Your Privacy Rights
When a Company Ignores Your Deletion Request: What to Do
The short version
When a company ignores your deletion request, escalate in order: confirm the deadline really passed, send one written follow-up, use the company's appeal process if your state requires one, then file with your state attorney general (and the CPPA if you are in California). The FTC is for deception, not individual fixes. None of these bodies will act as your lawyer, and in most states you cannot sue over an ignored request. Meanwhile, the fastest way to get a people-search listing down is still the site's own opt-out. This article is general information, not legal advice.
First, check whether the request was actually ignored
Before escalating, make sure the company is really late. Under the CCPA, a business must confirm receipt within 10 business days and respond in substance within 45 calendar days, and it can extend that once by 45 more days if it tells you. Most other state privacy laws use the same 45-plus-45 structure. "Ignored" means the full window has passed with nothing.
Three other things look like being ignored but are not. First, you sent the request through the wrong channel: California's Attorney General advises checking the privacy policy to confirm you used the designated method. Second, you never clicked the verification email, so the request was never opened. Third, the company is not covered by any privacy law that applies to you, which is common for small businesses and for residents of the roughly 30 states without a comprehensive privacy law.
If you filed with a people-search site rather than a regular business, the picture is simpler. Every major site has a free opt-out that runs on its own process, not on a legal deadline. Our opt-out guides list the verification step and typical turnaround for each one, and our post on how long opt-outs take covers the normal waiting times.
Rung one: a single written follow-up
The first escalation is a short, factual message to the company's privacy contact, not to general support. Regulators expect you to have given the business a chance to fix the problem, and a dated follow-up is the evidence you did. It also resolves a surprising share of cases, because many "ignored" requests are simply sitting in an unmonitored inbox.
Find the privacy email or postal address at the bottom of the privacy policy. State the original request date, the method you used, any confirmation number, which right you invoked, and the deadline you believe applies. Ask for written confirmation within ten business days. Keep every reply, and take a dated screenshot of your data still being live. The privacy complaint guide walks through the full paper trail.
Do not send five messages. One clear follow-up, with a deadline, is what a complaint reviewer wants to see later.
Rung two: the company's own appeal process
If the company refused your request, or answered with a form letter that did not address it, most state privacy laws give you a formal appeal. Virginia's law, for example, requires a controller to "establish a process for a consumer to appeal the controller's refusal to take action on a request," and to answer the appeal in writing within 60 days.
Colorado's law works the same way with a 45-day appeal deadline that can be extended by 60 days. Connecticut and most of the newer state laws copied the model. The important part is what happens when the appeal fails: Virginia's statute requires the company to give you "an online mechanism, if available, or other method through which the consumer may contact the Attorney General to submit a complaint." A denied appeal is your hand-off to the regulator.
California does not have a statutory appeal step. There, an unanswered follow-up moves you straight to rung three. Our state-by-state guide to data deletion rights shows which law, if any, covers you.
Rung three: your state attorney general
For most Americans, the state attorney general is the only body with real authority over a company that ignored a privacy request. As of 2026, 20 states have comprehensive privacy laws, and in nearly all of them the AG, not the consumer, is the enforcer. Filing there is the correct move, as long as you understand what it will and will not do.
What it can do: log your complaint, investigate, demand the company fix its practices, and sue or fine it. What it will not do: represent you. Colorado's Attorney General puts it bluntly: "Private citizens are not entitled to file lawsuits or enforce legal rights under the CPA." California's AG page says the same in its own words: "The Attorney General does not represent individual California consumers."
In practice, AG offices act on patterns. Your complaint matters most when it joins others about the same company, which is why a precise, dated complaint with the confirmation number is worth more than an angry one. Find your office through the USAGov attorney general directory, then look for a consumer or privacy complaint form.
Rung four: the CPPA, if you are in California
California is the only state with a dedicated privacy regulator, the California Privacy Protection Agency, and it takes complaints directly at cppa.ca.gov. It accepts both sworn and unsworn complaints, and unsworn ones can be anonymous. Sworn complaints attest to the truth of the allegations under penalty of perjury, which tends to carry more weight.
