Skip to main content
Category: Data Subject Rights

Right to Erasure Request

Also known as: Right to be Forgotten, Right to get your data deleted
Simply put

A right to erasure request is when an individual asks an organisation to delete personal data it holds about them. Under the UK GDPR this right is also commonly called the 'right to be forgotten'. A person can generally make such a request by contacting the organisation directly, and does not have to use a specific form or address it to a particular person.

Formal definition

A right to erasure request is a data subject request, recognised under Article 17 of the EU GDPR and the corresponding provisions of the UK GDPR, by which a data subject asks the controller to erase personal data concerning them, typically to be actioned without undue delay. The obligation falls on the controller rather than the processor, though the controller may need to instruct any processors acting on its behalf. This right is not absolute: it applies only in defined circumstances and is subject to exemptions and competing obligations, which are not detailed here. This entry does not cover the specific grounds on which erasure may be requested or refused, applicable time limits, downstream notification duties, or how equivalent rights are treated under other regimes such as the CCPA/CPRA or HIPAA, where deletion rights differ in scope and mechanics.

Why it matters

The right to erasure gives individuals a meaningful degree of control over personal data that organisations hold about them, and it is one of the more operationally demanding data subject rights to satisfy. Because a valid request can generally be made informally, by contacting the organisation through any channel, without a prescribed form or a named recipient, organisations cannot rely on a single intake process to catch every request. Front-line staff, help desks, and general contact addresses may all receive erasure requests, which means recognition and routing are as important as the deletion mechanics themselves.

The obligation to act rests with the controller rather than any processor. When personal data is spread across production systems, backups, analytics stores, and third-party processors acting on the controller's behalf, honouring a request typically requires the controller to instruct those processors and to locate data across its estate. This is where data governance and information security intersect with data subject rights: knowing where personal data lives, who is accountable for it, and how it can be reliably deleted or suppressed depends on data mapping and stewardship, not solely on security controls.

It is important to keep the right in proportion. The right to erasure is not absolute, it applies only in defined circumstances and is subject to exemptions and competing obligations, which are not detailed in this entry. Treating every erasure request as an unconditional obligation to delete, or conversely assuming an easy blanket refusal, both misstate the position. The right must be assessed against the specific grounds and applicable exemptions in each case.

Who it's relevant to

Data Protection Officers and Privacy Leads
DPOs and privacy teams are responsible for ensuring the organisation can recognise and respond to erasure requests received through any channel, and for assessing each request against the relevant grounds and exemptions rather than applying a blanket rule. Accountability here requires demonstrable processes and evidence, not merely a stated policy.
Data Controllers
The obligation to action an erasure request falls on the controller, which must locate the relevant personal data and, where processors act on its behalf, instruct them to erase it. Controllers cannot delegate this accountability to processors, even where processors carry out the technical deletion.
Front-line and Customer-facing Staff
Because an individual can contact any part of the organisation and does not have to use a specific form or address a specific person, staff who handle general enquiries need to recognise a potential erasure request and route it correctly, so that requests are not missed at the point of intake.
Data Governance and Stewardship Teams
Fulfilling erasure requests depends on knowing where personal data resides and who is accountable for it. Data catalogs, lineage, and stewardship, governance concerns distinct from but overlapping with security controls, underpin the ability to identify and act on the data an individual asks to have erased.
Individuals Exercising the Right
Data subjects, including former users or customers, can generally ask an organisation to delete personal data it holds about them by contacting the organisation directly and telling it what data they want erased. They do not have to complete a particular form to make the request.

Inside Right to Erasure Request

Data Subject Request
A request made by an identified or identifiable natural person asking a data controller to delete personal data relating to them. Under the EU GDPR and UK GDPR this is generally described as the right to erasure (sometimes called the right to be forgotten). Treatment differs under other regimes; for example, the CCPA and CPRA provide a distinct consumer right to deletion with its own conditions.
Controller Responsibility
The data controller generally bears the obligation to assess and respond to the request, since it determines the purposes and means of processing. Where a data processor holds the relevant data, the controller typically must instruct the processor to act, and the processor is generally obliged to assist the controller in meeting the request.
Conditional, Not Absolute
The right to erasure is qualified rather than unconditional. In most jurisdictions that recognise it, erasure applies only where specified grounds are met, and it can be refused or limited where an exemption or overriding basis applies. This entry does not enumerate every applicable ground or exemption.
Identity Verification
Before acting, the controller generally needs reasonable assurance that the requester is the data subject or an authorised representative, to avoid unauthorised deletion or disclosure. The specific verification standard depends on context and risk.
Scope of Data Affected
Assessing a request typically requires locating the relevant personal data across systems, backups, and any processors or third parties to whom the data was disclosed. Effective response generally depends on underlying data governance such as data catalogs, lineage, and ownership records, though those governance capabilities are distinct from the erasure obligation itself.
Record of the Decision
Accountability generally requires that the controller be able to demonstrate how the request was handled, including whether it was fulfilled, refused, or partially actioned and on what basis. Demonstrable evidence, not merely stated intent, is typically expected under governance and accountability frameworks.

