Content Removal

The GDPR Right to Erasure: How to Get Your Data Deleted

How the GDPR right to erasure works: the six grounds for deletion, when organizations can refuse, the one-month deadline, a request template, and what to do if they say no.

By Editorial Team 9 min read
A pile of white shredded paper sitting on top of a table

The GDPR right to erasure, in Article 17, lets you ask an organization to delete personal data it holds about you on specific grounds, such as when the data is no longer needed, you withdraw consent, or it was processed unlawfully. The organization generally has one month to respond and must usually act free of charge, but it can refuse where an exception applies, for example freedom of expression or a legal obligation to keep the data. The UK GDPR contains an almost identical right.

This guide focuses on erasure requests to companies and other organizations. Asking search engines to stop showing results for your name is a related but separate process, covered in our guide to the right to be forgotten. This is general information, not legal advice.

Who the right to erasure covers

The GDPR applies to organizations established in the EU or European Economic Area, and to organizations elsewhere that offer goods or services to people in the EU or monitor their behavior there. The UK GDPR applies in the same way for the UK. If an organization is covered, the people whose data it processes can use the right to erasure.

In practice, that means you can generally use it if you’re in the EU, EEA or UK and dealing with a company that serves you there. If you live in the US, the GDPR usually won’t help against a US company that doesn’t target Europe, though some US state privacy laws give a similar right to delete. Our guide on removing your information from the internet covers those routes.

The six grounds for erasure

Article 17 doesn’t give an automatic right to delete everything. You need at least one of these grounds:

  1. The data is no longer necessary for the purpose it was collected or processed for, such as an account you closed years ago.
  2. You withdraw consent, where consent was the legal basis for processing and there’s no other legal ground.
  3. You object to the processing and there are no overriding legitimate grounds to continue, or you object to processing for direct marketing, where the objection is absolute.
  4. The data was processed unlawfully, for example without any valid legal basis.
  5. Erasure is required to comply with a legal obligation the organization is subject to.
  6. The data was collected from a child in connection with an online service offered directly to them.

Your request doesn’t have to cite the article or name the ground in legal terms, but explaining why you think a ground applies usually gets a better response.

When an organization can refuse

The right to erasure doesn’t apply where processing is necessary for certain purposes. In general terms, these are:

Exception Typical example
Freedom of expression and information A news publisher’s archive article about you
Compliance with a legal obligation, or a task in the public interest or official authority An employer keeping payroll records for tax law, or a regulator keeping enforcement records
Public health Certain records kept for public health purposes
Archiving in the public interest, research or statistics Scientific or historical research where erasure would seriously impair the work
Legal claims A company keeping records it needs for a dispute with you

An organization can also refuse, or charge a reasonable fee, if a request is manifestly unfounded or excessive, for example a repeated request designed to disrupt rather than protect your data. It has to explain its reasons if it refuses.

The freedom of expression exception matters most for reputation problems. A news site isn’t required to delete an accurate article just because it names you. That’s why the practical route for old news coverage is often a delisting request, an update request or a correction, rather than erasure. Our guide on removing a news article from Google covers those options.

Deadlines and what the organization must do

  • One month to respond. The organization must act on your request without undue delay and within one month of receiving it.
  • Extension. It can extend by up to two further months if the request is complex or it has received many requests, but it must tell you within the first month and explain why.
  • Free of charge, in most cases.
  • Identity checks. If it has reasonable doubts about who you are, it can ask for information to confirm your identity. It shouldn’t demand more than it needs.
  • Telling others. If it shared your data with other recipients, it must generally tell them about the erasure unless that’s impossible or would involve disproportionate effort. If it made your data public, it must take reasonable steps to inform other controllers processing it that you’ve asked for erasure.

How to make an erasure request, step by step

  1. Find out what they hold. If you’re unsure, start with an access request. Our guide to making a data subject access request explains how, and the response tells you exactly what to ask them to delete.
  2. Find the right contact. Check the organization’s privacy notice for a data protection officer, a privacy email address or a request form.
  3. Identify the data. Be specific: an account, a profile page, photos, marketing lists, or all personal data they hold about you.
  4. State your ground. Explain briefly why one of the grounds applies.
  5. Ask about recipients. Ask them to tell anyone they shared the data with, and to confirm who those recipients are.
  6. Diary the deadline. Note the date one month from receipt.
  7. Follow up. If you hear nothing, send a short reminder before escalating.

