Right to Erasure (Data Deletion Request) Compliance Check
Check whether your business can properly handle 'right to be forgotten' requests under Article 17 of UK GDPR, separately from Subject Access Requests.
Why this matters
Article 17 of UK GDPR gives individuals a “right to erasure” — often called the right to be forgotten — that is legally distinct from the right of access dealt with by a Subject Access Request. An erasure request can be made whenever personal data is no longer necessary for the purpose it was collected for, when someone withdraws consent and no other lawful basis applies, when they object to processing and there are no overriding legitimate grounds, when data has been processed unlawfully, or where data about a child was collected for an online service. As with SARs, businesses normally have one calendar month to respond, extendable by two months for complex requests, and the Data (Use and Access) Act 2025 confirmed the same “stop the clock” pause while a business waits on clarification from the requester.
The right is not absolute — it can be refused where processing is necessary for freedom of expression, compliance with a legal obligation, public interest tasks, public health, archiving or research purposes, or the establishment of legal claims — but a blanket refusal without considering these grounds is itself a breach. Many small and medium UK businesses conflate erasure requests with SARs, or only delete data from their main customer database while leaving copies in backups, marketing platforms, spreadsheets, or with third-party processors. Article 17(2) also requires businesses that have made personal data public to take reasonable steps to tell other controllers processing it that erasure has been requested. The ICO treats mishandled erasure requests as an enforceable complaint in their own right, so having a documented, tested process for finding and removing personal data across every system it lives in matters as much as answering the request on time.
What you'll need
- Whether your business has a documented process for handling erasure ('right to be forgotten') requests
- Where personal data lives across your systems — CRM, marketing tools, backups, spreadsheets, and third-party processors
- Whether you can verify a requester's identity before acting on an erasure request
- Your current process for telling other organisations you've shared data with that erasure has been requested
What you'll get
A personalised compliance report covering: a score out of 100, an executive summary, a list of findings ranked by severity, and a prioritised action plan with timeframes.
Use this free tool to check whether your business can properly identify, verify, and act on ‘right to be forgotten’ erasure requests under Article 17 of UK GDPR — a distinct legal duty from handling Subject Access Requests. Get a clear, plain-English action plan in minutes.
General guidance only — not legal advice. Consult a qualified UK solicitor for specific issues.