← Blog · Sunday 9th August 2026 · How-to · 27 min read

The GDPR requests that move a dating app ban - access first, erasure last

The access request is the privacy route with reinstatements on the public record. The erasure request removes no ban record, and it destroys the evidence and the login your appeal runs on. Both letters, both clocks, and the order to send them in.

Stacks of old paper files
The short version
Access first. An Article 15 request makes them show what flagged you, and it is the privacy route with reinstatements on the public record: in the Irish Data Protection Commission’s own published cases, banned Tinder users whose access requests had been ignored complained to their data protection authority, and after the DPC took it up the company ran a fresh review and reinstated the account.
Erasure removes no ban record. Tinder keeps enforcement records for as long as it considers necessary plus a one-year safety window; Hinge up to two years; Bumble up to fifteen. That retention is lawful, and it survives your deletion request.
Erasure last, if ever. It deletes the evidence your other routes are built on, and it can kill the login Tinder’s Appeals Center runs on. Both requests carry a one-month clock in Europe, and any refusal must name its legal ground.

Every other route on this site asks the platform to change its mind. The privacy routes are different: they work on the file rather than the decision. That is genuinely powerful, and it is also where most advice about dating app bans goes wrong, because it reaches for the wrong one of the two.

There are two requests, and they do opposite things. An access request (GDPR Article 15, or its Californian and US state cousins) forces the company to hand over the personal data it holds about you. An erasure request (Article 17) asks the company to delete it. Advice columns love the second one, because deletion sounds like a cheat code: no record, no ban. It is not, and the next two sections set out exactly why, using the platforms’ own published retention periods.

The order that works is the other way round. Access first, because seeing the file is what makes every other route sharper and is the request with documented reinstatements behind it. Erasure last, if ever, because it is the one move that can destroy your own case. This guide covers the mechanism in plain English, what the platforms actually hold and for how long, both copy-paste letters, the clocks in Europe and the United States, the regulator complaint that follows an ignored access request, the routes to run in parallel while you wait, and the honest limits of all of it.

In this guide
  1. Access first: the privacy route with reinstatements on the record
  2. What an erasure request does not do to your ban record
  3. Article 15 in plain English: make them show what flagged you
  4. The access-request letter
  5. The clocks: one month in Europe, forty-five days in the States
  6. When they ignore it: the ICO, your DPA and the Irish DPC
  7. What to run while the access clock ticks
  8. Article 17 in plain English, and when erasure is safe to send
  9. The fight you should expect: the safety exemption
  10. The copy-paste erasure letter
  11. What comes back: the three reply scenarios
  12. The Californian parallel: CCPA §1798.105
  13. What erasure honestly does for a future fresh start
  14. What not to do
  15. Is it worth filing? The honest answer
  16. Questions people actually ask

Access first: the privacy route with reinstatements on the record

Understand what each rung of the ladder actually aims at, and the sequencing stops looking like paperwork and starts looking like strategy. A platform appeal asks a moderator to re-read a decision. The Match Group escalation desk asks a second human to look at the same file. A DSA Article 21 dispute asks a certified outside body to audit the process that produced the decision. A BBB complaint puts your version and theirs on a public record for three years. An access request does something none of them do: it makes the company show you what it holds.

That is the request with reinstatements behind it. The Irish Data Protection Commission - the lead regulator for the European Match Group entity - publishes case studies of complaints it has handled. Among them are banned Tinder users whose access requests had gone unanswered. They complained to their own data protection authority, the matter reached the DPC, and after the DPC’s correspondence the company, in the regulator’s words, conducted a fresh review of the account and reinstated it. Read that mechanism carefully, because the detail is the point: nobody ordered a reinstatement. A regulator asked about an ignored data request, a human being at the company looked at the account again, and the account came back. That is the only privacy route with that outcome on the record, and it starts with an access request - not a deletion request.

Keep it in proportion, though. The channel that reverses bans at scale is still the platform’s own appeal, and the platforms publish the numbers themselves in their EU Digital Services Act transparency reporting. These are theirs, not ours, and they are worth reading before you decide what to spend your one shot on.

