Glossary
Right to erasure
Also called: right to be forgotten, erasure request
The right to erasure allows an individual to require deletion of their personal data in defined circumstances. It is not absolute: a statutory retention obligation, a legal claim or a public interest ground can defeat it, and the decision must be reasoned and recorded.
Right to erasure explained
When it applies
Where the data is no longer necessary for the purpose collected, consent is withdrawn and there is no other basis, the individual objects and no overriding legitimate ground exists, the processing was unlawful, or erasure is required by another legal obligation.
When it does not
Where processing is necessary for compliance with a legal obligation, for the establishment or defence of legal claims, for reasons of public interest in public health, or for archiving in the public interest. In a document management context the first two do most of the work: an employment record, a financial record or a clinical record held under a statutory retention period generally cannot be erased on request.
The conflict, handled properly
This collision is common rather than exceptional, and a system that deletes on request without checking puts you in breach of one law while complying with another. The workable pattern is to surface the retention rule and any legal hold at the point deletion is attempted, so the conflict is visible before the decision rather than after it.
Recording the decision
Whether granted or refused, record what was decided, on what ground, by whom and when. A refusal without recorded reasoning is indistinguishable from a refusal without a reason, and that is the distinction a regulator will examine.
FAQ
Right to erasure: common questions
Does erasure mean deleting from backups too?
Strictly the obligation extends to all copies, but regulators have generally accepted that restoring and editing archived backups can be disproportionate. Document the approach you take rather than leaving it implicit.
Can we anonymise instead of deleting?
Yes, if the result is genuinely anonymous rather than pseudonymous — data that can be re-identified is still personal data and the obligation persists.
Related terms
- 21 CFR Part 1121 CFR Part 11 is the FDA regulation governing electronic records and electronic signatures in regulated life sciences.
- Business associate agreementA business associate agreement is the contract HIPAA requires between a covered entity and any vendor that creates, receives, maintains or transmits protected health information on its behalf.
- Data processing addendumA data processing addendum is the contract between a controller and a processor governing how personal data is handled.
- eIDASeIDAS is the EU regulation establishing a framework for electronic identification and trust services.
- ESIGN ActThe ESIGN Act is the US federal statute giving electronic signatures and records the same legal effect as paper, provided the parties intended to sign and consented to transact electronically.
- GDPRThe General Data Protection Regulation governs the processing of personal data in the EU, with an equivalent UK regime.
Last reviewed: August 28, 2026. Browse the full glossary.