Skip to main content
FixMyTech

How to Delete an Old Account You Cannot Log Into

By

Published

7 min read

Share

Short answer

Try a password reset first, since many old accounts only ever needed an email address. If that fails, send a deletion request citing data-protection law to the company's privacy or support address — UK and EU residents have a legal right to erasure that does not require you to log in. Expect a response within about a month.

On this page

The usual reason for wanting this is a forum from 2014, a shopping site that keeps emailing, or a service you signed up to with an email address you no longer have. The account holds an old password you may have reused and possibly a card number, and there is no way to log in and press Delete.

There is a route that does not require logging in. It is slower, it is written down in law in the UK and EU, and it works more often than people expect.

Try the easy things first

Most “cannot log in” accounts are not actually locked. Spend ten minutes here before the formal route.

Request a password reset. Old accounts frequently predate 2FA entirely, so if you can still receive mail at the registered address, the reset link is all you need.

Try every email address you have used. The sign-up may be under an address you have forgotten about. The reset form telling you an address is not recognised is itself useful information.

Check for sign-in with Google, Apple or Facebook. Many accounts have no password at all. Your Google account lists these under Security → your connections to third-party apps; Apple lists them under your name → Sign-In & Security → Sign in with Apple. If the service is there, signing in that way works immediately.

Look for a saved password. Your password manager or browser may hold a login you forgot you had, from a laptop you no longer use.

If any of these works, delete the account from inside it and stop here. Checking which services still have access to your main account is worth doing at the same time.

The deletion request that does not need a login

If you are in the UK or EU, data-protection law gives you a right to erasure. It applies to any company processing your personal data, it is not conditional on holding a working login, and most companies large enough to have a privacy team will action it.

The request itself is short. Long emails do worse, because they take longer to route to the right person.

Send it to the privacy address if there is one, otherwise support. Look for privacy@, dpo@, or the contact details in the privacy policy, since companies subject to this are generally required to publish one.

A workable version:

Subject: Data deletion request — [your email address]

I am requesting erasure of my personal data and deletion of my
account under the UK GDPR / GDPR.

Account email: [address used]
Username, if known: [username]
Approximate sign-up date: [year]

I no longer have access to this account and cannot sign in.
Please confirm in writing once the data has been deleted.

Three things that improve the outcome:

  • Send it from the registered email address if you still have it. That is the easiest verification they can do, and it removes their main reason to stall.
  • Give identifying details, not just a demand. An order number, a username, the year you joined, the last four digits of a card used.
  • Keep it factual. Quoting article numbers is unnecessary; naming the law is enough.

What to expect

Companies covered by UK or EU rules generally have about a month to respond, and can extend that for complex requests. In practice the large ones have a form or a privacy portal and act within days.

They may ask you to verify your identity, which is legitimate — deleting an account on the word of anyone who emails in would be its own security problem. Provide what they reasonably ask for and no more. A company requesting a photo of your passport to delete a forum account is overreaching, and you can say so.

They may also keep some data. Transaction records retained for tax purposes are a legitimate exception, and a deleted account can coexist with a retained invoice record. That is lawful and not a refusal.

If a company subject to these rules ignores you entirely, the escalation is a complaint to the relevant data-protection authority: the ICO in the UK, or the national regulator in an EU country. Complaints are free and the possibility of one tends to produce a response.

Where this does not apply

Being honest about the limits saves time.

Outside the UK and EU, the right is weaker. California residents have comparable rights under state law. Elsewhere it is often at the company’s discretion, though many apply their EU process globally because maintaining two systems is more work than one.

Small or defunct services may simply have nobody reading the inbox. A dormant forum run by one person in 2012 has no privacy team and probably no functioning contact address.

Acquired companies transfer the obligation to whoever bought them. Finding out who that is can take a search, but the acquirer is the correct recipient.

Accounts you cannot identify are a dead end. If you cannot say which email address or username the account used, the company cannot verify your claim and should not act on it.

In all of these, the practical fallback is damage limitation rather than deletion: make sure the password that account used is not in use anywhere else, and if a card is stored there, the card provider can block that merchant or reissue the number. Changing passwords in the right order is the relevant piece, because a reused password on a dead account is a live problem on your other ones.

Finding the accounts you have forgotten

Most people have far more than they think, and the dormant ones are the risky ones precisely because they hold old reused passwords.

  • Search your mail for “welcome to”, “verify your email”, “confirm your account”, “your new account”. This surfaces years of sign-ups quickly.
  • Read your password manager’s full list. Sort by date and work backwards.
  • Check sign-in-with providers. Google, Apple and Facebook each keep a list of every service you used them to sign into, and it is usually longer than expected.
  • Look at recurring card payments on your bank statement for subscriptions attached to accounts you forgot.

Delete what you can from inside each one as you go, which is far quicker than the formal route.

Realistic expectations

For a large company with a privacy portal, expect confirmation within a week or two. For a mid-sized one with no dedicated process, expect a month and possibly a reminder. For anything small, dormant or defunct, expect nothing, and treat the password as the thing you actually need to deal with.

The useful reframing is that deletion is about reducing future exposure, not undoing the past. Data already copied or indexed elsewhere stays there. What you are removing is a live account with your details and an old password in it, and that is still worth the email.

Frequently asked questions

Can a company refuse to delete my account?
They can refuse if they cannot verify you are the account holder, and they can keep some records they are legally obliged to retain, such as transaction history for tax purposes. They cannot simply decline because deleting is inconvenient for them.
What if the company no longer exists?
Then there is usually nobody to action a request. If the business was acquired, the acquirer inherits the data-protection obligations and is worth contacting. If it closed entirely, the data may have been deleted with it or sold, and you have no practical route.
Does deleting the account remove my data from the internet?
No. Anything already copied, indexed, archived or shared elsewhere persists independently. Deletion removes the account from that company's live systems, which is worth doing, but it is not a removal from search results or from third parties who received the data.
How do I find accounts I have forgotten about?
Search your email for words like "welcome", "verify your email" and "confirm your account", and check what your password manager and browser have saved. The sign-in-with-Google and sign-in-with-Apple settings also list every service you used them with.
Is it better to delete an old account or leave it?
Delete it where you can. A dormant account with an old reused password is a liability, because its breach exposes credentials you may still use elsewhere, and any card or address details it holds remain exposed with it.

All Accounts guides