GDPR Data Erasure Lawyer — Enforce Your Right to Delete Personal Data

GDPR Article 17 gives individuals a right to request erasure of personal data in defined circumstances. It can apply where information is no longer necessary, consent has been withdrawn without another lawful basis, processing is unlawful, or an objection succeeds against continued processing.

The right is powerful, but it is not automatic. Organisations may retain data where a valid exception applies, including freedom of expression and information, compliance with legal obligations, certain public-interest purposes, or the establishment, exercise or defence of legal claims.

Our lawyers assess the specific data, the controller’s legal basis and the applicable jurisdiction before preparing an erasure request. We handle disputes involving compliance databases, data brokers, online publishers and other organisations where continued processing of personal information may no longer be justified.

Where the main issue is search visibility rather than deletion from the underlying controller, a separate Right to Be Forgotten or search-engine delisting strategy may be more appropriate.

Book a call

Article 17 GDPR establishes the right to erasure, commonly referred to as the “right to be forgotten”. It allows a data subject to require a controller to erase personal data without undue delay when one of the grounds in Article 17(1) applies and no relevant exception prevents deletion.

The EU GDPR applies according to its territorial scope rules. This includes processing carried out in the context of an EU establishment and, in certain circumstances, processing by organisations outside the EU that offer goods or services to people in the Union or monitor their behaviour there.

The UK has a parallel right to erasure under the UK GDPR. The precise legal framework should therefore be identified before a demand is sent, particularly in cross-border cases.

The right can apply to many types of controllers, including:

  • commercial databases;
  • data brokers;
  • social and online platforms;
  • businesses holding customer information;
  • compliance and risk-screening providers;
  • publishers and media organisations where no overriding exemption applies.

It does not mean that every negative, embarrassing or publicly available item must be deleted.

For a broader explanation of Article 17, see our GDPR Right to Erasure guide.

When Erasure Is Available

Article 17(1) identifies specific situations in which personal data may have to be erased. The correct ground should be identified before an erasure demand is made, because a generic request to “delete everything” can be easier for a controller to reject.

Erasure may be available where:

  • The personal data is no longer necessary for the purposes for which it was collected or otherwise processed.
  • Consent has been withdrawn, where consent was the legal basis for processing and there is no other legal ground for continuing to process the data.
  • You object to processing under Article 21(1) and the controller cannot demonstrate overriding legitimate grounds for continuing the processing.
  • You object to direct marketing under Article 21(2), where the right to object is particularly strong.
  • The personal data has been unlawfully processed.
  • Erasure is required to comply with a legal obligation under EU or applicable Member State law.
  • The data was collected in connection with information-society services offered to a child in the circumstances covered by Article 17.

Inaccuracy should be treated carefully. Inaccurate data is primarily addressed by Article 16, the right to rectification. The mere fact that information is inaccurate does not create a separate Article 17 ground by itself. However, erasure may still be appropriate where the wider processing is unlawful, unnecessary or another Article 17 ground applies.

The right is also subject to Article 17(3). A controller may be entitled to retain data where processing remains necessary for freedom of expression and information, a legal obligation or public task, specified public-health or research purposes, or legal claims.

Organisations That Most Frequently Receive Our Erasure Demands

The legal analysis changes depending on the type of controller. A commercial data broker, AML compliance database and newspaper archive may all process the same personal information under very different legal bases.

Our work commonly involves:

  • Compliance screening databases: World-Check, LexisNexis Risk Solutions, Dow Jones Risk & Compliance, Refinitiv and similar platforms. These cases frequently involve legitimate interests, legal compliance and AML-related arguments that need to be analysed before full erasure can realistically be requested.
  • News archives and media organisations: Older reports about charges, investigations, litigation or allegations may require an assessment of privacy rights against freedom of expression and continuing public interest.
  • Data brokers: Aggregators may collect addresses, company affiliations, court records and other personal information from multiple public and commercial sources.
  • Online platforms and social media: Privacy-invasive or unlawfully processed information may sometimes be challenged under GDPR alongside platform rules or other legal causes of action.

For structured commercial profiles, see our data broker removal lawyer service.

Where inaccurate compliance information is driving KYC or banking problems, it may be necessary to combine GDPR rights with a broader compliance database dispute.

