Data Dictionary

Right to erasure

What is the right to erasure?

The right to erasure lets a person ask an organisation to delete the personal data it holds about them, and obliges the organisation to do so when one of a defined set of conditions applies. It is set out in Article 17 of the GDPR and is widely known as the right to be forgotten.

The right is not absolute, and this is the point most people miss. A request does not mean everything must be deleted on demand. Erasure is required only when a specific ground applies, and even then several exceptions can override it. An organisation that keeps invoices to satisfy tax law, for example, does not have to delete them just because a customer asks.

For businesses, the right turns a legal duty into a practical one: you have to be able to find every copy of a person's data across your systems, decide whether an erasure ground applies, and act within the deadline. That is harder than it sounds once data has spread through warehouses, backups, logs, and downstream tools.

When erasure applies

Article 17(1) lists the grounds that trigger the right. Erasure is required when:

  • The data is no longer needed. The personal data is no longer necessary for the purpose it was collected for.

  • Consent is withdrawn. The person withdraws the consent the processing relied on, and there is no other legal basis to keep going.

  • The person objects. They object to the processing and there are no overriding legitimate grounds, or they object to direct marketing.

  • The data was processed unlawfully. The processing broke the rules in the first place.

  • A legal obligation requires deletion. Union or Member State law says the data must be erased.

  • It concerns a child's data. The data was collected from a child in the context of online services offered to them.

There is a further duty in Article 17(2): if the organisation made the data public, it has to take reasonable steps, including technical measures, to tell other organisations processing that data that the person has asked for it to be erased.

The exceptions

Article 17(3) sets out where the right does not apply because keeping the data is necessary. The main exceptions cover processing needed for the right to freedom of expression and information, for compliance with a legal obligation or a task carried out in the public interest, for reasons of public interest in public health, for archiving in the public interest and scientific, historical, or statistical purposes where erasure would make those purposes impossible or seriously impair them, and for the establishment, exercise, or defence of legal claims.

In everyday terms, a request cannot be used to wipe records you are legally required to retain, to erase a journalistic archive, or to destroy evidence needed for a live dispute. When an exception applies, you keep the data and explain why.

What erasure means for data systems

The legal test is only half the job. The other half is technical: personal data rarely sits in one place. A single customer's PII can live in the operational database, a data warehouse, last night's backups, application logs, and the marketing and support tools it was synced out to. An erasure request has to reach all of them.

A few realities make this hard:

  • Backups resist deletion. You cannot easily surgically remove one person from an immutable backup. A common approach is to document that backups age out on a fixed schedule and to re-erase if a backup is ever restored.

  • Copies travel downstream. If data was pushed to a CRM or an email platform, those copies need erasing too, not just the source.

  • Deletion is not the only answer. Where a record must stay for analytics or legal reasons, anonymisation and pseudonymisation can be an alternative: strip or scramble the identifying fields so the data no longer relates to a person, and the erasure obligation falls away because it is no longer personal data. True anonymisation has to be irreversible to count.

This is where the right ties into data retention and data governance. If you already know what personal data you hold, where it flows, and how long each system keeps it, an erasure request is a process you can run. If you do not, every request becomes a manual hunt.

Responding to a request

Under the GDPR you generally have to respond without undue delay and within one month of receiving a request, with a possible extension of two further months for complex or numerous requests. You also have to confirm back to the person what you have done. Building this as a repeatable process, with a clear owner and a checklist of every system that holds personal data, beats improvising each time a request lands.

Last Updated: July 17, 2026 Back to Dictionary
Keywords
right to erasure right to be forgotten gdpr article 17 pii data retention anonymisation and pseudonymisation data governance privacy governance