Right to be Forgotten
The right to be forgotten is the ability of an individual to ask an organization to delete personal data held about them, or to have information about them removed from internet search results, in certain circumstances. It is not an absolute right, meaning a request can be refused where the organization has valid grounds to keep the data. It originated in the European Union and is closely related to what the EU GDPR calls the right to erasure.
The right to be forgotten (RTBF) is commonly used to describe two related but distinct concepts. First, it refers to the right to erasure codified in the EU GDPR (and mirrored in the UK GDPR), under which a data subject may request that a data controller erase personal data concerning them without undue delay in defined circumstances; the controller, not the processor, bears the obligation to act on and evaluate such a request against the applicable grounds and exemptions. Second, in common usage the phrase also references the de-indexing or delisting of personal data from search engine results, a concept associated with EU jurisprudence rather than being co-extensive with the statutory right to erasure. The right is qualified rather than absolute, and controllers may lawfully refuse or limit erasure where recognized grounds apply. This entry does not enumerate the specific conditions, exemptions, associated notification obligations to other recipients, time limits, or how the right is treated outside the EU/UK regimes, and treatment under other frameworks such as the CCPA/CPRA differs and is out of scope here. Any specific article numbers, dates, or procedural detail should be confirmed against the applicable legal text.
Why it matters
The right to be forgotten sits at the intersection of individual autonomy and organizational data practices, and it carries direct operational and legal consequences for data controllers. Because the right is qualified rather than absolute, organizations cannot simply automate deletion on request; they must be able to evaluate each request against recognized grounds and any applicable exemptions, and to document the reasoning where a request is refused or limited. This demands demonstrable accountability rather than stated intent, since an organization that cannot show how it assessed and actioned a request is exposed to challenge from both data subjects and supervisory authorities.
The term also matters because it is frequently conflated with two distinct ideas. In the EU GDPR (and mirrored in the UK GDPR), the phrase maps to the statutory right to erasure, which is an obligation borne by the data controller, not the processor. In common usage, however, the phrase also describes the de-indexing or delisting of personal data from search engine results, a concept associated with EU jurisprudence and first established in the European Union in May 2014 through a ruling of the European Court of Justice. Treating these as one and the same leads to misaligned processes, because a delisting request directed at a search engine and an erasure request directed at a controller involve different parties and different assessments.
For practitioners, the practical stakes are that erasure obligations must be operationalized across systems, backups, and any onward recipients, while recognizing that the right can be lawfully refused where valid grounds to retain data apply. This entry does not enumerate those specific grounds, exemptions, notification obligations, or time limits, nor does it address how equivalent or divergent rights are treated under frameworks such as the CCPA/CPRA, which fall outside its scope.
Who it's relevant to
Inside RTBF
Common questions
Answers to the questions practitioners most commonly ask about RTBF.