Generate GDPR-compliant data access, deletion, or portability requests in 7 languages
Dear Data Protection Officer, I am writing to exercise my right of access to personal data pursuant to Article 15 of the GDPR. I request that you provide me with: 1. A copy of all personal data you hold about me 2. The purposes of the processing 3. The categories of personal data concerned 4. The recipients or categories of recipients 5. The retention period or criteria used to determine it 6. Information about the source of the data Please provide this information in a commonly used electronic format within 30 days as required by Article 12(3) GDPR. My details: Name: [Your Name] Email: [Your Email] Account/Reference: [Account ID] Yours sincerely, [Your Name]
Generated letters cite GDPR Articles 15-21 as applicable. This tool does not constitute legal advice. Consult a data protection lawyer for specific GDPR compliance matters.
The GDPR hands individuals six enforceable levers over their personal data. Each letter this tool generates maps to one article: Access (Art. 15) to see what is held, Rectification (Art. 16) to fix it, Erasure (Art. 17) to delete it, Restriction (Art. 18) to pause processing, Portability (Art. 20) to take it elsewhere, and Objection (Art. 21) to stop marketing use. Whatever you choose, the company has 30 days to respond under Art. 12(3) — free of charge.
Six rights radiate from you as the data subject, and every request starts the same 30-day response clock.
Luis signed up for a fitness app three years ago and later deleted his account. He suspects the company still holds his profile and wants a copy before deciding whether to push for deletion.
To exercise your GDPR rights: pick the right — access, erasure, rectification, or portability — enter the company and your details, and the tool generates a compliant citation-backed letter ready to send to the DPO or privacy contact.
FreeToolHub GDPR Request Generator is a free browser-based tool that drafts GDPR data subject rights letters for access, deletion, and portability, no signup.
Generate a GDPR-compliant data deletion request in 1 minute. Free, no signup.
The GDPR Data Request Generator writes Article-cited request letters that EU residents can send to any company processing their personal data. It covers the six core rights: access (Article 15), rectification (Article 16), erasure (Article 17), restriction of processing (Article 18), objection (Article 21), and portability (Article 20). You pick a request type, fill in your name, email, company name, and account reference, and the tool merges those details into a properly structured letter addressed to the Data Protection Officer. The English access template, for example, requests six specific items: a copy of all personal data, processing purposes, data categories, recipients, retention criteria, and data sources. Letters are generated in your browser and can be copied or downloaded as a text file.
It is built for anyone in the EU, EEA, or UK whose data is held by companies: shoppers, app users, freelancers, and job applicants who want their records, corrections, or deletion. Privacy professionals use it to draft first-contact requests quickly instead of writing from scratch, and multilingual users benefit most: every template exists in English, German, French, Spanish, Italian, Dutch, and Portuguese, so you can write to a company in its own regulatory language. It also suits people who never sent such a request before and do not know which article to cite. The tool is a starting template, not a law firm: for complex cases involving refused requests, complaints to a supervisory authority, or litigation, get advice from a qualified data-protection lawyer.
(1) Choose one of the six request types (access, deletion, portability, rectification, restriction, or objection), each pre-linked to its GDPR article, then pick one of the seven languages. (2) Enter your name, email, the company's name, and an account or reference number; anything you leave blank appears as a bracketed placeholder such as [Your Name] so you cannot accidentally send an incomplete letter. (3) Copy the finished letter to your clipboard or download it as a text file named for your request type (for example, gdpr-delete-request.txt), and send it to the company's privacy contact. A Sample button loads a filled example so you can preview the output before typing anything, and the tool runs entirely client-side, so your details never leave the browser.
Under Article 12(3) GDPR, cited directly in the generated letters, a controller must respond without undue delay and at the latest within one month of receiving your request, which is why the access template asks for the information in a commonly used electronic format within 30 days. If your request is complex or you submit several at once, the company may extend the period by two further months, but it must tell you about the extension and its reasons within the first month. Keep a dated copy of every letter you send. If the deadline passes without an adequate answer, that copy is your evidence when you complain to your national supervisory authority, and the tool's download feature makes preserving one trivial.
Identify the company's privacy email or DPO contact, state that you invoke Article 17 (right to erasure), list the data or account involved, and request confirmation. Companies must respond within one month. This generator drafts compliant letters for access, deletion, correction, and portability.
One calendar month, extendable by two more months for complex cases with notice to you. Silence or refusal can be reported to your national data protection authority.
Access, rectification, erasure, restriction of processing, data portability, objection to processing, rights related to automated decision-making, and the right to withdraw consent. Each maps to a specific letter template in this tool.
Only when it has overriding legal grounds — legal retention duties, ongoing contract necessity, or public interest. The refusal must be explained, and you retain the right to complain to a regulator.
It generates a formal letter citing Article 17 (right to erasure), identifying your data by account email or user ID, specifying which data to delete, and demanding confirmation within the legally required 30-day response window. The letter references your rights under Articles 15, 17, and 21 for maximum legal weight.
If a company fails to respond within 30 days (extendable by 2 months for complex requests), you can file a complaint with your national Data Protection Authority. Fines for non-compliance reach €20 million or 4% of global revenue. This tool also generates a follow-up escalation letter citing the missed deadline.
What do you call a crab that plays baseball?
No paywalls, no signups, no data sold. Built by a solo developer who believes useful tools should be accessible to everyone.
☕Support me on Ko-fi— keep tools free100% of proceeds go towards hosting & building more free tools.