GDPR erasure basics: how to use your right to be forgotten

Breach / exposure. Updated 2026-09-13. About 6 minutes to read.

Send a written request naming the Article 17 ground you rely on, expect an answer within one month, and escalate to the ICO or your EU regulator if it is refused without a valid exemption.

Article 17 of the GDPR gives people in the European Union a right to have personal data erased in specific situations. The UK kept the same right in UK GDPR and the Data Protection Act 2018. Organisations must respond within one month, and in most cases the request costs you nothing.

It is not an absolute delete button. The right applies when one of six grounds is met, and a company can refuse where an exemption applies, such as a legal duty to keep records. Knowing which ground you are using makes a refusal much harder.

Below are the grounds, the exemptions, a request you can send today as numbered steps, and exactly where to complain in the EU and the UK when a company ignores you. The final section covers readers in Australia, where the law works differently.

When the right to erasure applies

Under Article 17(1), you can have personal data erased without undue delay when at least one of these grounds applies:

  • The data is no longer necessary for the purpose it was collected for, such as an old customer account you closed.
  • You withdraw consent and there is no other legal basis for the processing.
  • You object under Article 21 and there are no overriding legitimate grounds, or you object to direct marketing, which must always be honoured.
  • The data was processed unlawfully.
  • The data must be erased to comply with a legal obligation.
  • The data was collected from you as a child in connection with an online service.

When a company can lawfully say no

  • Exercising the right of freedom of expression and information, which is why news archives are rarely erased.
  • Complying with a legal obligation, such as tax, anti-money laundering or employment record keeping.
  • Performing a task in the public interest or official authority.
  • Public health purposes.
  • Archiving in the public interest, scientific or historical research, or statistics, where erasure would seriously impair that work.
  • Establishing, exercising or defending legal claims.

An exemption covers only the data it applies to. A retailer that must keep invoices for tax reasons still has to delete your marketing profile, browsing history and saved preferences.

Make the request: template as steps

  1. Find the privacy contact in the company's privacy notice. Many have a data protection officer email address or a privacy request form. You can also ask any part of the organisation, verbally or in writing, but writing gives you a record.
  2. Subject line: Request for erasure of personal data under Article 17 GDPR, or UK GDPR if the company is in the UK.
  3. Identify yourself with the details the company already holds: full name, account email, customer number and phone number.
  4. State the ground you rely on, for example that the data is no longer necessary because you closed your account, or that you withdraw consent.
  5. Add that you object to any processing for direct marketing and ask that data shared with other organisations be flagged for erasure, as Article 19 requires them to inform recipients.
  6. Ask for written confirmation of what was erased and, if anything is kept, which exemption applies and to which data.
  7. Close with the date and a note that you expect a response within one month.
  8. Keep a copy of the request and any acknowledgement.

Deadlines: one month, sometimes three

Under Article 12(3), a company must act on your request without undue delay and within one month of receiving it. It can extend by up to two further months where requests are complex or numerous, but it must tell you within the first month and explain why.

The request is free unless it is manifestly unfounded or excessive. A company can ask for more information if it genuinely needs it to confirm who you are. In the UK, the Data (Use and Access) Act 2025 confirms that the clock pauses while an organisation waits for information it needs to confirm your identity or clarify the request, so reply promptly to any reasonable question.

Where the company made your data public, Article 17(2) requires it to take reasonable steps to tell other controllers processing that data that you have asked for links and copies to be erased.

Search engines and the right to be forgotten

The 2014 Google Spain judgment of the Court of Justice of the EU established that search engines can be required to delist results for searches of your name where the information is inaccurate, inadequate, irrelevant or excessive. Google and Bing each run an online form for European and UK requests.

Delisting removes the result from searches of your name. It does not delete the page, and in 2019 the Court ruled that delisting is required on European versions of the search engine rather than worldwide. Requests about public figures, professional conduct and recent criminal matters are often refused on public interest grounds.

If they refuse or ignore you

  1. Reply to any refusal asking which exemption applies to which data, and why the rest cannot be deleted.
  2. In the UK, complain to the organisation first. Since 19 June 2026 organisations must have a data protection complaints process, acknowledge your complaint within 30 days, and tell you the outcome without undue delay.
  3. If that fails, complain to the ICO in the UK, or in the EU to the data protection authority in your country or where the company has its main European establishment. Ireland's Data Protection Commission is the lead authority for many large US tech companies.
  4. Keep your request, dates and every reply. Regulators ask for them.
  5. If the failure caused you distress or financial loss, you can also bring a court claim for compensation, ideally with legal advice.

Outside Europe: Australia and elsewhere

GDPR applies to organisations outside the EU that offer goods or services to people in the EU or monitor their behaviour, so an Australian or US company selling to European customers can be covered. Enforcement against companies with no European presence is difficult in practice.

Australia has no general right to erasure. Under the Privacy Act you can ask for access to your information and have it corrected under Australian Privacy Principle 13, and organisations must destroy or de-identify information they no longer need. A right to erasure against large digital platforms is proposed in the 2026 reform exposure draft but is not law. If an Australian organisation mishandles your request, complain to it first, then to the OAIC if you do not get a response within 30 days.

Frequently asked questions

Can I ask any company to delete my data under GDPR?

You can ask any company covered by GDPR, but it only has to erase data when one of the Article 17 grounds applies and no exemption does. Closed accounts, withdrawn consent and marketing data are the strongest cases.

Do I have to give a reason for an erasure request?

Legally you do not have to cite the article or use legal wording, but stating the ground, such as withdrawing consent or the data no longer being necessary, makes the request clearer and harder to refuse.

Can a company charge me for deleting my data?

No, unless the request is manifestly unfounded or excessive, for example repeated identical requests. In that case it can charge a reasonable fee or refuse, and must explain why.

Does the right to be forgotten remove news articles from the internet?

No. You may be able to get a search engine to delist an article from searches of your name, but the article stays on the publisher's site. Publishers can rely on the freedom of expression exemption.

Does UK GDPR still apply after Brexit?

Yes. The UK kept GDPR as UK GDPR alongside the Data Protection Act 2018, amended by the Data (Use and Access) Act 2025. The right to erasure and the one month deadline are the same, and the ICO is the regulator.

Tools that help

Related guides

Sources