Resource ● Last updated 26 August 2026 ● 19 min read
How to request deletion of your personal information online

In this article
Print & save
Share
Is this resource for me?
This resource is for you if:
- You want to know who holds your personal information and whether you can ask them to delete it.
- You’ve found your information on a data broker or people-search site.
- You have experienced family or domestic violence, and your location or contact details may be available online.
- You’ve received a data breach notice and want to reduce your digital footprint.
What will I learn?
By the end of this resource, you’ll know how to:
- Understand when an organisation may need to delete or de-identify your personal information.
- Ask what personal information an organisation holds about you.
- Make a deletion request and a privacy complaint.
- Opt out of data broker and people-search websites.
- Ask a search engine to remove certain results.
- Find urgent help if personal information online is putting your safety at risk.
Understanding your privacy rights in Australia
Australia’s national privacy law is the Privacy Act 1988 (Cth). It contains 13 Australian Privacy Principles (APPs) that set out how organisations and government agencies must handle personal information — things like collecting it, storing it securely, and getting rid of it when it’s no longer needed.
Once an organisation no longer needs your personal information for anything it’s allowed to use it for, it must take reasonable steps to destroy it or de-identify it, unless an exception applies. This rule is known as APP 11.2 (referred to throughout as ‘the deletion rule’):
The Privacy Act and all 13 APPs apply only to organisations and agencies known as ‘APP entities’. These include Australian Government agencies, most organisations with annual turnover above $3 million, and some smaller organisations, such as health service providers and businesses that trade in personal information. If an organisation is covered by the Privacy Act, APP 11.2 applies to the personal information it holds, subject to the exceptions explained below. Not every organisation or type of record is covered. The Office of the Australian Information Commissioner (OAIC) is the independent regulator that interprets and enforces the Privacy Act and the APPs. It’s who you’d complain to if an organisation isn’t meeting its obligations — covered later in this resource.
Important: what this is not
Australia does not currently have a standalone ‘right to be forgotten’ or a general right to make any organisation erase your information on demand, unlike some other countries (for example, countries in the EU). APP 11.2 places an obligation on organisations covered by the Privacy Act to destroy or de-identify personal information when they no longer need it for a permitted purpose, unless an exception applies. An organisation may still be allowed or required to keep some information.
Words we use
Personal information: your name, address, phone number, email, and similar details. Sometimes also called ‘data’ or ‘Personally Identifiable Information’ (‘PII’).
Australian Privacy Principle 11.2 or APP 11.2: the privacy law rule saying a company must delete or de-identify your information once it no longer needs it (with some exceptions).
Privacy Act: the main Australian law on how organisations must handle personal information.
OAIC: the Office of the Australian Information Commissioner, the government body that handles privacy complaints.
Data broker: a company that collects and sells personal information about people, often without them knowing.
De-identify: remove the details that could identify you, rather than deleting the record completely.
De-indexing: removing a page from search results like Google; the page itself still exists, it’s just harder to find.
Where should I start?
| If this sounds like you… | Go to |
|---|---|
| I have accounts on services I no longer use (old social media, forums, shopping sites, apps) I received a data breach notice about a service I no longer use I have accounts on platforms that were acquired by other companies | Pathway 1: Deletion |
| Searching my name on Google returns results I did not put there An old article, post, or news item about me appears in search results and I want it removed | Pathway 2: De-indexing |
| My address, phone number, or workplace appears on a people-search or data broker website Photos of me appear online without my permission | Pathway 3: Data broker opt-out |
| I am experiencing or have experienced family or domestic violence and my location or contact details may be accessible online Someone is using my personal information to harass, locate, or harm me I want to reduce my digital footprint for safety reasons | Pathway 4: Urgent safety |
True or false
PATHWAY 1: Getting your information deleted
This is for you if an organisation you no longer have a relationship with — an old social media account, a former employer, a shopping account you don’t use, a service you cancelled — still holds your personal information. Sending a deletion request may get it deleted or de-identified if the organisation is required to do so by APP 11.2 (the deletion rule). If your request is refused, you can complain to the OAIC.
What to do to get information deleted
Follow these steps to get your information deleted.
