Right to Erasure Request
A right to erasure request is when an individual asks an organisation to delete personal data it holds about them. Under the UK GDPR this right is also commonly called the 'right to be forgotten'. A person can generally make such a request by contacting the organisation directly, and does not have to use a specific form or address it to a particular person.
A right to erasure request is a data subject request, recognised under Article 17 of the EU GDPR and the corresponding provisions of the UK GDPR, by which a data subject asks the controller to erase personal data concerning them, typically to be actioned without undue delay. The obligation falls on the controller rather than the processor, though the controller may need to instruct any processors acting on its behalf. This right is not absolute: it applies only in defined circumstances and is subject to exemptions and competing obligations, which are not detailed here. This entry does not cover the specific grounds on which erasure may be requested or refused, applicable time limits, downstream notification duties, or how equivalent rights are treated under other regimes such as the CCPA/CPRA or HIPAA, where deletion rights differ in scope and mechanics.
Why it matters
The right to erasure gives individuals a meaningful degree of control over personal data that organisations hold about them, and it is one of the more operationally demanding data subject rights to satisfy. Because a valid request can generally be made informally, by contacting the organisation through any channel, without a prescribed form or a named recipient, organisations cannot rely on a single intake process to catch every request. Front-line staff, help desks, and general contact addresses may all receive erasure requests, which means recognition and routing are as important as the deletion mechanics themselves.
The obligation to act rests with the controller rather than any processor. When personal data is spread across production systems, backups, analytics stores, and third-party processors acting on the controller's behalf, honouring a request typically requires the controller to instruct those processors and to locate data across its estate. This is where data governance and information security intersect with data subject rights: knowing where personal data lives, who is accountable for it, and how it can be reliably deleted or suppressed depends on data mapping and stewardship, not solely on security controls.
It is important to keep the right in proportion. The right to erasure is not absolute, it applies only in defined circumstances and is subject to exemptions and competing obligations, which are not detailed in this entry. Treating every erasure request as an unconditional obligation to delete, or conversely assuming an easy blanket refusal, both misstate the position. The right must be assessed against the specific grounds and applicable exemptions in each case.
Who it's relevant to
Inside Right to Erasure Request
Common questions
Answers to the questions practitioners most commonly ask about Right to Erasure Request.