A template you can adapt

Subject: Request for erasure of personal data under Article 17 GDPR

Dear Data Protection Officer,

I am writing to request the erasure of personal data you hold about me under Article 17 of the GDPR [or the UK GDPR].

My details: [full name, email address and any account or reference number you use for me].

The data I am asking you to erase: [for example, my customer account and all associated records, or the profile page at the following address].

My reason: [for example, I closed my account in 2021 and the data is no longer necessary for the purpose it was collected for; or I withdraw my consent to this processing].

Please also inform any recipients to whom this data has been disclosed, and tell me who they are.

Please confirm the erasure within one month of receiving this request. If you decide not to erase any of the data, please explain the reason and the legal basis for keeping it.

Yours sincerely,

[Name]

Keep it factual and polite. You don’t need a lawyer to send this letter, and the organization shouldn’t require you to use a particular form.

Not sure where to start?

Get a free audit of your search results and review profiles, with a prioritized fix list.

Get a free audit

A worked example

This is an illustrative scenario, not a real client.

A graphic designer in Dublin finds that an old online portfolio site she stopped using years ago still shows a public profile with her full name, former home address and early work she no longer wants associated with her. The site is run by a company based in the EU.

She sends an erasure request through the site’s privacy form, explaining that she stopped using the service long ago, that the data is no longer necessary for providing it, and that she withdraws any consent she gave. She asks the company to delete the profile and confirm whether it shared her data with anyone. The company deletes the profile within the month and confirms it hadn’t passed the data on.

A week later the old profile still appears in search results. Because the source page is gone, she uses the search engine’s tool for outdated content to ask for the result to be refreshed.

If the organization says no or ignores you

  1. Read the reasons. If they rely on an exception, check whether it really covers all the data. Often part of the data can be deleted even if some must be kept.
  2. Reply once. Explain why you disagree, briefly, and ask them to reconsider.
  3. Complain to the data protection authority. In the EU, that’s the supervisory authority in the country where you live or work, or where the problem happened. In the UK, it’s the Information Commissioner’s Office, which generally expects you to raise the issue with the organization first. Our guide on making an ICO complaint walks through the UK process. For EU authorities, see our guide on how to make a GDPR complaint.
  4. Consider court action. You also have the right to take the organization to court. For that step, get advice from a lawyer, or in the UK and Ireland a solicitor, who handles data protection.

Common mistakes

  • Expecting erasure to remove news coverage. Journalism is usually protected by the freedom of expression exception.
  • Asking for everything without a ground. A vague demand is easier to refuse than a specific request with a reason.
  • Using the GDPR against a company it doesn’t cover. Check whether the organization is in, or targets people in, the EU or UK.
  • Missing the follow-up. If the month passes, act on it rather than waiting indefinitely.
  • Forgetting the search results. Deleting the source page doesn’t instantly change search results; you may need to request a refresh.

When to get help

Most erasure requests don’t need professional help. It’s worth getting advice when the organization refuses and the data is causing real harm, when the data is spread across many sites, or when the content is also defamatory. For defamation in the UK, see our guide to UK defamation law. Our content removal service works on legitimate removal routes, including data protection requests, and says plainly when a route is unlikely to work.

Frequently asked questions

What is the GDPR right to erasure?

It’s the right, under Article 17 of the GDPR, to ask an organization to delete your personal data on specific grounds, such as the data no longer being needed or consent being withdrawn. It isn’t absolute: organizations can refuse where exceptions apply, such as freedom of expression or legal obligations.

How long does a company have to delete my data under GDPR?

It must respond without undue delay and within one month of receiving your request. It can extend this by up to two further months for complex or numerous requests, but it must tell you within the first month and explain why.

Is the right to erasure the same as the right to be forgotten?

They’re closely related. Article 17 is headed the right to erasure (“right to be forgotten”). In everyday use, “right to be forgotten” often refers to asking search engines to delist results, while “right to erasure” means asking an organization to delete the data it holds.

Does the right to erasure apply in the UK after Brexit?

Yes. The UK GDPR contains an almost identical right, and complaints go to the Information Commissioner’s Office rather than an EU authority.

Can I use the GDPR right to erasure if I live in the US?

Usually only against organizations the GDPR covers, such as those that offer services to people in the EU. For US companies, check whether your state’s privacy law gives you a right to delete.

Editorial Team

The 123 Reputation Management editorial team writes practical guides on reviews, search results and online reputation.

Start with step 1

See what people see when they search for you.

Get a free, no-obligation reputation audit covering search results, review profiles and social mentions, with clear next steps.