How GDPR’s Right to Erasure Works in Practice
The GDPR’s right to erasure is often called the “right to be forgotten,” but that phrase can create unrealistic expectations. It does not give people a universal power to remove every mention of themselves from the internet. It gives individuals a legal route to ask an organisation to delete personal data when specific conditions apply.
In practice, the outcome depends on what data an organisation holds, why it holds it, which legal basis supports the processing, and whether another GDPR obligation requires retention. A company may need to erase a marketing profile while keeping an invoice, or remove a public account while preserving records needed to defend a legal claim.
The process is usually free and relatively straightforward, but a successful request benefits from precision. Knowing who controls the information, describing the relevant data, and understanding the permitted exceptions can make the difference between a meaningful deletion and a vague refusal.
What The Right To Erasure Covers
Article 17 of the General Data Protection Regulation allows a data subject to request the deletion of personal data without undue delay. The request can concern information held in a customer account, newsletter database, mobile application, employee file, advertising profile, or other identifiable record.
Erasure may be available when the data is no longer necessary for its original purpose. For example, a retailer might have no continuing reason to retain a dormant marketing profile after a person withdraws consent and asks to be removed from promotional systems. It may also apply when processing was based on consent and that consent has been withdrawn, provided there is no other lawful basis for keeping the information.
Other grounds include unlawful processing, an objection to processing based on legitimate interests, and data collected in relation to information society services offered directly to a child. The right can therefore overlap with objections to profiling, withdrawal of consent, and the broader principle of data minimisation.
Deletion is more than removing a visible account page. A controller should consider linked identifiers, segmentation records, contact details, device associations, and data shared with processors. However, the GDPR does not require an organisation to erase information that it never held, data that has genuinely been anonymised, or information that cannot reasonably be connected to the requester.
Who Can Make A Request
Any identifiable individual can exercise the right. You do not need to be an EU citizen, and you generally do not need to explain why you want the data deleted. The GDPR can apply when an organisation established in the European Economic Area processes personal data, or when it offers services to or monitors people in the European Union.
The request should normally be sent to the organisation that decides why and how the information is processed. This organisation is the data controller. A processor, such as a cloud hosting provider or email delivery service, usually acts on the controller’s instructions and may not be able to decide the request independently.
A privacy notice, account settings page, or data protection contact should identify the controller and its data protection officer where one is appointed. If several businesses are involved, send the request to the company with which you have a relationship and ask it to coordinate with relevant processors or partners.
The controller may ask for reasonable information to verify identity. This is intended to prevent someone from deleting another person’s account or personal records. It should not become an excuse to demand excessive documents. In many situations, confirming an email address, account number, or recent transaction is sufficient. If identity checks are disproportionate, the request may itself raise a data protection concern.
How To Submit A Clear Request
A deletion request can be made verbally or in writing, although email or an online form creates a useful record. State that you are exercising your right to erasure under Article 17 GDPR. Include the account email address, customer reference, username, telephone number, or other details that help the controller locate the relevant records.
Be specific about the scope. You might request deletion of a user account, direct-marketing profile, location history, support correspondence, or all personal data that is not subject to a lawful retention duty. If you want marketing to stop but still need an account for an active service, distinguish between those objectives. A request to erase everything could interfere with a contract you still rely on.
It is also reasonable to ask the organisation to confirm which categories were deleted, which were retained, the legal basis for retaining them, and whether recipients were informed. Article 17 requires a controller that has disclosed personal data to take reasonable steps to tell other controllers about the erasure request, taking available technology and implementation costs into account.
Keep copies of the request and any acknowledgement. A simple subject line such as “Article 17 erasure request” helps route the message, while a short factual description avoids turning the process into an argument. Background reading on privacy and technology can also sharpen your understanding; Twenty of Time’s brain food collection offers a wider context for thinking about data rights and digital power.
| Stage | What normally happens | What to watch for |
|---|---|---|
| Request | You identify yourself and ask for deletion | Avoid sending unnecessary sensitive documents |
| Verification | The controller confirms your identity | The check should be proportionate |
| Assessment | The organisation reviews the Article 17 grounds and exceptions | Erasure is not automatically granted |
| Response | The controller deletes data or explains a refusal | The answer should identify relevant reasons |
| Follow-up | You can challenge an incomplete or unlawful response | Keep dates, messages, and evidence |
What The Controller Must Do
The controller must respond without undue delay and, in any event, within one month of receiving the request. The period can be extended by up to two further months when requests are complex or numerous, but the organisation must tell you within the first month and explain the reason for the delay.
A response should state whether the data has been erased. If the controller refuses, it should explain the reason and tell you about your right to complain to a supervisory authority and seek a judicial remedy. Silence is not a valid substitute for a decision.
