Home Reviews About
Twenty of Time

How the GDPR Right to Erasure Works in Practice

The GDPR’s right to erasure is often called the “right to be forgotten”, but that label can make it sound broader than it is. Article 17 gives people a way to ask an organisation to delete personal data in defined circumstances. It does not create a universal power to remove every inconvenient search result, old account record, or public reference.

For people in Australia, the issue matters whenever a business serves customers in the European Union, monitors people in Europe, or operates across both markets. It also provides a useful comparison with Australian privacy law, which generally focuses on reasonable handling, security, access and correction rather than offering the same broad deletion mechanism.

What The Right To Erasure Covers

A person can request deletion when their personal information is no longer needed for the purpose for which it was collected. For example, an online retailer may have little reason to keep a customer’s marketing profile after the person closes an account and withdraws consent to promotional messages. A social platform may need to consider deleting a profile and associated posts when the user leaves, subject to other legal duties.

Erasure can also apply when processing relied on consent and that consent has been withdrawn, provided there is no alternative legal ground for retaining the data. It may be available where the person objects to processing based on legitimate interests and the organisation cannot show stronger grounds to continue. Unlawful processing, or data that must be deleted to comply with a legal obligation, can provide additional grounds.

The request concerns personal data, which is a wide category. Names, email addresses, account histories, location records, device identifiers, advertising profiles and inferred interests may all qualify when they relate to an identifiable person. Deleting a visible account page may therefore be insufficient if an organisation continues to hold the same profile in a customer database or sends it to a processor.

Erasure is also different from correction. If a credit file or customer record is inaccurate, the appropriate remedy may be rectification rather than deletion. A person cannot normally use Article 17 simply to remove correct information that is relevant to a lawful record.

Who Has To Act

The primary responsibility sits with the data controller: the organisation deciding why and how personal information is processed. A controller may be a European company, an Australian business selling goods to EU residents, or a service provider that deliberately offers services to people in the EU. The business does not need a physical office in Berlin or Paris for the GDPR to matter.

A small Melbourne software company could fall within the rules if it actively targets customers in the European market and processes their personal data. Merely having a website that can technically be viewed overseas does not automatically establish this connection. The organisation’s intentions, language, currency, advertising, delivery arrangements and customer relationships help determine whether the GDPR applies.

Controllers must take reasonable steps to tell processors and other recipients about a valid erasure request. If a company has supplied a customer’s details to an analytics provider, email platform or advertising partner, it may need to communicate the deletion request down that chain. This is why deletion can be technically complicated even when the original organisation wants to comply.

Large businesses commonly use identity systems, backups, fraud tools and customer-support archives that do not disappear at the same moment. A controller should still have a documented retention and deletion process. Keeping data indefinitely in a hidden system is not a substitute for compliance, especially where the organisation continues to use it.

For a broader view of how ordinary services accumulate information, this privacy and security review provides useful context for thinking about the number of systems involved in modern personal-data management.

How To Make A Request

A request does not need to cite Article 17 or use formal legal language. A clear message identifying the person, the relevant account and the data sought is usually enough. It helps to state whether the request concerns the whole account, a particular marketing profile, old records, search results, or information shared with named recipients.

The controller may ask for information to verify identity, especially where deletion could affect an account, financial record or health-related service. Verification should be proportionate. An organisation should not demand a complete passport scan for a low-risk newsletter record if a safer method can establish the requester’s identity.

The normal deadline is one month after receiving the request. This can be extended by up to two further months when the request is complex or numerous, but the organisation must explain the delay within the initial month. It must either erase the data, explain why an exception applies, or explain why the request is manifestly unfounded or excessive.

Deletion may mean removing data from active systems, stopping its use, and instructing relevant processors to do the same. Some records may instead be placed beyond ordinary use with access tightly restricted until a retention period expires. That approach needs to be genuine: a company cannot claim erasure while continuing to use the information for advertising or routine customer profiling.

A controller can refuse a request that is manifestly unfounded or excessive, including repeated requests designed to burden the organisation. It may charge a reasonable fee in limited circumstances. A refusal should identify the legal basis and explain the person’s right to complain to a supervisory authority or seek a judicial remedy.

Why Deletion Is Sometimes Refused

The most important limits protect freedom of expression and information. Journalism, academic work, artistic activity and other public-interest communication may justify retaining information that someone would prefer to remove. A newspaper is not generally required to erase an accurate article about a public event merely because a person dislikes its continued availability.

