GDPR, LGPD & CCPA compliance

Data Deletion Request Form Template

Accept data subject deletion requests with a structured form that captures identity verification, scope of deletion, sub-processor propagation requirements, and the 30-day response clock. Built for GDPR Article 17, LGPD Article 18 §VI, CCPA/CPRA, UK GDPR, and the patchwork of US state privacy laws (Virginia, Colorado, Connecticut, Utah, Texas, Oregon, Montana, Iowa, Tennessee).

Free — included in every plan

Data Deletion Request Form Template

Live preview — try the fields below.

No fields to preview.

Who this template is for

Data deletion requests — also known as 'right to be forgotten' under GDPR Article 17, 'right to delete' under California CCPA/CPRA, and 'eliminação dos dados pessoais' under Brazilian LGPD Article 18 §VI — are one of the most consequential privacy workflows a business has. The clock starts the moment the request lands in your inbox (30 days under GDPR, LGPD, and most US state laws; CCPA gives 45 days extendable once). Missing the deadline is a published enforcement action — the AEPD (Spain), CNIL (France), Garante (Italy), and ICO (UK) all publish DPA enforcement decisions monthly, and the ANPD (Brazil) has been actively fining since 2023. This template structures the request itself — identity verification (proportionate but mandatory), the scope of deletion the requester is asking for (account-only, marketing-only, all data including backups), the legal basis the controller relied on (consent, contract, legitimate interest), and the exceptions that may apply (legal retention obligation, freedom of expression, public interest, scientific research). It is the structured intake your DPO, privacy team, or outside privacy counsel actually wants — not the email inbox where requests get lost between Slack notifications, and not the $50K/year OneTrust DSAR Automation module that most companies outgrow into rather than buy on day one.

From request to documented deletion in one compliance-grade flow

Data subject submits the deletion request with their identity (full name, account email, optional account ID or username), the scope of deletion they are requesting (full account closure with all personal data, marketing data only, specific data categories, support tickets only — the GDPR Article 12 transparency principle requires you to honor the requester's stated scope unless an exception applies), and the legal basis they cite if they know it (often they do not, and the controller is expected to identify the basis). Identity verification follows: for low-risk requests (closing a free newsletter signup), email verification via a one-time link is sufficient; for medium-risk requests (closing a paying account with billing history), the form requires the requester to send the request from the account email and confirms via the existing account login or a secondary verification (SMS, government ID last-4); for high-risk requests (healthcare data, financial data, employment records), the form requires a proportionate identity proof such as a redacted government ID upload or notarized declaration. The form captures the request timestamp (which starts the response clock — 30 days under GDPR Art. 12(3), LGPD Art. 19, and most US state privacy laws; 45 days under CCPA Cal. Civ. Code § 1798.130(a)(2)), routes to the DPO or designated privacy contact, and creates a tracked record in your privacy management system. The controller's processing of the request: (1) verify identity is sufficient for the data sensitivity; (2) identify all systems and processors holding the personal data (CRM, marketing platform, analytics, support ticketing, payment processor, email service provider, backups); (3) apply legal exceptions where they exist (GDPR Art. 17(3) carve-outs: freedom of expression, legal obligation to retain, public interest, scientific or historical research, legal claims; LGPD Art. 16 retention exceptions; CCPA Cal. Civ. Code § 1798.105(d) exceptions); (4) propagate the deletion to sub-processors per GDPR Art. 17(2) — your DPA with each sub-processor should already require them to act on these requests, and the form's export captures the propagation checklist; (5) deliver the deletion confirmation to the data subject with the date, the systems where deletion was applied, the systems where retention exceptions applied (with the legal basis cited), and the timestamp. The audit trail — submitted, verified, propagated, completed — is the documentation a DPA inquiry, an ANPD investigation, or a class-action plaintiff will request.

What's included

Every field exists because some privacy team has been burned by its absence — usually during the regulator inquiry that came 18 months after a request was mishandled, or during the audit where the DPO had to reconstruct what was deleted, when, and by whom from Slack screenshots and Jira tickets.

Businesses using data deletion request forms

  • SaaS and consumer apps with EU/UK/Brazil users

    Any SaaS or app with users in the EU/EEA, UK, or Brazil has a hard legal obligation to accept and process erasure requests within 30 days. The form replaces the support-ticket inbox approach where requests get triaged like feature questions and miss the legal deadline. For US-based SaaS with California users (which is most US SaaS), CCPA/CPRA imposes the same workflow with a 45-day deadline. Pairs with your privacy policy's 'how to exercise your rights' section as the linked-to form.