Before you begin
APP 11.2 can require a covered organisation to destroy or de-identify information, but it does not create a formal individual deletion request process or set a deadline for answering one. Mark your request as a privacy complaint and explain what information you are concerned about and why you think it is no longer needed. The OAIC generally expects you to give the organisation 30 days to respond to a privacy complaint before complaining to the OAIC.
Write down the organisation’s name, the account or service you used, and any information you remember giving it, such as your name, address, email, phone number, financial details, or health information. If you do not know exactly what it holds, check your account and its privacy policy, or ask to access the personal information it holds about you under APP 12. You do not need a complete list before you contact the organisation.
Do not let this stop you from making a request. Look for the organisation’s privacy policy, usually linked at the bottom of its website or under ‘Privacy’, ‘Legal’ or ‘Help’. The policy should explain whether the organisation handles information under the Privacy Act and give privacy contact details. APP 11 applies to organisations that are ‘APP entities’ — this includes most private sector organisations with annual turnover above $3M, as well as health service providers, businesses that trade in personal information, and many others. Small businesses under $3M turnover are generally exempt. You do not need to find out the organisation’s turnover yourself. If you are unsure, send the request anyway and ask the organisation to explain whether it is covered. You can check the OAIC’s ‘Rights and responsibilities’ guidance on their website.
Start with the organisation’s privacy policy, ‘Contact us’ page, account settings or help centre. Search its website for ‘privacy officer’, ‘privacy complaint’ or ‘delete my data’. Email or filling in an online form is usually best because it gives you a record. If you can only find a phone number, call and ask for the email or postal address for privacy requests. Use the template below and keep a copy of what you send, including screenshots and any reference number. Clearly state that you are making a request that they delete or de-identify your information if required to do so in accordance with APP 11.2 of the Privacy Act 1988 (Cth). Describe the information you want deleted. State that you no longer have a relationship with the organisation and request an explanation if the organisation considers that it is not required by APP 11.2 to delete or de-identify your personal information.
If the conditions in APP 11.2 are met, the organisation must take reasonable steps to destroy the personal information or ensure it is de-identified. This can involve technical steps, such as securely deleting or de-identifying records, and organisational steps, such as applying retention policies across active systems and backups. What is reasonable depends on the circumstances.
Template letter: personal information deletion request
You can use this template letter to send to an organisation and request deletion of your personal information. Adapt this template to your specific situation.
Fill in the highlighted fields with your own information.
To: [ORGANISATION NAME] Privacy Officer
Subject: Request for deletion of personal information under APP 11 — Privacy Act 1988 (Cth)
Dear Privacy Officer,
I am writing to request the deletion (destruction or de-identification) of all personal information you hold about me, in accordance with Australian Privacy Principle 11.2 in Schedule 1 to the Privacy Act 1988 (Cth).
My details: [Full name, email address, and any account ID if applicable]
My relationship with your organisation: [Describe: former customer / account holder / service user. Last used: DATE]
Your organisation is required to take reasonable steps to destroy or de-identify personal information it no longer needs for any purpose for which the information may be used or disclosed by it under the Australian Privacy Principles, provided that the information is not contained in a Commonwealth record and your organisation is not required by or under an Australian law, or a court/tribunal order, to retain the information.
I no longer have an active relationship with your organisation, and I am not aware of any other purpose for which my information can be legitimately used under the Australian Privacy Principles.
I request that you:
- Delete all personal information held about me, including: name, address, email, phone number, date of birth, financial information, health information, and any other personal data.
- Provide written confirmation that deletion has occurred within 30 days.
- Advise me if any of my information has been shared with third parties who may also need to be notified.
If you are unable to comply with this request, please provide written reasons. Yours sincerely,
[YOUR NAME]
[DATE]
Template letter to request removal of personal information
Common reasons for refusal
The general rule: organisations can legitimately keep your information for as long as they need it for a permitted purpose under the Australian Privacy Principles, including ordinary record-keeping and legal compliance requirements, not just the specific situations listed below.
A refusal doesn’t automatically mean the organisation is in the wrong. A few legitimate reasons come up often:
- They’re legally required to keep certain records for a set time, for example, a bank keeping transaction records, or a medical practice keeping patient files.
