Removal guide · Epsilon

How to remove yourself from Epsilon

Epsilon routes all consumer privacy requests through a single web form at legal.epsilon.com/dsr. The form is a 3-step flow. Pick your country, pick one request type, fill in your contact info and submit. For US residents, there are 8 request types (delete, do-not-sell, do-not-share, opt-out of profiling, opt-out of sensitive PI use, access, correct, and appeal). Only one request per submission - but multiple submissions are accepted, so the fullest removal takes three or four separate requests (Delete + Do not sell + Do not share + Opt-out of profiling). Phone alternative at +1 (866) 267-3861; email privacy@epsilon.com.

Epsilon homepage screenshot

Before you remove your data: See the Epsilon data broker profile for ownership (Publicis Groupe), the DOJ $150M elder-fraud DPA, and the full data-product breakdown (CORE ID, Abacus, PeopleCloud Digital Media Solutions).

Quick facts

Removal Overview

Consumer Privacy Request Form
Method

Web form (legal.epsilon.com/dsr) · phone 1-866-267-3861

Active time

~3-5 minutes per submission

Processing time

15 business days for an opt-out · up to 45 days for delete, access and correction

Request types (US)

8

Per submission

One request type only

Account required

No

GPC honored

Yes

Escalation

privacy@epsilon.com · CPPA data-broker complaint

One request type per submission - by design. Epsilon's form only accepts one request type per submission (the page says so explicitly). To get the fullest removal you'll need to submit the form 3-4 times - once per request type. We list the recommended combination in section 04.

Outside the US? The same legal.epsilon.com/dsr form serves all jurisdictions; the available request types adjust based on the country you pick in step 1. EU / UK residents see GDPR-flavored options; Canadian residents see PIPEDA-flavored options. The structure of the flow is the same.

Epsilon employees and applicants: the page directs you to a different address - privacyofficer@publicisgroupe.com - rather than the consumer DSR form.

Prereqs

What you'll need before you start

3 things
  • Your full legal name, current postal address, and email. The form asks for all of these to match against stored records. If Epsilon has you under a previous name or address (maiden name, prior address), include that too in a separate submission - or note it in a follow-up email to privacy@epsilon.com.

  • An email inbox you actually check. Epsilon's DSR portal sends a confirmation email after each submission. Use a real address rather than a masked one so the verification matches against stored records cleanly.

  • 10-15 minutes if you're doing the full recipe. A single submission takes ~3-5 minutes; the full recommended combination (Delete + Do not sell + Do not share + Opt-out of profiling) is four submissions back-to-back.

The 3 steps

Submit the Consumer Privacy Request Form

~5 minutes per submission
01

Visit legal.epsilon.com/dsr and choose your country

Open legal.epsilon.com/dsr. The page is titled "Consumer Privacy Rights" and explains in plain language that Epsilon provides "marketing services to its clients, such as personalized online and offline advertising and licensing of consumer data." Scroll past the introductory text to the "CONSUMER PRIVACY REQUEST FORM" section (black header bar) and pick your country from the Country dropdown.

The available request types in step 2 depend on which country you pick - US residents see the 8-option list documented below; EU / UK / Canada / other jurisdictions see different option sets aligned to their respective privacy laws.

Top of legal.epsilon.com/dsr 'Consumer Privacy Rights' page. Epsilon logo at top left with horizontal navigation (Platform, Solutions, Resources, About). Page heading 'Consumer Privacy Rights' with a black English language selector at top right. Body text explains that Epsilon provides marketing services including personalized advertising and consumer data licensing, references the Epsilon Privacy Policy, gives the toll-free phone alternative +1-866-267-3861, directs Epsilon employees to privacyofficer@publicisgroupe.com, and notes that agents acting on behalf of consumers need additional written proof. Below the prose sits a black banner reading 'CONSUMER PRIVACY REQUEST FORM' with a Country dropdown set to 'Select' underneath.
Top of the Consumer Privacy Rights page. Pick your country from the dropdown to unlock the request-type list.
02

Choose one request type (US residents see 8 options)

Once you pick your country, Epsilon reveals a Request Type radio-button list. For US residents, the 8 options run as follows.

