CHAPTER IIIRIGHTS OF THE DATA SUBJECT

Article 17Right to erasure (right to be forgotten)

Official text

(1)The data subject shall have the right to obtain from the controller the erasure of personal data concerning him or her without undue delay and the controller shall have the obligation to erase personal data without undue delay where one of the following grounds applies:

(a)the personal data are no longer necessary in relation to the purposes for which they were collected or otherwise processed;

(b)the data subject withdraws consent on which the processing is based according to point (a) of Article 6 (1), or point (a) of Article 9 (2), and where there is no other legal ground for the processing;

(c)the data subject objects to the processing pursuant to Article 21 (1) and there are no overriding legitimate grounds for the processing, or the data subject objects to the processing pursuant to Article 21 (2);

(d)the personal data have been unlawfully processed;

(e)the personal data have to be erased for compliance with a legal obligation in Union or Member State law to which the controller is subject;

(f)the personal data have been collected in relation to the offer of information society services referred to in Article 8 (1).

(2)Where the controller has made the personal data public and is obliged pursuant to paragraph 1 to erase the personal data, the controller, taking account of available technology and the cost of implementation, shall take reasonable steps, including technical measures, to inform controllers which are processing the personal data that the data subject has requested the erasure by such controllers of any links to, or copy or replication of, those personal data.

(3)Paragraphs 1 and 2 shall not apply to the extent that processing is necessary:

(a)for exercising the right of freedom of expression and information;

(b)for compliance with a legal obligation which requires processing by Union or Member State law to which the controller is subject or for the performance of a task carried out in the public interest or in the exercise of official authority vested in the controller;

(c)for reasons of public interest in the area of public health in accordance with points (h) and (i) of Article 9 (2) as well as Article 9 (3);

(d)for archiving purposes in the public interest, scientific or historical research purposes or statistical purposes in accordance with Article 89 (1) in so far as the right referred to in paragraph 1 is likely to render impossible or seriously impair the achievement of the objectives of that processing; or

(e)for the establishment, exercise or defence of legal claims.

Commentary

Introduction

Article 17 of the General Data Protection Regulation (GDPR) establishes one of the most well-known yet frequently misunderstood rights available to individuals, the right to erasure, commonly referred to as the "right to be forgotten." It empowers data subjects to require controllers to delete personal data in specific circumstances and imposes a corresponding legal obligation upon controllers to erase such data without undue delay when the statutory conditions are met.

Although popularly portrayed as a sweeping "right to disappear from the internet," Article 17 is considerably more nuanced. It does not create an absolute right to delete any information merely because an individual no longer wishes it to exist. Instead, it balances competing interests, including freedom of expression, public interest, scientific research, legal obligations, and judicial proceedings. The provision therefore embodies one of the GDPR's central constitutional themes:privacy is fundamental but not absolute.

The provision must be interpreted alongside Articles 5, 6, 7, 8, 9, 12, 18, 19, 21, 77 and 79 GDPR, Articles 7, 8 and 11 of the Charter of Fundamental Rights of the European Union (CFR), Recitals 39, 65 and 66, and extensive jurisprudence of the Court of Justice of the European Union (CJEU), including the landmark Google Spain,GC and Others v CNIL,Google LLC v CNIL,Nowak,SCHUFA,Bundesrepublik Deutschland,Agentsia po vpisvaniyata, andÚjpesti Polgármesteri Hivatal decisions.

I. Purpose and Philosophy of Article 17

Article 17 serves multiple objectives simultaneously.

First, it gives practical effect to the storage limitation principle under Article 5(1)(e). Personal data should not remain stored forever merely because storage is inexpensive.

Second, it reinforces the purpose limitation principle in Article 5(1)(b). Once the purpose of processing has ended, the justification for retaining personal data generally disappears.

Third, it strengthens informational self-determination by allowing individuals to regain control over their digital identity.

Fourth, it seeks to mitigate the permanence of internet publications. Modern digital technologies permit unlimited copying, indexing, caching and republication. Consequently, deleting information only from the original website often provides little practical relief. Article 17(2) therefore introduces the additional "right to be forgotten" by requiring controllers, where appropriate, to inform other controllers processing publicly available data.

