Skip to content
Menu icon
Secure Privacy
  • GDPR
  • Key issues
  • Recitals
  • News
  • Publications
  • About Us
  • Blog

ChatGPT
Open in ChatGPT

Ask questions about this page

Perplexity
Open in Perplexity

Ask questions about this page

Claude
Open in Claude

Ask questions about this page

Google
Open in Google Search AI

Ask questions about this page


  • English
    • Deutsch(German)
    • Dansk(Danish)
    • Français(French)
    • Italiano(Italian)
    • Polski(Polish)
    • Español(Spanish)
    • Svenska(Swedish)
    • Български(Bulgarian)
    • Hrvatski(Croatian)
    • Čeština(Czech)
    • Nederlands(Dutch)
    • Eesti(Estonian)
    • Suomi(Finnish)
    • Ελληνικά(Greek)
    • Magyar(Hungarian)
    • Gaeilge(Irish)
    • Latviešu(Latvian)
    • Lietuvių(Lithuanian)
    • Malti(Maltese)
    • Português(Portuguese (Portugal))
    • Română(Romanian)
    • Slovenčina(Slovak)
    • Slovenščina(Slovenian)

DPO as a Service
DPO as a Service
Secure Privacy

ChatGPT
Open in ChatGPT

Ask questions about this page

Perplexity
Open in Perplexity

Ask questions about this page

Claude
Open in Claude

Ask questions about this page

Google
Open in Google Search AI

Ask questions about this page


  • English
    • Deutsch(German)
    • Dansk(Danish)
    • Français(French)
    • Italiano(Italian)
    • Polski(Polish)
    • Español(Spanish)
    • Svenska(Swedish)
    • Български(Bulgarian)
    • Hrvatski(Croatian)
    • Čeština(Czech)
    • Nederlands(Dutch)
    • Eesti(Estonian)
    • Suomi(Finnish)
    • Ελληνικά(Greek)
    • Magyar(Hungarian)
    • Gaeilge(Irish)
    • Latviešu(Latvian)
    • Lietuvių(Lithuanian)
    • Malti(Maltese)
    • Português(Portuguese (Portugal))
    • Română(Romanian)
    • Slovenčina(Slovak)
    • Slovenščina(Slovenian)

