Skip to content
compliancebase
GDPRChapter III — Right to Erasure

Article 17

Right to Erasure

GDPR · Regulation (EU) 2016/679 · Last verified August 2026

Objective

Erase personal data without undue delay when an applicable ground is met, while evaluating legal exceptions and notifying recipients where required.

Points of focus

  • Evaluate erasure grounds and exceptions consistently
  • Delete or irreversibly de-identify data across relevant systems
  • Communicate erasure to recipients and verify completion

Implementation notes

Maintain a deletion map by identifier and store, orchestrate deletion through idempotent jobs, quarantine failures, and document how encrypted backups age out without restoring erased records to active use. Operationalize evaluate erasure grounds and exceptions consistently in ticketing, IdP, or GRC workflows with named owners — not only in a static policy PDF. Retain erasure decision record and identity verification with reviewer identity, population scope, dates, and remediation outcomes auditors can sample. A recurring failure mode is that the account disappears from the ui while identifiers remain active in analytics Revisit after material architecture, vendor, data-flow, or leadership changes and document the decision.

Audit tip: Sample erasure decision record and identity verification with dates and named reviewers. Be ready to walk through how you detect and correct: the account disappears from the ui while identifiers remain active in analytics

Evidence auditors typically request:

  • Erasure decision record and identity verification
  • Deletion orchestration logs across systems and subprocessors
  • Backup handling and delayed-deletion documentation

Common gaps

  • The account disappears from the UI while identifiers remain active in analytics
  • Vendor deletion is assumed complete without API result or attestation

Cross-Framework Mapping

FrameworkRequirementImplementation note
GDPRArticle 17This control
SOC 2CC3.2, CC6.1Trust Services Criteria evidence may support accountability, but does not establish GDPR lawfulness.
ISO 27001A.5.34, A.8.10ISO privacy and security controls can implement parts of this duty when mapped to processing.
HIPAA164.308(a)(1)HIPAA overlap depends on whether the same data is both ePHI and GDPR personal data.

Primary sources

Frequently Asked Questions

Right to Erasure applies to the systems and commitments in your GDPR scope. Translate the requirement into concrete operating workflows — evaluate erasure grounds and exceptions consistently — with evidence stored where auditors and customers can sample it.

Lead with erasure decision record and identity verification and pair it with deletion orchestration logs across systems and subprocessors. Samples should show who performed the control, when, against which population, and what changed as a result.

Teams often fail because the account disappears from the ui while identifiers remain active in analytics Close the loop with dated operating records and test the control on a realistic production path.

Control operation can often be shared across SOC 2, ISO 27001, GDPR, and HIPAA — but each framework uses different vocabulary and accountability. Maintain an explicit crosswalk rather than assuming equivalence.

Review at least annually and after material product, vendor, or data-flow changes. High-risk or privileged paths may need quarterly sampling even when the criterion does not prescribe a cadence.

Framework versions referenced in this page:

  • GDPRRegulation (EU) 2016/679

Last verified: August 2026 · Primary sources linked above