- Your information is in a ‘Commonwealth record’ (a government record) — different rules apply under the Archives Act.
- There’s an ongoing legal case or dispute where your information may still be relevant.
- They need to keep standard corporate records even after you’ve stopped being a customer, for example, under the Corporations Act.
- They have another legitimate reason to use your information under the Australian Privacy Principles, for example, you’re still an active customer.
- If none of these reasons apply and they still refuse, you can complain to the OAIC.
You have other options too
Even if deletion is refused, you can always ask an organisation to let you see the personal information they hold about you, or to correct it if it’s wrong. These rights don’t depend on APP 11.2 and aren’t affected by whether your deletion request succeeds.
PATHWAY 2: Getting a page removed from search results
This is for you if your name, address, or other personal details appear in results from a search engine such as Google or Bing, or if an old page keeps appearing when someone searches your name. De-indexing removes a result from a particular search engine, but it does not delete the underlying page. The process depends on the search engine you use, not the browser. For example, Safari is a browser and may show results from Google, Bing, or another selected search provider.
What to do
First, ask the website that published the information to remove or update the page.
Then, use the relevant search engine’s removal process.
Google has separate tools for outdated pages and for private personal information. Use Google’s ‘Remove Outdated Content’ tool (google.com/webmasters/tools/removals) for outdated pages. For sensitive personal information (address, phone number, images), use Google’s ‘Request to Remove Personal Information from Google Search’ form (here).
Bing has a Content Removal Tool, particularly where the original page has already been removed or changed.
Other search engines may have narrower processes, so check their official help centre for ‘remove personal information’ or ‘remove search result’. Keep the page URL and screenshots of the result.
What can be de-indexed
Search engines are generally willing to consider requests covering:
- private addresses, phone numbers, or email addresses
- financial information such as credit card numbers
- usernames and passwords.
Removal is not automatic, and public interest or newsworthy material may remain.
PATHWAY 3: Opting out of a data broker or people-search site
Some websites collect and publish personal information about Australians without your knowledge, including addresses, phone numbers, and employment history. These are known as data brokers or people-search sites. Examples include reverse phone or address lookup sites, background-check sites, and marketing data brokers. A profile may include addresses, phone numbers, employment history, relatives, or other information gathered from public records and online sources.
What to do
Find the opt-out form (usually in Privacy Policy, footer, or by searching ‘[website name] opt out’). Submit the form. Some require email verification or ID. Keep a record. Allow up to 30 days for a response or for the results to be removed. Be cautious about giving a broker more information than necessary, or paying any fee, in exchange for a promised deletion.
If that doesn’t work, try Google de-indexing (see Pathway 2). It won’t remove the page but makes it much harder to find.
If neither opt-out nor de-indexing works: consider getting advice from a lawyer in the country where the site is based about what options exist there to force its removal. This is a real option, though it can be slow and expensive.
🛡 Reduce your future footprint – overall digital hygiene
- Think before you post. Once something is public, assume it can be copied and reposted elsewhere.
- Set your social media and photos to private or visible to friends only.
- Before handing over your details to a website, check what they’ll use it for and whether you can say no.
PATHWAY 4: Your safety is at risk
This is for you if you are experiencing or have experienced family or domestic violence and your location or contact details may be available online, or someone is using your personal information to harass, locate, or harm you.
Get help now
If you are in immediate danger, call Triple Zero (000). If someone is using online content to seriously threaten, harass, or abuse you, or has shared or threatened to share intimate images, report it to the eSafety Commissioner at esafety.gov.au/report.
The eSafety Commissioner can investigate certain types of serious online harm and may be able to help have harmful content removed. Before changing accounts, devices, or privacy settings, consider whether doing so could increase the risk or alert the person causing harm. Use a safer device if you can and seek specialist family or domestic violence support or legal advice.
Worth knowing: this eSafety Commissioner pathway is separate from the deletion right described in Pathway 1. It has a higher threshold to meet, but can act faster in urgent situations, and doesn’t depend on APP 11.2.
