GDPR Right to Be Forgotten: Article 17 Erasure (2026)

By Recording Law Editorial TeamReviewed June 9, 202630 min read
GDPR Right to Be Forgotten: Article 17 Erasure (2026)

Frequently Asked Questions

What is the right to be forgotten under GDPR?

The right to be forgotten is the informal name for the right to erasure under Article 17 of Regulation (EU) 2016/679 (GDPR). It gives individuals the right to request that a controller (any organisation processing their personal data) delete that data without undue delay, where one of six specific grounds applies. Those grounds include: the data is no longer needed for the purpose it was collected; consent has been withdrawn; the individual has successfully objected to processing; processing was unlawful; a legal obligation requires deletion; or the data was collected from the individual as a child for a digital service. The right is not absolute: five exceptions in Article 17(3) allow controllers to refuse where continued processing is necessary for freedom of expression, legal obligations, public health, research purposes, or defending legal claims.

How do I request erasure under GDPR?

Submit a written erasure request to the controller's data protection contact or privacy rights portal, which is usually linked from the organisation's website footer. Include your name and account identifiers, specify which data or categories of data you want deleted, state the Article 17(1) ground you are relying on, and ask for written confirmation of completion. The request is free of charge. The controller must respond within one calendar month. If it refuses, it must give reasons and tell you how to complain to your national data protection authority. If it does not respond at all within a month, that is itself a GDPR infringement and you can complain to your national DPA.

What are the exceptions to the right to be forgotten under GDPR?

Article 17(3) sets out five exceptions that allow a controller to refuse an erasure request even where one of the six grounds in Article 17(1) is met. Those exceptions are: (a) freedom of expression and information, covering journalism, commentary, and public-interest archives; (b) compliance with a legal obligation or performance of a public-interest task, covering mandatory retention periods under employment, tax, health, and financial law; (c) public health, covering disease surveillance and medical research; (d) archiving in the public interest, scientific or historical research, or statistics, where erasure would seriously impair the research; and (e) establishment, exercise, or defence of legal claims, covering litigation and regulatory proceedings. The controller must identify the specific applicable exception and communicate it to you in writing. A blanket refusal without citing a ground is itself a GDPR breach.

Does the right to be forgotten apply to Google search results?

Yes. The Court of Justice of the EU ruled in Google Spain (Case C-131/12, 2014) that search engines are data controllers and must remove links from results on request where one of the Article 17(1) grounds applies, even if the underlying web page remains lawfully published. You submit a de-referencing request directly to the search engine operator. However, Google v CNIL (Case C-507/17, 2019) confirmed that EU law does not require global de-listing: the obligation is limited to EU-Member-State-facing versions of the search engine (google.fr, google.de, etc.), though geo-blocking must prevent EU users from accessing de-listed results via non-EU domains such as google.com.

How long does a company have to delete my data after I request erasure?

Under Article 12(3) of the GDPR, the controller must act and confirm the action within one calendar month of receiving your request. The month runs from the date the request is received, not from any acknowledgment. The controller may extend this deadline by up to two further months for complex cases or high volumes of requests, but it must notify you of the extension and explain the reason within the first month. Silence for more than a month is a GDPR violation. If you receive no response within a month, lodge a complaint with your national data protection authority.

Can I request erasure of data that was collected when I was a child?

Yes, and this is one of the strongest erasure grounds available. Article 17(1)(f) GDPR gives you the right to request erasure of personal data collected from you as a child for an information-society service (a social media platform, app, game, or similar digital service). The GDPR sets the minimum consent age for such services at 16, though Member States may lower this to no less than 13. If data was collected from you when you were below the applicable age threshold, that collection was unlawful, and you have grounds under both Article 17(1)(d) (unlawful processing) and Article 17(1)(f). You can make this request as an adult; what matters is your age at the time of collection, not your current age.

What is the difference between a GDPR erasure request and a subject access request?

A subject access request (SAR) under Article 15 GDPR is an information right: it lets you find out what personal data a controller holds about you, why it holds it, and how it is processing it. An erasure request under Article 17 is an action right: it directs the controller to delete the data. The two rights are often used in sequence, with a SAR first to identify what data exists and on what legal basis, then an erasure request once you have that information. Both are free of charge and carry a one-month response deadline under Article 12. Making a SAR does not automatically trigger erasure, and making an erasure request does not entitle you to a copy of the data before it is deleted.

Does the right to be forgotten apply worldwide or only in the EU?

The GDPR right to erasure applies to data subjects located in the EU and to controllers established in the EU or targeting EU residents. It does not automatically extend to cover processing of non-EU individuals by non-EU companies. For search engine de-referencing specifically, the CJEU in Google v CNIL (C-507/17, 2019) ruled that EU law only requires de-listing from EU-Member-State-facing versions of the search engine, not globally. A US resident has no GDPR right to demand a US company erase data, though they may have rights under US state laws such as the California CCPA right to deletion.

What can I do if a company refuses my erasure request?

If a controller refuses your erasure request, it must give you written reasons citing a specific Article 17(3) exception, and it must tell you how to escalate. You have two main routes: first, lodge a complaint with your national supervisory authority (in the UK, the ICO; in France, the CNIL; in Germany, the relevant state DPA or BfDI; in Ireland, the DPC), which can investigate and order the controller to comply; second, seek a judicial remedy directly against the controller in the courts of the Member State where the controller is established, under Article 79 GDPR. Unjustified refusals, and failures to respond at all, can result in administrative fines of up to 20 million euros or 4 percent of global annual turnover, whichever is higher.

Is there a right to be forgotten in the United States?

There is no federal US equivalent to the GDPR right to be forgotten. The closest analogue is the right to deletion under California's CCPA/CPRA, codified at California Civil Code section 1798.105, which applies only to California residents dealing with covered businesses and contains broad exceptions. At the federal level, COPPA gives parents the right to request deletion of data collected from children under 13, but it is narrower in scope and applies only to operators of child-directed services. US courts have generally declined to require search engines to de-list lawful content, relying on the First Amendment and Section 230 of the Communications Decency Act.

Sources and References

  1. Regulation (EU) 2016/679 (GDPR), Official Journal of the European Union, full text including Articles 12, 17, 21 and Recitals 65-66(eur-lex.europa.eu)
  2. CJEU, Case C-131/12, Google Spain SL and Google Inc. v. AEPD and Mario Costeja Gonzalez, Grand Chamber, 13 May 2014(eur-lex.europa.eu)
  3. CJEU, Case C-507/17, Google LLC v. Commission nationale de l'informatique et des libertes (CNIL), Grand Chamber, 24 September 2019(eur-lex.europa.eu)
  4. EDPB Guidelines 5/2019 on the Criteria of the Right to be Forgotten in Search Engines Cases under the GDPR, adopted 7 July 2020 after public consultation(edpb.europa.eu)
  5. EDPB Coordinated Enforcement Action: Implementation of the Right to Erasure by Controllers (CEF 2025 Report, 18 February 2026)(edpb.europa.eu)
  6. California Civil Code section 1798.105 (CCPA/CPRA right to deletion), California Legislative Information(leginfo.legislature.ca.gov)
Share: