operating-jurisdiction list, and routes to the appropriate privacy team if you have regional privacy counsel.
Data deletion request FAQs
Related templates
Free Product-Market Fit Survey Template
The classic Sean Ellis PMF survey: "how would you feel if you couldn't use this product?" Plus the ICP, benefit, and roadmap questions that follow.
View templateFeature request form — capture problems, not just solutions
Feature request form template with problem-not-feature framing, current-workaround capture, and direct integration with Canny, Featurebase, Productboard
View templateUser onboarding survey — personalize activation and segment new signups
Online user onboarding survey template for SaaS, consumer apps, developer tools, and marketplaces.
View templateReady to build forms that work for you?
Create your first form in minutes. Your submissions will thank you.