You've almost certainly seen the acronyms — GDPR in emails from European companies, CCPA in California privacy notices — without necessarily knowing what rights they actually grant you as an individual, or how to use them.
GDPR, in plain terms
The General Data Protection Regulation is a European Union law that applies to any company handling the personal data of EU residents, regardless of where the company itself is based. It gives individuals several concrete rights, including:
- The right to access — you can request a copy of every piece of personal data a company holds about you.
- The right to erasure — often called "the right to be forgotten," letting you request that a company delete your data under most circumstances.
- The right to data portability — you can request your data in a format that lets you move it to another service.
CCPA, in plain terms
The California Consumer Privacy Act (and its expansion, the CPRA) grants California residents a related but distinct set of rights, including the right to know what personal data a business has collected about them, the right to request deletion, and the right to opt out of their data being sold to third parties — often via a "Do Not Sell or Share My Personal Information" link many sites are now required to display.
Do these protect you if you're not in the EU or California?
Often, yes, indirectly. Many companies find it simpler to apply the same privacy controls to all users globally rather than building region-specific systems, so features originally built for GDPR or CCPA compliance frequently end up available to everyone, even if not legally required elsewhere.
How to actually use these rights
Most companies of any reasonable size now have a privacy request form, usually linked from their privacy policy footer, where you can submit access or deletion requests directly. It's a legitimate, straightforward process — you're not asking for a favor, you're exercising a right the law already grants you.
Where prevention still beats deletion requests
Data rights are powerful, but they're reactive — you're cleaning up data that already exists. It's simpler to avoid generating it in the first place for services you don't actually need a long-term relationship with, which is exactly the gap a temporary email address is built to fill.