# Right to Erasure — legal context bundle

> Curated from overview.legal on 2026-08-22. Canonical page: https://overview.legal/topics/right-to-erasure
> Sources are cited per item. Verify against the official texts before relying on them.

Right to be forgotten and data erasure

## Overview

## Legal Framework

Article 17 GDPR establishes the right to erasure, commonly known as the right to be forgotten. Under Article 17(1), data subjects may obtain erasure of personal data where one of six grounds applies: the data is no longer necessary for the original purpose; the lawful basis was consent and that consent is withdrawn; the data subject objects to processing under Article 21(1) and there are no overriding legitimate grounds; the data subject objects to direct marketing under Article 21(2); the data was unlawfully processed; or erasure is required to comply with a legal obligation under EU or Member State law. A controller receiving a valid erasure request must erase the personal data without undue delay, and in any event within one month of receipt of the request, extendable by two months where necessary under Article 12(3).

Article 17(2) imposes an obligation on controllers who have made the data public to take reasonable steps to inform other controllers processing the data that the data subject has requested erasure. Article 17(3) sets out exemptions where erasure is not required, including processing necessary for freedom of expression, legal compliance, public interest archiving, scientific or statistical research, and the establishment or defense of legal claims.

Article 19 GDPR supplements this by requiring controllers to notify each recipient to whom personal data were disclosed of any erasure carried out under Article 17(1), unless this proves impossible or involves disproportionate effort. Upon request, the controller must inform the data subject about those recipients.

## Key Developments

The scope of erasure is not unlimited. Doctrinal commentary establishes that the right does not extend to correcting or removing impressions, opinions, research results, or conclusions with which the data subject disagrees. The accuracy of such content must be challenged through appropriate procedural channels rather than through an erasure demand. A data subject's disagreement with portions of a report does not, by itself, constitute grounds for erasure.

The Gerechtshof Arnhem-Leeuwarden (case 200.256.426) addressed the balancing of interests between intellectual property rights and data protection rights, weighing Article 17 of the EU Charter of Fundamental Rights against property protections. The court's approach confirms that erasure claims require a contextual balancing exercise rather than automatic application.

The Digital Rights Ireland ruling established that legally mandated metadata retention constitutes a justified interference only when directed at fighting serious crime, based on objective criteria, and subject to clear substantive and procedural conditions. This frames the outer limits of lawful retention that resists erasure demands.

The EDPB's Guidelines 5/2019 clarify the criteria and grounds for exercising the right to be forgotten specifically in search engine cases, providing a structured framework for evaluating delisting requests. Recent developments include the EDPB's CEF implementation report on the right to be forgotten (February 2026) and an updated One-Stop-Shop case digest on the right to object and right to erasure (June 2026), reflecting continued enforcement attention.

## Practical Guidance

- **Establish a structured intake and verification process** for erasure requests that identifies the applicable ground under Article 17(1)(a)-(f) and assesses whether any exemption under Article 17(3) applies before acting.
- **Maintain a data mapping system** that tracks all recipients of personal data, enabling compliance with the Article 19 notification obligation when erasure is carried out.
- **Train staff to distinguish erasure grounds from disagreement claims** — a data subject's objection to opinions or conclusions in a report does not automatically trigger an erasure obligation; assess whether the request genuinely falls within Article 17(1).
- **Document the balancing exercise** when erasure requests conflict with other rights or legitimate interests, particularly freedom of expression, legal claims, or research purposes, as courts expect a contextual, reasoned assessment.
- **Apply the one-month response deadline** under Article 12(3), with documented extensions where complexity justifies a two-month extension, and provide the data subject with reasons for any delay.

## Legislation (full text of key provisions)

### Notification obligation regarding rectification or erasure of personal data or restriction of processing

*Source: GDPR, gdpr-art-19-en, 2016-04-27 — https://overview.legal/posts/90457*

The controller shall communicate any rectification or erasure of personal data or restriction of processing carried out in accordance with Article 16, Article 17(1) and Article 18 to each recipient to whom the personal data have been disclosed, unless this proves impossible or involves disproportionate effort. The controller shall inform the data subject about those recipients if the data subject requests it.