Recital 65 explains that the right is particularly important where individuals disclosed personal data as children without fully appreciating the long-term consequences of online publication.

The philosophy behind Article 17 is therefore preventive rather than punitive. It seeks to ensure that personal data remain available only as long as justified by legitimate purposes.

II. Relationship with GDPR Principles

Article 17 cannot be understood independently of Article 5 GDPR.

Almost every ground for erasure reflects one or more fundamental processing principles.

GDPR PrincipleRelationship with Article 17
LawfulnessUnlawful processing requires deletion.
Purpose limitationData unnecessary for the original purpose must be erased.
Data minimisationControllers should not retain unnecessary data.
Storage limitationData cannot be stored indefinitely.
AccuracyIncorrect data may require rectification or deletion.
AccountabilityControllers must proactively implement deletion mechanisms.

Thus, Article 17 operationalises the broader principles governing lawful data processing.

III. Right to Erasure versus Right to be Forgotten

One of the greatest misconceptions concerns the terminology.

The expressions "right to erasure" and "right to be forgotten" arenot synonymous.

The right to erasure is established primarily by Article 17(1).

The right to be forgotten is the additional obligation contained in Article 17(2), applicable when personal data have been made public.

Accordingly:

Article 17(1):

  • delete personal data held by the controller.

Article 17(2):

  • notify other controllers processing publicly available copies or links.

Recital 66 confirms this distinction.

Consequently, deleting information from one database is not necessarily sufficient when identical copies continue circulating online.

IV. Nature of the Right

Article 17 creates both:

  1. a subjective right of the data subject; and

  2. an independent legal obligation imposed upon controllers.

This distinction is extremely important.

Unlike contractual rights, deletion does not depend exclusively upon an individual's request.

Whenever one of the grounds listed in Article 17(1) arises, controllers must erase the data even if no request has been made.

The CJEU confirmed this principle in Újpesti Polgármesteri Hivatal (C-46/23), observing that requiring a prior request would permit controllers to continue unlawful processing indefinitely where individuals remained unaware of the infringement. Such an interpretation would undermine the effectiveness (effet utile) of the GDPR.

Thus, Article 17 embodies the GDPR's accountability philosophy: compliance is proactive rather than reactive.

V. Interaction with Article 12

Article 17 itself contains almost no procedural rules.

Instead, all procedural requirements are governed by Article 12.

Controllers must:

  • facilitate requests;

  • communicate in plain language;

  • verify identity where appropriate;

  • respond within one month;

  • provide reasons for refusal;

  • generally act free of charge.

The obligation to erase "without undue delay" therefore operates together with Article 12's procedural framework.

VI. Meaning of "Erasure"

The GDPR deliberately avoids defining "erasure."

However, deletion must be effective.

Merely hiding data from users is insufficient if the information remains readily recoverable.

Effective erasure means rendering information practically irretrievable without disproportionate effort.

Examples

include:

  • secure overwriting;
  • cryptographic destruction;
  • shredding physical documents;
  • destruction of storage media;
  • permanent deletion from active databases. Simple logical deletion, where only directory references disappear while underlying files remain intact, generally does not satisfy Article 17. Similarly, deleting only visible copies while leaving searchable backup archives permanently accessible would rarely comply with the GDPR.

VII. Scope of Deletion

Deletion must be comprehensive.

Controllers should consider:

  • production systems;

  • archives;

  • cloud storage;

  • contractor databases;

  • employee devices used for business;

  • replicated databases;

  • disaster recovery systems;

  • temporary caches.

Nevertheless, absolute physical destruction of every historical backup is not always required.

Backups maintained solely for disaster recovery may temporarily retain deleted information provided:

  • restoration remains exceptional,

  • backup access is tightly restricted,

  • deleted data are erased upon restoration,

  • retention periods remain limited.

This reflects a practical interpretation of proportionality.

VIII. Anonymisation as Erasure

An interesting question concerns anonymisation.