  • E-commerce and DTC brands

    Customer deletion requests in e-commerce are complicated by the transaction history retention obligation under tax law (US: IRC retention rules typically 3-7 years; Spain: Art. 30 Código de Comercio 6 years for accounting records, Ley General Tributaria 4 years for tax; Brazil: 5 years for fiscal records under Lei 8.137/90). The form's exception-handling lets you delete the marketing profile, account credentials, and personal-data-not-tied-to-transactions while retaining anonymized transaction records for the tax retention period — the lawful middle path under GDPR Art. 17(3)(b) and equivalents.

  • Healthcare practices and digital health apps

    Healthcare data has its own retention rules that often override pure-privacy deletion requests. US HIPAA does not include a right to deletion — only a right to amend and a right to access — but CCPA and state laws apply to health-data-holding entities that are not covered entities (digital health, wellness apps, mental-health apps). EU GDPR Art. 9 sensitive data (health) has stricter conditions, and member-state law often imposes minimum retention periods (Spain: 5 years from last clinical entry under Ley 41/2002 historia clínica; Brazil: 20 years for medical records under CFM Resolução 1.821/2007). The form captures the data type and surfaces the applicable retention exception.

  • HR and employment-data controllers

    Employee-data deletion has the most complex exception map — payroll records must be retained for the statute of limitations on wage claims (varies by jurisdiction, typically 3-7 years), tax records under federal/state/national obligations, OSHA injury records (5 years US), Spanish work-time records (4 years under RDL 8/2019), Brazilian eSocial records (varies by event, 5+ years), and pension records (often 10+ years or for life of the obligation). The form distinguishes between former-employee-initiated deletion of preferences/marketing-data (immediately actionable) and full employee-record deletion (only after retention periods expire).

  • Marketing agencies and email service providers

    Service providers and processors under GDPR Art. 28 / LGPD Art. 39 / CCPA service-provider definition have a derived obligation to action deletion requests on behalf of their client controllers. The form distinguishes between requests received directly from data subjects (route back to the controller) and requests received from controllers asking the processor to delete the subject's data (process immediately and confirm completion). For agencies running campaigns on Klaviyo, Mailchimp, Brevo, ActiveCampaign, Constant Contact, HubSpot, Marketo, the form generates the processor-to-controller confirmation that the DPA requires.

  • Public sector, education, and grant-funded research

    Public-sector controllers have additional exception grounds under GDPR Art. 17(3) — public interest, official authority, and (in some member states) freedom-of-information obligations. Research data benefits from the Art. 89 research exception with appropriate safeguards. For Brazilian public-sector controllers, LGPD Art. 23 specifies the public-power processing regime with additional ANPD oversight. The form's exception fields capture the specific public-interest or research basis cited, which is the documentation auditors and ombudsmen actually inspect.

Tailor it to your privacy program

Every privacy program has its own routing, retention, and verification rules. Configure the identity verification tier based on data sensitivity — email-link verification for newsletter-only data, account-login verification for SaaS accounts, government-ID upload for high-risk financial or health data (with the redaction guidance prominent so requesters do not over-share). Set the scope-of-deletion options to match your data categories — many companies separate 'account closure' from 'marketing data only' from 'full erasure including backups' because each has different operational implications and timeline. Configure the response SLA per regulation — 30 days under GDPR Art. 12(3) and LGPD Art. 19, 45 days under CCPA Cal. Civ. Code § 1798.130(a)(2), 25 working days under UK GDPR — and the form auto-tracks the clock from submission. Add the legal-exception checklist your DPO uses: GDPR Art. 17(3) carve-outs (freedom of expression, legal obligation, public interest, research, legal claims); LGPD Art. 16 retention exceptions; CCPA exceptions including the 'transaction completion' and 'security' carve-outs; sectoral retention rules from your industry (financial: FINRA 4511 for broker-dealers, SOX 404 for issuers; healthcare: state-specific medical record retention; tax: IRS 7-year guidance and equivalent national rules). Integrate with your privacy management platform — OneTrust DSAR Automation, TrustArc, Securiti, BigID, Transcend, DataGrail, Osano, WireWheel, Ethyca for full enterprise DSR workflow; or Termly, Cookiebot Privacy Center, Iubenda, SafeLab LGPD (Brazil), Yzr (Spain) for SMB privacy. For agencies and B2B service providers, add the 'processor passthrough' option that flags requests for routing back to the originating controller. For multi-locale operations, the form captures the requester's claimed jurisdiction (which determines the SLA clock and the applicable law), validates against your operating-jurisdiction list, and routes to the appropriate privacy team if you have regional privacy counsel.