Platform (2025) Appeals Reversed Rate Median
Match Group, all EU brands 191,929 61,109 31.8% 17h 36m
Hinge 86,650 31,251 36.1% 19h
Tinder, account bans 56,991 12,058 21.2% 19h
OkCupid 4,723 1,685 35.7% 27h
Plenty of Fish 354 123 34.7% 4h
Bumble, all appeals 41,982 9,065 21.6% 61 min
Bumble, account suspensions only 26,318 2,419 9.2% about 4h
Badoo 127,648 9,422 7.4% 2h 55m
Grindr, global 840,723 91,795 10.9% 281h

Two things fall out of that table. The first is timing, and it kills a number you will see repeated all over this subject: nobody publishes a turnaround, and the honest sentence is most decisions land within a day, some take weeks, and no app promises a time. Bumble’s median is 61 minutes; Grindr’s is 281 hours, which is nearly twelve days, and that is the median rather than the tail. The second is that roughly one appeal in three gets reversed at the Match Group brands. Theirs, not ours. We publish our own numbers separately, including the zeros.

There is one more figure worth carrying into your case. Of Tinder’s 2,169,598 EU account terminations in 2025, 94% were scam, fraud and inauthentic-account sweeps, overwhelmingly automated. If you are a real person caught in an automated sweep, you are in the most reversible category there is, and the job of your file is to prove personhood rather than to argue morality. The conduct categories - harassment, harm, minors - were human-decided, and those are the cases we decline at intake.

What an erasure request does not do to your ban record

This is the part most guides get wrong, and it is worth being blunt: an erasure request does not delete your ban record. If you have read the opposite argument somewhere - that deleting the data leaves the fingerprinting machine nothing to match against, so the ban quietly stops working - it is a tidy theory that the platforms’ own published retention policies contradict in writing.

What they say they keep, in their own privacy documentation:

None of that is a loophole they are sneaking through. Retention for the purpose of keeping banned users out is exactly the kind of processing regulators have accepted as capable of being lawful, and a refusal that names legitimate interests or the defence of legal claims and scopes it properly is a compliant refusal, not a scandal. You can argue about the scope - and further down we show you how - but you should not send the letter expecting the ban record itself to disappear.

Now the part that actually costs you money, because it is not merely that erasure fails to help. Sent early, it does damage.

So the record is not the target. The file is. Which brings us to the request that actually opens it.

Article 15 in plain English: make them show what flagged you

Article 15 - the subject access request - entitles you to a copy of the personal data a company holds about you, plus the purposes it is processed for, the categories involved, who it is shared with, and how long it will be retained. It costs you nothing but an email and some patience, it runs on the same one-month statutory clock as erasure, and it does four jobs no other route can:

If you were banned on Tinder, check what you already hold before you write anything. The case card inside the Appeals Center shows more than most people notice: a Case ID, the policy section cited, the violation type, a Flagged by line distinguishing automated detection from user reports from Tinder’s own review, and a Reviewed by line. Screenshot all of it. A “Flagged by: automated” card, held next to the fact that 94% of terminations were automated sweeps, is the spine of a personhood case - and it tells your access request what to ask for by name.

One caveat from observed practice: access packages from dating platforms are generous with profile data and thin on moderation data. The ban reason and the enforcement notes are often withheld or summarised, typically citing other users’ privacy or the integrity of the moderation systems. Do not treat that as a dead end. A written statement that moderation records exist but will not be shown to you is itself useful: it confirms the category exists, dates it, and gives your escalation something concrete to be about.

Worth knowing

The company is allowed to verify your identity before acting, and in the UK the clock now runs from the moment they receive the identification they asked for. So identify the account precisely up front - the email, the number, the approximate signup date - and send from the address on the account. If they ask for reasonable proof of identity, provide it promptly and note the date; a verification request that arrives late and vague is a delay tactic wearing a compliance costume, and the timeline you are keeping will say so. On Hinge, incidentally, a request for identification during an appeal is a good sign rather than a bad one: it means the file is being handled by someone.

The access-request letter

The access request needs no artistry. It needs the statute, the account, and a list of categories specific enough that a generic export does not answer it. Send it to the privacy contact named in the app’s privacy policy, from the email address on the account, and keep proof of when it went.

Letter one - the access request

Subject: Subject access request under GDPR Article 15 [or: UK GDPR / CCPA §1798.110] - [your account email]

“I am making a subject access request under Article 15 GDPR [adjust for UK GDPR or your state law]. I am the holder of the account registered to [email] / [phone number], created around [month, year] and closed or suspended by you on or around [date].

