Right to be Forgotten
Follow topic LLM context A cited markdown file you can paste into your AI assistant (ChatGPT, Claude, a RAG or project knowledge base) to ground it in this topic. Contains: the overview, key law text, case law, enforcement and guidance for this topic. Everything links back to its source on overview.legal — legal information, not advice.Right to have personal data erased under certain conditions
Overview
24 sources · Jul 23, 2026Legal Framework
Article 17 GDPR establishes the right to erasure, commonly known as the right to be forgotten. Under Article 17(1), a data subject may demand erasure of personal data where one of six grounds applies, including where the data are no longer necessary for the purposes for which they were collected, where consent is withdrawn, where the data subject objects under Article 21, or — critically — where the personal data have been unlawfully processed (Article 17(1)(d)). Once a valid erasure request is received, the controller must erase the data without undue delay and in any event within one month.
Article 19 GDPR extends the obligation beyond the controller's own systems: the controller must communicate any erasure to each recipient to whom the data were disclosed, unless this proves impossible or involves disproportionate effort. The data subject is entitled to information about those recipients upon request. This cascading obligation means erasure is not a localized event but a supply-chain responsibility.
The right is not absolute. Recitals 51 and 65, as confirmed in GC and Others v CNIL, emphasize that data protection must be balanced against other fundamental rights, including freedom of expression and information. Article 17(3) sets out explicit exemptions for processing necessary for freedom of expression, legal compliance, public health, archiving, and scientific or statistical purposes.
Key Developments
Dutch courts have begun shaping the practical boundaries of Article 17. The Gerechtshof Arnhem-Leeuwarden confirmed that where a lawful basis such as Article 6(1)(c) (legal obligation) supports processing — in that case, BKR registration — an erasure request under Article 17(1)(d) must fail if the processing is not unlawful. The court also held that the risk of a costs order does not negate the Article 79 right to an effective judicial remedy.
The Rechtbank Rotterdam awarded compensation for immaterial damage where a controller unlawfully retained reports containing personal data, violating the data subject's private life. This signals that failure to honour a valid erasure request can trigger not only administrative fines but civil liability under Article 82.
A kantonrechter decision involving ASR insurance fraud registers illustrates the evidential burden: where a data subject claims unlawful processing and seeks erasure, the controller bears a heightened duty to substantiate the lawfulness of its processing ground. If the data are processed unlawfully, the right to erasure under Article 17(1)(d) is engaged as a matter of course.
The rectification right under Article 16 — closely linked to Article 17 — does not extend to erasing opinions, impressions, or research conclusions with which the data subject disagrees. Those must be challenged through appropriate procedures; mere disagreement is not a ground for erasure.
Enforcement remains active. The Italian Garante fined Geturhotels €6,000 for direct marketing violations involving retention of data beyond legitimate purposes, and the Romanian ANSPDCP fined Cucina di Fabio €3,000 in a similar context. The EDPB has issued Guidelines 5/2019 on erasure in search engine cases and conducted a coordinated enforcement action on implementation practices across controllers.
Practical Guidance
- Map all recipients before acting on an erasure request. Article 19 requires notification to every recipient to whom the data were disclosed. Maintain a current data-flow inventory so this obligation can be met within the one-month deadline.
- Assess lawfulness first under Article 17(1)(d). If processing lacks a valid Article 6 basis, erasure is mandatory. Document the legal basis assessment contemporaneously — courts have placed a heightened evidential burden on controllers to justify retention.
- Distinguish factual correction from opinion deletion. Article 16 does not permit erasure of subjective assessments or research conclusions. Train staff handling data subject requests to identify and route such complaints to the appropriate dispute mechanism rather than auto-erasing.
- Apply the proportionality test for downstream notification. Article 19 allows non-notification where it is impossible or disproportionately burdensome, but this exception must be documented with a reasoned assessment, not assumed.
- Prepare for civil exposure alongside administrative risk. Per the Rotterdam ruling, unlawful retention can trigger Article 82 compensation claims. Erasure procedures should be integrated with the organization's damage-prevention and incident-response protocols.