Right to Erasure and How To Handle It

Right to Erasure and How To Handle It

Updated: August 2026

The right to erasure, GDPR’s “right to be forgotten,” lets individuals ask a company to delete their personal data. Article 17 defines it, and it isn’t unconditional: GDPR sets out specific grounds for when the right applies and specific exceptions that let a company refuse. Here’s what qualifies, what doesn’t, and how to handle a request when one lands on your desk.

Key Takeaways

The right to erasure only applies in specific circumstances, such as when data is no longer needed for the purpose it was collected for, consent has been withdrawn, or the data was processed unlawfully. It doesn’t give data subjects an unconditional right to delete everything a company holds on them.

Companies can lawfully refuse an erasure request in specific cases, including compliance with a legal obligation, exercising freedom of expression, public interest archiving or research, and establishing or defending legal claims.

Requests must be handled without undue delay, generally within one month. Complex requests can be extended by up to two months, but the individual has to be told the reason for the delay before the first month is up.

What is the Right to Erasure?

The Right to Be Forgotten is a fundamental right defined in GDPR. Also known as the Right to Erasure, this principle is defined in Article 17. Companies must recognise these requests and know how to handle them.

Most importantly, the Right to Erasure is not absolute, and companies may retain certain information where required to protect themselves from legal action or to operate their business.

If you receive an RTE, please feel free to contact us – we are always happy to help.  You can find more info from the ICO here: https://ico.org.uk/for-organisations/guide-to-data-protection/guide-to-the-general-data-protection-regulation-gdpr/individual-rights/right-to-erasure/

For more background, please keep reading.

RTE – Not an Absolute Right!

One of the highest-profile forms of data privacy protection is the “Right to Erasure,” or, as we most commonly know it, “The Right to Be Forgotten.” The idea of having the power to compel a company to erase all data traces from their system is a nightmare – if you look from an organisation’s side. Engaging these requests accurately requires well-designed, robust, and perspective methods.

Under the General Data Protection Regulation (GDPR), the right to erasure, a.k.a. the right to be forgotten, is the hardest data subject right and the second most difficult GDPR obligation in practice.

Who Can Request Data Erasure?

Do you remember what Martin Luther King Jr. used to say, “a right delayed is a right denied”?  We’ll use this sentence in a different context today. These days, in the modern GDPR era, data subjects have more rights over their data than ever, with legal frameworks that set guidelines for exercising those rights. Data subjects can call on the right to erasure or access at any time for any data you hold about them, including fines. The words “delay” or “denied” don’t sound very nice, do they?

Imagine dozens of data subjects sending you requests all day, every day, and calling upon their rights. Your system will be in turmoil, not to mention the huge fines that will follow if you fail to provide what they need regarding their personal data.

Legal Basis for the Right to Erasure

So, what should you know about the notorious Right to Erasure?

Under Article 17 of the GDPR, for every natural person who requests erasure of personal data, the company must provide the service without undue delay. The Right to Erasure, or, as we most commonly know it, the right to be forgotten, does not always have absolute power. In fact, according to Article 17, the Right to Erasure only applies under the following conditions:

Personal data are no longer necessary in relation to the purposes for which they were collected or otherwise processed;

The data subject withdraws consent on which the processing is based according to point (a) of Article 6(1), or point (a) of Article 9(2) and where there is no other legal ground for the processing;

The data subject objects to the processing pursuant to Article 21(1), and there are no overriding legitimate grounds for the processing, or the data subject objects to the processing pursuant to Article 21(2);

The personal data have been unlawfully processed;

The personal data have to be erased for compliance with a legal obligation in Union or Member State law to which the controller is subject;

The personal data have been collected in relation to the offer of information society services referred to in Article 8(1);

When does the right to erasure not apply?

As stated above, the GDPR has a few exceptions around the right to erasure that give businesses a way to handle this nightmare more easily. According to Article 17, it is important to note that companies do not have to comply with an individual’s right to be forgotten under the following conditions: the companies do not have to comply with an individual’s rights, such as:

Exercising the right of freedom of expression and information;

For compliance with a legal obligation which requires processing by Union or Member State law to which the controller is subject or for the performance of a task carried out in the public interest or in the exercise of official authority vested in the controller;

For reasons of public interest in the area of public health in accordance with points (h) and (i) of Article 9(2) as well as Article 9(3);

For archiving purposes in the public interest, scientific or historical research purposes or statistical purposes in accordance with Article 89(1) in so far as the right referred to in paragraph 1 is likely to render impossible or seriously impair the achievement of the objectives of that processing; or

For the establishment, exercise, or defence of legal claims.