Please provide a copy of all personal data you hold concerning me, including but not limited to: profile data and photographs; message content and metadata; device, network and advertising identifiers; location data; payment and subscription records; identity or selfie verification data; reports made about my account; and moderation and enforcement records, including the reason recorded for the action taken against my account, whether it was flagged by automated means, by user reports or by human review, and any case or reference number attached to it.

Please also confirm, for each category: the purposes of processing, the categories of recipients, and the retention period applied or the criteria used to set it.

If any data is withheld, please identify the category withheld and the specific exemption relied on. I look forward to your response within one calendar month. [Name]”

Note the two clauses doing the heavy lifting, because they are what turn a data dump into leverage. Asking whether the action was flagged by automated means engages the platform’s own moderation taxonomy rather than yours. Asking it to name the exemption for anything withheld means a refusal to show moderation notes still hands you a dated, written admission that moderation notes exist. Send it, diarise the deadline, and get on with the routes in the parallel section while you wait.

The clocks: one month in Europe, forty-five days in the States

Both privacy requests run on statutory deadlines rather than on the company’s goodwill. That is the whole reason they are worth sending: a missed deadline is verifiable from a calendar, with no judgment call left for anyone to make.

Where you are The deadline The extension What else to know
EU (GDPR) One calendar month Up to two further months, complex or numerous requests only You must be told about the extension, with reasons, inside the first month
UK (UK GDPR) One calendar month Up to two further months The clock runs from receipt of any identification they reasonably asked for
California (CCPA) 45 days A further 45 days with notice Receipt must be acknowledged within 10 business days
Virginia, Colorado, Connecticut, Texas 45 days A further 45 days Then a 60-day internal appeal, and then the state Attorney General

Practicalities that decide whether the clock works for you:

When they ignore it: the ICO, your DPA and the Irish DPC

A missed deadline is not the end of the route; it is the point where the route gets interesting. Where the complaint goes depends on where you are:

Build the complaint out of documents, not adjectives. The strongest version is almost clerical: request sent on [date]; identity verified on [date]; statutory deadline of [date]; response received on [date], or not at all; response failed to state retention periods or to name an exemption for what was withheld. Attach everything. What you are handing the regulator is a completed compliance test with the answers already marked wrong, and the less editorialising you do, the better it reads.

Be precise about what this can and cannot produce, because this is the one place on the site where a privacy filing has reinstatements behind it and we would rather you understood the mechanism than got excited about the headline. Regulators do not reinstate dating profiles. They have no power to, they say so, and they move in months rather than weeks. What happened in the DPC’s published cases is that a regulator’s correspondence about an ignored access request caused the company to look at the account again, and on looking again it reinstated. That is a second human read, obtained through a door the company did not choose. It is worth having. It is not a promise, and nobody can make it one.

One boundary worth marking, because it is where people waste a filing: this is the escalation for an ignored or defective access request. It is not an appeal against a lawful erasure refusal. A company that refuses to delete your ban record, names legitimate interests or the defence of legal claims, and scopes the refusal to the records it needs is not committing a breach for a regulator to find.

What to run while the access clock ticks

A month is a long time to sit still, and nothing about a pending data request requires it. These run in parallel, and none of them depends on the privacy routes.

The platform’s own appeal

The channel that reverses at scale, and the one where the details are per app rather than generic. Six months from the action is the published outside limit on Tinder, Bumble, Badoo, OkCupid, Match and Plenty of Fish; Hinge, Grindr and Feeld publish no window at all. Sooner is better everywhere. On Tinder it is a one-tap submission inside the Appeals Center with no statement box, so the craft goes into decoding the case card and into the routes that do take words. On Hinge it is the in-app Appeal button with a statement box, and emails to staff are not processed and can delay the queue. On Bumble and Badoo it is the form inside the block notification, or a “Dispute my block” ticket. On OkCupid, Plenty of Fish and Match it is one shared web form, one submission, and on OkCupid silence is the denial, since it replies only when it reverses. Grindr uses a web wizard with a hard 1,000-character cap and one file under 50MB. The appeal-writing guide covers the words; the ladder covers the order.