Where personal identifiers are irreversibly removed such that individuals are no longer identifiable, the GDPR no longer applies.

Accordingly, genuine anonymisation is widely regarded as satisfying Article 17 because personal data cease to exist.

However, pseudonymisation is different.

Replacing names with identifiers while retaining re-identification keys does not amount to deletion because the individual remains identifiable.

IX. Data Concerning the Data Subject

Article 17 applies to personal data "concerning" the requesting individual.

This includes:

  • identification data;

  • behavioural information;

  • online identifiers;

  • profiling;

  • inferred characteristics;

  • photographs;

  • biometric templates.

Frequently, however, information concerns multiple individuals simultaneously.

Examples

include:

  • group photographs;
  • emails;
  • chat conversations;
  • meeting recordings. Deletion must then balance competing rights. Suppose a group photograph contains one individual requesting deletion while another has a legitimate interest in continued publication. Rather than deleting the entire photograph, the controller may blur or redact only the requesting individual, thereby satisfying both interests. This illustrates that Article 17 focuses upon eliminating the connection between the person and the data, not necessarily destroying every underlying document.

X. Article 17(1)(a): Data No Longer Necessary

The first deletion ground reflects the principles of purpose limitation and storage limitation.

Once personal data are no longer necessary for the purposes for which they were collected, controllers must erase them.

The assessment is contextual.

The controller must ask:

  • Has the original purpose been fulfilled?

  • Is continued retention objectively necessary?

  • Is another compatible processing purpose available?

Only if no legitimate purpose remains must deletion occur.

The CJEU's judgment in Nowak (C-434/16) illustrates this principle.

The Court observed that examination scripts and examiner comments may constitute personal data.

Once examination procedures have concluded and legal challenges are no longer possible, retaining identifiable examination papers may cease to be necessary, thereby triggering Article 17.

Controllers should therefore define retention schedules before collecting personal data.

Retention "until further notice" rarely complies with Article 5 or Article 17.

XI. Further Processing and Compatibility

Deletion is not automatically required merely because the original purpose has ended.

Controllers may continue processing where:

  • another lawful purpose exists;

  • compatibility requirements under Article 6(4) are satisfied.

For example:

An insurance company processes claim documentation to settle flood compensation.

After settlement concludes, the same information may remain necessary for actuarial research concerning climate risks.

Deletion therefore need not occur immediately because a compatible lawful purpose continues.

The analysis always focuses upon necessity.

XII. Controller's Independent Duty

Controllers should not wait for requests.

Internal governance should include:

  • retention schedules;

  • automated deletion rules;

  • periodic review of databases;

  • destruction logs;

  • deletion policies;

  • lifecycle management.

These accountability mechanisms transform Article 17 from an individual remedy into an organisational compliance obligation.

Failure to implement deletion policies frequently constitutes both:

  • infringement of Article 5; and

  • infringement of Article 17

XII. Article 17(1)(b): Withdrawal of Consent

Article 17(1)(b) requires erasure where the data subject withdraws consent under Article 6(1)(a) or Article 9(2)(a), provided thatno other legal ground for processing exists.

This provision must be read together with Article 7(3), which gives the data subject the right to withdraw consent at any time.

The important point is that withdrawal of consent does not automatically invalidate every processing operation involving the individual's data. It terminates the legal basis of consent. The controller must then determine whether another lawful basis independently justifies continued processing.

Consider a customer who provides:

  • personal data for contractual performance under Article 6(1)(b); and

  • separate consent for promotional emails under Article 6(1)(a).

If the customer withdraws marketing consent, the controller must stop processing the data for marketing. It does not, however, necessarily have to delete the customer's billing information if that information remains necessary to perform the contract or satisfy a statutory retention obligation.

This distinction is fundamental:

Withdrawal of consent terminates consent-based processing; it does not necessarily require destruction of all personal data held by the controller.

Article 17(1)(b) therefore contains an explicit safeguard against interpreting withdrawal as an unconditional right to deletion.

There is also an important distinction between:

  1. valid consent subsequently withdrawn, and

  2. consent that was invalid from the beginning.

