General legal information, published for everyone. It does not apply the law to anyone’s particular situation and is not legal advice. Laws change and differ by place; check the primary sources below.
Quick summary
- Deleting an online account usually stops or limits future use of the service, but it may not immediately remove every copy of information connected with it.
- Privacy laws in some places provide a right to request deletion, subject to exceptions for legal obligations, security, disputes, records, and public-interest purposes.
- Immediate danger or credible threats are emergency matters, and emergency services are the first point of contact.
What it means
Deleting an online account usually stops or limits future use of the service, but it may not immediately remove every copy of information connected with it. Privacy laws in some places provide a right to request deletion, subject to exceptions for legal obligations, security, disputes, records, and public-interest purposes. Immediate danger or credible threats are emergency matters, and emergency services are the first point of contact.
How the law works
How the law usually works
An account is usually governed by two overlapping systems: the service’s contract and privacy law.
The contract may explain how to close an account, what happens to user content, and how long the company keeps records. “Deactivation,” “suspension,” and “deletion” may have different meanings. Deactivation can leave the account and data stored, while deletion normally means the company removes or anonymizes data from active systems.
Privacy laws may give you a right to request erasure or deletion of personal information. That right is usually not absolute. A company may be allowed to retain information to:
- Comply with a legal obligation, court order, tax rule, or regulatory requirement
- Detect fraud, abuse, hacking, or other security problems
- Establish, exercise, or defend legal claims
- Complete a transaction or provide a service you requested
- Keep records needed for freedom of expression, journalism, research, or public interest
- Maintain information that has been properly anonymized
Deletion also may not remove information held by other people. Messages, screenshots, reposts, search-engine results, data brokers, connected applications, backups, and archived pages can remain after the original account is gone. A platform may also retain limited records—such as a deletion request, fraud-prevention identifiers, or billing records—without keeping the account publicly available.
Some services may remove your profile but preserve content sent to other users. User-generated posts may be copied or quoted elsewhere. Removing your own account generally does not give you a right to erase another person’s lawful copy.
Common processes
- Review the service’s settings and privacy policy. People commonly check whether there is a permanent-delete option, a separate data-download option, and an explanation of retention periods. They may save important receipts, messages, account history, or evidence before deletion.
- Secure the account first. Common steps include changing the password, ending active sessions, removing connected applications, cancelling subscriptions, and checking whether a social-media account is linked to other services. People dealing with harassment may preserve evidence before blocking or reporting the account.
- Download or export data. Many platforms offer an archive containing posts, photographs, messages, login information, or transaction records. The format and contents may differ from the information held internally by the company.
- Submit the deletion request. This may be done through account settings, a privacy portal, an email address, or a written request. A clear request usually identifies the account, asks for deletion of personal information and closure of the account, and asks what information will be retained and why.
- Complete identity verification carefully. A company may request information to confirm that you control the account. People commonly provide only what is reasonably necessary and use the company’s official website or published privacy contact rather than an unsolicited link.
- Ask connected services and data brokers separately. Deleting an account normally does not delete information held by advertisers, payment processors, app developers, search engines, or data-broker websites. Each organization may have its own request process.
- Keep records of the process. People commonly save the request, confirmation, dates, ticket numbers, and the company’s explanation of any refusal or retention. These records can matter if a regulator or court later becomes involved.
- Check what remains afterward. People may search for old profiles, contact recipients about copies, review connected apps, and ask search engines to remove links where a legal or policy-based removal process applies. Search-engine delisting is different from deleting the source information.
Deadlines and time limits
Under the EU General Data Protection Regulation and the United Kingdom’s data-protection framework, organizations generally respond to an erasure request without undue delay and usually within one month. That period can commonly be extended by up to two more months for complex or numerous requests, with an explanation.
Under California’s consumer-privacy law, covered businesses commonly have up to 45 days to respond to a deletion request, with a possible extension of another 45 days when reasonably necessary and properly explained. Other US state laws use different periods and may not apply to every business or person.
Canada’s federal private-sector privacy law does not create one universal deadline for every deletion request. A business may have retention duties, and provincial privacy laws may apply instead or in addition. Australia’s Privacy Act generally requires information no longer needed for an authorized purpose to be destroyed or de-identified when practicable, but it does not create one general account-deletion deadline.