### Right to erasure (‘right to be forgotten’)

*Source: GDPR, gdpr-art-17-en, 2016-04-27 — https://overview.legal/posts/90426*

### Recital 66 — right to erasure online environment

*Source: GDPR, gdpr-rec-66-en, 2016-04-27 — https://overview.legal/posts/91647*

To strengthen the right to be forgotten in the online environment, the right to erasure should also be extended in such a way that a controller who has made the personal data public should be obliged to inform the controllers which are processing such personal data to erase any links to, or copies or replications of those personal data. In doing so, that controller should take reasonable steps, taking into account available technology and the means available to the controller, including technical measures, to inform the controllers which are processing the personal data of the data subject's request.

### Recital 59 — modalities for data subject rights exercise

*Source: GDPR, gdpr-rec-59-en, 2016-04-27 — https://overview.legal/posts/91633*

Modalities should be provided for facilitating the exercise of the data subject's rights under this Regulation, including mechanisms to request and, if applicable, obtain, free of charge, in particular, access to and rectification or erasure of personal data and the exercise of the right to object. The controller should also provide means for requests to be made electronically, especially where personal data are processed by electronic means. The controller should be obliged to respond to requests from the data subject without undue delay and at the latest within one month and to give reasons where the controller does not intend to comply with any such requests.

### Recital 65 — data subject rectification and erasure rights

*Source: GDPR, gdpr-rec-65-en, 2016-04-27 — https://overview.legal/posts/91645*

A data subject should have the right to have personal data concerning him or her rectified and a ‘right to be forgotten’ where the retention of such data infringes this Regulation or Union or Member State law to which the controller is subject. In particular, a data subject should have the right to have his or her personal data erased and no longer processed where the personal data are no longer necessary in relation to the purposes for which they are collected or otherwise processed, where a data subject has withdrawn his or her consent or objects to the processing of personal data concerning him or her, or where the processing of his or her personal data does not otherwise comply with this Regulation. That right is relevant in particular where the data subject has given his or her consent as a child and is not fully aware of the risks involved by the processing, and later wants to remove such personal data, especially on the internet. The data subject should be able to exercise that right notwithstanding the fact that he or she is no longer a child. However, the further retention of the personal data should be lawful where it is necessary, for exercising the right of freedom of expression and information, for compliance with a legal obligation, for the performance of a task carried out in the public interest or in the exercise of official authority vested in the controller, on the grounds of public interest in the area of public health, for archiving purposes in the public interest, scientific or historical research purposes or statistical purposes, or for the establishment, exercise or defence of legal claims.

### Recital 68 — data subject data portability right

*Source: GDPR, gdpr-rec-68-en, 2016-04-27 — https://overview.legal/posts/91651*

To further strengthen the control over his or her own data, where the processing of personal data is carried out by automated means, the data subject should also be allowed to receive personal data concerning him or her which he or she has provided to a controller in a structured, commonly used, machine-readable and interoperable format, and to transmit it to another controller. Data controllers should be encouraged to develop interoperable formats that enable data portability. That right should apply where the data subject provided the personal data on the basis of his or her consent or the processing is necessary for the performance of a contract. It should not apply where processing is based on a legal ground other than consent or contract. By its very nature, that right should not be exercised against controllers processing personal data in the exercise of their public duties. It should therefore not apply where the processing of the personal data is necessary for compliance with a legal obligation to which the controller is subject or for the performance of a task carried out in the public interest or in the exercise of an official authority vested in the controller. The data subject's right to transmit or receive personal data concerning him or her should not create an obligation for the controllers to adopt or maintain processing systems which are technically compatible. Where, in a certain set of personal data, more than one data subject is concerned, the right to receive the personal data should be without prejudice to the rights and freedoms of other data subjects in accordance with this Regulation. Furthermore, that right should not prejudice the right of the data subject to obtain the erasure of personal data and the limitations of that right as set out in this Regulation and should, in particular, not imply the erasure of personal data concerning the data subject which have been provided by him or her for the performance of a contract to the extent that and for as long as the personal data are necessary for the performance of that contract. Where technically feasible, the data subject should have the right to have the personal data transmitted directly from one controller to another.

