Right to Erasure (Right to be Forgotten)
The right to erasure — sometimes called the "right to be forgotten" — allows you to request that an organisation delete your personal data in certain circumstances. It is one of eight rights under UK GDPR and can be a powerful tool for removing outdated, irrelevant, or unlawfully held data about you from online platforms and databases.
Key points
- You can request erasure when data is no longer necessary for the purpose it was collected, or where you withdraw consent.
- The right to erasure applies when data has been unlawfully processed, or must be erased to comply with a legal obligation.
- Organisations are not obliged to erase data where exemptions apply — such as for legal claims, scientific research, or freedom of expression.
- Organisations must respond to an erasure request within one month.
- If erasure is refused, you can complain to the ICO or apply to a court for a compliance order.
When You Can Request Erasure
Under Article 17 of UK GDPR, you have the right to request erasure of your personal data when one of the following grounds applies:
- The personal data is no longer necessary for the purpose it was originally collected or processed.
- You withdraw consent on which the processing was based, and there is no other legal ground for processing.
- You object to the processing under the right to object, and there are no overriding legitimate grounds for continued processing.
- The personal data has been unlawfully processed — i.e., processed without a valid legal basis.
- The personal data must be erased to comply with a legal obligation in UK or EU law applicable to the controller.
- The personal data was collected in relation to the offer of information society services to a child (online services), where parental consent was required.
When Organisations Can Refuse Erasure
The right to erasure is not absolute. Organisations can refuse to comply where the processing is necessary for:
- Exercising the right of freedom of expression and information — including journalism and public interest material about public figures or matters of public concern.
- Compliance with a legal obligation — for example, a bank must retain financial records for a statutory minimum period even if you request deletion.
- Performance of a task carried out in the public interest — including archiving in the public interest, scientific or historical research, or statistical purposes.
- The establishment, exercise, or defence of legal claims — organisations involved in or anticipating litigation may retain data necessary to defend themselves.
- Public health purposes
If an organisation refuses your erasure request, they must explain which exemption applies and how it is relevant to your specific data.
Getting Information Removed from Search Engine Results
A specific application of the right to erasure is requesting that search engines de-index search results that link to pages containing outdated, irrelevant, or damaging information about you. Both Google and Bing have online request forms for UK users.
Search engines balance your right to erasure against the public's right to access information. De-indexing is more likely to be granted where the information is:
- No longer accurate or up to date (e.g., an old criminal conviction that is now spent)
- Irrelevant to your current public role or activities
- Disproportionately damaging given your status as a private individual
De-indexing removes the page from search results but does not delete the underlying content from the website hosting it — you may need to contact the site directly as well.
How to Make an Erasure Request
To submit an erasure request:
- Write to the organisation's Data Protection Officer (DPO) or data controller, clearly stating that you are exercising your right to erasure under Article 17 of UK GDPR.
- Specify exactly which data you want deleted and, if relevant, the ground on which you are relying (e.g., "the data is no longer necessary" or "I am withdrawing my consent").
- The organisation has one month to respond. They must either confirm erasure, explain which exemption applies, or ask for clarification.
- If the organisation refuses without adequate justification, complain to the ICO or apply to a court under Section 167 of the DPA 2018 for a compliance order.
Frequently asked questions
Can I request that a newspaper remove an old article about me from their website?
I withdrew my consent to a marketing list. The company still has my data — can I demand erasure?
What happens to my data if I request erasure but the company shares it with third parties?
Does the right to erasure apply to data held in paper files as well as digital records?
What to do next
- 1ICO right to erasure guidance
The ICO's official guide to the right to be forgotten.
- 2Google content removal
Request de-indexing of search results linking to your personal data.
- 3Data subject access requests
Request a copy of all data held about you first, then decide what to request for erasure.
- 4UK GDPR rights overview
All eight of your data protection rights explained.
Official bodies and resources
Information Commissioner's Office
RegulatorThe UK's independent authority for data protection and information rights, enforcing the UK GDPR and Data Protection Act 2018.
Citizens Advice
CharityProvides free, confidential, and independent advice on a wide range of issues including benefits, housing, debt, and employment.
Was this page helpful?
Related guides
UK GDPR Rights for Individuals
The UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018 (DPA 2018) give individuals in the UK eight legally enforceable rights over how organisations collect, store, and use their personal data. These rights apply whether the data is held by a business, public body, or online platform.
6 min
Data Subject Access Requests
A Subject Access Request (SAR) is a formal request you can make to any organisation asking them to provide a copy of all personal data they hold about you and information about how it is used. It is one of your most powerful rights under UK GDPR and is entirely free in most cases.
6 min
When a Company Has a Data Breach
A personal data breach occurs when an organisation accidentally or unlawfully destroys, loses, alters, discloses, or gives access to your personal data without authorisation. When this happens, UK GDPR places obligations on the organisation — including notifying you if the breach is likely to cause you harm — and gives you rights to complain and potentially claim compensation.
6 min
Disclaimer