Privacy Compliance Services

The industry files

Asking a company about your data often goes through a separate firm hired to run the process, so the request creates a file of its own. Proving who you are can mean sending a passport to answer an email. The cookie banner keeps a record of what you clicked.

The read at a glance

Tracking priority Standard

A privacy request can leave a copy of your passport with the company you complained to.

If it leaks Low

A leak exposes the ID you handed over to prove who you are, alongside the requests you made.

Expect it kept Years

Request correspondence and any ID you sent to verify yourself are kept for the limitation period.

Identity demanded Optional

To act on a privacy request, some services first ask you to prove who you are with an ID document.

Industry profile reviewed 23 August 2026. Also machine-readable via the free API.

If it leaks

The file here is thin and unusually pointed: who you are, what you asked to have deleted, and the document you sent to prove it. A leak exposes your identity papers beside the fact that you are someone who asks.

What repeats in the policies

The request itself

Asking creates a file of its own

Ask a company to show or delete what it holds, and the request is often handled by a separate firm hired to run that process. It now holds your name, your email, what you asked for and what came back. The act of asking is itself a record, kept by a company you did not pick.

Proving it is you

The check can cost more than the request

This is where these requests stall. Being asked for a passport or a driving licence is routine, so exercising a right means handing over a strong identity document. Regulators have said such checks should be proportionate to what is being asked, so the demand is not always the last word.

The banner

The consent tool keeps the proof

The box asking you to accept cookies exists partly to produce evidence that you did. Consent platforms log which choices you made, on which sites and when, and hold them to be produced if the choice is ever challenged. The record outlives the preference it recorded.

What a company here typically holds

Worked out from the industry, not from any one company. What you actually handed over is yours to record.

Contact InfoMessages Identity Documents · maybe

What lawfully stays after you leave

Two kinds of hold. Law sets it: a statute makes them keep it. They set it: a ground the company grants itself.

Records tied to a live or potential dispute They set it the limitation period of the claim

They can keep records to defend a live or possible legal claim.

Who wants this data

Sold or shared Unlikely

Selling your data would defeat the service; correspondence is generally not traded.

AI training Low

Request correspondence has little value as training data.

Even anonymised, this can still be you

A verification copy of your passport identifies you outright, and fifteen ordinary attributes re-identify 99.98% of people without it (Rocher et al., Nature Communications, 2019).

Name, date of birth, postcode Sometimes

Fifteen demographic attributes re-identify 99.98% of Americans in a released dataset (Rocher, Hendrickx and de Montjoye, Nature Communications, 2019); date of birth, postcode, and sex alone did it for most people in the first study of the problem (Sweeney, 2000).

How you write Typical

Language models infer where a person lives, their income, and their sex from their writing alone, at near-human accuracy and at scale (Staab et al., ICLR 2024).

The studies Estimating the success of re-identifications in incomplete datasets using generative models (Nature Communications 10, 3069, 2019)·Simple Demographics Often Identify People Uniquely (Carnegie Mellon University, Data Privacy Working Paper 3, 2000)·Beyond Memorization: Violating Privacy via Inference with Large Language Models (ICLR 2024, 2024)

The wording that does the work

Clauses that recur across this industry, and what each one actually permits.

“to provide and improve our services”

“to provide and improve our services”

The catch-all purpose. Analytics, profiling, personalisation and AI training all fit under it. When they want to do something new with your data, this sentence usually already allows it.

The move An objection tells them to use your data to run the service and nothing more.

“we do not sell your personal information”

“we do not sell your personal information”

Usually this means no cash changes hands. Your data can still go to ad networks, analytics firms and partners, because they count that as sharing rather than selling.

The move Use the do-not-sell switch where there is one, and put an objection in writing as well.

“service providers, partners, and affiliates”

“service providers, partners, and affiliates”

This is how your data leaves with no name attached. Recipients are described by what they do rather than named, and you cannot send a request to a company you cannot name.

The move An access request can ask for recipients by name rather than by category, and UK and EU law put that choice with you.

“aggregated or de-identified information”

“aggregated or de-identified information”

Taking your name off does not take away the pattern, and the pattern often still points at you. Policies give themselves free use of this data with no end date, on the basis that it is no longer about you.

The move If a deletion comes back as 'anonymised', keep the reply. It usually means de-identified, and it is their claim, not a fact you can check.

“retained as long as necessary, or as required by law”

“retained as long as necessary, or as required by law”

They can keep it for legal duties, tax rules, fraud prevention, possible lawsuits and their own business reasons. None of those has a firm end date, so deletion turns into something you have to argue for.

The move Which reasons apply to you, and how long each runs, is a request of its own.

“you grant us a licence to use your content”

“you grant us a licence to use your content”

This is a contract term rather than a data setting, so a privacy request cannot undo it. A careful version ends when your account does. A broad one can be passed on, never expires and survives deletion.

The move Their terms say whether the licence ends when the account does. Close the account and log the date here.

“we process this information on behalf of our client”

“we process this information on behalf of our client”

The firm presents every decision as its client's, which lets it decline to answer for the file and send you back. It still chose what its own portal collects and how long that is kept.

The move The client and the firm each hold a copy, and the same request works on both.

“we may require additional information to verify your identity before processing your request”

“we may require additional information to verify your identity before processing your request”

The request stalls until you hand over more than you started with, and the document you send to prove who you are becomes a new record in the same file.

The move What became of a document sent for verification is a fair question of its own.

“we store a record of your consent preferences as proof of consent”

“we store a record of your consent preferences as proof of consent”

A log of what you clicked, where and when, kept as evidence for a future complaint or audit. It is retained for that purpose rather than for yours.

The move The log is data about you, and an access request covers the choices held under your identifiers.

Their own policy is the one that binds them. Pin it down with a request, and keep the reply.