### Recital 73 — lawful restrictions on data subject rights

*Source: GDPR, gdpr-rec-73-en, 2016-04-27 — https://overview.legal/posts/91661*

Restrictions concerning specific principles and the rights of information, access to and rectification or erasure of personal data, the right to data portability, the right to object, decisions based on profiling, as well as the communication of a personal data breach to a data subject and certain related obligations of the controllers may be imposed by Union or Member State law, as far as necessary and proportionate in a democratic society to safeguard public security, including the protection of human life especially in response to natural or manmade disasters, the prevention, investigation and prosecution of criminal offences or the execution of criminal penalties, including the safeguarding against and the prevention of threats to public security, or of breaches of ethics for regulated professions, other important objectives of general public interest of the Union or of a Member State, in particular an important economic or financial interest of the Union or of a Member State, the keeping of public registers kept for reasons of general public interest, further processing of archived personal data to provide specific information related to the political behaviour under former totalitarian state regimes or the protection of the data subject or the rights and freedoms of others, including social protection, public health and humanitarian purposes. Those restrictions should be in accordance with the requirements set out in the Charter and in the European Convention for the Protection of Human Rights and Fundamental Freedoms.

## Case law

### USR - Us I-755/2025-8

*Source: Administrative Court in Rijeka, 2025-11-11 — https://overview.legal/posts/49225 — original: https://gdprhub.eu/index.php?title=USR_-_Us_I-755/2025-8*

Facts — The data subject was a member of the management board of Zagrebački holding, a company owned by the City of Zagreb, from 3 September 2021 until 31 March 2023. A television broadcaster published several pieces, including a video on its YouTube channel, reporting on the data subject’s resignation. The publications mentioned his name, role, employer, salary, and information on the brand of his private car. The data subject filed a complaint with the Croatian Personal Data Protection Agency (AZOP), claiming that the publication constituted unlawful processing under the GDPR because the media lacked a valid legal basis under Article 6, the reporting was inaccurate and excessive, and it did not serve any genuine public interest. He latter further claimed during the lawsuit against AZOP's decision that the authority had incorrectly and incompletely established the facts, misapplied substantive law, and breached procedural rules. He emphasized that the published personal data was unrelated to transparency in public administration, that he was neither a public figure nor a political actor, and that any public interest ended once he left office on 31 March 2023. He invoked his right to erasure under Article 17 GDPR and sought removal of the content, annulment of AZOP’s decision, or alternatively, a remittal for a new procedure. AZOP contested the lawsuit in full, maintaining that it had acted in accordance with Article 34 of the Croatian GDPR Implementation Act and Article 77 GDPR. It argued that the publication fell within a justified public interest under Article 8 of the Croatian Media Act and that it had properly carried out a balancing test between privacy (Article 8 ECHR) and freedom of expression (Article 10 ECHR). According to AZOP, the reporting was necessary, proportionate, and not sensationalistic, and did not excessively intrude on the data subject’s privacy. It added that consent was not required because the processing relied on legitimate interest under Article 6(1)(f) GDPR. Holding — The Administrative Court dismissed the action and upheld AZOP’s decision. Because Zagrebački holding is a city-owned and publicly funded company, the court considered information about the data subject’s salary, compensation for using his private vehicle in official duties, and his managerial role to be directly connected to the use of public resources. This placed the publication within the legitimate public interest in transparency recognised by Article 8 of the Media Act. In its proportionality assessment, the court accepted AZOP's application of Article 5 and 6 GDPR, emphasizing that the published data did not touch upon the data subject’s family or intimate life but related solely to his public functions. Publication was therefore limited to what was necessary to inform the public about the management of a publicly owned company. The data subject’s claims that the publication was false or harmful to his reputation did not alter the outcome, as AZOP is not empowered to determine the truthfulness or tone of journalistic content, particularly under the journalistic exemption in Article 85 GDPR. Issues of accuracy or reputational harm must instead be pursued through media-law mechanisms such as requests for correction or civil actions. On the erasure request, the court held that the right to be forgotten under Article 17 GDPR cannot override freedom of expression and information where media reporting is involved. Although the data subject no longer served on the board, the publication continued to contribute to public understanding of how a major public entity was run during his tenure, thus the public interest persisted and erasure was not justified. Finally, the court reiterated that consent was not required because Article 6 GDPR offers alternative lawful bases for processing. Since Article 6(1)(f) was satisfied, the absence of consent was irrelevant. Concluding that AZOP had properly applied the law and that the interference with the data subject’s privacy was proportionate, the court upheld the decision and denied the data subject’s claim and costs.

