PurpleLab Opt Out: Privacy and HCP Request Steps
PurpleLab provides a general rights form plus a product-specific healthcare-provider route, with important limits for de-identified audience data.

PurpleLab opt out steps depend on what you want to change. The official PurpleLab privacy center identifies PurpleLab OneTrust data-subject form, privacy email or phone, with a product-specific form for identifiable healthcare-provider data. PurpleLab may verify a name and email, request more information, or require signed authorization or a power of attorney for an agent. Use the route that matches the browser, device, identifier, or retained record, save the confirmation, and do not treat a narrow advertising choice as a universal deletion.
PurpleLab opt out quick facts
| Question | Current answer |
|---|---|
| Official route | PurpleLab OneTrust data-subject form, privacy email or phone, with a product-specific form for identifiable healthcare-provider data |
| Main scope | Corporate website and contact data, identifiable healthcare-provider information, and separately described de-identified claims and consumer-audience data |
| Verification | PurpleLab may verify a name and email, request more information, or require signed authorization or a power of attorney for an agent |
| Expected result | Available requests can include access, correction, deletion, sale or sharing opt-out, consent withdrawal, and appeal, but PurpleLab says it cannot identify an individual inside certain de-identified consumer audience data |
| Reappearance risk | A request does not control a healthcare organization’s records, independent partner systems, or newly sourced professional information that falls outside the confirmed request |
Last checked August 29, 2026. Provider pages, forms, device menus, and applicable rights can change. Start from the current provider policy and keep the smallest useful record of what you submitted.
How to opt out of PurpleLab

- Start at PurpleLab’s privacy center and choose the policy that matches your relationship: corporate website or contact data, product data, or healthcare-provider information.
- Open the linked OneTrust form, or use the published privacy email or toll-free number when the form does not fit the request.
- Choose access, correction, deletion, sale or sharing opt-out, consent withdrawal, or appeal as applicable. Describe the system or relationship you want PurpleLab to check.
- Provide only the details needed for matching and identity verification. If an agent submits the request, keep the signed authorization and be ready to verify directly.
- Save the confirmation and compare the response with the scope requested. Contact the separate organization that holds a medical, insurance, or patient record when that record is outside PurpleLab’s systems.
Choose the right request before sharing information
A targeted-advertising choice, sale or sharing opt-out, access request, correction, deletion, consent withdrawal, and device setting can produce different results. Pick the narrow control that matches your goal. This reduces unnecessary data disclosure and makes the provider response easier to verify.
Confirm that the form domain belongs to the provider or its named request processor before entering an email, device identifier, IP address, professional number, or identity document. If the official page offers a ticket, verification email, or appeal route, store it with the request date.
PurpleLab distinguishes identifiable healthcare-provider information from consumer audience data that it says is de-identified before it can identify a person. That distinction changes what a request can produce. An HCP can use the product-specific form, while a consumer may be told that PurpleLab cannot locate an individual record in a de-identified audience.
The current privacy center lists access, deletion, correction, sale or sharing opt-out, non-discrimination, and appeal. The product policy also discusses profiling opt-out and consent withdrawal where applicable. These rights depend on jurisdiction and on PurpleLab maintaining information it can associate with the requester.
Identity verification can scale with sensitivity and request type. The product policy gives name and email verification as an example and says requests may be declined when identity cannot be confirmed. Authorized-agent requests can require written permission or a power of attorney.
This route is not a medical-record deletion tool. PurpleLab’s data products, healthcare-provider information, a hospital’s records, an insurer’s files, and a patient portal are different systems with different controllers and request paths.
Verification and processing behavior
PurpleLab may verify a name and email, request more information, or require signed authorization or a power of attorney for an agent. Verification protects another person’s information, but it can also reveal whether the provider can match the supplied detail. If no message arrives, check the address, spam folder, form status, and identifier scope before opening another ticket.
No single completion time applies to every request covered here. Browser or device signals can register quickly, while access, correction, deletion, partner propagation, or agent requests can take longer. Use the deadline in the provider confirmation or applicable policy for your specific request, and follow up on the same ticket.