DPO as a Service
DPO as a Service
  • GDPR
  • Key issues
  • Recitals
  • News
  • Publications
  • About Us
  • Blog
to select
to navigate
to close
Search by
  • Chapter 1 (Art 1 - 4) General provisions
    • Art. 1 GDPR – Subject-matter and objectives
    • Art. 2 GDPR – Material scope
    • Art. 3 GDPR – Territorial scope
    • Art. 4 GDPR – Definitions
  • Chapter 2 (Art 5 - 11) Principles
    • Art. 5 GDPR – Principles relating to processing of personal data
    • Art. 6 GDPR – Lawfulness of processing
    • Art. 7 GDPR – Conditions for consent
    • Art. 8 GDPR – Conditions applicable to child’s consent in relation to information society services
    • Art. 9 GDPR – Processing of special categories of personal data
    • Art. 10 GDPR – Processing of personal data relating to criminal convictions and offences
    • Art. 11 GDPR – Processing which does not require identification
  • Chapter 3 (Art 12 - 23) Rights of the data subject
    • Art. 12 GDPR – Transparent information, communication and modalities for the exercise of the rights of the data subject
    • Art. 13 GDPR – Information to be provided where personal data are collected from the data subject
    • Art. 14 GDPR – Information to be provided where personal data have not been obtained from the data subject
    • Art. 15 GDPR – Right of access by the data subject
    • Art. 16 GDPR – Right to rectification
    • Art. 17 GDPR – Right to erasure (‘right to be forgotten’)
    • Art. 18 GDPR – Right to restriction of processing
    • Art. 19 GDPR – Notification obligation regarding rectification or erasure of personal data or restriction of processing
    • Art. 20 GDPR – Right to data portability
    • Art. 21 GDPR – Right to object
    • Art. 22 GDPR – Automated individual decision-making, including profiling
    • Art. 23 GDPR – Restrictions
  • Chapter 4 (Art 24 - 43) Controller and processor
    • Art. 24 GDPR – Responsibility of the controller
    • Art. 25 GDPR – Data protection by design and by default
    • Art. 26 GDPR – Joint controllers
    • Art. 27 GDPR – Representatives of controllers or processors not established in the Union
    • Art. 28 GDPR – Processor
    • Art. 29 GDPR – Processing under the authority of the controller or processor
    • Art. 30 GDPR – Records of processing activities
    • Art. 31 GDPR – Cooperation with the supervisory authority
    • Art. 32 GDPR – Security of processing
    • Art. 33 GDPR – Notification of a personal data breach to the supervisory authority
    • Art. 34 GDPR – Communication of a personal data breach to the data subject
    • Art. 35 GDPR – Data protection impact assessment
    • Art. 36 GDPR – Prior consultation
    • Art. 37 GDPR – Designation of the data protection officer
    • Art. 38 GDPR – Position of the data protection officer
    • Art. 39 GDPR – Tasks of the data protection officer
    • Art. 40 GDPR – Codes of conduct
    • Art. 41 GDPR – Monitoring of approved codes of conduct
    • Art. 42 GDPR – Certification
    • Art. 43 GDPR – Certification bodies
  • Chapter 5 (Art 44 - 50) Transfers of personal data to third countries or international organisations
    • Art. 44 GDPR – General principle for transfers
    • Art. 45 GDPR – Transfers on the basis of an adequacy decision
    • Art. 46 GDPR – Transfers subject to appropriate safeguards
    • Art. 47 GDPR – Binding corporate rules
    • Art. 48 GDPR – Transfers or disclosures not authorised by Union law
    • Art. 49 GDPR – Derogations for specific situations
    • Art. 50 GDPR – International cooperation for the protection of personal data
  • Chapter 6 (Art 51 - 59) Independent supervisory authorities
    • Art. 51 GDPR – Supervisory authority
    • Art. 52 GDPR – Independence
    • Art. 53 GDPR – General conditions for the members of the supervisory authority
    • Art. 54 GDPR – Rules on the establishment of the supervisory authority
    • Art. 55 GDPR – Competence
    • Art. 56 GDPR – Competence of the lead supervisory authority
    • Art. 57 GDPR – Tasks
    • Art. 58 GDPR – Powers
    • Art. 59 GDPR – Activity reports
  • Chapter 7 (Art 60 - 76) Cooperation and consistency
    • Art. 60 GDPR – Cooperation between the lead supervisory authority and the other supervisory authorities concerned
    • Art. 61 GDPR – Mutual assistance
    • Art. 62 GDPR – Joint operations of supervisory authorities
    • Art. 63 GDPR – Consistency mechanism
    • Art. 64 GDPR – Opinion of the Board
    • Art. 65 GDPR – Dispute resolution by the Board
    • Art. 66 GDPR – Urgency procedure
    • Art. 67 GDPR – Exchange of information
    • Art. 68 GDPR – European Data Protection Board
    • Art. 69 GDPR – Independence
    • Art. 70 GDPR – Tasks of the Board
    • Art. 71 GDPR – Reports
    • Art. 72 GDPR – Procedure
    • Art. 73 GDPR – Chair
    • Art. 74 GDPR – Tasks of the Chair
    • Art. 75 GDPR – Secretariat
    • Art. 76 GDPR – Confidentiality
  • Chapter 8 (Art 77 - 84) Remedies, liability and penalties
    • Art. 77 GDPR – Right to lodge a complaint with a supervisory authority
    • Art. 78 GDPR – Right to an effective judicial remedy against a supervisory authority
    • Art. 79 GDPR – Right to an effective judicial remedy against a controller or processor
    • Art. 80 GDPR – Representation of data subjects
    • Art. 81 GDPR – Suspension of proceedings
    • Art. 82 GDPR – Right to compensation and liability
    • Art. 83 GDPR – General conditions for imposing administrative fines
    • Art. 84 GDPR – Penalties
  • Chapter 9 (Art 85 - 91) Provisions relating to specific processing situations
    • Art. 85 GDPR – Processing and freedom of expression and information
    • Art. 86 GDPR – Processing and public access to official documents
    • Art. 87 GDPR – Processing of the national identification number
    • Art. 88 GDPR – Processing in the context of employment
    • Art. 89 GDPR – Safeguards and derogations relating to processing for archiving purposes in the public interest, scientific or historical research purposes or statistical purposes
    • Art. 90 GDPR – Obligations of secrecy
    • Art. 91 GDPR – Existing data protection rules of churches and religious associations
  • Chapter 10 (Art 92 - 93) Delegated acts and implementing acts
    • Art. 92 GDPR – Exercise of the delegation
    • Art. 93 GDPR – Committee procedure
  • Chapter 11 (Art 94 - 99) Final provisions
    • Art. 94 GDPR – Repeal of Directive 95/46/EC
    • Art. 95 GDPR – Relationship with Directive 2002/58/EC
    • Art. 96 GDPR – Relationship with previously concluded Agreements
    • Art. 97 GDPR – Commission reports
    • Art. 98 GDPR – Review of other Union legal acts on data protection
    • Art. 99 GDPR – Entry into force and application
Home > Chapter 3 - Rights of the data subject > Art. 17 GDPR – Right to erasure (‘right to be forgotten’)

