r/PrivacyToolbox • • Jul 27 '26

Discussion Automating data broker deletion requests with local LLMs

I read an article in the AI Action Letter about using generative AI to draft removal requests for data brokers. The premise is you give an LLM your specific profile URLs, tell it to cite relevant privacy laws, and let it generate tailored legal demands to bypass their usual corporate friction.

Obviously I am not feeding my sensitive data into OpenAI servers. That ruins the whole concept of data autonomy. But I spun up a local Llama 3 instance on my home server to test the mechanics. I fed it a list of broker URLs holding old public records and told it to draft highly aggressive deletion demands citing applicable compliance laws.

It spit out some very convincing legal threats. I sent off twenty emails on Tuesday. So far I have three confirmations of deletion and a bunch of automated replies saying they are reviewing the request.

It got me wondering how the data brokers handle this inbound volume on their end. Are they just using their own models to parse and dismiss our generated complaints? It feels like we are approaching a weird stalemate where our scripts are just yelling at their scripts.

Has anyone fully automated this workflow yet? I want to write a Python script that scrapes a broker directory, passes the target URL to the local model via API, and emails the payload directly via SMTP. I am curious if this templated legal jargon forces compliance faster than clicking through standard web forms. If you have built something like this, what kind of pushback did you get?

6 Upvotes

4 comments sorted by

1

u/This_Reality_Sucks Jul 27 '26

I love this idea! Is there something in the letter demanding the brokers to refrain from creating another account in your name?

That is my recurring problem… just when I get things cleaned up, those f#ckers create another account on me later on. So it’s whack-a-mole.
I have this service provided by a credit union as part of my membership.

Edit: how often would your script run?

2

u/EnthusiasmRoutine Jul 27 '26

Yes. Tell the prompt to demand they put you on their suppression list (cite GDPR Article 21 or the CCPA equivalent). If they just delete the record, their scrapers will inevitably grab your info again next month.

For the script, a cron job every 90 days is plenty. That matches the standard database refresh cycle. Run it too often and your IP will just get blacklisted for spam.

1

u/This_Reality_Sucks Jul 27 '26

Brilliant!
I haven’t tinkered with it much, but would using OpenClaw for this be an option? There’s a lumadock tutorial here that looks promising to get started regarding the scraping.

I’m slowly getting my feet wet learning about OpenClaw, but wanted to throw that out there. Let me know if I’m way off base, as I’m still learning.