So now that you know what Article 17 of the GDPR says, should you be worried? Of course, you should. There is plenty you need to know about the Right to Erasure, but is there a way to handle it? Of course there is!

Becoming a fully GDPR-compliant organisation can be intimidating. You need a proactive game plan, but you must also be aware it might not be enough, so keep a backup plan in your sleeve. 

A great starting point is a thorough, company-wide data audit from both legal and technical standpoints to cover all bases.

First, review how you collect personal data and how you process it so you can be sure you are fully GDPR-compliant. Also, determine what data you will collect, why you have it, how you will use it, and for what purposes. It’s equally important to consider how you will dispose of outdated or irrelevant data and how you will safeguard the critical information you still need. Don’t forget to ask for the minimum information needed to confirm identity.

When Can a Business Refuse an Erasure Request?

Most customers think that deleting their data is a simple step, just a click away. Well, it’s not as easy as it looks.

The systems, applications, and databases that process personal data should let the organisation locate and delete it easily. This can be difficult, especially if the data is held across different systems or platforms. Sometimes, you might hold data in the cloud; you must ensure it is deleted everywhere. 

As mentioned above, you must act on a request without undue delay, which means you don’t have long to comply with the erasure. If the request is particularly complex, you might be able to extend it by two months. You must inform the individual before the first month is up by giving a clear reason for the delay. Also, be prepared for a visit from the regulator if an extension happens, because not every individual understands.

Keep the children in mind; they have special protection under the GDPR. The Right to Erasure is particularly relevant, especially if the data is available on the internet.

Conclusion

The key to compliance is having a full set of policies and procedures designed to protect all the information it processes. No matter what sector your company operates in or the size of your business, it is essential. If your company breaks any data protection laws, it could face an investigation by your supervisory authority, which may impose punishments ranging from hefty fines to enforcement notices. For these reasons, an organisation must ensure compliance with a formalised set of data protection policies and procedures.

Frequently Asked Questions

What is the right to erasure under GDPR?

It’s the right, set out in Article 17, for an individual to ask a company to delete personal data held about them. It’s also known as the right to be forgotten, and it applies without undue delay after the company receives a valid request.

When doesn’t the right to erasure apply?

It doesn’t apply where the company needs to keep processing the data to exercise freedom of expression, comply with a legal obligation, perform a task in the public interest, carry out public health or archiving/research purposes, or establish, exercise, or defend a legal claim.

How long does a company have to respond to an erasure request?

Without undue delay, and generally within one month. If the request is particularly complex, the company can extend the period by up to two months, but it must tell the individual why before the first month is up.

Can a business ever refuse to delete someone’s data?

Yes, in the specific circumstances GDPR sets out under Article 17, such as a legal obligation to retain the data, an ongoing legal claim, or freedom of expression concerns. Outside those exceptions, you must action a valid erasure request.

About the Author

Zlatko Delev

Head of Commercial & Country Manager

Zlatko Delev is Head of Commercial and Country Manager at GDPRLocal, where he leads the company’s commercial strategy and market presence. He brings international experience across sales, marketing, and customer success, along with a legal background from his studies at Iustinianus Primus Law School in Skopje, Macedonia.

Zlatko sits at the front line of GDPRLocal’s client relationships, guiding organisations through the first stages of their compliance journey and helping them understand where they stand and where they need to go on GDPR, information security, and the emerging landscape of AI regulation. His role bridges commercial strategy with practical data protection knowledge, ensuring clients get clear, actionable direction from their very first conversation with GDPRLocal.

Alongside his commercial focus, Zlatko has trained extensively in project management and organisational leadership, including risk management, stakeholder communication, agile methodology, and digital marketing, a broad skill set that supports his structured, delivery-focused approach to growing GDPRLocal’s business internationally.