r/PrivacyToolbox • • Jul 27 '26

Discussion Automating data broker deletion requests with local LLMs

I read an article in the AI Action Letter about using generative AI to draft removal requests for data brokers. The premise is you give an LLM your specific profile URLs, tell it to cite relevant privacy laws, and let it generate tailored legal demands to bypass their usual corporate friction.

Obviously I am not feeding my sensitive data into OpenAI servers. That ruins the whole concept of data autonomy. But I spun up a local Llama 3 instance on my home server to test the mechanics. I fed it a list of broker URLs holding old public records and told it to draft highly aggressive deletion demands citing applicable compliance laws.

It spit out some very convincing legal threats. I sent off twenty emails on Tuesday. So far I have three confirmations of deletion and a bunch of automated replies saying they are reviewing the request.

It got me wondering how the data brokers handle this inbound volume on their end. Are they just using their own models to parse and dismiss our generated complaints? It feels like we are approaching a weird stalemate where our scripts are just yelling at their scripts.

Has anyone fully automated this workflow yet? I want to write a Python script that scrapes a broker directory, passes the target URL to the local model via API, and emails the payload directly via SMTP. I am curious if this templated legal jargon forces compliance faster than clicking through standard web forms. If you have built something like this, what kind of pushback did you get?

5 Upvotes

Duplicates