A platform may delete an active account quickly while taking longer to remove information from backups, disaster-recovery systems, or records subject to a retention period. Confirm the applicable deadline with the company, the relevant privacy regulator, a court, or a licensed attorney where you live.
Documents that usually matter
- The service’s terms of use, privacy policy, and retention or deletion policy
- Screenshots or copies of the account settings and deletion confirmation
- The written deletion request and any response
- Identity-verification communications
- Subscription, payment, tax, or transaction records
- Data-export files
- Evidence of harassment, impersonation, threats, or unauthorized access
- Notices about a legal hold, investigation, dispute, or court proceeding
- Records showing information held by third parties or appearing in search results
Deleting evidence connected with a dispute can create practical problems. People commonly preserve relevant records before closing the account and avoid altering evidence that may be needed for a complaint or legal proceeding.
How it differs by jurisdiction
United States. There is no single, comprehensive federal right for every person to have all personal information deleted from every business. Some federal rules regulate particular industries or types of information, while state privacy laws may provide deletion rights. California’s law is broad but includes exceptions and applies only to covered businesses and qualifying consumers. Colorado, Connecticut, Virginia, Utah, and other states have their own requirements, definitions, exemptions, and deadlines. Contract terms, sector-specific rules, and court orders can also affect retention.
England and Wales. The UK GDPR provides a right to erasure in specified circumstances, subject to exceptions. The Data Protection Act 2018 supplements that framework. A company can refuse or limit deletion where an exception applies, such as legal obligations, freedom of expression, or legal claims. Complaints about a data-protection response commonly go first to the organization and may then be raised with the Information Commissioner’s Office.
Canada. The federal Personal Information Protection and Electronic Documents Act (PIPEDA) applies to many private-sector organizations, but substantially similar provincial laws can apply instead in some provinces. Quebec, British Columbia, and Alberta are especially important examples. Canadian law commonly focuses on appropriate purposes, consent, access, correction, safeguards, and retention rather than providing one broad deletion right identical to the GDPR. Sector-specific rules may change the result.
Australia. The Privacy Act 1988 and the Australian Privacy Principles generally require covered organizations to take reasonable steps to destroy or de-identify personal information they no longer need, subject to exceptions. The law does not necessarily require immediate deletion whenever a person closes an account. State and territory laws, health-record rules, employment records, and sector-specific obligations can also matter.
When people consult a lawyer
Legal advice can be useful when:
- The company refuses deletion and the information could cause serious harm
- You received a legal hold, subpoena, court order, or regulatory notice
- The account involves employment, health, financial, educational, or children’s information
- You suspect identity theft, doxxing, stalking, extortion, or unauthorized access
- You need removal of defamatory, intimate, or impersonating material
- Deletion could destroy evidence needed for a claim or defense
- You operate a business that must design a lawful deletion and retention process
For immediate threats or physical danger, contact emergency services first. For non-emergency harassment, people commonly report the conduct to the platform and preserve evidence before taking steps that could remove useful records.
Primary sources
- RegulationEuropean Union: Regulation (EU) 2016/679, General Data Protection Regulation, especially Articles 12–17, EUR-Lex official text.See citation
- StatuteUnited Kingdom: Data Protection Act 2018; Information Commissioner’s Office, “Right to erasure” guidance.England & Wales
- StatuteCanada: Personal Information Protection and Electronic Documents Act, Justice Laws Website; Office of the Privacy Commissioner of Canada, guidance on retention and deletion.Canada
- StatuteAustralia: Privacy Act 1988 and Australian Privacy Principles, Federal Register of Legislation; Office of the Australian Information Commissioner, Australian Privacy Principles Guidelines.Australia
- Official sourceUnited States—California: California ConsumerUnited States (federal)
Links go to official or widely used free sources. Check that a source is current before relying on it. Browse all sources →
- Last updated
- Sep 26, 2026
- Jurisdiction
- General — United States, England & Wales, Canada, Australia
- Written by
- House Legal editorial (AI-generated, earlier format)