Art. 17 GDPR – Right to erasure (‘right to be forgotten’)
The data subject shall have the right to obtain from the controller the erasure of personal data concerning him or her without undue delay and the controller shall have the obligation to erase personal data without undue delay where one of the following grounds applies:
Where the controller has made the personal data public and is obliged pursuant to paragraph 1 to erase it, the controller, taking account of available technology and cost of implementation, shall take reasonable steps, including technical measures, to inform controllers processing the data that the data subject has requested erasure of any links to, copy of, or replication of those personal data.
Paragraphs 1 and 2 shall not apply to the extent that processing is necessary:
Article 17 gives individuals the right to have their personal data erased in defined circumstances, most commonly when it’s no longer needed, consent is withdrawn, or processing was unlawful. It isn’t absolute, since five exceptions let a controller refuse, from freedom of expression to legal claims. Getting the exceptions wrong in either direction, by refusing a valid request or erasing data the company was still entitled to keep, is what tends to draw regulatory attention.
| Chapter | Chapter 3, Rights of the data subject (Art. 12 to 23) |
|---|---|
| Applies to | Every controller processing personal data of an identifiable individual in the EU/EEA |
| Maximum fine | €20.000.000 or 4% of worldwide annual turnover, whichever is higher (Art. 83(5)(b)) |
| In force since | 25 May 2018 |
| Explained by recitals | 65, 66 |
| Closest UK equivalent | UK GDPR Art. 17 (identical wording) |
When Can a Controller Refuse an Erasure Request?
Article 17 is one of the most frequently exercised, and most commonly mishandled, data subject rights. A refusal is only valid if it maps to a specific Art. 17(3) exception:
| Situation | Can the controller refuse? |
|---|---|
| Data is still needed for the original purpose it was collected for | Yes, refusal is valid |
| Data is needed to comply with a legal retention obligation, for example tax records | Yes, refusal is valid |
| Data is needed to establish, exercise, or defend a legal claim | Yes, refusal is valid |
| Journalistic or archival content protected by freedom of expression | Yes, refusal is valid |
| Individual simply changed their mind about a lawful, ongoing service | No, not a ground on its own unless another Art. 17(1) ground applies |
| Data was unlawfully processed in the first place | No, it must be erased |
What Does Complying With an Erasure Request Actually Involve?
- Confirm which Art. 17(1) ground applies before acting either way. A blanket policy of never deleting data is not compliant
- If the data was made public, take reasonable steps to inform other controllers processing copies of it or links to it (Art. 17(2))
- Respond within one month (Art. 12(3)), extendable by two months for complex requests, with a clear explanation either way
- Refusing a request requires citing a specific Art. 17(3) exception rather than internal discretion
- Track downstream processors and copies. Erasure isn’t complete if a backup, processor, or cached copy still exists
GDPR Article 17 Fines: Enforcement Cases and Amounts
Article 17 failures rarely headline on their own. They tend to surface as one finding within a broader decision about how a company handles data subject rights generally.
| Organisation | Authority | Date | Fine |
|---|---|---|---|
| IMY (Sweden) | Mar 2020 | SEK 75.000.000 (approx. €7.000.000) | |
| Carrefour France | CNIL (France) | Nov 2020 | €2.250.000 |
All Article 17 enforcement cases →
Recitals That Explain Article 17
Recital 65, Right of Rectification and Erasure
Explains the grounds for erasure, including when data is no longer needed, consent is withdrawn, or an objection succeeds, and situates the right alongside the right to rectification.
Recital 66, Right to Be Forgotten
Extends the erasure obligation to publicly available data, directing controllers to take reasonable steps, including technical measures, to inform other controllers processing that data, taking available technology and cost into account.
Article 17 Compliance Checklist
- Build a documented process for logging, evaluating, and responding to erasure requests within one month
- Map which Art. 17(1) ground and, if refusing, which Art. 17(3) exception applies before responding
- Include downstream processors and any publicly posted copies in the erasure scope, not just the primary system
- Request additional identity verification only where there is genuine doubt about who is asking, rather than as a routine step for every request
- Track response time performance, since a spike in request volume does not excuse missed deadlines even though corrective measures taken afterward can still count in a company’s favour
- Distinguish erasure from anonymisation or access restriction, since they are not automatically the same thing