Deleting your data from a dating app
A ready-made request template and the deadlines. They must reply within a month.
Deleting your data from a dating app is free and needs no lawyer: under the GDPR the controller has to answer your request within one month. The order is this — a written request to the service itself first, and only if it refuses or stays silent, a complaint to the Finnish Data Protection Ombudsman. The first step cannot be skipped: the ombudsman as a rule does not handle complaints from people who never contacted the controller. Below is a ready-made request text to copy and fill in with your own details.
Deleting an account and deleting data are different things
This is where to start, because most people stop at the first and consider the matter closed.
The “delete account” button removes you from what other users see. The data meanwhile stays with the controller for a period it set itself. Tinder describes its safety period explicitly: three months after an account is closed and a year after a ban, correspondence with support for six years, and transactional data for ten years under tax requirements.
Hiding a profile is even less like deleting it. On the Finnish Treffit24 a hidden profile simply stops being shown to others, while deleting a profile cannot be undone and the data is not recoverable.
A GDPR deletion request is a separate action with different consequences: it obliges the controller to answer within a deadline and to explain what exactly was deleted, what was kept, and on what basis.
So the correct sequence is: export your data first if the service allows it, then send a written request, and only then delete the account. After deletion there will be nothing left to request it from.
What exactly you can demand
There are several rights, and it is better to ask for what you need rather than for “everything”.
The right of access gives you a copy of your data plus information on the purposes of processing, the recipients and the retention periods. The most useful part here is the list of recipients: it is what shows where the data went on to.
The right to erasure applies, among other cases, where the data is no longer needed for the purposes it was collected for, or where you have withdrawn the consent the processing rested on. For dating services the second ground works almost always, because consent is the basis for processing special category data.
A separate provision covers anyone whose profile has spread across the web: if the controller made the data public, it has to take reasonable steps, including technical measures, to inform other controllers of your demand that links, copies and replications be erased.
In practice it makes sense to ask for both in one letter: first a copy of the data with the list of recipients, then erasure. Otherwise you delete the data without finding out where it had already gone.
A ready-made request text
Copy it and fill in your own details. You can write in Finnish, English or another language — the GDPR does not stipulate a language, but a Finnish service answers faster in Finnish or English.
Subject line: Pyyntö henkilötietojen poistamiseksi / GDPR data deletion request.
Text: “I hereby exercise my rights as a data subject under EU Regulation 2016/679. Account: [the email address or user name used at registration]. I request that you: 1) provide a copy of all personal data you process about me, including information on the purposes of processing, the categories of data, the recipients and the retention periods (Art. 15); 2) erase all my personal data (Art. 17), as I withdraw the consent on which the processing is based; 3) inform the other controllers to whom the data was disclosed of my request that links and copies be erased (Art. 17(2)). Please confirm receipt and provide a response within one month in accordance with Art. 12(3). Please send the response to [your email address].”
Send it to the address given in the service’s privacy policy under contacts or under the data protection officer. Large apps have a dedicated form — that works too, but take a screenshot of the submission.
Keep the date of sending: the month runs from it. That is the one thing that cannot be reconstructed later if you did not keep it.
Deadlines and what to do if they are missed
The deadlines are specific, and knowing them changes the tone of a correspondence by itself.
A reply is due without undue delay and in any case within one month of the request being received.
It can be extended by at most two months where the request is complex or where there are many requests. But the extension, with reasons, has to be notified within the first month. Silence for a month followed by a letter saying “we need more time” is a breach in itself.
If the controller refuses to act on the request, it has to state the reasons for the refusal without delay and at the latest within a month, and explain the possibility of lodging a complaint with a supervisory authority and of going to court.
The request is free. A charge may be made only for manifestly unfounded or excessive requests, in particular repetitive ones — and it is for the controller to justify that, not for you.
If a month has passed and nothing has arrived, send a short reminder referring to the first letter and its date. That is often enough: with many services requests get lost in support rather than being deliberately refused.
How to lodge a complaint in Finland
The second step, and there is no point taking it early.
The Finnish Data Protection Ombudsman states the condition plainly: contact the ombudsman only if the controller refused on grounds you consider insufficient. Cases where the controller was never contacted are as a rule not handled.
The form is submitted through the Turvalomake secure service of the state ICT centre. It can be filed anonymously by leaving the contact fields empty — but then you will get no answer either, so anonymity makes sense only if the aim is to report a breach rather than to resolve your own case.
Attach the correspondence: the first request with its date, the controller’s answer or confirmation that there was none, and the reminder if you sent one.
Since the beginning of 2024 the office has had a duty, within three months of a case being opened, either to issue a decision or to tell you its estimate of when it will decide. If it does neither, that can be complained about to the administrative court. But the target for actually handling a case is one year, and that is worth building into your expectations.
The office’s contact details: email tietosuoja(at)om.fi, postal address PL 800, 00531 Helsinki, telephone +358 29 566 6700.
If the profile has ended up in a search engine
A separate task, and it is dealt with in parallel rather than afterwards.
The erasure demand goes both to the site owner and to the search engine itself — two different recipients, and the search engine’s answer does not depend on the site’s.
The Finnish ombudsman states the procedure like this: contact the search engine directly demanding that the search result be removed, and separately contact the site’s publisher — a site usually has administrator details to which a data deletion request can be sent.
The deadlines are the same: one month, extendable to three where the request is complex.
It is important to understand the limit: removal from a search engine takes the page out of the results but does not delete the page itself. That is why both have to be contacted.
Whether your profile will end up in the index can be checked before you register — see what actually stays hidden.
What to look for in your data export
Most people request a copy of their data and, having received the archive, never open it: the files look unreadable. And the most useful part is precisely in there.