Where consent was valid but subsequently withdrawn, Article 17(1)(b) is the natural ground for erasure.

Where the purported consent never satisfied GDPR requirements, for example, because it was neither freely given nor sufficiently informed, the processing may instead constitute unlawful processing, engaging Article 17(1)(d).

The distinction matters because Article 17(1)(b) concerns a change in the legal basis, whereas Article 17(1)(d) addresses the underlying unlawfulness of the processing.

XIII. Article 17(1)(c): Objection to Processing

Article 17(1)(c) creates two different situations.

First situation: Article 21(1) objection

The data subject may object to processing based on Article 6(1)(e) or Article 6(1)(f) where grounds relating to their particular situation exist.

The controller must cease processing unless it demonstrates compelling legitimate grounds overriding the individual's interests, rights and freedoms, or the processing is necessary for legal claims.

Where the objection succeeds and no overriding grounds exist, Article 17(1)(c) requires erasure.

This establishes a close relationship between Articles 17 and 21.

The CJEU has confirmed this relationship in Agentsia po vpisvaniyata (C-200/23), recognising that the data subject's rights to object and obtain erasure operate together where no overriding legitimate grounds justify continued processing.

Second situation: Direct marketing

Article 17(1)(c) also covers objections under Article 21(2).

Here the position is significantly stronger.

If an individual objects to processing for direct marketing, the controller must stop that processing.

There is no balancing exercise comparable to Article 21(1).

The controller cannot say:

"Our commercial interests outweigh your objection."

They do not.

Article 21(3) makes the position categorical: personal data may no longer be processed for direct marketing once the individual objects.

XIV. The Difference Between Stopping Processing and Deleting Data

This distinction is frequently overlooked.

Suppose an online retailer uses a customer's email address for:

  • contractual communications; and

  • marketing.

The customer objects to marketing.

The controller must stop marketing.

But it may continue retaining the email address for contractual communications where Article 6(1)(b) remains applicable.

Thus:

Objection ≠ automatic deletion of every instance of the data.

Article 17 concerns erasure where the relevant statutory conditions are fulfilled. Other lawful purposes can preserve particular processing activities.

This is why data mapping is essential. A controller should know:

  • what data it holds;

  • why it holds it;

  • which legal basis supports each purpose;

  • which systems contain the data;

  • which retention period applies.

Without this information, compliance with Article 17 becomes practically impossible.

XV. Article 17(1)(d): Unlawful Processing

Article 17(1)(d) requires deletion where personal data have been unlawfully processed.

This provision is closely connected to Articles 5(1)(a) and 6.

Article 6 contains an exhaustive list of lawful bases. Processing must therefore fit within one of those bases.

The CJEU has repeatedly emphasised the restrictive character of Article 6.

In SCHUFA Holding (Joined Cases C-26/22 and C-64/22), the Court reaffirmed that Article 6 contains an exhaustive framework for determining when processing can be lawful.

Consequently, if processing cannot be supported by:

  • consent;

  • contract;

  • legal obligation;

  • vital interests;

  • public task; or

  • legitimate interests,

the processing may be unlawful.

Article 17(1)(d) can consequently become applicable.

XVI. Not Every GDPR Violation Automatically Requires Erasure

This point requires considerable care.

A controller's breach of the GDPR does not automatically mean that Article 17(1)(d) requires deletion.

Example

a controller might violate an accountability obligation under Article 30 concerning records of processing activities.

That breach does not necessarily mean that the underlying processing itself lacks a lawful basis.

The CJEU addressed this issue in Bundesrepublik Deutschland (C-60/22).

The Court distinguished between:

  • violations of obligations governing accountability and organisational compliance; and

  • unlawfulness of the actual processing.

Therefore:

GDPR infringement ≠ automatically Article 17 erasure.

The relevant question is whether the processing itself is unlawful.

XVII. Present Unlawfulness

Another important issue is the temporal dimension.

Article 17(1)(d) refers to data that "have been unlawfully processed."

The relevant assessment nevertheless concerns whether continued processing is presently lawful.