Be clear-eyed about the limits, in the agency's own words: "The Agency does not represent individual consumers and cannot act as your attorney," and it "is not required to take any action on your complaint." Complaints "may be used to broadly monitor industry compliance or to inform an enforcement action." That is the honest deal: your complaint is evidence, not a ticket.
The evidence is being used. In September 2025 the CPPA fined Tractor Supply $1.35 million, its largest penalty to date, over failures including ineffective opt-out mechanisms. Its enforcement head said, "We made it an enforcement priority to investigate whether businesses are properly implementing privacy rights." Fines can reach $2,663 per violation and $7,988 per intentional violation under the amounts in force since January 2025.
If a data broker ignored your DROP request
A California resident who used the state's DROP platform and still sees their data on a registered broker has a stronger position than anyone else in the country. DROP is the CPPA's own program, so the CPPA is the correct venue, and the penalty structure is designed to make ignoring requests expensive rather than merely embarrassing.
Since August 1, 2026, registered brokers must check DROP at least every 45 days and delete matching records. The Delete Act sets an administrative fine of $200 per deletion request for each day a broker fails to delete, and separately $200 per day for failing to register. In August 2026 the agency announced its first action under both the CCPA and the Delete Act: LocateSmarter, an Iowa broker, agreed to pay $116,490 for registering late and for demanding the last four digits of Californians' Social Security numbers before letting them opt out.
Give the broker the 45-day window before complaining, since it may not have pulled your request yet. Our California DROP guide covers what the platform does and does not reach.
Rung five: the FTC, for deception rather than delay
The Federal Trade Commission is the wrong place to get your record deleted and the right place to report a company that lied about it. If a privacy policy promised deletion and the company plainly did not deliver, or a site's "remove" button does not do what it says, that is a deception claim, and deception is the FTC's core territory.
The agency is candid about its role. In its own words: "The FTC and other agencies use your report to investigate and bring cases, but can't resolve cases for individuals." Reports go into a secure database shared with roughly 2,800 law enforcement agencies. The FTC has used exactly this kind of pattern before: its 2023 case against TruthFinder and Instant Checkmate included a "Remove" button that only hid the item from that one customer's report while leaving it visible to everyone else. The companies paid $5.8 million.
File at ReportFraud.ftc.gov. Keep it factual and attach the same dated evidence you built for rung one.
What each rung can and cannot do
The ladder is worth climbing, but each step does something different, and none of them substitutes for the others. This table sets out the deadline that applies at each rung and the realistic outcome, so you can decide how far to go for a given company.
| Rung | Deadline that applies | Can do for you | Cannot do |
|---|---|---|---|
| Original request | 45 days, extendable once by 45 (CCPA, VA, CO and most states) | Obliges a covered company to act | Bind companies outside the law's scope |
| Written follow-up | Your own ten business days | Often resolves it; creates the record | Force a reply |
| Company appeal | 60 days (VA); 45 days plus 60 (CO) | Formal second review; AG hand-off if denied | Exist in California |
| State attorney general | None fixed for you | Investigate, fine, sue the company | Represent you or promise action |
| CPPA (California) | None fixed for you | Audit, fine up to $7,988 per intentional violation | Act as your attorney |
| FTC | None | Log deception for pattern cases | Resolve your individual case |
Deadlines from the CPPA and California Attorney General CCPA pages, Virginia Code 59.1-577, and the Colorado Attorney General's Colorado Privacy Act page; FTC role per the FTC's own consumer guidance. Checked September 2026.
Can you just sue?
For an ignored deletion request, almost never. State privacy laws overwhelmingly leave enforcement to the attorney general and give consumers no private right of action. California's CCPA is the closest thing to an exception, and even there the CPPA is explicit: "You cannot sue businesses for most CCPA violations. However, you can sue a business under the CCPA if there is a data breach."
That breach claim is narrow. It covers non-encrypted, non-redacted personal information stolen because the business failed to keep reasonable security, with statutory damages the CPPA lists at $107 to $799 per consumer per incident under the 2025 adjusted amounts. It does not cover a company that simply never answered you.