The first thing to find is the list of recipients. Under the right of access a controller has to state not only what it holds about you but who it disclosed it to. This is usually a separate section of the answer or a file named something like partners or third parties. If the recipients are described as “partners and service providers” with no names, that is grounds for a follow-up letter: a generalisation is not an answer here.
The second is retention periods by category. Not a general phrase but specifics: how long the profile is kept, how long the messages, how long the payment data. A discrepancy between what the policy on the site says and what was sent to you is information in itself.
The third is what you never entered. Exports regularly turn out to contain more than a person remembers: a history of profiles viewed, the time of every login, a list of devices, approximate coordinates. That is the behavioural layer, collected by itself.
The fourth is what was deleted. The archive often contains messages and photographs you had deleted from the interface. Deleting on screen and deleting in the database are different operations, and an export shows that plainly.
And a practical tip: save the archive before sending the erasure request. After deletion you will be unable to re-check anything or to cite its contents, and it is exactly that content you may need if the matter reaches a complaint.
Common refusals and how to answer them
Three formulations come up more often than others, and all three are dealt with in the same calm way.
“We are required to keep the data by law.” Sometimes true — transactional data, for instance, really is kept under tax requirements. But the obligation covers specific categories, not everything. Ask them to state which data exactly and under which provision, and to delete the rest.
“Your request is being processed”, with no date. The answer: cite Art. 12(3) and ask for either a response or a notification of extension with reasons, noting the date of your first letter.
“Delete your account in the settings.” The answer: deleting an account is not the same as erasing personal data, and you are exercising a right under Art. 17, not asking for a profile to be closed.
It is better to keep the tone of the correspondence businesslike and short. Emotion does not speed things up; a reference to a specific article with a date does, because it moves the letter out of the support enquiries category and into the category of requests the controller is accountable for.
What is collected about you at all, and why the law is stricter here than usual, is covered in what apps collect about you.
The sequence of steps and the deadlines
| Step | What to do | Deadline |
|---|---|---|
| 1. Export | Download your data if the service allows it | Before everything else |
| 2. Request | A written request under Art. 15 and 17, keep the date | Answer within 1 month |
| 3. Reminder | A short letter referring to the first one | After a month of silence |
| 4. Complaint | The Turvalomake form, attach the correspondence | Decision or estimate in 3 months |
| 5. Search engine | A separate demand to the search engine | The same one month |
| 6. Deleting the account | Only after the data has been received | Last of all |
The request is free. A charge is permissible only for manifestly unfounded or repetitive requests, and it is for the controller to justify it.
Frequently asked
How do I delete my data from a dating app?
Send the controller a written request citing Articles 15 and 17 of the GDPR: first a copy of the data with the list of recipients, then erasure. They have to answer within one month. Delete the account last — after deletion there will be nothing left to request it from. A ready-made request text is on this page.
Does deleting my account delete my data?
No. The “delete account” button removes you from what other users see, but the data stays with the controller for the period it has set. Tinder, for example, deletes profile data three months after an account is closed, keeps correspondence with support for six years, and transactional data for ten years.
How long does the controller have to answer?
One month from receipt of the request. It can be extended by at most two months where the request is complex or where there are many requests, but the extension, with reasons, has to be notified within the first month. If refused, the reasons and your right to complain have to be given within the same period.
How much does filing a request cost?
Nothing. A request and a complaint to the ombudsman are free. A controller may charge only for manifestly unfounded or excessive requests, in particular repetitive ones — and it is for the controller to justify that, not for you.
Where do I complain if the controller stays silent or refuses?
To the Finnish Data Protection Ombudsman, but only after contacting the controller itself — cases without that are as a rule not handled. The form is submitted through the Turvalomake secure service; it can be anonymous, but then there will be no answer. Attach the correspondence with dates.
What do I do if my profile is visible in a search engine?
Contact both recipients in parallel: the search engine, demanding that the search result be removed, and the site owner, with a data deletion request. Removal from a search engine takes the page out of the results but does not delete the page itself. The deadlines are the same — one month.
What should I look at in the data export I receive?
Four things: the list of recipients (if they are described as “partners and service providers” with no names, that is grounds for a follow-up letter), retention periods by category, data you never entered (viewing history, logins, devices, coordinates), and things you deleted from the interface that remained in the database. Save the archive before sending the erasure request.
How do I answer “we are required to keep the data by law”?
Ask them to state which categories of data exactly and under which provision. A retention obligation covers specific categories — transactional data under tax requirements, for instance — not everything indiscriminately. The rest is to be erased.
What language should the request be written in?
Any: the GDPR does not stipulate a language. In practice a Finnish service answers faster in Finnish or English, and an international one in English. Another language is formally permissible but raises the chance that the letter will take longer to process.
Do I have to attach a copy of an identity document to the request?
As a rule no. A controller may ask for confirmation of identity if it has reasonable doubts, but by default writing from the email address the account is registered to is enough. A demand for a passport copy with no explanation is worth challenging rather than complying with automatically.
What do I do if the service has shut down or no longer answers?
Contact the Data Protection Ombudsman, attaching evidence of the attempt to make contact: the letter with its date and confirmation of non-delivery or of no answer. The duty to respond does not disappear because a service stopped being developed. If the company has been wound up, the supervisory authority will say what happens next.
Sources
- GDPR, Art. 12, 15, 17 — deadlines, access, erasure
- Tietosuoja.fi: the right of access and deadlines
- Tietosuoja.fi: notification to the ombudsman — the controller first
- Tietosuoja.fi: form for reporting a fault — Turvalomake, can be anonymous
- Tietosuoja.fi: search engines
- Tinder: retention periods after deletion
- Suomi24 / Treffit24: description of data processing
2586 words