Suppose processing initially lacked a lawful basis but the controller subsequently obtains valid consent and thereby establishes a lawful basis for future processing.

The historical infringement may still have consequences, but Article 17(1)(d) does not necessarily require permanent deletion if the present processing is lawful.

This illustrates why Article 17 should not be treated as an automatic punitive mechanism.

XVIII. Inaccurate Data and Erasure

Incorrect personal data frequently intersect with Article 17(1)(d).

However, Article 16 ordinarily provides the more direct remedy: rectification.

Example

if a bank incorrectly records a customer's address, the appropriate response is generally to correct it rather than delete the entire customer record.

If the inaccurate data cannot lawfully be retained or corrected, Article 17 may become relevant.

Article 17 should therefore be distinguished from Article 16:

  • Article 16: "Make the information accurate."

  • Article 17: "Remove the information where the statutory conditions for erasure exist."

XIX. Article 17(1)(e): Legal Obligation to Erase

Article 17(1)(e) applies where personal data must be erased to comply with a legal obligation under Union or Member State law.

This provision demonstrates that deletion obligations can originate outside the GDPR itself.

Example

national legislation may establish:

  • mandatory destruction periods;

  • deletion of specific records after a defined period;

  • rules governing retention of particular categories of information.

The important requirement is that the legal obligation must actually bind the controller.

A purely contractual obligation is not enough.

Example

if a controller promises a customer that certain data will be deleted after five years, that contractual obligation does not itself transform into Article 17(1)(e). The relevant ground requires an obligation imposed by Union or Member State law.

XX. Article 17(1)(f): Children's Data and Information Society Services

Article 17(1)(f) provides an additional protection for data collected in connection with information society services referred to in Article 8(1).

This provision reflects a particular concern:

Children may consent to online processing without understanding its long-term consequences.

Recital 65 expressly recognises this problem.

A teenager may upload:

  • photographs;

  • videos;

  • comments;

  • personal information;

  • embarrassing content;

  • social-media material.

Years later, the individual may reasonably wish that such information no longer form part of their digital identity.

The GDPR therefore provides enhanced protection.

Importantly, the protection continues even after the person becomes an adult.

This is a significant expression of the GDPR's recognition that consent given during childhood should not permanently bind an individual to an earlier digital identity.

XXI. Article 17(2): The "Right to Be Forgotten"

Article 17(2) represents the most distinctive part of the provision.

It applies where:

  1. the controller has made the personal data public; and

  2. the controller is obliged to erase those data under Article 17(1).

In such circumstances, the controller must take reasonable steps, including technical measures, to inform other controllers processing those data that the individual has requested deletion of:

  • links;

  • copies; or

  • replications.

The rationale is simple.

Imagine:

Original website → Search engine → News aggregator → Social-media repost → Archive → Third-party database

Deleting the original page does not necessarily eliminate the information.

Article 17(2) attempts to deal with this multiplication effect.

XXII. "Made the Personal Data Public"

The provision applies specifically when data have been made public.

This generally means disclosure to an indeterminate or unrestricted audience.

Examples

include:

  • publicly accessible websites;
  • open social-media pages;
  • public databases;
  • publicly accessible publications. By contrast, information shared with a limited group behind authentication controls may not constitute publication in the same sense. A data breach also should not automatically be treated as intentional publication under Article 17(2). If hackers steal information from a controller's database, the controller has not necessarily "made the data public" for purposes of Article 17(2), although other GDPR obligations concerning the breach may arise.

XXIII. "Reasonable Steps"

Article 17(2) deliberately avoids demanding impossible outcomes.

The controller must consider:

  • available technology;

  • implementation costs;

  • scale of dissemination;

  • technical feasibility;

  • identity of recipients;

  • likelihood of continued processing.

The obligation is therefore one of reasonable diligence, not absolute technological omnipotence.

A controller cannot realistically guarantee that every copy of information on the entire internet will disappear.

But it must take meaningful measures proportionate to the circumstances.

