Article 17
Right to Erasure
GDPR · Regulation (EU) 2016/679 · Last verified August 2026
Objective
Erase personal data without undue delay when an applicable ground is met, while evaluating legal exceptions and notifying recipients where required.
Points of focus
- Evaluate erasure grounds and exceptions consistently
- Delete or irreversibly de-identify data across relevant systems
- Communicate erasure to recipients and verify completion
Implementation notes
Maintain a deletion map by identifier and store, orchestrate deletion through idempotent jobs, quarantine failures, and document how encrypted backups age out without restoring erased records to active use. Operationalize evaluate erasure grounds and exceptions consistently in ticketing, IdP, or GRC workflows with named owners — not only in a static policy PDF. Retain erasure decision record and identity verification with reviewer identity, population scope, dates, and remediation outcomes auditors can sample. A recurring failure mode is that the account disappears from the ui while identifiers remain active in analytics Revisit after material architecture, vendor, data-flow, or leadership changes and document the decision.
Audit tip: Sample erasure decision record and identity verification with dates and named reviewers. Be ready to walk through how you detect and correct: the account disappears from the ui while identifiers remain active in analytics
Evidence auditors typically request:
- Erasure decision record and identity verification
- Deletion orchestration logs across systems and subprocessors
- Backup handling and delayed-deletion documentation
Common gaps
- The account disappears from the UI while identifiers remain active in analytics
- Vendor deletion is assumed complete without API result or attestation
Cross-Framework Mapping
| Framework | Requirement | Implementation note |
|---|---|---|
| GDPR | Article 17 | This control |
| SOC 2 | CC3.2, CC6.1 | Trust Services Criteria evidence may support accountability, but does not establish GDPR lawfulness. |
| ISO 27001 | A.5.34, A.8.10 | ISO privacy and security controls can implement parts of this duty when mapped to processing. |
| HIPAA | 164.308(a)(1) | HIPAA overlap depends on whether the same data is both ePHI and GDPR personal data. |
Primary sources
- EUR-Lex GDPR Article 17: Regulation (EU) 2016/679, Article 17 — Right to Erasure