Right to Erasure (Article 17 GDPR)

Also known as the 'right to be forgotten' — limited by statutory retention obligations

Practitioner's note: This article is practice-oriented compliance documentation, not legal advice. We are a compliance specialist, not a law firm. For legally binding information please consult a licensed lawyer.

TL;DR

The right to erasure under Article 17 GDPR (also known as the 'right to be forgotten') grants data subjects the right to obtain the erasure of their data without undue delay. It applies where: processing is no longer necessary, consent has been withdrawn, an objection has been raised without overriding grounds, or processing has been unlawful. It is limited by statutory retention obligations (German Commercial Code (HGB), Fiscal Code (AO), Social Code (SGB)).

What is the Right to Erasure (Article 17 GDPR)?

Article 17 (1) lists 6 grounds for erasure. Article 17 (3) provides exceptions: statutory retention obligations, legal defense, public interest, and research. Practical conflict: the German Commercial Code (HGB) and the Fiscal Code (AO) require 10 years of retention — the erasure claim is therefore not enforceable to that extent. Solution: restrict processing instead of deleting, then delete after the retention period.

Practical example

Example: a customer requests erasure of their order history. The controller checks: - Active business relationship? No → no legitimate interest - Accounting retention? 10 years → restrict processing instead of deletion - Marketing newsletter? Immediate erasure possible

Frequently asked questions

Must I reach out to third parties?
For data made public: yes (Article 17 (2)) — reasonable measures to inform recipients of the erasure claim.
What about backups?
Backup data is also subject to the erasure claim — delete during the next backup cycle or restrict access in a documented manner.
A customer requests 'erasure' — but only restriction of processing is possible?
Restriction of processing may replace erasure where the latter is not legally possible (retention obligation). Provide clear information to the customer.

See also