Legal obligations are another major exception. A bank may need to retain transaction records to meet anti-money-laundering requirements. An employer may have to preserve payroll or tax documents. A Sydney accountant cannot simply delete records because a former client invokes the GDPR if another law requires those records to remain available.

Public health, archiving, research and statistical purposes can also limit erasure where deletion would seriously impair the relevant objective. Legal claims matter as well: data may need to be retained to establish, exercise or defend a claim. A business facing a dispute may preserve relevant messages even after an account holder asks for complete deletion.

The right is especially difficult with search engines. Search results can sometimes be delisted when they are inaccurate, outdated or no longer relevant, but delisting does not erase the source page. The result may remain visible when someone searches the web in another way, and public figures or matters of significant public interest receive closer scrutiny.

Backups create a further practical boundary. A controller may be able to isolate information in disaster-recovery copies and allow it to disappear through the normal overwrite cycle, rather than instantly editing every backup. The organisation should prevent restoration from reintroducing the deleted data into active systems.

How Australian Rules Compare

Australia does not currently provide a direct equivalent to the GDPR’s broad right to erasure for every individual covered by the federal Privacy Act. Australian organisations must take reasonable steps to destroy or de-identify personal information when they no longer need it for the purpose collected, unless an exception applies. That is an important obligation, but it is not the same as giving a person an independent right to demand deletion whenever a listed Article 17 ground exists.

Australian privacy complaints generally involve the organisation first, followed where appropriate by the Office of the Australian Information Commissioner. The Privacy Act also provides access and correction rights. Sector-specific laws may impose their own retention requirements, and the rules can differ between private businesses, government agencies and regulated industries.

Issue GDPR right to erasure Australian privacy position
Main source Article 17 of the GDPR Privacy Act 1988 and the Australian Privacy Principles
Who may use it Individuals whose data is covered by the GDPR Individuals covered by the relevant Australian privacy scheme
Basic mechanism A person can request deletion on specified grounds Organisations should destroy or de-identify information no longer needed, subject to exceptions
Response period Generally one month, with a possible extension Access and correction processes have their own requirements; no identical one-month erasure rule
Key limits Legal duties, expression, public interest, research, claims and other Article 17 exceptions Legal retention, business needs, authorised uses and applicable sector rules
Regulator Relevant EU data protection authority Office of the Australian Information Commissioner for covered matters
Search results Delisting may be possible in limited cases No general Australian equivalent to the GDPR search-delisting framework

Australian consumers may encounter both systems in the same transaction. A Brisbane resident buying from a French retailer might make a GDPR request to that retailer, while the retailer’s Australian logistics partner may be governed primarily by Australian rules. The answer depends on the organisation’s role, the data flow and the territorial reach of the GDPR.

The comparison is also relevant to identifiers. Telecommunications companies, banks and platforms often use email addresses or phone numbers to connect records across services. Concerns about phone numbers as identifiers show why deleting one visible account may not remove every linked profile or inferred association.

Making A Request Effective

A useful request is specific without being unnecessarily broad. Include the account email, customer number or username; identify the information or processing concerned; state the relevant reason; and ask the organisation to confirm what was deleted, what was retained, and why. If the concern is targeted advertising, say so directly rather than asking vaguely for “all data”.

Keep evidence of the request and the response. Save the date, the organisation’s privacy contact, screenshots, confirmation emails and any explanation for refusal. If the company does not respond within the applicable period, or gives an incomplete explanation, the record will help with a complaint to the relevant European supervisory authority.

Deletion is not always the best privacy remedy. Restriction of processing can be more suitable while accuracy or lawfulness is being disputed. An objection may stop direct marketing. Access can reveal what a business holds before a person decides whether to seek correction, restriction or erasure. Choosing the remedy that matches the problem prevents an organisation from treating a sweeping request as confused or excessive.

Technology policy also affects the practical meaning of deletion. Proposals and systems that expand online monitoring can create more copies, more recipients and more retention points. The debate around Chat Control concerns illustrates why privacy rights depend on the architecture of services, not just the wording of a request.

For an Australian resident, the practical sequence is straightforward: identify which entity controls the information, check whether the GDPR applies, send a precise written request, record the deadline, and assess any refusal against the recognised exceptions. The next concrete step is to list one organisation holding your personal data and send it a written erasure request naming the account, the data concerned and the reason for deletion.