Auditen
Home / Frameworks / GDPR / The right to erasure ('right to be forgotten')
GDPR · Art. 17

The right to erasure ('right to be forgotten')

The right to erasure requires organizations to delete personal data upon request when specific conditions are met, such as the data no longer being necessary for its original purpose or consent being withdrawn. Organizations must erase this data without undue delay and ensure that any third parties who have received the data are also notified of the requirement to erase it.

What it means

The intent is to provide individuals with control over their personal information, allowing them to "be forgotten" when there is no longer a valid legal basis for the organization to retain their data. It applies across all formats and locations where the data resides.

This right is not absolute. An organization may lawfully refuse a request if the processing is necessary for compliance with a legal obligation (such as tax or employment laws), for reasons of public interest in the area of public health, or for the establishment, exercise, or defense of legal claims.

In practice, this means an organization must be able to identify every location where a specific individual's data exists—including backups and third-party vendor systems—and ensure it is either permanently deleted or rendered irreversibly anonymous.

How to meet it

Evidence an auditor asks for

  • A Request Log documenting the date of receipt, verification steps taken, decision outcome, and completion date for each erasure request.
  • Copies of communications sent to data subjects confirming that their data has been erased or explaining the legal grounds for refusal.
  • Technical logs or system audit trails showing the execution of deletion commands in production databases.
  • Records of notifications sent to third-party vendors instructing them to delete specific personal data records.

Common pitfalls

  • Ignoring backups: Organizations often delete data from live production environments but fail to ensure it is removed from (or overwritten in) long-term archives and snapshots.
  • Over-deletion: Deleting all data immediately without checking legal retention requirements, thereby violating other laws (e.g., financial record-keeping mandates).
  • Assuming vendor automation: Relying on the assumption that deleting a user in a primary SaaS tool automatically triggers deletion across all of that vendor's sub-processors and mirrored backups.