The Match Group escalation desk

Less well known than it should be, and free: Match Group runs a social support escalation desk at matchgroup-socialsupport.com that will take a second human look across any of its brands - Tinder, Hinge, OkCupid, Plenty of Fish, Match. You will need a reference from an existing customer-care ticket, so raise one first if you have not. It is one look, not a standing right of appeal, so it is worth spending after the in-app appeal rather than before.

The EU certified dispute body, named correctly

Under DSA Article 21, EU users can take a moderation decision to a certified out-of-court dispute body. Name the body rather than the category, because coverage differs and most guides get this wrong:

The decisions are not binding on the platform, and the platforms report implementing them unevenly - Tinder 62%, Hinge 72% in 2025. The full Article 21 guide has the mechanics, and the European Commission’s own page on out-of-court dispute settlement explains the framework.

The money, and the public record

Your paid subscription is a separate fight with separate deadlines - store refunds from your own Apple or Google account, 14 days on Tinder web and Hinge’s Stripe purchases, the EU and UK withdrawal right, three business days in twelve US states, Bumble’s 6-day weekly and 14-day monthly rule. It is all in the money guide, and it is the reason erasure waits.

The BBB is worth being honest about. US and Canadian residents can file one complaint per business per 24 months; the company gets 14 days to answer; the complaint and the answer stay visible for three years. What it does is build a public, dated record. What it does not do is lift bans - Match Group answers ban complaints with a template stating that Tinder is unable to process appeal requests submitted through the BBB portal, and plenty of complaints against other apps go unanswered entirely. File it if you want the record. Do not file it expecting a reversal.

Footnote, and only that: your State Attorney General logs patterns. Washington, Colorado, Texas and California all state in their own words that they do not investigate or resolve individual complaints. We will file it if you want your case in the pattern data. Nobody should sell it to you as a lever.

Article 17 in plain English, and when erasure is safe to send

GDPR Article 17 (EU), the UK GDPR’s equivalent, and CCPA §1798.105 (California) give you the right to request deletion of personal data a company holds about you. That right is real and worth exercising. It is simply not an unban mechanism, and the sequencing matters more than the drafting.

Article 17 is not unconditional. You need at least one of its grounds. In plain English, the grounds most relevant to a closed account are:

Who can use it? The GDPR protects people in the EU and the UK GDPR mirrors it for the UK. You do not need citizenship - being in the jurisdiction is the operative fact. For most EU users of Match Group apps (Tinder, Hinge, OkCupid and Plenty of Fish; note that Bumble is a separate company), the responsible entity sits in Ireland, which is why the Irish DPC keeps appearing above. Americans outside California have no comparable federal right, though the growing patchwork of state privacy laws borrows the same shape.

When erasure is safe to send

Send it when the appeal has been decided and cannot be refiled; when the Match Group escalation look has been used or does not apply; when any Article 21 case is closed or unavailable for your app; when the refund fight is settled; when the access response is in your hands; and when you have your own copies of everything - screenshots, receipts, emails, the case card - saved somewhere the platform cannot reach. That is the whole checklist. Every item on it is something erasure can take away from you if you send the letter early.

The fight you should expect: the safety exemption

Erasure is not absolute, and you should walk in expecting the fight rather than being disappointed by it. Companies can refuse where retention is necessary for legal obligations or the defence of legal claims, and platforms additionally argue that keeping ban records is necessary to keep banned users out. Expect a refusal on those grounds, and expect it to be at least partly correct. Two things still matter about it: it must be specific (a compliant refusal names its legal ground; a template brush-off with no ground at all is itself a compliance failure), and the scope is arguable even where the principle is not.

What they will argue

The refusal, when it comes, usually stands on some combination of three legs. First, defence of legal claims: enforcement records might be needed if the ban is ever litigated. Second, legitimate interests: the platform’s real interest in keeping removed users removed, framed as protecting the rest of the user base, and described in exactly those terms in their privacy policies alongside the retention periods quoted earlier. Third, a soft appeal to everyone’s safety that is more atmosphere than argument: nobody wants to be the company that deleted a record and readmitted someone dangerous. None of these legs is fake. That is why the counter-argument is not “safety does not matter” - it is the next section.