### WORTEN-EQUIPAMENTOS PARA O LAR SA V. ACT (AUTHORITY FOR WORKING CONDITIONS), 30.5.2013 (“WORTEN”)

*Source: CJEU, 2013-05-30 — https://overview.legal/posts/6169 — original: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:62011CJ0342&ref=6169*

Security: Data protection law requires controllers (not Member States) to adopt technical and organizational measures which, having regard to the state of the art and cost of their implementation, are to ensure a level of security appropriate to the risks represented. Controller must ensure that only those persons duly authorized have access. (¶¶ 24–25, 28–29)

### DIGITAL RIGHTS IRELAND LTD V. IRELAND,

*Source: CJEU, 2014-04-08 — https://overview.legal/posts/6161 — original: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:62012CJ0293&ref=6161*

Data retention: Legally mandated communications meta-data retention can only be a justified interference with the right of privacy and the right to data protection under EU law if the retention is done for the purpose of fighting ‘serious crime’, on the basis of objective criteria and where there are clear substantial and procedural conditions laid down by law.

## Guidance

### Guidelines 5/2019 on the criteria of the Right to be Forgotten in the search engines cases under the GDPR (part 1)

*Source: EDPB, edpb-guidelines-on-the-criteria-of-the-right-to-be-forgotten-in-the-search-engines-cases-under-th, 2020-07-07 — https://overview.legal/posts/38070 — original: https://www.edpb.europa.eu/documents/guideline/guidelines-52019-on-the-criteria-of-the-right-to-be-forgotten-in-the-search_en*

The European Data Protection Board (EDPB) issued these guidelines to clarify the criteria and grounds for exercising the right to erasure (right to be forgotten) specifically in the context of search engine cases under the GDPR. The document details the six grounds under Article 17(1) that allow data subjects to request delisting, alongside the relevant exceptions, such as the right to freedom of expression and information. As a guidance instrument, it does not impose administrative fines but instead aims to harmonize how search engine providers handle and balance delisting requests across the EU.

### Guidelines 01/2022 on data subject rights - Right of access

*Source: EDPB, edpb-guidelines-on-data-subject-rights---right-of-access, 2023-04-17 — https://overview.legal/posts/38055 — original: https://www.edpb.europa.eu/documents/guideline/guidelines-012022-on-data-subject-rights-right-of-access_en*

The right of access of data subjects is enshrined in Art. 8 of the EU Charter of Fundamental Rights. It has been a part of the European data protection legal framework since its beginning and is now further developed by more specified and precise rules in Art. 15 GDPR.

### Guidelines 04/2022 on the calculation of administrative fines under the GDPR

*Source: EDPB, edpb-guidelines-on-the-calculation-of-administrative-fines-under-the-gdpr, 2023-05-24 — https://overview.legal/posts/38068 — original: https://www.edpb.europa.eu/documents/guideline/guidelines-042022-on-the-calculation-of-administrative-fines-under-the-gdpr_en*

The European Data Protection Board (EDPB) has adopted these guidelines to harmonise the methodology supervisory  authorities use  when calculating of the amount of the fine. These Guidelines complement the previously  adopted Guidelines on the application and setting of administrative fines  for the purpose  of the Regulation 2016/679 (WP253), which focus on the circumstances in which to impose a fine. The calculation of the amount of the fine is at the discretion of the supervisory  authority, ...

### Guidelines 03/2022 on Deceptive design patterns in social media platform interfaces: how to recognise and avoid them

*Source: EDPB, edpb-guidelines-on-deceptive-design-patterns-in-social-media-platform-interfaces-how-to-recognise, 2023-02-24 — https://overview.legal/posts/38056 — original: https://www.edpb.europa.eu/documents/guideline/guidelines-032022-on-deceptive-design-patterns-in-social-media-platform_en*

These Guidelines offer practical recommendations to social media providers as controllers of social media, designers and users of social media platforms on how to assess and avoid so-called 'deceptive design patterns' in social media interfaces that infringe on GDPR requirements. To this end, the EDPB recommends  that  controllers  make  use  of  interdisciplinary  teams,  consisting,  among  others,  of designers,  data  protection  officers  and  decision-makers.  It  is  important  to  note  ...

