Skip to main content
green gradient background, "The Future of Application Security Is Already Here." and a read the report button.
Category: Data Subject Rights

Right to Erasure

Also known as: Right to be Forgotten, Right to get your data deleted
Simply put

The right to erasure lets individuals ask an organisation that holds personal data about them to delete that data. It is commonly known as the 'right to be forgotten'. This right is not absolute and applies only in certain circumstances, so a request will not always require deletion.

Formal definition

The right to erasure is a data subject right established under Article 17 of the GDPR (and the UK GDPR), supported by the notification obligation in Article 19. It entitles a data subject to obtain, from the data controller, erasure of personal data concerning them without undue delay where one of the specified grounds applies. The right is qualified rather than absolute: it is available only in defined circumstances and is subject to applicable exemptions. Requests may be made verbally or in writing, and controllers are generally required to respond within a set timeframe (described in the evidence as one month), though readers should verify current deadlines and exemptions against the latest official text. Scope, grounds, and exceptions should be confirmed against the applicable jurisdiction's regime, as the evidence addresses the EU GDPR and UK GDPR contexts.

Why it matters

The right to erasure is one of the more visible data subject rights because it directly touches the tension between an individual's control over their personal data and an organisation's operational and legal reasons for retaining it. For compliance teams, the significance lies less in the headline concept — often popularised as the 'right to be forgotten' — and more in its qualified nature. Because the right applies only where one of the specified grounds is met and is subject to exemptions, treating every erasure request as an automatic instruction to delete can be as much a compliance failure as ignoring valid requests. Getting the assessment right requires understanding when the right is engaged and when a lawful basis for continued processing overrides it.

The operational stakes are practical. An organisation must be able to locate personal data across its systems, evaluate whether a ground for erasure applies, apply any relevant exemptions, and respond within the required timeframe. The evidence describes a one-month response window, but readers should verify current deadlines against the applicable regime, as timeframes and the conditions that may extend them depend on the official text. Failure to handle requests correctly — whether by over-deleting data needed for legal obligations or under-responding to valid requests — exposes an organisation to regulatory scrutiny under the GDPR and UK GDPR.

Because requests may be made verbally or in writing, the right also shapes front-line processes: staff who interact with individuals need to recognise an erasure request even when it is not labelled as one and route it appropriately. This makes the right a matter of both governance design and everyday staff awareness, not solely a legal-team concern.

Who it's relevant to

Data Protection Officers and Privacy Teams
DPOs and privacy specialists are responsible for designing the processes that receive, assess, and respond to erasure requests. They must ensure the organisation can evaluate whether a ground under Article 17 applies, apply relevant exemptions, and meet the response timeframe described in the evidence as one month, verifying current deadlines against the applicable regime.
Data Controllers
The right is exercised against the data controller, which bears the obligation to erase personal data without undue delay where a valid ground applies. Controllers must also consider the notification obligation under Article 19. Whether an organisation acts as controller or processor affects where the responsibility to action a request sits, and this distinction should be confirmed for each processing activity.
Customer-Facing and Front-Line Staff
Because individuals can make an erasure request verbally or in writing, staff who interact with the public need to recognise such a request even when it is not formally labelled, and escalate it through the correct internal process so that the response timeframe is not missed.
Compliance and Legal Counsel
Legal and compliance professionals advise on whether a request meets a specified ground, whether an exemption or competing lawful basis permits continued retention, and how the right operates within the applicable EU or UK regime. Application to specific circumstances requires professional judgment against the latest official text.

Inside Right to Erasure

Statutory basis
The right to erasure (often called the 'right to be forgotten') is established under the EU GDPR, generally at Article 17, and under the UK GDPR as retained and adapted in UK law. It is a binding legal right within these jurisdictions, not a voluntary standard. Other jurisdictions may provide analogous but distinct deletion rights that should not be assumed identical.
Grounds for erasure
A data subject may generally request erasure where, among other conditions, the personal data is no longer necessary for the purposes for which it was collected, consent is withdrawn and no other legal basis applies, the data subject objects and there are no overriding legitimate grounds, or the data has been unlawfully processed. The specific enumerated grounds should be verified against the current official text.
Exemptions and limitations
The right is not absolute. Erasure may be refused or restricted where processing is necessary for compliance with a legal obligation, for the exercise or defence of legal claims, for reasons of public interest (such as public health), for archiving, scientific or historical research, or for freedom of expression and information. Applicability depends on the facts and the applicable legal basis.
Controller and processor responsibilities
The obligation to action a valid erasure request rests primarily with the controller, who determines purposes and means of processing. Processors act on the controller's documented instructions and are generally not the decision-maker on whether erasure applies, though contractual and technical arrangements must enable the controller to fulfil the request.
Notification and downstream propagation
Where a controller has made personal data public or shared it with other recipients, it may be required, taking account of available technology and cost, to inform those recipients or third parties of the erasure request so they can act on it. The precise extent of this obligation should be confirmed against the current text.
Response timeframe and process
Requests are generally subject to the GDPR's timelines for responding to data subject rights, with possible extension in complex cases. Controllers must typically respond, and may need to verify the requester's identity before acting. Exact periods and permissible extensions should be verified against the applicable regulation.

