Right to Erasure
The right to erasure lets individuals ask an organisation that holds personal data about them to delete that data. It is commonly known as the 'right to be forgotten'. This right is not absolute and applies only in certain circumstances, so a request will not always require deletion.
The right to erasure is a data subject right established under Article 17 of the GDPR (and the UK GDPR), supported by the notification obligation in Article 19. It entitles a data subject to obtain, from the data controller, erasure of personal data concerning them without undue delay where one of the specified grounds applies. The right is qualified rather than absolute: it is available only in defined circumstances and is subject to applicable exemptions. Requests may be made verbally or in writing, and controllers are generally required to respond within a set timeframe (described in the evidence as one month), though readers should verify current deadlines and exemptions against the latest official text. Scope, grounds, and exceptions should be confirmed against the applicable jurisdiction's regime, as the evidence addresses the EU GDPR and UK GDPR contexts.
Why it matters
The right to erasure is one of the more visible data subject rights because it directly touches the tension between an individual's control over their personal data and an organisation's operational and legal reasons for retaining it. For compliance teams, the significance lies less in the headline concept — often popularised as the 'right to be forgotten' — and more in its qualified nature. Because the right applies only where one of the specified grounds is met and is subject to exemptions, treating every erasure request as an automatic instruction to delete can be as much a compliance failure as ignoring valid requests. Getting the assessment right requires understanding when the right is engaged and when a lawful basis for continued processing overrides it.
The operational stakes are practical. An organisation must be able to locate personal data across its systems, evaluate whether a ground for erasure applies, apply any relevant exemptions, and respond within the required timeframe. The evidence describes a one-month response window, but readers should verify current deadlines against the applicable regime, as timeframes and the conditions that may extend them depend on the official text. Failure to handle requests correctly — whether by over-deleting data needed for legal obligations or under-responding to valid requests — exposes an organisation to regulatory scrutiny under the GDPR and UK GDPR.
Because requests may be made verbally or in writing, the right also shapes front-line processes: staff who interact with individuals need to recognise an erasure request even when it is not labelled as one and route it appropriately. This makes the right a matter of both governance design and everyday staff awareness, not solely a legal-team concern.
Who it's relevant to
Inside Right to Erasure
Common questions
Answers to the questions practitioners most commonly ask about Right to Erasure.

