Most people assume the personal data scattered across the internet is simply out of their control. It isn't. The GDPR in Europe and the CCPA/CPRA in California give you concrete, enforceable rights, and data brokers are legally required to honor them. The gap between having a right and using it is almost entirely procedural — knowing which article to cite, which portal to use, and how long a company can stall.
The rights that matter most
- Right of access (GDPR Art. 15) — demand a copy of every piece of personal data a company holds about you, plus the categories of recipients it was shared with.
- Right to erasure (GDPR Art. 17, 'right to be forgotten') — require deletion, not suppression, when the data is no longer necessary or you withdraw consent.
- Right to opt out of sale or sharing (CCPA §1798.120, CPRA) — brokers must stop selling or sharing your information, including for cross-context behavioural advertising.
- Right to correct (CPRA §1798.106) — fix inaccurate records that feed background checks, tenant screening, and people-search listings.
- Right to limit use of sensitive personal information (CPRA §1798.121) — restrict precise geolocation, race, health, and similar categories.
- Right to non-discrimination — a company may not degrade your service because you exercised a privacy right.
GDPR vs. CCPA: which one protects you?
GDPR covers anyone in the EU/EEA and reaches any company worldwide that processes their data. CCPA/CPRA covers California residents, and a growing set of state laws — Virginia's VCDPA, Colorado's CPA, Connecticut's CTDPA, Texas, Oregon, and others — extend comparable rights across the US. In practice, most large brokers apply one global process because maintaining fifty different workflows is more expensive than honouring the strictest standard. That means it is usually worth submitting a request even if you do not live in a covered jurisdiction.
California's Delete Act (SB 362) requires registered data brokers to honour deletion requests submitted through a single state-run DROP mechanism — one request, propagated to every registered broker.
Deadlines companies must meet
- GDPR: one month from receipt, extendable by two months for complex requests, with notice.
- CCPA/CPRA: acknowledge within 10 business days, substantively respond within 45 days (one 45-day extension permitted).
- Most US state laws: 45 days, with a 45-day extension.
- If a deadline passes, escalate: your national Data Protection Authority in the EU, or the California Privacy Protection Agency and Attorney General in the US.
How to actually exercise your rights
- Find each broker's official privacy-request portal — registered brokers must publish one, and California maintains a public registry of them.
- Submit in writing, cite the specific statute, and keep a dated copy of every confirmation email.
- Provide only the minimum data needed to locate your record; never send ID documents unless verification is legally required and the channel is secure.
- Set a calendar reminder for the statutory deadline and follow up the day after it lapses.
- Re-check listings quarterly — brokers re-ingest from voter rolls, property records, and marketing lists, so profiles reappear.
Where MyTrace.fyi fits
This is precisely the workflow MyTrace.fyi automates. A footprint audit finds where your identity is exposed, maps each finding to that broker's official removal portal, and generates a pre-filled request citing the right statute for your jurisdiction — so exercising your rights takes minutes instead of weeks, and re-listings get caught on the next scan.