The books are the most organised thing about them
We have spent most of this publication on one half of a fact: they keep what you give them, for years, through account closures and rebrands and acquisitions, and the copies do not come back. Held on its own, that half reads as a reason to do nothing. If the file outlives everything you do about it, why do anything.
This issue is about the other half. A company's records are not a void that swallows what you send. They are the most organised asset the company owns: indexed, backed up, retained on schedules, because retention is where the value is. And the same machinery that keeps your data is what receives your request. A written request does not bounce off the file. It enters it.
That is the inversion worth sitting with. The reason to send something is not the hope that the file will be erased. It is the certainty that the file will be kept, and what a company may do with a kept file next year, or five years from now, is exactly what a standing instruction inside that file is for. If they are going to hold a record about you for years, one entry in it can be yours.
Any employee, any form, one named owner
What happens when a request arrives is not improvised, because the regulator does not allow it to be. The UK regulator's guidance to companies is explicit about intake: a valid request has no required form. It can be made in writing or out loud, including over social media, to any part of the organisation, and any employee may receive one. Companies are told to train all staff to recognise a request, to appoint a specific person or central team to own the response, to keep registers of where personal data lives so it can be found, and to keep a log of each request: who handled it, its due date, what was supplied, what was withheld and why.
That is not a courtesy the company extends. It is what gets audited. Request handling is one of the nine areas in the UK regulator's own audit framework, tracker template included, and certification auditors ask for the same records: requests received, requests answered, how fast. California went further and wrote the log into law, with no size threshold at all: every business subject to the state's privacy law must keep records of every consumer request and how it was answered, for at least 24 months. The largest must publish the totals every year in their own privacy policies: requests received, complied with, denied, and the median days taken to respond.
The machinery, per the regulators
In Europe the request log is the regulator's stated expectation and audit subject; in California it is written regulation.
The machinery is real enough that its failure is what enforcement looks like. When a major British political party let its requests pile up after a cyber-attack, the public reprimand that followed read like an inventory of the queue: how many outstanding, how far past deadline, the unmonitored inbox where hundreds more sat unread, the staff finally assigned to nothing but the backlog. The regulator did not treat the pile as noise. The pile was the case.
What changes the moment it lands
A written request also does something no settings toggle does: it changes the company's legal position on arrival.
In the UK it does so with a criminal statute. Once an access request is in, altering, blocking, destroying or concealing the information to avoid handing it over is a criminal offence, and it attaches both to the organisation and to the person who does it. The precision matters: data deleted on an ordinary schedule, deletion that would have happened anyway, is not caught. Deleting it because you asked is. From the moment your request lands, the ordinary churn of their systems has a line drawn through it: whatever happens to your file, it may not lawfully happen in order to avoid answering you.
You do not have to earn any of this. The English courts settled years ago that nothing requires you to explain why you want your information, and European guidance says the same about form: no set wording, no legal citations required. In one Swedish case, a customer's objection counted from the day it arrived even though it never cited any law.
And even refusal is regulated. A company that turns you down owes you its reasons, in writing, within the same deadline, along with a note of where to complain. Since June 2026, UK organisations must also run a complaints route of their own and acknowledge a complaint within thirty days. There is no version of receiving your request that lawfully ends in nothing. We have written about what the complaint route is really worth as a backstop; the point here is narrower and harder. Answering you is not optional paperwork. It is the thing the entire machinery above exists to do.
The request that never expires
Among the requests you can send, one stands apart in how it ages: the objection to direct marketing. The general objection right comes with a balancing test we have written about before, where the company weighs its own "compelling legitimate grounds" against yours. The marketing objection has no such clause. The law's sentence simply ends: the data shall no longer be processed for those purposes.
It takes effect when it arrives. A Swedish regulator ruled against a retailer that kept mailing a customer after she objected; the company argued her details had re-entered its systems from a third-party list, and the regulator rejected the excuse and stated the standard plainly: she "shall not have to repeat" her objection. Once is the design.
And in the UK, the regulator's guidance takes the final step. Companies are told to honour a marketing objection not by deleting you but by keeping you: a suppression entry holding just enough information to make sure the preference is respected, permanently. They cannot contact you later to ask whether you have changed your mind. A moment of inattention years from now, some box left unticked, does not override it. There is no automatic right, even for you, to have the entry removed. We have pointed at this mechanic twice before as an irony, the stop that keeps you on file. Hold it the other way up. Of everything a company holds about you, the one entry it is told to keep for good is your no. The record that outlives your data is the one with your instruction in it.
The stop request, by the rules
The once-is-enough standard is a European regulator's ruling; the permanence of the entry is UK guidance.
To be precise about the boundary: that weight belongs to the marketing objection. Other requests age differently, and the broader objection still ends in the company's own weighing. But the marketing objection is also the request with the least homework attached. It needs no evidence, no explanation, no law cited, and nothing from you ever again.
The eraser that files you
There is one more consequence of the books being real, and it lands on the industry that sells escape from them. A service that removes you from databases handles your name, your addresses, your identifiers, on an ongoing basis, which makes it a holder of your data with the same duties as every other: intake, logging, answering. It has to keep you on file to know who to keep removing, renewed monthly, and the industry it petitions has already spent years refusing requests that do not come from you.
A service that sells your absence has to keep you on file to deliver it.
You cannot get off the books. Not the companies', not the intermediaries', not anyone's. What you can decide is whether anything in those books is in your words, and whether you hold a dated copy of what was said.
Send it once, from the address they know
The mechanics this issue points to are deliberately small. Pick a company that can already place you, one where you hold or held an account. Send the request from the email address they have on file, so the question is about the record they already keep. One job per request. Note the date, and keep what comes back where you can find it.
That is the whole procedure. There is no follow-up you owe. Whatever comes back is a dated claim, in their words, in your inbox. If nothing comes back, the deadline turns the silence itself into a result you can point to. You are not chasing an outcome. You are placing an entry, in books they are required to keep and answer for.
The plan, as ever, is your own record: what you asked, when you asked it, and what they said back. Start your record →
They keep records about you. The request is the one entry you write yourself.