When a broker ignores you
Most brokers comply once a request lands — the request itself, and the liability it creates, is what does the work. Some don’t. Here’s the escalation path.
1. Know the deadline
- GDPR (EU/EEA): one month from the request.
- CCPA (California): 45 days.
- Other US state laws: typically 30–45 days.
2. Keep the evidence
Run eraser export. It produces a single document — per broker: what was sent
and when, a copy of the request, every reply and its date, and an explicit list
of the controllers that are past the deadline with no substantive response.
--format html prints cleanly to PDF for attaching to a complaint.
3. Complain to a supervisory authority
Under GDPR Article 77 you can lodge a complaint with the data protection
authority of the EU/EEA country where you live, where you work, or where the
infringement happened. The authorities page lists all of them;
eraser export also names the one for your country.
Set expectations: most authorities are slow — cases can take years. But an open complaint is itself pressure on the company.
noyb.eu publishes complaint templates and sometimes takes strategic cases directly.
4. Consider the DELETE Act (California)
California’s DELETE Act will let residents delete themselves from every registered data broker through a single request via the CPPA — check whether that mechanism is live before doing it broker by broker.
None of this is legal advice. You are responsible for what you submit to any authority.