- Record the request type, official domain, date, and confirmation or status.
- Note the browser, device, app, account, household, or identifier that the choice covers.
- Complete verification promptly without sending information the official route did not request.
- Recheck the same environment first, then cover other browsers and devices separately.
What changes after the opt-out
Available requests can include access, correction, deletion, sale or sharing opt-out, consent withdrawal, and appeal, but PurpleLab says it cannot identify an individual inside certain de-identified consumer audience data. An advertising opt-out can still leave contextual ads, measurement, security processing, or legally retained records. A deletion request can also have exceptions. Treat the provider’s confirmed scope as the result instead of assuming every copy held by every partner disappears.
Independent publishers, apps, device makers, browsers, data suppliers, and customer systems can keep their own controls. A request to PurpleLab does not automatically change those systems. When the official policy points to another controller, partner, operating system, or industry tool, record that as a separate action.
Why the choice can reappear or stop working
A request does not control a healthcare organization’s records, independent partner systems, or newly sourced professional information that falls outside the confirmed request. Cookie-based preferences live in one browser environment. Mobile and connected-device choices can depend on an advertising identifier or operating-system setting. A broader rights response may also retain a limited suppression or audit record so the provider can remember or document the request.
Recheck after browser cleanup, a new browser profile, app reinstall, operating-system reset, phone replacement, new streaming device, advertising-ID reset, or a change in the information suppliers use to match you. Compare any new exposure with the original confirmation before deciding whether another request is needed.
Broader privacy rights and manual removal
This guide maps published provider controls and does not interpret the law or promise an outcome. Available rights depend on residence, relationship, data, and whether the provider can identify a matching record. Read the form’s verification and retention text before requesting deletion.
For a wider removal workflow, use the data broker opt-out list, the guide to removing yourself from data brokers, and the opt-out guide hub.
Build a repeatable privacy check
Keep a small log with the provider, route, identifier scope, request type, date, verification state, confirmation, and next check date. This makes a later reappearance easier to diagnose and prevents a browser preference from being mistaken for a device-wide or partner-wide deletion.
You can also run a free data broker scan to look for other exposed records. Related reading: HealthLink Dimensions privacy guide, OptimizeRx privacy guide, and Swoop privacy choices guide.
Frequently asked questions
Does the PurpleLab opt out delete everything?
No. The result depends on the selected route and data the provider can match. Advertising, sale, or sharing choices can limit a defined use without deleting every retained record. Use the separate deletion route when available and read any exceptions or system limits.
How do I know the PurpleLab request worked?
Keep the status page, confirmation, or completed-request message and recheck the same environment. A change in the ads you see is weak proof because contextual ads can continue. A provider status, response, or access record is stronger evidence.
Should I repeat the opt-out on another device?
Yes when the policy describes the choice as browser-specific, device-specific, app-specific, account-specific, or identifier-specific. One desktop cookie does not normally cover a phone, connected television, separate browser profile, or reset mobile identifier.
What if the official form changes?
Return to the current provider privacy page and follow its latest privacy-center or rights link. If the form is unavailable, use the published privacy contact, state the request type, and include the existing ticket without sending more personal information than needed.
Sources
Official PurpleLab privacy center, checked August 29, 2026. Open official source.
Official PurpleLab Product Privacy Policy, checked August 29, 2026. Open official source.
Continue reading
Related privacy guides
EasyOptOuts vs OneRep: Price, Coverage, and Best Fit
Compare EasyOptOuts and OneRep on current pricing, coverage definitions, scan cadence, household plans, automation, guarantees, and best fit.
Read articlePulsePoint Opt Out: Browser, Device, and Data Rights
Use PulsePoint’s current cookie tool, mobile and connected-TV controls, or separate privacy-rights and healthcare-provider request routes.
Read articleRTB House Opt Out: Browser Toggle and Privacy Rights
RTB House offers a browser-specific advertising toggle plus Global Privacy Control, mobile settings, and separate DPO requests for broader rights.
Read article