XXIV. What Can Reasonable Measures Include?

Depending on circumstances, measures may include:

  • contacting known recipients;

  • notifying major websites reproducing the content;

  • issuing deletion requests;

  • communicating with search engines;

  • using technical exclusion mechanisms;

  • implementing de-indexing measures;

  • publishing corrections;

  • notifying downstream controllers;

  • monitoring known copies.

The controller should document what measures were taken and why those measures were considered reasonable.

XXV. Article 17(2) Does Not Create Absolute Liability for Every Copy

This is another important limitation.

Suppose Controller A publishes personal information.

Controller B independently obtains the information and processes it for a completely different lawful purpose.

Controller A's obligation to inform B does not automatically mean B must delete the information.

B must conduct its own assessment under Article 17.

Article 17(2) therefore does not transform the original controller into a universal guarantor of deletion throughout the internet.

Each controller remains responsible for the lawfulness of its own processing.

XXVI. Article 17(2) and Article 19

Article 17(2) should be distinguished from Article 19.

Article 17(2)

Applies where:

  • personal data were made public;

  • Article 17(1) requires erasure;

  • reasonable steps must be taken to inform other controllers.

Article 19

Generally concerns notification of recipients to whom personal data have been disclosed following:

  • rectification;

  • erasure;

  • restriction.

Article 19 is therefore broader in terms of the disclosure relationship, while Article 17(2) specifically addresses the special problem of public dissemination.

XXVII. Search Engines and the Right to Delisting

The modern interpretation of Article 17 cannot be understood without the CJEU's search-engine jurisprudence.

The landmark decision is Google Spain (C-131/12).

The Court recognised that search-engine operators can have independent responsibilities concerning personal data appearing in search results.

The practical importance is enormous.

There is a difference between:

deleting information from the source website

and

removing the search engine's association between the individual's name and that information.

The latter is generally described as delisting orde-referencing.

The original webpage may remain online while the search result disappears when a person's name is searched.

This demonstrates that the "right to be forgotten" is not necessarily a right to destroy historical information.

It may instead be a right to reduce the accessibility and discoverability of personal information.

XXVIII. Balancing Privacy and Freedom of Expression

The search-engine cases reveal the fundamental tension underlying Article 17.

On one side:

  • privacy;

  • dignity;

  • reputation;

  • informational self-determination.

On the other:

  • freedom of expression;

  • freedom of information;

  • journalism;

  • public debate;

  • historical record.

Article 17 therefore cannot be applied mechanically.

The controller must consider the nature of the information and the public interest in its continued accessibility.

XXIX. Article 17(3): Exceptions

Article 17(3) establishes the principal exceptions to erasure.

These exceptions demonstrate why the "right to be forgotten" is not absolute.

The right does not apply to the extent processing is necessary for:

  1. freedom of expression and information;

  2. legal obligations/public tasks;

  3. public health;

  4. archiving, research and statistics;

  5. establishment, exercise or defence of legal claims.

The critical word is "necessary."

A controller cannot invoke an exception merely by identifying a broad public interest.

It must demonstrate that continued processing is actually necessary for the protected objective.

XXX. Article 17(3)(a): Freedom of Expression and Information

This is perhaps the most constitutionally significant exception.

Deletion may be refused where processing is necessary to exercise freedom of expression and information.

This provision reflects Article 11 of the Charter.

It is particularly important for:

  • journalism;

  • newspapers;

  • academic publications;

  • artistic works;

  • political commentary;

  • public-interest reporting.

The GDPR does not establish privacy as superior to freedom of expression.

Instead, it requires reconciliation.

Article 85 reinforces this by requiring Member States to reconcile data protection with freedom of expression and information.

XXXI. Public Figures

Public figures will frequently have a reduced expectation that information concerning their public activities will disappear.

Example

information concerning:

  • political office;

  • professional misconduct;

  • public regulatory actions;

  • major public controversies;

may have substantial public interest.

However, being a public figure does not eliminate privacy rights.

Information unrelated to public functions may still justify erasure.

The assessment must therefore distinguish between:

public interest

and

mere public curiosity.

These are not the same.

XXXII. Age of Information

The passage of time can significantly affect the balance.

Information that was relevant ten years ago may no longer have the same public significance.

