Most people never send these letters, not because the right is unclear but because the wording feels like a legal exam. It is not. A valid request only has to identify you, say what you want, and name the right the law gives you. This writes it for you.
| Request | Legal basis | Deadline to answer |
|---|---|---|
| See what they hold | GDPR / RGPD, art. 15 | One month, extendable by two further months |
| Have it erased | GDPR / RGPD, art. 17 | One month, extendable by two further months |
| Deletion (California) | CCPA | 45 days, extendable by another 45 |
The GDPR deadline comes from Article 12: the controller must respond without undue delay and in any event within one month of receipt, and that period may be extended by two further months where necessary. For California, the Attorney General states businesses must respond within 45 calendar days and may extend by another 45 if they notify you.
Name the article, because a request citing Article 17 lands on a different desk from one asking to close an account. Give them enough to find you, since most refusals are really failures to match you to a record. And put the deadline in writing, which turns a vague ask into a dated obligation and is also the evidence you would need if you later complained to a supervisory authority.
Silence is itself a breach of the deadline. In the EU and the UK you can complain to your national data protection authority, and you do not need a lawyer to do it. Keep the sent copy and the date: that is the whole evidence file.
Related reading: What is a data broker