Data deletion request FAQs

Those are full privacy management platforms — they bundle DSR (Data Subject Request) intake with automated discovery of personal data across your systems, automated propagation to sub-processors, consent management, cookie banners, privacy impact assessments, ROPA (Record of Processing Activities) maintenance, and breach notification workflows. Pricing typically starts at $20K-50K per year for SMB tiers (Osano, Ethyca, smaller deployments of TrustArc) and runs $100K+ per year for enterprise (OneTrust, BigID, Securiti, Transcend). This template handles the request-intake workflow itself — structured capture, identity verification, scope definition, exception flagging, SLA clock — without the full platform commitment. Most companies under 50 employees or $20M revenue do not justify the platform cost; companies above that scale that already have a privacy platform usually keep using it. The teams that stay on this approach permanently are typically the ones running on a Google Workspace + Jira + Slack stack for privacy, where the form is the structured front-door and the propagation runbook is documented manually in Confluence or Notion.
Under GDPR Article 12(6), the controller may ask for additional information necessary to confirm the identity of the data subject — but only what is proportionate to the data sensitivity. The EDPB Guidelines 01/2022 on data subject rights (right of access, with parallel reasoning for erasure) state that identity verification must be reasonable and proportionate — requesting a full passport scan to delete a newsletter signup is disproportionate and would itself be a GDPR violation. The form's tiered approach (email verification for low-risk, account-login for medium, redacted ID for high-risk) is built around this proportionality principle. Under CCPA Cal. Civ. Code § 1798.130 and the CPRA regulations, the controller must use commercially reasonable methods to verify identity, with the standard scaling to the sensitivity of the data requested. Under LGPD Art. 19, the controller must respond to verified requests with proportionate verification. The form captures the verification method used and the timestamp, which is the documentation a regulator will request if a third party disputes that a request was handled correctly.
Yes — but every exception must be specifically cited and documented, not a blanket 'we keep all data.' GDPR Article 17(3) lists the exhaustive carve-outs: (a) freedom of expression and information; (b) compliance with a legal obligation (tax retention, employment record retention, financial services records); (c) public interest in public health; (d) archiving, scientific/historical research, statistical purposes; (e) establishment, exercise, or defense of legal claims. LGPD Article 16 has similar carve-outs (legal obligation, study by research entity, contract execution, exercise of regulatory rights, transfer to a third party). CCPA Cal. Civ. Code § 1798.105(d) lists 9 carve-outs including transaction completion, security/fraud prevention, free speech, scientific research, internal use compatible with the context of collection, legal obligations. The most common exception for B2B SaaS is 1798.105(d)(1) — transaction completion (you can keep records of past transactions for accounting/tax/legal-claim purposes). The form captures the specific exception cited and routes the request for partial deletion with the exception data retained. Refusal of the whole request without exception is the regulator-attractor — partial deletion with documented exceptions is the lawful response.
Backups are the hardest part of right-to-erasure operationally. The ICO (UK Information Commissioner's Office) guidance, mirrored by the EDPB and AEPD, treats backups practically: you do not have to restore a backup just to delete one record, but you must (1) flag the data for deletion so it does not get restored back into production, (2) delete it when the backup expires per its normal retention schedule, and (3) document this approach in your retention policy. The form captures this with a 'backup propagation' checklist that gets logged. Sub-processors are firmer — GDPR Art. 17(2) requires the controller to inform other controllers/processors of the request 'taking account of available technology and cost,' and your DPA with each sub-processor (per Art. 28(3)(g)) should already require the processor to delete data on instruction. The form generates the sub-processor notification list based on the data scope (marketing data → Klaviyo/Mailchimp/Brevo; CRM data → Salesforce/HubSpot/Pipedrive; analytics → GA4, Mixpanel, Amplitude, Segment; support → Intercom, Zendesk, Help Scout; payments → Stripe/Mercado Pago/Pagar.me); the workflow then tracks each sub-processor's confirmation of deletion.
A compliant response includes: (1) confirmation of receipt within 5 working days for high-volume operations under EDPB best practice, with the clock running from receipt; (2) verification of identity using proportionate methods, documented; (3) within the regulatory deadline (30 days GDPR/LGPD; 45 days CCPA; 25 working days UK GDPR), either the completed deletion confirmation or a one-time extension notice with reason; (4) the deletion confirmation itself, listing the systems where the data was deleted, the systems where retention exceptions applied with the specific exception cited, the timestamp of deletion, and the contact for follow-up questions; (5) information about the right to lodge a complaint with the supervisory authority (AEPD for Spain, CNIL for France, BfDI for Germany, Garante for Italy, ICO for UK, DPC for Ireland, ANPD for Brazil, the California Privacy Protection Agency for CCPA). The form generates all of this from the workflow data, including the timestamped audit trail. The audit trail is what regulators actually request when they investigate — the deletion itself is the action; the documentation is the evidence.

Ready to build forms that work for you?

Create your first form in minutes. Your submissions will thank you.

Be first in lineLimited early accessSet up in 2 minutes