How to argue proportionality back

The GDPR’s principles of data minimisation and storage limitation say retention must be limited to what is necessary for the stated purpose, and necessity is where the platform’s position is weakest. Run the safety rationale to its logical end and ask what it actually requires:

Set your expectations at the right height. On these arguments the ban record itself will usually survive. What you are realistically pruning is everything around it: the photographs, the messages, the identifiers that had nothing to do with keeping you off the service. That is a worthwhile outcome for its own sake, and it is not an unban.

From the case desk

The refusal letters users share with us have a family resemblance: the same two paragraphs, the statute named in general terms, no per-category reasoning, no retention period as applied to the account in front of them. That sameness is not a defeat - it is your best exhibit. A regulator reading a specific, dated, per-category request next to a boilerplate refusal does not need persuading about which party engaged with the law.

The copy-paste erasure letter

What follows is a template - fill the brackets, delete what does not apply, and resist the urge to decorate. The best erasure requests are boring: no ban story, no grievance, no threats. This letter is not an appeal (that is a different document with different rules); it is a statutory request and should read like one. Send it to the privacy contact in the app’s privacy policy, from the email on the account, after the checklist above is satisfied and your access response is in hand.

Letter two - the erasure request

Subject: Erasure request under GDPR Article 17 [or: UK GDPR Article 17 / CCPA §1798.105] - [your account email]

“I am writing to exercise my right to erasure under Article 17 GDPR [adjust for UK GDPR / CCPA]. I am the holder of the account registered to [email] / [phone number], created around [month, year].

Please erase all personal data you hold concerning me, including but not limited to: profile data and photographs; messages; device, network and advertising identifiers; location data; payment and verification data; and any data shared with or held by affiliated services. [If you received an Article 15 response: This includes each category of data identified in your access response of [date].]

My grounds are that the data is no longer necessary for the purpose for which it was collected, my account having been closed by you on or around [date]; further and in the alternative, I object to any continued processing based on legitimate interests. If you retain any category on safety, legal-claims or legitimate-interest grounds, please state the specific legal basis for that category and the retention period applied to it, and confirm that the remaining categories have been erased.

Please confirm completion, or provide your response in the terms above, within one calendar month of this request. I reserve the right to complain to the supervisory authority. [Name]”

Note what the letter does, because every sentence is carrying weight. It names the statute. It identifies the account precisely so verification cannot eat the clock. It includes affiliated services, which is the Match Group cross-brand question in one phrase, since one company operates Tinder, Hinge, OkCupid and Plenty of Fish. It states grounds rather than feelings. It concedes, deliberately, that some categories may lawfully be retained - and then makes the company say which, and for how long, and confirm that the rest is gone. That concession is not softness; it is what stops the reply being a single sentence about safety that covers the whole account. And it reserves the regulator without threatening anybody.

What comes back: the three reply scenarios

Within the month, or the lawful extension, one of three things arrives. Each has a correct next move.

Scenario What it looks like Your move
Full compliance Written confirmation that your data has been erased Get the confirmation to cover affiliated services explicitly; archive it
Partial compliance Profile data deleted; enforcement records retained, with or without stated grounds The expected outcome. Mine the specification; challenge categories kept without a ground
Boilerplate or silence Two paragraphs with no per-category grounds - or nothing at all past the deadline Regulator complaint, attaching your request, their reply or its absence, and the dates

They comply fully: rare on a banned account, and worth confirming rather than assuming. Ask one follow-up question in writing: does the confirmation cover data held by affiliated services? A yes closes the Match Group loop. A hedge tells you what to ask about next. Note that full erasure of everything erasable still leaves the enforcement record where the company has told you it is keeping it.

They comply partially: this is the normal outcome, and it is more valuable than it looks. The written specification of what they kept and why is a map of what the ban actually rests on, and no appeal rejection ever gives you that. Read it against the proportionality arguments above: any category retained without a stated ground or period is a specific, nameable defect. And the specification feeds the routes that are still open - a DSA Article 21 case statement built on the platform’s own written retention position is a different animal from one built on guesswork.

They send boilerplate or nothing: complain to the regulator, attaching your request and their response. Regulators measure companies in deadlines and specificity, both of which you now have in writing. Silence is the strongest version of this branch, not the weakest, because there is no judgment call in a missed statutory deadline. On The Advocate, we build that regulator complaint as standard.