Art. 17 GDPR – Right to erasure (‘right to be forgotten’)

Art. 17(1)
The data subject shall have the right to obtain from the controller the erasure of personal data concerning him or her without undue delay and the controller shall have the obligation to erase personal data without undue delay where one of the following grounds applies:
(a) the personal data are no longer necessary in relation to the purposes for which they were collected or otherwise processed. No longer necessary
(b) the data subject withdraws consent on which the processing is based according to point (a) of Article 6(1), or point (a) of Article 9(2), and where there is no other legal ground for the processing. Consent withdrawn
(c) the data subject objects to the processing pursuant to Article 21(1) and there are no overriding legitimate grounds for the processing, or the data subject objects pursuant to Article 21(2). Objection
(d) the personal data have been unlawfully processed. Unlawful processing
(e) the personal data have to be erased for compliance with a legal obligation in Union or Member State law to which the controller is subject. Legal obligation
(f) the personal data have been collected in relation to the offer of information society services referred to in Article 8(1). Child’s consent
Art. 17(2)
Where the controller has made the personal data public and is obliged pursuant to paragraph 1 to erase it, the controller, taking account of available technology and cost of implementation, shall take reasonable steps, including technical measures, to inform controllers processing the data that the data subject has requested erasure of any links to, copy of, or replication of those personal data.
Art. 17(3)
Paragraphs 1 and 2 shall not apply to the extent that processing is necessary:
(a) for exercising the right of freedom of expression and information. Freedom of expression
(b) for compliance with a legal obligation, or for the performance of a task carried out in the public interest or in the exercise of official authority vested in the controller. Legal obligation or public task
(c) for reasons of public interest in the area of public health in accordance with Article 9(2)(h),(i) and Article 9(3). Public health
(d) for archiving purposes in the public interest, scientific or historical research purposes, or statistical purposes under Article 89(1), insofar as erasure is likely to render impossible or seriously impair those objectives. Archiving or research
(e) for the establishment, exercise or defence of legal claims. Legal claims

In short
Article 17 gives individuals the right to have their personal data erased in defined circumstances, most commonly when it’s no longer needed, consent is withdrawn, or processing was unlawful. It isn’t absolute, since five exceptions let a controller refuse, from freedom of expression to legal claims. Getting the exceptions wrong in either direction, by refusing a valid request or erasing data the company was still entitled to keep, is what tends to draw regulatory attention.
ChapterChapter 3, Rights of the data subject (Art. 12 to 23)
Applies toEvery controller processing personal data of an identifiable individual in the EU/EEA
Maximum fine€20.000.000 or 4% of worldwide annual turnover, whichever is higher (Art. 83(5)(b))
In force since25 May 2018
Explained by recitals65, 66
Closest UK equivalentUK GDPR Art. 17 (identical wording)

When Can a Controller Refuse an Erasure Request?

Article 17 is one of the most frequently exercised, and most commonly mishandled, data subject rights. A refusal is only valid if it maps to a specific Art. 17(3) exception:

SituationCan the controller refuse?
Data is still needed for the original purpose it was collected forYes, refusal is valid
Data is needed to comply with a legal retention obligation, for example tax recordsYes, refusal is valid
Data is needed to establish, exercise, or defend a legal claimYes, refusal is valid
Journalistic or archival content protected by freedom of expressionYes, refusal is valid
Individual simply changed their mind about a lawful, ongoing serviceNo, not a ground on its own unless another Art. 17(1) ground applies
Data was unlawfully processed in the first placeNo, it must be erased

What Does Complying With an Erasure Request Actually Involve?