### Guidelines 02/2022 on the application of Article 60 GDPR

*Source: EDPB, edpb-guidelines-on-the-application-of-article-60-gdpr, 2022-03-14 — https://overview.legal/posts/38066 — original: https://www.edpb.europa.eu/documents/guideline/guidelines-022022-on-the-application-of-article-60-gdpr_en*

With the introduction of the GDPR, the concept of the one-stop shop was established as one of the main innovations. In cross-border processing cases, the supervisory authority in the Member State of the controller's or processor's main establishment is the authority leading the  enforcement of the GDPR for the respective cross-border processing activities, in cooperation with all the authorities which may face the effects of the processing activities at stake: be it  through  the establishments ...

### Guidelines 01/2021

*Source: EDPB, edpb-guidelines-on-examples-regarding-personal-data-breach-notification, 2022-01-03 — https://overview.legal/posts/38047 — original: https://www.edpb.europa.eu/documents/guideline/guidelines-012021-on-examples-regarding-personal-data-breach-notification_en*

The European Data Protection Board (EDPB) adopted Guidelines 01/2021 on December 14, 2021, providing practical examples and analysis regarding personal data breach notification obligations under Articles 33 and 34 of the GDPR. The guidelines present hypothetical scenarios covering ransomware attacks and data exfiltration incidents, illustrating how controllers should assess risk to determine whether notification to supervisory authorities and communication to data subjects are required. The document serves as interpretive guidance for controllers evaluating breach severity, appropriate mitigation measures, and notification decisions, and does not impose any fines or sanctions.

### Guidelines 10/2020 on restrictions under Article 23 GDPR

*Source: EDPB, edpb-guidelines-on-restrictions-under-article-23-gdpr, 2021-10-13 — https://overview.legal/posts/38062 — original: https://www.edpb.europa.eu/documents/guideline/guidelines-102020-on-restrictions-under-article-23-gdpr_en*

The European Data Protection Board (EDPB) issued these guidelines to clarify the scope and application of Article 23 of the GDPR, which allows Member States to restrict certain data subject rights and controller obligations. The guidelines outline the necessary conditions and safeguards, emphasizing that any restrictions must respect the essence of fundamental rights and be implemented via foreseeable, proportionate legislative measures. This document serves as authoritative guidance for interpreting the specific grounds and requirements under which Member States may legally impose such limitations.

### Guidelines 07/2020 on the concepts of controller and processor in the GDPR

*Source: EDPB, edpb-guidelines-on-the-concepts-of-controller-and-processor-in-the-gdpr, 2021-07-07 — https://overview.legal/posts/38069 — original: https://www.edpb.europa.eu/documents/guideline/guidelines-072020-on-the-concepts-of-controller-and-processor-in-the-gdpr_en*

The concepts of controller, joint controller and processor play a crucial role in the application of the General Data Protection Regulation 2016/679 (GDPR), since they determine who shall be responsible for compliance with different data protection rules, and how data subjects can exercise their rights in practice. The precise meaning of these concepts and the criteria for their correct interpretation must be sufficiently clear and consistent throughout the European Economic Area (EEA). The conc...

## Recent developments

### One-Stop-Shop case digest on right to object and right to erasure updated

*Source: European Data Protection Board, 2026-06-25 — https://overview.legal/posts/53055 — original: https://www.edpb.europa.eu/news/one-stop-shop-case-digest-on-right-to-object-and-right-to-erasure-updated_en*

Brussels, 25 June - The EDPB has published an update of the One-Stop-Shop (OSS) case digest on right to object and right to erasure. This project has been developed in the framework of the of the Support Pool of Experts programme, which aims to support cooperation among Data Protection Authorities (DPAs).Thematic one-stop-shop case digests are drafted on the basis of one-stop-shop decisions taken from the EDPB’s public register (based on Art.60 GDPR). Such case digests complement the EDPB's publ