The Erasure Process

A legally effective erasure strategy begins with identifying who actually controls the data and why they claim to be entitled to process it.

Our process typically involves:

  1. Identify the controller and the data.
    We determine which organisation is processing the personal data, what information is involved and which jurisdictional rules apply.
  2. Establish what is being processed.
    Where necessary, a subject access request or other disclosure mechanism may be used to clarify the data, source, recipients, retention period and claimed legal basis. A subject access request is not a mandatory prerequisite to every Article 17 request.
  3. Prepare the erasure demand.
    We identify the specific Article 17 ground, address foreseeable objections and provide supporting evidence where appropriate.
  4. Assess the controller’s response.
    The controller may agree to erase the data, offer rectification or restriction, request proportionate identity verification, or rely on a statutory exception.
  5. Escalate an unjustified refusal.
    Depending on jurisdiction and circumstances, this may involve a complaint to the competent data protection authority or court proceedings.

Under GDPR procedural rules, controllers must generally respond without undue delay and within one month. That period can be extended by a further two months where necessary because of the complexity or number of requests, but the individual must be told of the extension and reasons within the initial month.

A request does not need complex legal terminology to be valid. The value of legal representation is primarily in identifying the correct legal basis, anticipating exceptions and building the evidence necessary if the matter has to be escalated.

Related Services

GDPR erasure is only one of several possible remedies. The correct route depends on where the information is stored and what outcome is required.

For compliance database cases, see LexisNexis Right to Erasure and World-Check removal.

If the information should remain at its original source but should no longer appear prominently in name-based search results, see our Right to Be Forgotten lawyer service.

Where the objective is to remove or challenge the original publication itself, see online content removal and news article removal.

For Google-specific visibility problems, see remove content from Google.

GDPR Erasure vs Rectification: Which Right Applies

GDPR provides distinct rights to rectification under Article 16 and erasure under Article 17.

Rectification is generally appropriate where the controller has personal information about you but that information is inaccurate or incomplete. The objective is to correct the record rather than remove it.

Erasure is appropriate where continued processing itself should cease because one of the Article 17 grounds applies.

For example:

  • an incorrect date of birth may call for rectification;
  • an incorrect allegation in a database may require rectification and potentially other remedies;
  • information retained after the original purpose has expired may support erasure;
  • data processed without a valid legal basis may support erasure;
  • information processed on legitimate-interest grounds may require an Article 21 objection before Article 17(1)(c) becomes relevant.

In compliance screening cases, more than one GDPR right can sometimes apply. An entry may contain inaccurate information while the controller also lacks sufficient justification for retaining some or all of the data.

A lawyer should therefore avoid automatically demanding complete deletion where rectification, restriction or objection provides the stronger legal route.

For LexisNexis-specific data issues, see our LexisNexis dispute service.

GDPR Damages for Unlawful Processing

Article 82 GDPR provides a right to compensation where a person has suffered material or non-material damage as a result of an infringement of the Regulation.

Compensation is not automatic simply because a GDPR violation occurred.

The Court of Justice of the European Union has confirmed that three elements are required:

  • an infringement of the GDPR;
  • material or non-material damage;
  • a causal link between the infringement and that damage.

At the same time, EU law does not require non-material damage to reach a particular minimum threshold of seriousness.

Potential material consequences may include demonstrable financial losses caused by unlawful processing.

Potential non-material damage can depend on the facts and may include loss of control over personal data or other proven adverse consequences. The existence and causal connection must still be established.

For example, if inaccurate or unlawfully processed compliance data contributes to banking restrictions or failed onboarding, the evidence must distinguish the GDPR infringement from other legitimate reasons the institution may have had for its decision.

An Article 82 damages claim should therefore be assessed separately from the erasure request itself. Successful deletion does not automatically establish entitlement to damages, and a refusal to erase does not automatically create a compensation claim.

Frequently Asked Questions

The right to erasure is highly fact-specific. The most important questions concern the legal basis for continued processing, whether an Article 17 ground applies and whether the controller can rely on an exception.

What is the right to erasure under GDPR?

Article 17 GDPR gives a data subject the right to request deletion of personal data in specified circumstances.

These include where data is no longer necessary for its original purpose, consent has been withdrawn without another lawful basis, a qualifying objection succeeds, the data has been processed unlawfully, erasure is legally required, or certain data was collected in relation to information-society services offered to a child.