  1. Do not sell my Personal Information - CCPA right; stops Epsilon from selling your data to clients
  2. Do not share my Personal Information / Opt-out of Cross-Context Behavioral or Targeted Advertising - CPRA right; stops use for targeted advertising across sites
  3. Access my Personal Information & 3rd Party Disclosures - get a copy of what Epsilon holds about you and who they've shared it with
  4. Correct my Personal Information - fix inaccuracies in Epsilon's records
  5. Delete my Personal Information - purge records (the strongest option)
  6. Opt-out of Profiling / Automated Decision-Making - CPRA right; stops modeled / predictive use of your data
  7. Opt-out / Revoke Consent of use of my Sensitive Personal Information - CPRA right; specific to sensitive categories
  8. Appeal the result of my prior privacy request - if Epsilon denied a prior request, this is the escalation path

The form rules state "Only one request per submission. Multiple submissions are accepted." Pick the one you want for this submission - we'll cover the recommended combination of 3-4 submissions in section 04.

Epsilon Consumer Privacy Request Form with Country dropdown set to 'United States'. Below it, 'Request Type (Only one request per submission. Multiple submissions are accepted)' header followed by 8 radio button options each with a question-mark help icon: (1) Do not sell my Personal Information - currently selected with a filled blue radio; (2) Do not share my Personal Information / Opt-out of Cross-Context Behavioral or Targeted Advertising; (3) Access my Personal Information and 3rd Party Disclosures; (4) Correct my Personal Information; (5) Delete my Personal Information; (6) Opt-out of Profiling / Automated Decision-Making; (7) Opt-out / Revoke Consent of use of my Sensitive Personal Information; (8) Appeal the result of my prior privacy request.
Eight request-type radios for US residents. Pick one per submission; resubmit for additional types.
03

Fill in your contact info and click Submit request

Scroll down past the radio buttons to the contact fields: Email, First Name, Last Name, Street Address, City, State / Province, and ZIP / Postal Code. Fill them all in - they're how Epsilon matches the request against stored records (the more complete the match, the higher the chance the request actually covers your data). Click the blue Submit request button at the bottom.

For Delete and Correction requests the page then shows an Identity Verification Required notice and OneTrust emails you a Confirm email link. Epsilon does not start processing until you click it, so keep the tab open, find that message and complete the click.

You should receive an automatic confirmation email shortly after submitting. Save the confirmation - it's your tracking reference if Epsilon misses the statutory deadline (45 days for delete, access and correction requests, 15 business days for an opt-out).

Lower half of the Epsilon Consumer Privacy Request Form showing the contact fields: Email, First Name, Last Name, Street Address, City, State / Province, and ZIP / Postal Code (the submitted details in each field are blacked out). At the bottom sits a rounded blue 'Submit request' button.
Fill all the contact fields and click Submit request. Save the confirmation email.

Full removal recipe

The recommended 4-submission combination

~15 minutes total

Because Epsilon's form only accepts one request type per submission, getting full coverage means filing the form multiple times. The combination below gives a US resident the fullest removal Epsilon's form allows.

  1. Submission 1 - Delete my Personal Information. The strongest option. Purges Epsilon's stored data on you (subject to whatever exemptions apply under CCPA / CPRA, e.g., regulatory record-keeping). Do this one first.
  2. Submission 2 - Do not sell my Personal Information. Belt-and-suspenders. Even if delete is denied or partially applied, the do-not-sell flag stops Epsilon from licensing your data to clients going forward.
  3. Submission 3 - Do not share / Opt-out of Cross-Context Behavioral or Targeted Advertising. Separate from do-not-sell under CPRA. This covers the cross-device, programmatic-advertising use case that PeopleCloud Digital Media Solutions (formerly Conversant) is built around.
  4. Submission 4 - Opt-out of Profiling / Automated Decision-Making. Covers the modeled / predictive use of your data (response-propensity scoring, lookalike audiences, etc.). This is the option category most directly implicated in the 2008-2017 DTC Unit conduct that drove the DOJ $150M DPA.

If you live in a CPRA-extending state with sensitive-PI rights: add a 5th submission for Opt-out / Revoke Consent of use of my Sensitive Personal Information. CPRA defines sensitive PI to include precise geolocation, government IDs, racial or ethnic origin, religious beliefs, union membership, biometric data, health data, sexual orientation, and contents of private communications. Whether Epsilon holds any of these on you specifically isn't documented, but the right to opt out costs you nothing to exercise.

Tip: file all submissions on the same day. Epsilon's verification process appears to match against a single set of contact details, and back-to-back submissions are easier to track than spread-out ones. Save each confirmation email separately so you have a paper trail per request type.

Confirm it worked

Did it actually work?

