Article 17 reaches every copy you control, including backups and endpoints. A confirmation email is not evidence. What an audit-ready erasure record actually contains.
Article 17 gives individuals the right to have personal data erased in defined circumstances, and it carries the same one-month deadline as an access request. Most organisations can delete a record. Far fewer can show, months later, what was deleted, from where, and what was deliberately kept.
That gap is where erasure complaints are decided, because the individual's next move after 'we have deleted your data' is often to point at a copy you missed.
When the right applies, and when it doesn't
Erasure is not absolute. It applies where one of the Article 17(1) grounds is met, for example the data is no longer necessary for the purpose it was collected for, consent is withdrawn and there is no other lawful basis, or the data was unlawfully processed. It is disapplied under Article 17(3) where processing is necessary for reasons including compliance with a legal obligation, and the establishment, exercise or defence of legal claims.
In practice that means most erasure responses are partial: some data goes, some is retained on a named ground. The response has to say which is which. 'We have deleted everything' is usually either inaccurate or an admission that you deleted something you were required to keep.
The copies people forget
| Location | Why it's missed | What to do |
|---|---|---|
| Backups | Restoring a whole backup to remove one record is disproportionate | Document the approach, put the data beyond use, delete on the normal backup cycle, and tell the individual that is the position |
| Endpoints and shared drives | Not indexed, not in the ROPA, not owned by anyone | Search for the subject's identifiers across the estate rather than asking each system owner |
| Mailboxes | Search usually covers the inbox and stops there | Include sent items, archives and attachments |
| Exports and reports | Point-in-time snapshots taken for analysis | Treat any recurring export as a location in its own right |
| Third-party processors | Deletion happens with you, not with them | Inform recipients under Article 19 and confirm they acted |
| Logs and audit trails | Often retained on a legal or security ground | Retain where justified, and record the ground rather than staying silent |
The ICO's right to erasure guidance accepts that where deleting data from a backup is not immediately possible, you may put it beyond use, provided you do not use it for any other purpose and delete it when the backup is next refreshed. Say so in the response rather than leaving the individual to assume the backup was wiped.
What an audit-ready erasure record contains
- The request, the date received, and the identity verification performed
- The identifiers you searched on, including variants such as former surnames and secondary email addresses
- Every system and location searched, including the ones that returned nothing
- What was deleted, from where, and on what date
- What was retained, with the Article 17(3) ground for each item
- Anything put beyond use rather than deleted, and when it will age out
- The recipients informed under Article 19
- The response sent to the individual, and the date it went
The list of places that returned nothing is the line item people skip and the one that carries the weight. It is what turns 'we looked' into a record of exactly what you looked at.
Proving deletion in unstructured data
For a database, deletion is verifiable with a query. For files on endpoints and shares, the only real proof is a second pass that returns nothing for the identifiers you searched. That means the search has to be repeatable and recorded, with the same identifiers and the same scope, so the two passes are actually comparable. A search you cannot reproduce is not evidence of anything.
The overlap with access requests
An erasure request and an access request need the same first step: find every place the subject's personal data exists. Teams that have built that capability for access requests already hold most of what erasure needs. Teams that handle access requests by asking department heads to check their own systems find erasure much harder, because the answer has to be complete rather than good enough to compile a response from.
Sources & references
- Article 17 - Right to erasure ('right to be forgotten'), UK GDPR - legislation.gov.uk
- Right to erasure - ICO
- Article 19 - Notification obligation regarding rectification or erasure of personal data or restriction of processing - legislation.gov.uk
- Article 12 - Transparent information, communication and modalities, UK GDPR - legislation.gov.uk


