← Glossary

Regulation & Compliance

Right to erasure ("right to be forgotten")

Also: right to be forgotten · GDPR Article 17 · erasure request · deletion request · data deletion

Last reviewed: — regulation changes; check the primary source below before relying on a date or a threshold.

In one sentence

The right to erasure, in Article 17 of the GDPR, obliges an organisation to delete your personal data without undue delay when one of six grounds applies, for example when it no longer needs the data or when you withdraw consent, unless an exception such as a legal obligation to keep it applies.

When an organisation must delete your data

Article 17(1) lists six grounds. One is enough:

  1. the data is no longer necessary for the purpose it was collected for;
  2. you withdraw your consent and there is no other legal ground;
  3. you object under Article 21, for example to direct marketing, and (for 21(1)) there are no overriding legitimate grounds;
  4. the data was processed unlawfully;
  5. a legal obligation requires erasure;
  6. the data was collected when you were a child, in relation to an online service.

If the organisation had made the data public, Article 17(2) also requires it to take reasonable steps to tell other organisations processing it that you asked for erasure of links and copies.

When it may refuse

Article 17(3) lists the exceptions: processing that is necessary for freedom of expression and information, for a legal obligation or a public-interest task, for public health, for archiving, research or statistics in the public interest, or for establishing, exercising or defending legal claims. A bank that must keep transaction records for a legal retention period can refuse to delete them, but must still delete what it does not need for that purpose, such as marketing profiles.

The deadline is the same as for an access request (Article 12(3)): one month, extendable by two further months with notice. A refusal must give reasons and mention the right to complain to a supervisory authority (Article 12(4)).

Try it yourself hands-on

Bob Sample closed his account at Example Games Ltd two years ago and still receives their newsletters.

  1. Open the GDPR Request Generator with Erasure (Art. 17) selected.
  2. Fill in the organisation (Example Games Ltd), his name (Bob Sample) and the e-mail address he used with them (bob@example.com) so they can find the record.
  3. Under Why should they erase it?, tick They no longer need it for the purpose they collected it for (17(1)(a)), since the account is closed, and I object under Article 21 (17(1)(c)) for the newsletters. For direct marketing an objection needs no reason and cannot be overridden (Article 21(2) and (3)).
  4. Copy or download the letter and keep proof of the date you sent it. The tool shows when the one-month deadline ends.

Not sure what they hold? Send an access request first, then ask for erasure of what you find.

Common misreadings

  • It is not absolute. Data kept under a legal obligation (invoices, for example) may stay; ask what is kept, why and until when.
  • Unsubscribing is not erasure. An unsubscribe link usually adds you to a suppression list; your profile may remain. Ask for erasure explicitly if that is what you want.
  • Search engines are a separate request. Removing a search result about you is a request to the search engine, not to the site that published the page.