Common questions

Answers to the questions practitioners most commonly ask about Right to Erasure.

Does the right to erasure mean data subjects can always demand that their data be deleted?
No. The right to erasure under the GDPR is not absolute. It applies only in specific circumstances, such as where personal data is no longer necessary for the purpose for which it was collected, where consent is withdrawn and no other legal basis applies, or where the data has been unlawfully processed. It is also subject to several exemptions, for example where processing is necessary for compliance with a legal obligation, for the exercise or defence of legal claims, or for reasons of freedom of expression. Whether the right applies in a given case is fact-specific and depends on the legal basis for processing and any applicable exemption.
Is the right to erasure the same as the 'right to be forgotten' and does it apply everywhere?
The two terms are often used interchangeably, but they are not identical. 'Right to be forgotten' originated as shorthand from case law concerning the de-listing of search results, while the right to erasure is the codified GDPR right addressing deletion of personal data more broadly. Its scope is also jurisdictional: it is a right under EU and UK data protection law and does not apply universally. Other jurisdictions, including many US frameworks, address deletion differently or not at all. Readers should verify which regime governs a particular processing activity, noting the GDPR's potential extraterritorial reach for organizations targeting or monitoring individuals in the EU.
What is the typical timeframe for responding to an erasure request?
Under the GDPR, requests to exercise data subject rights generally must be actioned without undue delay and within the standard response period set out in the regulation, which may be extended in certain complex cases. Because specific durations and extension conditions are set by the regulation and interpreted in supervisory authority guidance, verify the current timeframes and any conditions against the official text before relying on them. Establishing an internal deadline shorter than the statutory limit is a common operational practice, though not itself a legal requirement.
How should an organization handle an erasure request when the same data is held by processors or third parties?
Where a controller has engaged processors, the controller generally remains responsible for ensuring the request is honoured, and the processor is typically obliged under its data processing agreement to assist. Where personal data has been made public or disclosed to other controllers, the GDPR may require reasonable steps to inform those recipients of the erasure request, taking account of available technology and cost. The precise obligations depend on the roles of the parties and the terms of the relevant agreements, so map data flows and contractual responsibilities before responding.
Can a request be refused, and what should the organization do if it declines?
Yes, in cases where an exemption applies or where the request is manifestly unfounded or excessive, a controller may refuse or may in some circumstances charge a reasonable fee, subject to the conditions in the regulation. Where a request is declined, the controller should generally inform the data subject of the reasons, of their right to lodge a complaint with the relevant supervisory authority, and of the possibility of a judicial remedy. Refusals should be documented to support accountability. Whether a particular refusal is justified requires case-by-case professional judgment.
What does erasure require in practice, and is anonymization an acceptable alternative to deletion?
Erasure generally involves removing personal data from live systems and addressing copies in backups, logs, and archives, which often requires a defined process rather than a single deletion action. Backup environments are frequently handled through documented retention and overwrite cycles rather than immediate deletion, and the acceptability of that approach depends on the circumstances and applicable guidance. Anonymization, where data is rendered no longer identifiable such that it falls outside the scope of personal data, may in some cases achieve an equivalent outcome, but only if the anonymization is genuine and irreversible; pseudonymization does not meet this threshold because the data remains personal data. Assess each approach against current supervisory guidance and the specific data involved.

Common misconceptions

The right to erasure is an absolute right that forces deletion of any data on request.
The right applies only where specific grounds are met and is subject to several exemptions, including legal obligations to retain data, defence of legal claims, and freedom of expression. In many cases a controller may lawfully decline or partially fulfil a request based on the facts and applicable legal basis.
The right to erasure is a universal, global entitlement that works the same everywhere.
It is a right under the EU and UK GDPR with defined territorial and, in some cases, extraterritorial scope. Other jurisdictions, including US state privacy laws, may provide comparable deletion rights, but their conditions, exemptions, and definitions differ and should not be treated as identical.
Compliance with an erasure request always means permanent, immediate destruction of all copies including backups.
The obligation is to cease processing and remove the data as required, but treatment of backups, archives, and downstream recipients depends on technological feasibility, retention obligations, and applicable exemptions. Enforcement expectations on backups continue to evolve and should be assessed case by case.

Best practices

Establish a documented erasure-request workflow that captures receipt, identity verification, assessment against the statutory grounds and exemptions, decision, and response within the applicable timeframe.
Assess each request on its facts rather than applying a blanket deletion policy, recording the legal basis for granting, partially fulfilling, or refusing it in case enforcement or a complaint arises.
Maintain accurate data maps and records of processing so you can locate personal data across systems, including backups and third-party recipients, when evaluating whether and how erasure can be actioned.
Define clear controller-processor responsibilities in contracts and technical arrangements so processors can support erasure on the controller's instruction.
Implement a process to notify relevant recipients or third parties of erasure where required, taking account of technological feasibility and cost.
Verify obligations, timelines, and exemptions against the current official text of the applicable regulation and seek professional judgment for fact-specific situations, as requirements differ across jurisdictions and may be amended over time.
Application Security Isn’t Optional Anymore.