The Californian parallel: CCPA §1798.105

Californians get the domestic cousin of all this. The CCPA’s §1798.110 gives you the right to know what personal information a business has collected about you, and §1798.105 the right to request deletion. The mechanics rhyme with the European version: submit through the business’s designated privacy channel, verify your identity, and get a response inside the statutory window (the current deadlines and your full set of rights are laid out on the California Attorney General’s CCPA page). The sequencing rule is identical: ask what they hold first, ask for deletion last.

The exemption fight rhymes too. The CCPA lets businesses keep data needed to detect security incidents and protect against malicious, deceptive, fraudulent or illegal activity, which is where a ban-record retention argument pitches its tent, just as the safety exemption does in Europe. The same proportionality logic applies even though the statutory language differs: security purposes justify retaining what the security purpose needs, category by category, not the whole account in amber. Demand the same per-category specificity in a refusal.

Where the parallel weakens is enforcement. There is no Californian equivalent of filing an individual ICO complaint and having a caseworker assess your file; enforcement runs through the Attorney General and the state privacy agency, and a complaint joins the pile that informs their priorities rather than starting a case about you. Users in Virginia, Colorado, Connecticut and Texas have a better-shaped route: 45 days, a 45-day extension, then a 60-day internal appeal that the company must answer in writing, and only then the state AG. That internal appeal is the useful part, because it puts a second person inside the company on your file. Pair any of it with the money routes, which are fully available to Americans and, unlike the complaint routes, actually end in a number in your account.

What erasure honestly does for a future fresh start

Time for the section other guides write dishonestly. Search results around this topic are full of the implication that erasure is a legal cheat code: delete the record, stroll back in. That is not what this is, and pretending otherwise would put you in genuine trouble, so let us be exact about the boundary.

What erasure is not: a licence to create a new account while banned. The ban is a term of your contract with the platform, and it survives regardless of what data they hold - as the retention periods at the top of this guide make plain, the enforcement record is the thing they keep. A new account created to get around a ban breaches the terms on day one, whatever the state of their database. Worse, attempted resets are precisely what the modern enforcement stack exists to catch - the reset era is dying for exactly the reasons the device-ban piece lays out - and a caught evasion attempt can poison legitimate appeals that were still open. We do not help with evasion, and this article is not a workaround dressed in statute.

What erasure honestly is: record hygiene, and a right worth exercising for its own sake. Two real things it buys you. First, it ends the platform’s ongoing hold on your photographs, messages and identifiers - data you have every reason to want out of a company you no longer have a relationship with, ban or no ban. Second, it forces the retention rationale into writing, which is worth having on file even after the other routes have closed. What it does not buy you is a clean slate at the platform, because the piece of the file that defines you as banned is the piece they have told you, in advance and in public, that they are keeping.

Which is why the sequencing rule is the single most important sentence in this guide: erasure goes last. An appeal asks the platform to re-examine your account; an erasure request asks it to destroy the thing being examined. Run the appeal first. Most decisions land within a day, some take weeks, and no app promises a time - but the median at every Match Group brand is under a day and a half, so waiting for it costs you very little. Then the escalation desk, then the EU body if your app is covered, then the money, then the letter above. If you are unsure where you are in that sequence, the checker will place you.

What not to do

The failure modes of this route are mostly self-inflicted, and every one of them is avoidable:

The honest bit

Nothing on this page guarantees anything, and the decision always belongs to the platform. We can tell you how often the apps reverse appeals, because they publish it and we have quoted it above with their names on it. We cannot tell you how often they comply with erasure requests, because no reliable public numbers exist and we will not invent them. What we can tell you is which outcomes are possible, which are likely, and what each one is worth - and that a route with a statutory clock and a regulator behind it is a fundamentally different proposition from shouting into a support form.

Is a GDPR request against a dating app worth filing?

The access request: almost always. It costs one email, the clock is statutory, it is the only way to see what actually flagged you, and when it is ignored the escalation behind it is the one privacy route with reinstatements on the public record. Send it early, and send it even if you also intend to do nothing else.

The erasure request: yes, at the end, for what it honestly is. Expect the enforcement record to survive. Value it for the rest of the file coming down, and for the written retention position it forces. Do not value it as an unban, and do not let it near a live appeal.

