The Right to Erasure, commonly referred to as the “Right to Be Forgotten”, is one of the most powerful and most frequently invoked rights under the General Data Protection Regulation (GDPR). Codified in Article 17 GDPR, it allows individuals to require organisations to delete personal data concerning them without undue delay where certain legal conditions are met.

For businesses, the right to erasure operates at the intersection of legal compliance, data governance, and operational reality. While often described in broad terms, the right is neither absolute nor automatic. It requires careful assessment of legal grounds, retention requirements, competing rights, and technical feasibility. European regulators have repeatedly signalled that failures in erasure handling are a significant source of complaints and enforcement risk.

This page explains when the right to erasure applies, when it does not, how it must be implemented in practice, and what regulators expect from businesses when handling erasure requests.

Legal Basis and Purpose of the Right to Erasure

Article 17 GDPR provides that a data subject has the right to obtain from the controller the erasure of personal data concerning them without undue delay, and that the controller has a corresponding obligation to erase such data where one of several specified grounds applies.

The purpose of this right is closely linked to core GDPR principles such as data minimisation, purpose limitation, storage limitation, and lawfulness of processing. Once personal data is no longer justified by a lawful purpose, individuals must have the ability to require its removal. This is particularly important in a digital environment where data can persist indefinitely and be replicated across systems, platforms, and third parties.

When Does the Right to Erasure Apply?

The right to erasure applies only where at least one of the grounds set out in Article 17(1) GDPR is satisfied. These grounds are exhaustive and must be assessed case by case.

Data Is No Longer Necessary

Erasure is required where personal data is no longer necessary in relation to the purposes for which it was collected or otherwise processed. This ground reflects the storage limitation principle and commonly applies where a contractual relationship has ended, a service has been discontinued, or data has outlived its operational purpose. Controllers should be able to demonstrate why data remains necessary if they refuse erasure on this basis.

Withdrawal of Consent

Where processing is based on consent and the data subject withdraws that consent, erasure must follow unless another lawful basis applies. Consent must be revocable, and organisations cannot continue processing simply for convenience once consent has been withdrawn.

Successful Objection to Processing

Where a data subject objects to processing under Article 21 GDPR and there are no overriding legitimate grounds for continuing that processing, erasure is required. For direct marketing, the balance is stricter: where a data subject objects, processing must cease and erasure must follow.

Unlawful Processing

Personal data that has been processed unlawfully—whether due to lack of legal basis, breach of data-protection principles, or non-compliance with transparency obligations—must be erased.

Legal Obligation to Erase

Erasure is also mandatory where required by EU or Member State law. This may arise, for example, in response to sector-specific rules or court orders.

Children’s Data in Information Society Services

Special emphasis is placed on erasing personal data collected from children in connection with information society services. Regulators attach particular importance to this ground, reflecting heightened vulnerability and long-term risk.

The Right to Erasure Is Not Absolute: Exceptions under Article 17(3)

One of the most common misunderstandings is that the right to be forgotten allows individuals to delete any personal data on demand. Article 17(3) sets out important exceptions where erasure does not apply.

Freedom of Expression and Information

Processing necessary for the exercise of the right to freedom of expression and information may override erasure requests. This exception plays a central role in media, publishing, academic, and archival contexts, and often requires careful balancing.

Legal Obligations and Public Interest Tasks

Where processing is necessary to comply with a legal obligation or to perform a task carried out in the public interest or in the exercise of official authority, data must not be erased. Common examples include tax records, employment law obligations, and regulatory record-keeping.

Public Health, Research, and Archiving

Erasure may be restricted where data is processed for public-interest purposes in the area of public health, or for scientific, historical, or statistical research, provided appropriate safeguards are in place.

Establishment, Exercise, or Defence of Legal Claims

Data necessary for current or anticipated legal claims must generally be retained. Regulators consistently recognise litigation hold obligations as a legitimate bar to erasure.

These exceptions mean that organisations must evaluate erasure requests through a legal lens, not merely a technical one.

