What is the "Right to Erasure" (or "Right to be Forgotten") under the GDPR?
The GDPR's right to erasure, also known as the right to be forgotten, allows individuals to request the deletion of their personal data in specific circumstances. This guide explains when the right applies, its exceptions, controllers' obligations, response deadlines, and practical compliance tips.
Key points: (1) The GDPR gives individuals the right to request that their personal data be erased in certain circumstances. This is commonly known as the right to be forgotten. (2) Individuals may submit an erasure request verbally or in writing. (3) Controllers must respond without undue delay and, in most cases, within one month. (4) The right is not absolute and only applies where one of the grounds in Article 17 GDPR is satisfied. (5) Even where no request is made, organizations must delete personal data when retention is no longer justified under the GDPR's storage limitation principle.
What is the right to erasure and why is it important?
The right to erasure, commonly referred to as the right to be forgotten, allows individuals to request that an organization delete personal data concerning them when there is no lawful reason to continue processing it. The right is intended to give individuals greater control over their personal information and to ensure that organizations do not retain personal data longer than necessary.
The right is closely linked to several of the GDPR's core principles, particularly lawfulness, purpose limitation, and storage limitation. It recognizes that personal data should not be kept indefinitely and that individuals should, in appropriate circumstances, be able to require organizations to remove information that is no longer needed or lawfully processed.
However, the right to erasure is not absolute. Organizations are only required to erase personal data where one of the specific grounds in Article 17 GDPR applies, and none of the statutory exceptions prevent deletion.
Article 17 establishes both:
- the individual's right to obtain the erasure of personal data without undue delay; and
- the controller's corresponding obligation to erase that data when one of the legal grounds applies.
In addition, where the controller has made the personal data public, Article 17 requires the controller to take reasonable steps, taking into account available technology and implementation costs, to inform other controllers processing the data that the individual has requested the deletion of any links, copies, or replications of that personal data.
Unlike some other GDPR rights, however, the right to erase does not apply to all types of processing. Whether it is available depends on the purpose of the processing and the legal basis the organization relies on.

An individual may request the erasure of personal data where any of the following circumstances applies:
- The data is no longer necessary for the purposes for which it was originally collected or processed.
- Consent was the legal basis for processing and the individual withdraws that consent, with no other lawful basis remaining.
- The individual objects to processing based on legitimate interests, and the controller cannot demonstrate overriding legitimate grounds to continue processing.
- The individual objects to processing for direct marketing, in which case the processing for that purpose must stop.
- The personal data has been processed unlawfully, such as where there is no valid legal basis for the processing.
- Erasure is required to comply with a legal obligation under EU or Member State law.
- The personal data was collected with consent in connection with the offer of information society services directly to a child as described in Article 8.
Although the right to erasure is an important data subject right, it does not guarantee deletion whenever an individual requests it. Controllers must assess each request carefully and determine whether one of the Article 17 grounds applies and whether any of the statutory exceptions prevent erasure.
The GDPR seeks to balance an individual's privacy rights against other important legal and societal interests, including freedom of expression, legal obligations, scientific research, public health, and the administration of justice.
As a result, organizations should evaluate every erasure request on its specific facts rather than automatically granting or refusing it.
How can an Erasure Request be made?
EU data protection law does not prescribe any specific form for making a request for erasure. An individual may make a request verbally or in writing, and it may be submitted to any department within the organization. The request does not need to be directed to a specific individual or contact point, nor must it refer to the "right to erasure," the "right to be forgotten," or cite any particular legal provision.
A request is valid as long as the individual clearly indicates that they want their personal data deleted or erased.
Because any employee could potentially receive a valid request, organizations should ensure that staff who regularly interact with data subjects are trained to recognize erasure requests and promptly forward them to the appropriate personnel for handling.
Verifying the individual's identity
Where a controller has reasonable doubts about the identity of the person making an erasure request, it may ask for additional information to verify the requester's identity. However, the controller should request only the information that is necessary to confirm the individual's identity. The guiding principle is proportionality.
The one-month period for responding to the request begins once the controller has received the additional information necessary to verify the individual's identity.
When requesting additional information, the controller must inform the individual, without undue delay, of:
- the reasons why the additional information is being requested;
- the right to lodge a complaint with the competent supervisory authority; and
- the right to seek a judicial remedy to enforce their rights under the GDPR.
Organizations should avoid requesting excessive identification, particularly where they already have sufficient information to verify the individual's identity. The identity verification process should be proportionate to the nature of the personal data involved and the risks associated with unauthorized disclosure or deletion.
Fulfilling an Erasure Request
Once a controller determines that an erasure request is valid and that no exception applies, it must take all reasonable steps to permanently erase the individual's personal data without undue delay.
Depending on the organization's systems and infrastructure, complying with an erasure request may require more than simply deleting information from active databases. Controllers should ensure that the erasure process addresses all relevant copies of the personal data, including data stored in backup systems where appropriate.
As a general matter, organizations should:
- erase the personal data from live or production systems;
- ensure that the data is also addressed within backup and disaster recovery systems;
- inform the individual how the organization will implement the erasure request, including how data contained in backups will be handled; and
- implement technical and organizational measures to prevent deleted data from being restored or used again unless a lawful basis exists.
What about backup systems? Immediate deletion from backup systems is not always technically feasible. In many organizations, backups are designed to preserve the integrity of entire systems rather than permit the selective deletion of individual records. Where immediate deletion from backups is not possible, controllers should ensure that the personal data is placed "beyond use." In practice, this may mean that the backup copy is retained solely until it is overwritten in accordance with the organization's normal backup retention schedule and must not be restored or used for any other purpose except where strictly necessary (for example, disaster recovery). Controllers should document these technical limitations and ensure that backup retention practices are consistent with the GDPR's storage limitation principle and the organization's documented retention policies.
Best practices for handling a deletion request