The right is commonly called the right to be forgotten, although the two expressions are sometimes used in different practical contexts, particularly when discussing search-engine delisting.

The right is not absolute. Article 17(3) contains important exceptions.

Can a data controller legally refuse an erasure request?

Yes.

A controller may be entitled to retain data where an Article 17(3) exception applies. Examples include processing necessary for:

  • freedom of expression and information;
  • compliance with a legal obligation;
  • performance of certain public-interest tasks;
  • specified public-health purposes;
  • archiving, scientific, historical or statistical purposes under the required conditions;
  • establishment, exercise or defence of legal claims.

A refusal should not consist merely of a generic statement that the organisation has a “legitimate interest”. The controller needs to assess the actual legal basis, the grounds relied upon by the individual and any applicable exception.

Where no action is taken on a valid request, the individual must generally be informed of the reasons and available complaint or judicial remedies.

How long does a GDPR erasure request take?

The controller must generally respond without undue delay and within one calendar month.

For complex requests, or where the individual has made a number of requests, the response period can be extended by up to a further two months. The controller must notify the individual about the extension within the initial one-month period and explain the reason.

The deadline may also be affected where proportionate additional information is genuinely required to confirm the requester’s identity.

A one-month deadline is a deadline for responding to the request. It should not be marketed as a guarantee that every complex erasure dispute will be fully resolved within one month.

What happens if a data controller ignores my erasure request?

If a controller does not respond within the applicable period, or refuses the request on grounds that appear legally unjustified, the next step depends on jurisdiction.

Options may include:

  • making a formal complaint to the controller;
  • lodging a complaint with the competent supervisory authority;
  • seeking a court order enforcing data-protection rights;
  • pursuing compensation under Article 82 where an infringement has actually caused material or non-material damage.

In the UK, the ICO recommends first raising the issue with the organisation and giving it an opportunity to resolve the matter before escalating a complaint.

The relevant regulator depends on the jurisdiction and the establishment or activities of the controller.

Does GDPR erasure apply to compliance databases such as World-Check?

Potentially, yes, provided the processing falls within the territorial scope of the applicable GDPR regime.

However, the existence of Article 17 does not mean a compliance database must automatically delete every profile on request.

Compliance providers may rely on legal bases such as legitimate interests and may point to regulatory or AML-related requirements. Whether those arguments justify the continued processing of the specific data at issue depends on factors including accuracy, necessity, proportionality, source information, retention and applicable legal obligations.

Where the problem is inaccurate data, Article 16 rectification may be relevant. Where processing is based on legitimate interests, an Article 21 objection may also need to be considered.

For database-specific assistance, see our World-Check removal and LexisNexis Right to Erasure services.

Additional GDPR Erasure Questions

These practical questions concern timing and refusals, which are among the most common points of dispute after an Article 17 request has been submitted.

How long does a GDPR erasure take?

A controller normally has one calendar month to respond.

Where the request is complex or numerous requests have been made, the controller can extend the response period by a further two months, provided the individual is informed of the extension and reasons within the first month.

Some requests result in prompt deletion. Others develop into disputes over legitimate interests, freedom of expression, statutory retention requirements or legal claims and may require regulatory or judicial escalation.

The statutory response period should therefore be distinguished from the total time required to resolve a contested case.

Can an organisation refuse to delete my data?

Yes, where continued processing is lawfully justified.

For example, Article 17(3) permits continued processing in circumstances involving freedom of expression and information, legal obligations, certain public-interest purposes, research and archiving requirements, or legal claims.

A controller may also reject or charge a reasonable administrative fee for a request that is manifestly unfounded or excessive, subject to the requirements of applicable data protection law. In ordinary cases, individuals are not charged for exercising the right to erasure.

Where the refusal appears unjustified, we assess:

  • the legal basis claimed by the controller;
  • the specific Article 17 ground relied upon;
  • whether another right such as rectification, restriction or objection is stronger;
  • the evidence supporting continued retention;
  • whether regulatory or court enforcement is proportionate.

Frequently Asked Questions

The data controller must respond within one calendar month. Compliance timescales vary: some organisations act quickly once a valid legal demand is received; others require escalation to a data protection authority. Our experience is that well-documented legal demands receive substantive responses faster than standard consumer requests.

Book a call
Your message send!