Consequently, Article 17 analysis may need to consider:

  • age;

  • continuing relevance;

  • accuracy;

  • present public interest;

  • current role of the individual;

  • sensitivity of the information.

This temporal dimension is central to the concept of being "forgotten."

The right is therefore not simply about deleting information that is embarrassing. It is about reassessing whether continued identification remains justified.

XXXIII. Article 17(3)(b): Legal Obligations and Public Tasks

Controllers may refuse deletion where continued processing is necessary:

  • to comply with Union or Member State law;

  • to perform a public-interest task;

  • to exercise official authority.

Tax and accounting retention requirements provide straightforward examples.

A company may be legally required to retain invoices and transaction records for a defined period.

A customer cannot simply demand immediate deletion under Article 17 if the law requires continued retention.

Similarly, public authorities may have statutory obligations to maintain records.

The crucial requirement remains necessity.

XXXIV. Article 17(3)(c): Public Health

The right to erasure may also yield to public-health requirements.

The provision refers specifically to processing under Article 9(2)(h) and (i) and Article 9(3).

Examples

can include processing necessary for:

  • occupational medicine;
  • medical diagnosis;
  • health-system management;
  • public-health protection;
  • protection against serious cross-border health threats. The sensitivity of health data makes this exception particularly important. Nevertheless, the existence of a public-health purpose does not authorise unlimited retention. Only data necessary for the relevant purpose should continue to be processed.

XXXV. Article 17(3)(d): Archiving, Research and Statistics

Scientific and historical research can sometimes require retention of information that individuals would otherwise be entitled to erase.

Suppose a longitudinal study has collected data from thousands of participants.

If one participant could demand deletion whenever desired, the integrity of the study might be seriously compromised.

Article 17(3)(d) therefore protects research where erasure would:

  • make the research impossible; or

  • seriously impair its objectives.

The exception is not unlimited.

Article 89(1) requires appropriate safeguards.

The controller must still respect principles such as:

  • data minimisation;

  • security;

  • purpose limitation;

  • appropriate safeguards.

XXXVI. Statistical Research

Statistical integrity may similarly justify retention.

Example

deleting a statistically significant portion of a dataset could distort:

  • sample composition;

  • longitudinal comparisons;

  • statistical validity.

However, controllers cannot simply label ordinary commercial analytics "statistical research" to avoid deletion.

The purpose and necessity of processing must be genuine.

XXXVII. Article 17(3)(e): Legal Claims

The final exception concerns the:

  • establishment;

  • exercise; or

  • defence

of legal claims.

This prevents Article 17 from becoming a mechanism for destroying evidence.

Example

a company involved in litigation may need to retain:

  • emails;

  • contracts;

  • transaction records;

  • employee records;

  • communications;

  • audit trails.

A litigant should not be able to demand deletion of evidence merely by invoking Article 17.

However, the exception does not justify indefinite retention simply because litigation is theoretically possible.

There must be a genuine connection with legal claims.

XXXVIII. Article 17 and Article 18

Article 17 should also be distinguished from Article 18, the right to restriction of processing.

Deletion is permanent in its intended effect.

Restriction is different.

Under Article 18, data may remain stored but cannot ordinarily be actively processed except under specified conditions.

This becomes particularly important where:

  • the individual contests accuracy;

  • processing is unlawful but the individual opposes erasure;

  • the controller no longer needs the data but the individual requires it for legal claims;

  • an objection is being assessed.

Thus, Article 17 and Article 18 form complementary remedies.

XXXIX. Article 17 and Legal Remedies

An important analytical point is that Article 17 does not exhaust the remedies available for unlawful processing.

A data subject may:

  • complain to a supervisory authority under Article 77;

  • seek judicial remedies under Article 79;

  • seek compensation under Article 82 where the statutory conditions are met;

  • seek restriction under Article 18;

  • seek rectification under Article 16.

Consequently, if a particular GDPR infringement does not trigger Article 17, the data subject is not necessarily without remedy.

This prevents Article 17 from becoming the sole mechanism through which unlawful processing is challenged.