### EDPB identifies challenges hindering the full implementation of the right to erasure

*Source: European Data Protection Board, 2026-02-18 — https://overview.legal/posts/52724 — original: https://www.edpb.europa.eu/news/news/2026/edpb-identifies-challenges-hindering-full-implementation-right-erasure_en*

Brussels, 18 February - The European Data Protection Board (EDPB) has adopted a report on its Coordinated Enforcement Framework (CEF) action on the right to be forgotten (Art.17 GDPR). The Board selected this topic as it is one of the most frequently exercised GDPR rights and one about which DPAs frequently receive complaints from individuals. The main objectives of this coordinated action are to ensure that the right to erasure is effectively exercised by individuals in Europe and understand ho

### Respondent has no right to erasure of personal data

*Source: IT en Recht, 2023-03-01 — https://overview.legal/posts/6236 — original: https://www.itenrecht.nl/artikelen/geintimeerde-heeft-geen-recht-op-wissing-van-persoonsgegevens#entry-3985*

Hague Court of Appeal February 3, 2023, IT 4226; ECLI:NL:GHDHA:2023:306 (Veilig Thuis v. the respondent) In this case, a man requested the deletion of his personal data processed by Veilig Thuis. The court ruled that Veilig Thuis's processing of the man's data was lawful under the Social Support Act (Wmo) and that the request for data deletion was therefore denied. Safe Home is not obliged to erase the man's personal data in order to comply with the legal obligation under Article 17(1)(e) AVG, b

### "Exploring the Right to be Forgotten: Understanding Article 17 and 21 of the GDPR and Article 35 of its Implementation Law on Requesting Removal of Search Results on Google Search"

*Source: Dutch Courts, 2023-02-23 — https://overview.legal/posts/6240 — original: https://deeplink.rechtspraak.nl/uitspraak?id=ECLI:NL:RBLIM:2022:6330&pk_campaign=rss&pk_medium=rss&pk_keyword=uitspraken#entry-3929*

Personal data protection. Request for removal of search results from the Google Search search engine: the right to be forgotten. Articles 17 and 21 General Data Protection Regulation (AVG) and Article 35 AVG Implementation Act.

### Dirkzwager: ABRvS geeft uitleg aan het AVG-begrip "de instelling, uitoefening of onderbouwing van een rechtsvordering"

*Source: Dirkzwager, 2022-10-05 — https://overview.legal/posts/6332 — original: https://www.dirkzwager.nl/kennis/artikelen/abrvs-geeft-uitleg-aan-het-avg-begrip-de-instelling-uitoefening-of-onderbouwing-van-een-rechtsvordering/#entry-968*

> Privacybescherming is niet absoluut. Dat staat zelfs letterlijk zo in de privacywetgeving. De AVG bevat daarom ook allerlei uitzonderingen. Een van de uitzonderingen die enkele keren terugkomt in de AVG ziet op de verwerking van persoonsgegevens in het kader van "de instelling, uitoefening of onderbouwing van een rechtsvordering". Tot op heden was echter niet heel erg duidelijk wat die woorden nu precies betekenen. Een recente uitspraak van de Afdeling bestuursrechtspraak van de Raad van State

## Related topics

- **Personal Data** — https://overview.legal/topics/persoonsgegevens
  Information relating to identified or identifiable natural persons
- **Controllers** — https://overview.legal/topics/controllers
  Entities that determine purposes and means of processing
- **Right to be Forgotten** — https://overview.legal/topics/recht-op-vergetelheid
  Right to have personal data erased under certain conditions
- **Processing** — https://overview.legal/topics/verwerking
  Any operation performed on personal data
- **Lawful Basis** — https://overview.legal/topics/lawful-basis-article-6
  This topic is essential as Article 6 GDPR provides the specific legal bases that determine whether processing is lawful, which is the core requirement of the 'L
- **Right to Rectification** — https://overview.legal/topics/right-to-rectification
  Right to have inaccurate personal data corrected

---
Generated by overview.legal · https://overview.legal/topics/right-to-erasure · 2026-08-22