What Does “Erasure” Mean in Practice?

Erasure requires actual deletion of personal data, not simply restricting access or hiding data from view. Regulators have made clear that disabling accounts or anonymising data improperly may not satisfy Article 17, particularly where data remains identifiable or recoverable.

Back-Ups and Archives

Supervisory authorities acknowledge that immediate deletion from backup systems may not always be technically feasible. However, controllers must ensure that erased data is not restored or used from backups, that restoration processes preserve erasure instructions, and that deletion occurs on the next backup cycle where possible. Failure to address backup systems explicitly is a common compliance gap identified by regulators.

Obligation to Inform Third Parties (Article 19 GDPR)

Where a controller has shared personal data with other recipients, Article 19 GDPR requires the controller to inform those recipients of the erasure request, unless this proves impossible or involves disproportionate effort.

Additionally, where data has been made public, controllers must take reasonable steps—taking into account available technology and the cost of implementation—to inform other controllers processing that data of the erasure request, including the removal of links or copies. This obligation reflects the origin of the “right to be forgotten” concept in case law concerning online publication.

Recognising and Handling Erasure Requests

No Formal Requirements

As with other GDPR rights, no specific wording is required. Any communication requesting deletion, removal, or “forgetting” of personal data may constitute an erasure request. Organisations must ensure staff can recognise such requests across all channels.

Time Limits

Controllers must respond without undue delay and in any event within one month. Extensions of up to two additional months are permitted for complex cases, but only if the data subject is informed within the initial period.

Verification of Identity

Identity verification is permitted where necessary, but must be proportionate and should not be used to frustrate the exercise of rights.

When Can a Controller Refuse an Erasure Request?

Where none of the Article 17(1) grounds apply, or where an Article 17(3) exception clearly overrides the request, a controller may refuse erasure.

Refusals must be reasoned and lawful, communicated clearly and transparently, and accompanied by information about the right to complain to a supervisory authority or seek a judicial remedy. In practice, regulators closely scrutinise refusals, particularly where controllers rely on broad claims such as “legal obligation” or “legitimate interest” without supporting analysis.

Enforcement Focus and Regulatory Trends

The right to erasure has been a major focus of enforcement activity across Europe. In 2025, the European Data Protection Board (EDPB) selected erasure as the topic of its Coordinated Enforcement Framework (CEF) action, involving 32 supervisory authorities and hundreds of controllers across sectors.

That coordinated action identified recurring weaknesses, including lack of documented erasure procedures, inconsistent application of exceptions, reliance on ineffective anonymisation instead of true deletion, and insufficient communication with data subjects. Regulators have made clear that erasure compliance is no longer assessed in isolation, but as an indicator of overall governance maturity.

The Right to Erasure and Data Governance

From a business perspective, erasure requests often expose broader data-management issues. Effective compliance depends on accurate data mapping and inventories, clear retention schedules, system-wide deletion capabilities, and vendor and processor coordination.

Organisations that cannot identify where data is held or shared cannot comply with erasure obligations effectively. Regulators increasingly link erasure compliance with Article 30 records of processing and data-mapping accuracy.

Sector-Specific Considerations

The practical operation of the right to erasure varies significantly by sector. Online platforms, employment contexts, financial services, healthcare, and research environments each raise distinct balancing questions between erasure and competing obligations.

Businesses operating in regulated or high-risk sectors should expect enhanced scrutiny and should document their legal assessments carefully.

Conclusion

The Right to Erasure (Right to Be Forgotten) under Article 17 GDPR is a core mechanism through which individuals regain control over their personal data. For businesses, it is one of the most legally complex GDPR rights, requiring careful analysis of lawful bases, exceptions, technical feasibility, and downstream data sharing.

Regulators across Europe have made it clear that erasure compliance is a priority area. Organisations that approach erasure requests with clear procedures, documented reasoning, and robust data-governance frameworks are best positioned to meet both legal obligations and regulatory expectations.

See Also