  • Confirm which Art. 17(1) ground applies before acting either way. A blanket policy of never deleting data is not compliant
  • If the data was made public, take reasonable steps to inform other controllers processing copies of it or links to it (Art. 17(2))
  • Respond within one month (Art. 12(3)), extendable by two months for complex requests, with a clear explanation either way
  • Refusing a request requires citing a specific Art. 17(3) exception rather than internal discretion
  • Track downstream processors and copies. Erasure isn’t complete if a backup, processor, or cached copy still exists

GDPR Article 17 Fines: Enforcement Cases and Amounts

Article 17 failures rarely headline on their own. They tend to surface as one finding within a broader decision about how a company handles data subject rights generally.

OrganisationAuthorityDateFine
GoogleIMY (Sweden)Mar 2020SEK 75.000.000 (approx. €7.000.000)
Carrefour FranceCNIL (France)Nov 2020€2.250.000

All Article 17 enforcement cases →

Recitals That Explain Article 17

Recital 65, Right of Rectification and Erasure
Explains the grounds for erasure, including when data is no longer needed, consent is withdrawn, or an objection succeeds, and situates the right alongside the right to rectification.

Recital 66, Right to Be Forgotten
Extends the erasure obligation to publicly available data, directing controllers to take reasonable steps, including technical measures, to inform other controllers processing that data, taking available technology and cost into account.

Article 17 Compliance Checklist

  • Build a documented process for logging, evaluating, and responding to erasure requests within one month
  • Map which Art. 17(1) ground and, if refusing, which Art. 17(3) exception applies before responding
  • Include downstream processors and any publicly posted copies in the erasure scope, not just the primary system
  • Request additional identity verification only where there is genuine doubt about who is asking, rather than as a routine step for every request
  • Track response time performance, since a spike in request volume does not excuse missed deadlines even though corrective measures taken afterward can still count in a company’s favour
  • Distinguish erasure from anonymisation or access restriction, since they are not automatically the same thing

Related Recitals

(65) Right of Rectification and Erasure
(66) Right to be Forgotten

Article 17 Enforcement Cases

Google’s Fine (Sweden)
Carrefour France’s Fine

Frequently Asked Questions about Article 17

+ What is the right to be forgotten under the GDPR?
Article 17 gives individuals the right to have their personal data erased in certain circumstances, such as when the data is no longer needed, consent is withdrawn, or processing was unlawful.
+Is the right to erasure absolute under the GDPR?
No. Erasure can be refused where processing is necessary for freedom of expression, legal obligations, public health, archiving in the public interest, or the establishment of legal claims.
+ When can a company refuse a deletion request?
A controller can refuse erasure where it still has a valid legal basis or obligation to keep the data, for example to comply with law or to defend legal claims.
+ Does erasure mean the data has to be physically destroyed?
Not necessarily by one specific method, but the data must be effectively and irreversibly removed. Regulators have found that anonymising or restricting access, without rendering the data truly unidentifiable, does not satisfy Article 17.
+ How is Article 17 different from Article 21’s right to object?
Article 21 lets someone object to processing in the first place, particularly for direct marketing or legitimate interest processing. A successful objection under Art. 21 is itself one of the six grounds that then triggers the Art. 17 erasure obligation.

Related Key Issues

  • GDPR Right to be Forgotten
  • GDPR Consent
  • GDPR Email Marketing

Related Articles

  • Art. 21 GDPR – Right to object
  • Art. 22 GDPR – Automated individual decision-making, including profiling
  • Art. 23 GDPR – Restrictions
  • Art. 12 GDPR – Transparent information, communication and modalities for the exercise of the rights of the data subject
Art. 16 GDPR – Right to rectification
Art. 18 GDPR – Right to restriction of processing

About us :

gdpr-law.eu is published and maintained by
Secure Privacy
. Secure Privacy has helped 15,000+ businesses achieve privacy compliance across 50+ countries since 2018.

Ratings:Rated 4.8★ on G2.

Quick Links :

  • Home
  • All 99 GDPR Articles
  • Recitals
  • Key issues
  • News
  • Publications
  • DPO as a Service
  • About Us
  • Contact

Legal :

  • Privacy Policy
  • Cookie Policy
  • Terms of Use
  • Editorial Policy

Contact & Socials :

  • LinkedIn (Secure Privacy)
  • x.com

© 2026 Secure Privacy. gdpr-law.eu is a free public resource. Content is for informational purposes only and does not constitute legal advice.

Scroll to Top