If you would rather not run the sequence yourself, this is what we do. The case desk builds every route: the access request, the appeal your app actually accepts, the Match Group escalation statement, the EU pack where a certified body covers your app, the money claims, and at the end the erasure letter and, on The Advocate, the regulator complaint. We file every route in your name - Tinder’s Appeals Center runs on your own login and Hinge accepts appeals only in-app, so nobody else can lawfully submit those - and we file the rest in your name. We never ask for your password. Filed within 48 hours, 24 on The Advocate, or your money back, and we file anyway. Intake first, pay after; if we do not take the case, you are refunded. Start here and we will tell you at intake whether your case is one we take.

Questions people actually ask

Should I send an access request or an erasure request first?

Access, every time. It shows you what the platform holds, forces retention periods into writing, and is the request whose escalation has produced reinstatements in the Irish DPC’s published cases. An erasure request sent first deletes the evidence the access request would have given you, and can take the login your appeal runs on with it.

Does a GDPR erasure request remove a Tinder ban?

No, and it does not remove the ban record either. Tinder’s published position is that enforcement records are kept for as long as necessary plus a safety window after closure, and that retention can be lawful. File the erasure request for what it reliably produces - the rest of your data deleted and a written retention position - not for a reversal.

Has a data request ever actually got anyone back in?

Indirectly, and it is documented. In the Irish Data Protection Commission’s published cases, banned Tinder users whose access requests went unanswered complained to their data protection authority; after the DPC’s correspondence the company carried out a fresh review of the account and reinstated it. The regulator did not order reinstatement and could not have. What it produced was a second human look. That is worth having and it is not a promise.

Can Tinder refuse to delete my data?

Partially, yes. Erasure has exemptions, and a refusal citing the defence of legal claims or safety-adjacent legitimate interests is the expected move, often correctly. What it cannot lawfully do is refuse vaguely: a compliant refusal states its legal ground, and you have asked for grounds and retention periods per category. A refusal that skips that is the compliance failure you take to the regulator.

How long does a GDPR request take?

One calendar month from the request, in practice from identity verification, extendable by up to two further months for genuinely complex cases - and they must tell you about any extension, with reasons, inside the first month. California runs 45 days plus 45, with receipt acknowledged inside 10 business days. Escalation to a regulator afterwards runs on the regulator’s timetable, which is months.

How long does the appeal itself take?

Most decisions land within a day. Some take weeks. No app promises a time, and neither do we. The medians the platforms published for 2025 run from 61 minutes at Bumble to 281 hours at Grindr, and the tail is longer than the median everywhere.

Do I need a lawyer to send one of these?

No. Both rights are designed to be exercised by individuals, the letters above cover the mechanics, and regulator complaints are likewise built for unrepresented people. A lawyer becomes relevant only if you are contemplating actual litigation, which for most banned users is disproportionate to what is at stake.

Does deleting my dating app account delete my data?

No, and this is the most common confusion in the whole area. Account deletion is a product feature; platforms describe retaining categories of data afterwards, sometimes for years. Only the statutory request obliges a response about what is held and starts a clock. You can send an access request even if you deleted the account years ago.

Can I send an erasure request if I live in the US?

The GDPR will not apply to you, but Californians have CCPA §1798.105, and Virginia, Colorado, Connecticut and Texas among others have their own deletion and access rights with a 45-day clock and a 60-day internal appeal behind it. If no state law applies, your leverage lives in the platform’s own appeal and the refund routes. The BBB and your State Attorney General build a record; neither lifts a ban.

Will sending an erasure request make my ban worse or hurt my appeal?

It cannot deepen a ban - you are exercising a legal right, and retaliating against that would be its own problem for the platform. The genuine risk is sequencing, and it is real: erasure can moot a live appeal, destroy the evidence a refund claim or a DSA case needs, and remove the login Tinder’s Appeals Center requires. Appeal first. Erase last.

What happens if the platform just ignores my request?

Silence past the statutory deadline is the cleanest escalation you can be handed: a missed deadline is verifiable from a calendar, with no judgment call for a regulator to weigh. Complain to the ICO or your national data protection authority with the dated request attached, and let the absence of any response speak for you.

AppealMyBan

Written by the case desk at AppealMyBan - the same desk that drafts the appeals. Banned for years, built this out of the frustration, publishes real numbers including the zeros.

Keep reading

The Advocate builds the access request, the escalation and the regulator complaint that follows an ignored one. See the tiers →