Although the GDPR does not require organizations to adopt formal procedures for handling erasure requests, establishing internal processes helps ensure that requests are handled consistently, efficiently, and in compliance with Article 17.
As a matter of good practice, organizations should:
- maintain a policy for recording the details of erasure requests, particularly those made by telephone or in person;
- confirm with the individual that the organization has correctly understood the scope of the erasure request, helping to avoid misunderstandings or later disputes;
- keep a log of verbal erasure requests and the actions taken in response;
- document the legal basis for granting or refusing each request, including any applicable exceptions under Article 17(3); and
- maintain records demonstrating when the personal data was erased and, where applicable, how other controllers or processors were notified.
Organizations may also provide standard request forms to make the process easier for individuals. However, the GDPR does not require individuals to use a particular form, and a controller cannot refuse to act on an otherwise valid erasure request simply because it was submitted in a different format.
Personal Data Collected from Children. The GDPR places particular emphasis on the right to erasure where the request relates to personal data collected from a child.
- Controllers and processors should give special consideration to erasure requests involving personal data that was collected from or about children, particularly where the processing relates to online services.
- This enhanced protection continues to apply even after the individual is no longer a child, recognizing that children (or their parents) may not have fully understood the risks or long-term consequences of consenting to the processing of their personal data at the time it was collected.
Informing Others About the Erasure.
In certain circumstances, the GDPR requires controllers to notify other organizations that personal data has been erased. This obligation arises where:
- the personal data has been disclosed to other recipients; or
- the personal data has been made public, such as on websites, social media platforms, online forums, or other publicly accessible online services.
Personal data disclosed to others. Where the controller has disclosed the personal data to other recipients, it must take reasonable steps to inform each recipient of the erasure, unless doing so proves impossible or involves a disproportionate effort. Upon request, the controller must also inform the individual of the recipients to whom the erasure notification has been sent. For these purposes, the GDPR defines a recipient broadly to include any natural or legal person, public authority, agency, or other body to whom personal data has been disclosed, including other controllers, processors, and persons acting under their authority who are authorized to process the data.
Personal data made public. Where the controller has made the personal data public, Article 17(2) requires the controller to take reasonable steps, taking into account available technology and the cost of implementation, to inform other controllers processing that data that the individual has requested the erasure of:
- any links to the personal data; and
- any copies or replications of that personal data.
The GDPR recognizes that controllers cannot always guarantee the complete removal of publicly available information, but they must take reasonable and proportionate measures to notify other controllers of the erasure request.
Responsibility for complying with an erasure request rests with the controller. Controllers must ensure that they have appropriate contractual arrangements in place with their processors so that erasure requests are handled properly, regardless of whether the request is received directly by the controller or by the processor. The time limit for responding to an erasure request cannot be extended simply because the controller must rely on a processor to assist in fulfilling the request.
Time Limits, Refusals, and Fees
Under the GDPR, controllers must respond to a request for erasure without undue delay and, in most cases, within one month of receiving the request. In certain circumstances, this deadline may be extended where permitted by the GDPR.
When Can a Controller Refuse a Request?: The right to erasure is not absolute. Although Article 17 gives individuals the right to request the deletion of their personal data in certain circumstances, controllers may refuse an erasure request where the GDPR provides an applicable exception.
A controller is not required to erase personal data where processing is necessary:
- to exercise the right to freedom of expression and information;
- to comply with a legal obligation;
- for the performance of a task carried out in the public interest or in the exercise of official authority;
- for archiving purposes in the public interest, scientific or historical research, or statistical purposes where erasure would make those purposes impossible or seriously impair them; or
- for the establishment, exercise, or defense of legal claims.
Special Categories of Data: The GDPR also recognizes additional exceptions for special category data. The right to erasure does not apply where processing is necessary:
- for public health purposes in the public interest, such as protecting against serious cross-border threats to health or ensuring high standards of quality and safety for healthcare, medicinal products, or medical devices; or
- for preventive or occupational medicine, medical diagnosis, the provision of health or social care, or the management of health or social care systems or services, where the data is processed by, or under the responsibility of, a professional who is subject to a legal duty of confidentiality.
In addition, Member State law may restrict the right to erasure in certain circumstances.
Manifestly Unfounded or Excessive Requests: Where a controller determines that an erasure request is manifestly unfounded or excessive, it may:
- charge a reasonable fee to cover the administrative costs of handling the request; or
- refuse to act on the request.
If the controller refuses to comply with an erasure request, it must inform the individual without undue delay and, in any event, within one month of receiving the request. The response must explain:
- the reasons for refusing the request;
- the individual's right to lodge a complaint with the competent supervisory authority; and
- the individual's right to seek a judicial remedy.

Additional Reading
Article 17 GDPR
Suitable Recitals: (65) Right of Rectification and Erasure (66) Right to be Forgotten