Back to Blog
DSAR

The right to erasure: what counts as proof you deleted it

Published 17 September 20263 min readBy EmberHound

Article 17 reaches every copy you control, including backups and endpoints. A confirmation email is not evidence. What an audit-ready erasure record actually contains.

Article 17 gives individuals the right to have personal data erased in defined circumstances, and it carries the same one-month deadline as an access request. Most organisations can delete a record. Far fewer can show, months later, what was deleted, from where, and what was deliberately kept.

That gap is where erasure complaints are decided, because the individual's next move after 'we have deleted your data' is often to point at a copy you missed.

When the right applies, and when it doesn't

Erasure is not absolute. It applies where one of the Article 17(1) grounds is met, for example the data is no longer necessary for the purpose it was collected for, consent is withdrawn and there is no other lawful basis, or the data was unlawfully processed. It is disapplied under Article 17(3) where processing is necessary for reasons including compliance with a legal obligation, and the establishment, exercise or defence of legal claims.

In practice that means most erasure responses are partial: some data goes, some is retained on a named ground. The response has to say which is which. 'We have deleted everything' is usually either inaccurate or an admission that you deleted something you were required to keep.

The copies people forget

LocationWhy it's missedWhat to do
BackupsRestoring a whole backup to remove one record is disproportionateDocument the approach, put the data beyond use, delete on the normal backup cycle, and tell the individual that is the position
Endpoints and shared drivesNot indexed, not in the ROPA, not owned by anyoneSearch for the subject's identifiers across the estate rather than asking each system owner
MailboxesSearch usually covers the inbox and stops thereInclude sent items, archives and attachments
Exports and reportsPoint-in-time snapshots taken for analysisTreat any recurring export as a location in its own right
Third-party processorsDeletion happens with you, not with themInform recipients under Article 19 and confirm they acted
Logs and audit trailsOften retained on a legal or security groundRetain where justified, and record the ground rather than staying silent
The ICO's right to erasure guidance accepts that where deleting data from a backup is not immediately possible, you may put it beyond use, provided you do not use it for any other purpose and delete it when the backup is next refreshed. Say so in the response rather than leaving the individual to assume the backup was wiped.

What an audit-ready erasure record contains

  • The request, the date received, and the identity verification performed
  • The identifiers you searched on, including variants such as former surnames and secondary email addresses
  • Every system and location searched, including the ones that returned nothing
  • What was deleted, from where, and on what date
  • What was retained, with the Article 17(3) ground for each item
  • Anything put beyond use rather than deleted, and when it will age out
  • The recipients informed under Article 19
  • The response sent to the individual, and the date it went

The list of places that returned nothing is the line item people skip and the one that carries the weight. It is what turns 'we looked' into a record of exactly what you looked at.

Proving deletion in unstructured data

For a database, deletion is verifiable with a query. For files on endpoints and shares, the only real proof is a second pass that returns nothing for the identifiers you searched. That means the search has to be repeatable and recorded, with the same identifiers and the same scope, so the two passes are actually comparable. A search you cannot reproduce is not evidence of anything.

The overlap with access requests

An erasure request and an access request need the same first step: find every place the subject's personal data exists. Teams that have built that capability for access requests already hold most of what erasure needs. Teams that handle access requests by asking department heads to check their own systems find erasure much harder, because the answer has to be complete rather than good enough to compile a response from.

Sources & references

  1. Article 17 - Right to erasure ('right to be forgotten'), UK GDPR - legislation.gov.uk
  2. Right to erasure - ICO
  3. Article 19 - Notification obligation regarding rectification or erasure of personal data or restriction of processing - legislation.gov.uk
  4. Article 12 - Transparent information, communication and modalities, UK GDPR - legislation.gov.uk

Related resources

Want more of this in Google?

See what personal data your endpoints are hiding

EmberHound scans your devices for GDPR and PCI data automatically - no manual discovery required.

Your cookie choices

We use cookies to run this site, measure how it is used, and to advertise on other platforms. You can accept or refuse each purpose separately.

Keeps you signed in and remembers this choice. Always on.

Google Analytics, Sentry and Vercel. Which pages are used, and what breaks.

LinkedIn, X and Meta pixels, loaded through Google Tag Manager.

Cookie policy