Where the organisation has passed your personal data to other controllers, it must take reasonable steps to inform them of the request, subject to technical feasibility and proportionality. This does not mean every copy in every system will disappear instantly. Data may exist in live databases, archives, security logs, fraud-prevention tools, backups, and third-party services with different deletion schedules.
Backups illustrate the practical distinction between erasure and immediate physical destruction. A controller may isolate a backup so it is not restored into an active system, then delete the information during the normal backup cycle. It should not use backups as a permanent loophole, and it should have a defensible retention and restoration policy.
Why A Request May Be Refused
The right to erasure is qualified by Article 17 exceptions. A company may retain data when processing is necessary for freedom of expression and information, compliance with a legal obligation, or the performance of a task carried out in the public interest or under official authority.
Retention can also be justified for public health, archiving in the public interest, scientific or historical research, statistical purposes, or the establishment, exercise, or defence of legal claims. A bank may need transaction records to comply with financial regulations. An employer may have to preserve payroll information. A business defending a dispute may retain relevant correspondence even after closing an online account.
A controller may also refuse when it has a separate lawful basis that overrides the specific erasure ground. Withdrawing consent does not require deletion if the organisation can lawfully process the data under contract or a statutory obligation. Similarly, objecting to direct marketing should normally stop marketing, but it does not necessarily erase purchase records needed for accounting.
The refusal must still be carefully reasoned. “We have a legal obligation” is often too vague by itself. The organisation should identify the type of obligation, the categories of data retained, and, where appropriate, how long retention is expected to last. If only part of the record is necessary, partial erasure or restricted access may be more appropriate than keeping everything.
Online Profiles, Brokers, And Search Results
Deleting an account from a website does not automatically remove information copied by advertisers, data brokers, analytics platforms, or public search engines. Each organisation may be a separate controller, with its own source of the data and its own legal assessment. A request to the original service therefore may not reach every downstream recipient.
This matters when the information is used for behavioural advertising or location intelligence. Investigations into location data brokers show how personal information can move through commercial ecosystems that are difficult for individuals to see. If a company has shared your data, ask who received it and whether those recipients were notified.
Search engine delisting is related but distinct. A search provider may remove links from results for searches involving a person’s name when privacy rights outweigh public-interest considerations. The source page may remain online, meaning delisting is not the same as deletion. Public figures, journalism, criminal records, and information that remains relevant to public debate can receive different treatment.
Internet service providers create another separate layer. Deleting an account with a website does not control browsing information held by an ISP, and an ISP may have its own statutory retention rules. Understanding ISP browsing history can help distinguish a GDPR erasure request from a request about network-level collection and disclosure.
Turning A Refusal Into A Review
If the answer is incomplete, first compare it with the scope of your original request. The controller may have deleted the active account but retained billing records, or removed direct identifiers while keeping a pseudonymous advertising profile. Ask for clarification in writing rather than assuming that a general confirmation covers every system.
You can also request access to your personal data before or alongside erasure. An access request may reveal the categories of information, recipients, retention periods, and legal bases involved. That information can make a later deletion request more precise, although a controller may need to balance disclosure against the rights of other people.
If the organisation misses the deadline, gives no meaningful reason, or appears to retain data unlawfully, complain to the relevant data protection authority. The appropriate authority may depend on where the controller is established and where the processing affects you. You can also consider court proceedings, particularly where ongoing publication, profiling, or financial harm makes the issue urgent.
Practical Steps For A Stronger Request
A well-documented request reduces confusion and creates evidence if the matter escalates. Before sending it, identify the organisation, decide whether you want full or partial deletion, and separate erasure from related goals such as stopping marketing or closing a contract.
Use these practical steps:
- Name the account, service, or data category involved and provide a reasonable identifier.
- Cite Article 17 GDPR and state whether you are withdrawing consent, objecting to processing, or asking for deletion because the data is no longer necessary.
- Ask the controller to notify relevant recipients and identify any data it must retain.
- Request a written response within the GDPR’s one-month deadline.
- Save the request, identity-verification messages, response, and dates in one file.
The strongest requests remain calm and narrowly factual. They do not need legal jargon, threats, or a long account of personal circumstances. If the controller refuses, its explanation gives you the information needed to assess whether a supervisory-authority complaint or further access request is justified.
The right to erasure works best as a targeted legal mechanism rather than a promise of total disappearance. It can remove unnecessary profiles, end unwanted processing, and force organisations to account for information shared with others. It cannot override every retention rule, public-interest purpose, or legal claim.
When sending a request, focus on the data, the purpose, and the organisation responsible for the processing. Keep a clear record of what happens next, and use the GDPR’s complaint process when a controller ignores its duties or relies on an unexplained exception. That is how an abstract privacy right becomes a practical way to regain control over personal information.