Updated: August 2026
The right to erasure, GDPR’s “right to be forgotten,” lets individuals ask a company to delete their personal data. Article 17 defines it, and it isn’t unconditional: GDPR sets out specific grounds for when the right applies and specific exceptions that let a company refuse. Here’s what qualifies, what doesn’t, and how to handle a request when one lands on your desk.
• The right to erasure only applies in specific circumstances, such as when data is no longer needed for the purpose it was collected for, consent has been withdrawn, or the data was processed unlawfully. It doesn’t give data subjects an unconditional right to delete everything a company holds on them.
• Companies can lawfully refuse an erasure request in specific cases, including compliance with a legal obligation, exercising freedom of expression, public interest archiving or research, and establishing or defending legal claims.
• Requests must be handled without undue delay, generally within one month. Complex requests can be extended by up to two months, but the individual has to be told the reason for the delay before the first month is up.
The Right to Be Forgotten is a fundamental right defined in GDPR. Also known as the Right to Erasure, this principle is defined in Article 17. Companies must recognise these requests and know how to handle them.
Most importantly, the Right to Erasure is not absolute, and companies may retain certain information where required to protect themselves from legal action or to operate their business.
If you receive an RTE, please feel free to contact us – we are always happy to help. You can find more info from the ICO here: https://ico.org.uk/for-organisations/guide-to-data-protection/guide-to-the-general-data-protection-regulation-gdpr/individual-rights/right-to-erasure/
For more background, please keep reading.
One of the highest-profile forms of data privacy protection is the “Right to Erasure,” or, as we most commonly know it, “The Right to Be Forgotten.” The idea of having the power to compel a company to erase all data traces from their system is a nightmare – if you look from an organisation’s side. Engaging these requests accurately requires well-designed, robust, and perspective methods.
Under the General Data Protection Regulation (GDPR), the right to erasure, a.k.a. the right to be forgotten, is the hardest data subject right and the second most difficult GDPR obligation in practice.
Do you remember what Martin Luther King Jr. used to say, “a right delayed is a right denied”? We’ll use this sentence in a different context today. These days, in the modern GDPR era, data subjects have more rights over their data than ever, with legal frameworks that set guidelines for exercising those rights. Data subjects can call on the right to erasure or access at any time for any data you hold about them, including fines. The words “delay” or “denied” don’t sound very nice, do they?
Imagine dozens of data subjects sending you requests all day, every day, and calling upon their rights. Your system will be in turmoil, not to mention the huge fines that will follow if you fail to provide what they need regarding their personal data.
So, what should you know about the notorious Right to Erasure?
Under Article 17 of the GDPR, for every natural person who requests erasure of personal data, the company must provide the service without undue delay. The Right to Erasure, or, as we most commonly know it, the right to be forgotten, does not always have absolute power. In fact, according to Article 17, the Right to Erasure only applies under the following conditions:
• Personal data are no longer necessary in relation to the purposes for which they were collected or otherwise processed;
• The data subject withdraws consent on which the processing is based according to point (a) of Article 6(1), or point (a) of Article 9(2) and where there is no other legal ground for the processing;
• The data subject objects to the processing pursuant to Article 21(1), and there are no overriding legitimate grounds for the processing, or the data subject objects to the processing pursuant to Article 21(2);
• The personal data have been unlawfully processed;
• The personal data have to be erased for compliance with a legal obligation in Union or Member State law to which the controller is subject;
• The personal data have been collected in relation to the offer of information society services referred to in Article 8(1);
As stated above, the GDPR has a few exceptions around the right to erasure that give businesses a way to handle this nightmare more easily. According to Article 17, it is important to note that companies do not have to comply with an individual’s right to be forgotten under the following conditions: the companies do not have to comply with an individual’s rights, such as:
• Exercising the right of freedom of expression and information;
• For compliance with a legal obligation which requires processing by Union or Member State law to which the controller is subject or for the performance of a task carried out in the public interest or in the exercise of official authority vested in the controller;
• For reasons of public interest in the area of public health in accordance with points (h) and (i) of Article 9(2) as well as Article 9(3);
• For archiving purposes in the public interest, scientific or historical research purposes or statistical purposes in accordance with Article 89(1) in so far as the right referred to in paragraph 1 is likely to render impossible or seriously impair the achievement of the objectives of that processing; or
• For the establishment, exercise, or defence of legal claims.
So now that you know what Article 17 of the GDPR says, should you be worried? Of course, you should. There is plenty you need to know about the Right to Erasure, but is there a way to handle it? Of course there is!
Becoming a fully GDPR-compliant organisation can be intimidating. You need a proactive game plan, but you must also be aware it might not be enough, so keep a backup plan in your sleeve.
A great starting point is a thorough, company-wide data audit from both legal and technical standpoints to cover all bases.
First, review how you collect personal data and how you process it so you can be sure you are fully GDPR-compliant. Also, determine what data you will collect, why you have it, how you will use it, and for what purposes. It’s equally important to consider how you will dispose of outdated or irrelevant data and how you will safeguard the critical information you still need. Don’t forget to ask for the minimum information needed to confirm identity.
Most customers think that deleting their data is a simple step, just a click away. Well, it’s not as easy as it looks.
The systems, applications, and databases that process personal data should let the organisation locate and delete it easily. This can be difficult, especially if the data is held across different systems or platforms. Sometimes, you might hold data in the cloud; you must ensure it is deleted everywhere.
As mentioned above, you must act on a request without undue delay, which means you don’t have long to comply with the erasure. If the request is particularly complex, you might be able to extend it by two months. You must inform the individual before the first month is up by giving a clear reason for the delay. Also, be prepared for a visit from the regulator if an extension happens, because not every individual understands.
Keep the children in mind; they have special protection under the GDPR. The Right to Erasure is particularly relevant, especially if the data is available on the internet.
The key to compliance is having a full set of policies and procedures designed to protect all the information it processes. No matter what sector your company operates in or the size of your business, it is essential. If your company breaks any data protection laws, it could face an investigation by your supervisory authority, which may impose punishments ranging from hefty fines to enforcement notices. For these reasons, an organisation must ensure compliance with a formalised set of data protection policies and procedures.
It’s the right, set out in Article 17, for an individual to ask a company to delete personal data held about them. It’s also known as the right to be forgotten, and it applies without undue delay after the company receives a valid request.
It doesn’t apply where the company needs to keep processing the data to exercise freedom of expression, comply with a legal obligation, perform a task in the public interest, carry out public health or archiving/research purposes, or establish, exercise, or defend a legal claim.
Without undue delay, and generally within one month. If the request is particularly complex, the company can extend the period by up to two months, but it must tell the individual why before the first month is up.
Yes, in the specific circumstances GDPR sets out under Article 17, such as a legal obligation to retain the data, an ongoing legal claim, or freedom of expression concerns. Outside those exceptions, you must action a valid erasure request.