Other routes exist: small claims court on a contract or consumer-protection theory, a lawyer's demand letter, or one of the state laws with unusual teeth such as New Jersey's Daniel's Law for protected professions. Our post on whether you can sue a data broker goes through each honestly. Treat all of them as long shots compared with the ladder above.
Meanwhile, get the listing down the practical way
While the ladder grinds, remember that most people who ask this question are dealing with a people-search site, and those have a faster path than any regulator. Every major site runs a free opt-out. The formal legal request may sit unanswered, while the site's own removal form, submitted with the listing URL and confirmed by email, clears the page in days.
So run both tracks. Keep the legal complaint moving for the record, and in parallel file the site's opt-out. Our library of data broker removal guides, organized by category, shows the exact form and verification step for each one. If the listing later comes back, which is normal because brokers re-ingest public records, file again rather than starting a new complaint.
If you are not sure which sites still show you, RedactZero's free exposure scan lists the brokers likely to hold a record on a US adult and links each to its guide, without storing what you enter. Combine that with the escalation ladder, and an ignored request becomes an inconvenience instead of a dead end.
See who still lists you
Run a free exposure scan to find the data brokers and breaches tied to your details, then file the free opt-outs that regulators cannot do for you - no account, nothing stored.
Frequently asked questions
How long does a company have to respond to a deletion request?
Under the CCPA, a business must acknowledge your request within 10 business days and respond in substance within 45 calendar days, extendable once by another 45 days if it notifies you. Most other state privacy laws also use a 45-day deadline with one 45-day extension.
What should I do first if my deletion request is ignored?
Check that you used the company's designated request method and completed any email or identity verification step, then send one written follow-up to the privacy contact listed in its privacy policy. Quote the original date, any confirmation number, and the legal deadline you believe applies.
Can I appeal if a company refuses my deletion request?
In most states with a comprehensive privacy law, yes. Virginia, Colorado, and Connecticut, among others, require the company to run an appeal process. If the appeal is denied, the company must tell you how to complain to the state attorney general.
Will my state attorney general get my data deleted?
Usually not directly. State attorneys general enforce privacy laws on behalf of the public, so your complaint goes into a pool used to spot patterns and choose enforcement targets. Colorado's AG states plainly that private citizens cannot enforce the Colorado Privacy Act themselves.
What does the CPPA do with a complaint?
The California Privacy Protection Agency accepts sworn and unsworn complaints, uses them to monitor industry compliance, and may investigate or refer them. It says it does not represent individual consumers, cannot act as your attorney, and is not required to act on any specific complaint.
Can the FTC resolve my deletion request?
No. The FTC says it uses reports to investigate and bring cases but cannot resolve cases for individuals. Your report goes into a secure database shared with about 2,800 law enforcement agencies. It is still worth filing if the company lied about what it collects or deletes.
Can I sue a company for ignoring my deletion request?
In almost every state, no. State privacy laws leave enforcement to the attorney general. California allows consumers to sue only over certain data breaches, not over ignored deletion requests. Small claims or a lawyer's demand letter are options, but neither is a guaranteed route.
What if a data broker ignores my California DROP request?
Complain to the CPPA, which runs DROP. Registered brokers have had to process DROP requests since August 1, 2026, checking the platform at least every 45 days, and the Delete Act sets a fine of $200 per deletion request per day for brokers that fail to delete.
Sources: California Privacy Protection Agency (cppa.ca.gov FAQ, complaint page, CPI-adjusted penalty page, September 30, 2025 Tractor Supply and August 2026 LocateSmarter announcements); California Attorney General CCPA page (oag.ca.gov); Virginia Code 59.1-577; Colorado Attorney General, Colorado Privacy Act resource page; Federal Trade Commission consumer guidance on reports and the September 2023 TruthFinder and Instant Checkmate settlement; MultiState count of state privacy laws in effect in 2026; Fenwick & West summary of Delete Act penalties. Checked September 2026.