Indirect verification
  1. Expect an automatic confirmation email from the DSR portal within minutes of each submission. Save them. If the confirmation never arrives, check spam and re-submit.
  2. The statutory ceiling is 45 days (CCPA / CPRA) for delete, access and correction requests, extendable once to 90 days with notice, and 15 business days for an opt-out of sale or sharing. Within that window Epsilon should send a written disposition - either confirming the action taken (deleted, opt-out applied, etc.) or explaining why the request was denied.
  3. You won't see your data disappear from a public page because Epsilon doesn't publish to a public page - it licenses data to enterprise clients. The downstream signals to watch for are fewer unsolicited postal mailers from retail / loyalty programs, fewer cold marketing emails, fewer targeted ads referencing household demographic facts you didn't share with the site running the ad.
  4. File an Access request first if you want to see what they have. Submission option 3 (Access my Personal Information & 3rd Party Disclosures) gives you a copy of stored data and a list of third parties Epsilon has shared with. Two requests per 12 months max under CCPA.
  5. Re-run annually. Epsilon's data flows refresh constantly from retail co-op contributors, email programs, and the Conversant / PeopleCloud Digital Media Solutions ad network. Under California law an opt-out doesn't lapse, and Epsilon can't resume selling your data unless you later agree to it, but a yearly run with any new address, phone or email catches records filed under details you didn't submit.

Troubleshooting

If it doesn't work

Common failures
  • No confirmation email after submitting. Check spam / promotions. If it's not there within a few hours, the submission may not have gone through; re-submit. The phone fallback at 1-866-267-3861 is available if the web form keeps failing.

  • Epsilon can't match you to stored records. Common for people who use masked email addresses, have moved recently, or recently changed names. Submit a follow-up using previous contact details (previous email, previous address, maiden name) - one previous value at a time. The privacy@epsilon.com email is a more flexible channel for these cases.

  • You filed Delete and got a "no records found" reply. Treat it as inconclusive rather than as success. It usually means Epsilon could not match the details you gave to a record, so the record may still exist under other details. Re-submit with previous contact details as described above, one at a time, or file an Access request (request type 3) to see what Epsilon holds before you delete.

  • You're being directed to publicisgroupe.com. That's expected if you're an Epsilon employee or job applicant; HR data goes through privacyofficer@publicisgroupe.com rather than the consumer DSR form.

  • You don't hear back within the deadline. That is 15 business days for an opt-out of sale or sharing and 45 days for delete, access or correction. Email privacy@epsilon.com referencing your submission date and the request type, citing the CCPA / CPRA statutory deadline.

  • You're appealing a prior denial. That's literally what option 8 (Appeal the result of my prior privacy request) is for. Include the original request's confirmation number so Epsilon can tie the appeal to the underlying disposition.

Stay off

Keep your data out of Epsilon (and the broader marketing-data ecosystem)

Annual re-check advised
  • Re-run the full recipe annually. Epsilon's data accumulates from retail-loyalty programs, email engagement, and the PeopleCloud Digital Media Solutions ad network. Suppression flags don't prevent new data ingestion from accelerating sources; an annual re-submission is the maintenance cycle.

  • Turn on Global Privacy Control. Epsilon honors the GPC browser signal as a valid opt-out for cross-context behavioral advertising. Enable GPC in Firefox (built-in) or install an extension like DuckDuckGo Privacy Essentials or Privacy Badger in Chrome / Edge.

  • Suppress upstream loyalty data. Abacus, Epsilon's retail data cooperative, builds its purchase-history pool from ~1,800 participating retailers. Reading the privacy disclosures on loyalty-program signup pages and opting out of "data sharing with marketing partners" at the retailer level reduces what flows into Abacus to begin with.

  • Epsilon is one of several. Other US marketing-data brokers in this directory include Acxiom (Omnicom-owned post-Nov 2025), ZoomInfo (B2B contact data), Foursquare (location intelligence), and CoreLogic (property + mortgage data). Opt-outs at those companies are separate.

  • Industry-wide opt-outs help at the margin. The DMA Choice direct-mail suppression and the DAA WebChoices interest-based-ads tool cover industry-association members generally. Epsilon participates in DAA. These are complements to the Epsilon-specific opt-out, not replacements.

Take yourself off data broker sites

Redact scans 120+ data broker sites from your device, finds where your details are listed, and submits the removal requests for you. If a broker relists you, it files again.

Last updated:

September 10, 2026