If it doesn’t work: Complaining to the OAIC
This complaints process is most relevant to Pathway 1 and may also apply in Pathway 3 where the data broker has an Australian link and is covered by the Privacy Act. De-indexing requests under Pathway 2 are handled through the relevant search engine’s removal process, rather than by the OAIC.
If your request is ignored: send a follow-up email with a 14-day final deadline. If still unresolved, consider lodging a complaint with the OAIC at oaic.gov.au. Include: your original request, any response (or non-response), and any evidence the data is still being held.
Real examples
The situation:
You Google your own name and find a people-search website that lists your current home address, phone number, employer, and estimated salary. You never signed up to this site. You are concerned about your safety.
What you should do:
Use the site’s own opt-out process first and keep a copy of the request. For overseas sites, enforcement options may be limited, but you can request de-indexing from Google (which stops the page appearing in search results even if the underlying site still exists). If your safety is at risk, contact the eSafety Commissioner and seek legal advice.
Be very cautious about giving more information to, or paying any money in exchange for, a promised deletion. This is a common trap on data broker sites. Making the request directly to the data broker is often still the best first step.
The situation:
You closed a social media account two years ago. You recently received a data breach notice from that platform saying your email, phone number, and date of birth may have been exposed. You want your information deleted. The platform may be based overseas, but the Privacy Act can still apply to an overseas organisation if it has an Australian link, including where it carries on business in Australia. If you are unsure, make the request and ask the organisation to explain whether Australian privacy law applies.
What you should do:
Closing an account does not necessarily delete all information connected with it. If the organisation is covered by the Privacy Act and no longer needs the information for a permitted purpose, APP 11.2 requires it to take reasonable steps to destroy or de-identify the information, unless an exception applies.
The situation:
You made a deletion request to an organisation six weeks ago. They sent a one-line email saying ‘we have noted your request’ but have not confirmed deletion. What do you do?
What you should do:
You generally need to complain to the organisation first and give it about 30 days to respond. If it does not respond, or you are not satisfied with its response, you can lodge a privacy complaint with the OAIC for free at oaic.gov.au. Include your original request, the organisation’s response or non-response, your follow-up, and any evidence that the information is still being held or used. If the organisation cannot demonstrate that it is permitted by APP 11.2 to retain your information, they may be in breach of the Privacy Act.
Key takeaways
You have rights
Australia does not have a general right to have all personal information deleted on demand. However, organisations covered by the Privacy Act must take reasonable steps to destroy or de-identify information they no longer need, unless an exception applies.
Keep copies
Keep copies of your request, screenshots, and any responses. If the organisation does not respond within about 30 days, or you are not satisfied with its response, you can complain to the OAIC.
Know what you’re removing
Removing a search result is different from deleting the original page. Ask the website to remove or update the content first, then use the search engine’s removal process if needed.
Prioritise safety
If information online creates an immediate safety risk, prioritise safety over the standard deletion process. Call Triple Zero (000) in an emergency and consider reporting serious online harm to the eSafety Commissioner.
Know what information is out there
Closing an account does not necessarily delete the personal information connected with it. Contact the organisation’s privacy officer in writing and clearly describe what you want deleted or de-identified.
Use opt out processes
If a data broker or people-search website publishes your details, use its opt-out process and provide only the information necessary to identify the listing. If that does not work, request de-indexing from the search engine.
Key contacts
- OAIC: 1300 363 992 | oaic.gov.au – Privacy complaints and deletion refusals.
- eSafety Commissioner: esafety.gov.au/report – Serious online harm and image-based abuse removal.
- IDCARE: 1800 595 160 | idcare.org – Free support if your information is being misused.
- 1800RESPECT: 1800 737 732 | 1800respect.org.au – Family and domestic violence support.
- Justice Connect: justiceconnect.org.au – Free legal advice for eligible Australians.
Justice Connect is grateful to Telstra for their generous support to create this resource. Learn more about Telstra’s work building Australians’ digital skills and confidence so they can take part in the online world.

This resource was last updated on 26 August 2026. This is legal information only and does not constitute legal advice. You should always contact a lawyer for advice specific to your situation. Please view our disclaimer for more information.
More self-help resources
Do you need legal help?
You might be eligible for free legal help from our lawyers. Making an online application is the quickest and best way to apply for free legal help.