XL. Controllers' Practical Compliance Architecture

For organisations, Article 17 requires considerably more than responding to deletion emails.

A mature Article 17 compliance programme should contain at least:

1. Data inventory

Know where personal data are stored.

2. Purpose mapping

Identify the purpose attached to each category.

Identify the legal basis for each purpose.

4. Retention schedules

Define when data should automatically be deleted.

5. Deletion workflows

Create procedures for receiving and executing requests.

6. Identity verification

Prevent fraudulent deletion requests.

7. Downstream notification

Identify relevant processors and recipients.

8. Backup controls

Ensure deleted information is not casually restored.

9. Audit trails

Maintain evidence of deletion decisions.

10. Exception handling

Document why data were retained when Article 17(3) applied.

XLI. The Burden of Justification

When refusing an erasure request, a controller should not simply state:

"We have a legitimate interest."

That is insufficient.

The controller should identify:

  1. the relevant processing;

  2. its purpose;

  3. its legal basis;

  4. the Article 17 ground invoked;

  5. the applicable exception;

  6. why continued processing is necessary;

  7. why less intrusive alternatives are insufficient.

This is especially important when relying on Article 17(3).

The word "necessary" requires a substantive assessment rather than a formulaic assertion.

XLII. Critical Assessment: Is the "Right to Be Forgotten" Oversold?

The political and popular presentation of Article 17 often suggests that individuals possess an absolute right to erase themselves from the internet.

That is inaccurate.

Article 17 does not mean:

"If I dislike information about myself, everyone must delete it."

It means:

"Where one of the statutory grounds for erasure applies, and no applicable exception protects continued processing, the controller must erase the relevant personal data."

This is considerably narrower.

The right is therefore better understood as a conditional right of informational deletion, accompanied in appropriate cases by mechanisms designed to reduce further dissemination.

XLIII. The Internet Makes Erasure Structurally Difficult

Article 17 confronts a technological problem that legislation cannot completely solve.

Digital information can be:

  • copied;

  • cached;

  • screenshotted;

  • downloaded;

  • mirrored;

  • indexed;

  • archived;

  • reproduced outside the EU.

Consequently, legal erasure cannot guarantee metaphysical disappearance.

Article 17 therefore operates primarily through control over identifiable processing relationships, not through literal destruction of every digital representation worldwide.

This is one reason why Article 17(2) speaks in terms of "reasonable steps" rather than guaranteed elimination.

XLIV. Overall Evaluation

Article 17 is best understood as a carefully calibrated mechanism situated between two extremes.

At one extreme lies unlimited retention:

"Once data are online, they remain forever."

At the other lies absolute deletion:

"Every individual can erase any information about themselves."

The GDPR adopts neither.

Instead, it asks:

Is continued processing still justified?

If the purpose has ended, consent has been withdrawn without another legal basis, a valid objection succeeds, processing is unlawful, law requires deletion, or protected children's data fall within Article 17(1)(f), erasure follows.

If continued processing is necessary for expression, legal obligations, public health, research, archiving or legal claims, Article 17 yields to those interests.

The provision therefore embodies the GDPR's broader constitutional model of rights-balancing rather than rights absolutism.

Conclusion

Article 17 is simultaneously adata-subject right, a controller obligation, a storage-limitation mechanism and, in appropriate circumstances, an instrument for controlling digital dissemination. Its significance lies not merely in allowing individuals to request deletion, but in forcing controllers to reconsider the fundamental question underlying personal-data governance: Why are we still keeping this personal data? If the controller cannot provide a legally sufficient answer, continued retention becomes increasingly difficult to justify. At the same time, Article 17 recognises that privacy does not exist in isolation. Historical records, journalism, public health, scientific research, legal proceedings, statutory retention requirements and freedom of expression can all justify continued processing. The most accurate understanding of Article 17 is therefore not "the right to disappear", but ratherthe right not to have personal data retained or disseminated without a continuing legal and legitimate justification.

That distinction is crucial. Article 17 does not promise that the internet will forget. It imposes a legal duty on controllers to ensure that personal data do not remain available merely because they can be retained.