Common questions

Answers to the questions practitioners most commonly ask about Right to Erasure Request.

Does a valid erasure request always mean the data controller must delete the data?
No. The right to erasure is not absolute. Under the EU GDPR and UK GDPR, it applies in specific circumstances, and it is subject to exemptions where processing remains necessary, for example to comply with a legal obligation, to exercise or defend legal claims, or for certain public interest purposes. The controller must assess whether an applicable ground or exemption applies rather than deleting automatically. This answer does not cover the precise conditions or exemptions in any single jurisdiction, which should be checked against the relevant instrument.
If we encrypt or tokenize the data instead of deleting it, does that satisfy an erasure request?
Generally no. Encryption and tokenization are security measures; they do not by themselves render data non-personal, particularly where the controller retains the means to reverse them or link back to an individual. Where reversal remains possible, the data typically remains personal data and still within scope of the request. Whether a de-identification approach can substitute for deletion depends on the specific facts, the jurisdiction, and whether the result is genuinely irreversible, which is a high bar. This entry does not assess any particular technique against a specific legal standard.
Who within the organisation is accountable for responding to an erasure request?
The data controller bears the primary obligation to respond, as it determines the purposes and means of processing. Where a processor holds relevant data, the controller typically instructs the processor to act, and the processor's obligations are generally governed by the controller-processor contract. A data protection officer, where appointed, commonly advises on and monitors handling but does not assume the controller's accountability. Accountability under governance frameworks generally requires demonstrable evidence of how the request was assessed and actioned, not merely a stated intent to comply.
How should we handle erasure of data that has been shared with third parties or made public?
Where a controller has disclosed or made personal data available to others, it may, depending on the applicable regime and circumstances, need to take reasonable steps to inform other recipients or controllers of the erasure request. What is reasonable typically accounts for available technology and cost. The extent of this obligation, and how it applies to onward recipients, varies by jurisdiction and by the facts. This answer does not detail the specific standards or thresholds in any single instrument.
What should we do when only part of the requested data can be erased?
It is common for some data to qualify for erasure while other data must be retained under an applicable exemption or overriding ground. In such cases the controller generally erases what is eligible and retains only what is justified, documenting the basis for retention. Communicating to the individual which data was erased and why other data was kept supports the demonstrable accountability that governance frameworks expect. Retention periods and rules themselves are out of scope of this entry and should be assessed separately.
What records should we keep to show an erasure request was handled properly?
To meet accountability expectations, controllers typically document the request, the identity verification performed, the assessment of whether an erasure ground and any exemptions applied, the systems and any processors affected, the actions taken, and the outcome communicated to the individual. This evidentiary record is generally distinct from a records of processing activities obligation and from any data inventory tool, though those artefacts can help locate relevant data. This entry does not specify retention periods for such records, which depend on the applicable regime and organisational policy.

Common misconceptions

The right to erasure is absolute and any request must always result in deletion.
In most jurisdictions that recognise it, the right is conditional. Erasure can be lawfully refused or limited where a recognised ground for the request is not met or where an overriding basis or exemption applies. The specific grounds and exemptions vary by regime and are out of scope for this entry.
Encrypting, tokenizing, or pseudonymizing the data satisfies an erasure request because it is no longer personal data.
Encryption, tokenization, and pseudonymization are generally security or risk-reduction measures and do not, on their own, render data non-personal. Pseudonymized data is typically still personal data because it remains reversible. These techniques do not by themselves discharge an erasure obligation.
The processor can ignore an erasure request because only the controller is accountable to the data subject.
While the controller generally holds the primary obligation to the data subject, a processor holding the relevant data is typically required to act on the controller's instructions and to assist the controller in fulfilling the request. Responsibility is allocated between the parties rather than resting solely with one.

Best practices

Verify the identity of the requester with a standard proportionate to the risk before taking any deletion action, to prevent unauthorised erasure or disclosure.
Assess each request against the applicable conditions and any exemptions rather than deleting automatically, and record the reasoning where a request is refused or partially actioned.
Use data governance capabilities such as catalogs, lineage, and ownership records to locate affected personal data across systems, backups, processors, and third-party recipients.
Define and document processor instructions and assistance arrangements so that data held by processors can be actioned when the controller receives a request.
Do not rely on encryption, tokenization, or pseudonymization as a substitute for erasure, since such data generally remains personal data.
Maintain demonstrable evidence of how each request was handled to support accountability, recognising that stated intent alone is generally insufficient.