The right to get your data deleted is also known as the ‘right to erasure’. You can ask an organisation that holds data about you to delete that data. In some circumstances, they must then do so. You may sometimes hear this called the ‘right to be forgotten’.
The right only applies in the following circumstances:
After you have cancelled your gym membership, the gym no longer needs to keep details of your name, address, age and health conditions.
You agreed to take part in a market research study and now don’t want to.
For more information on the right to object, read ‘Your right to object to how your data is used’.
It hasn’t complied with the rules on data protection.
You used social media or a gaming app as a child.
The law gives children special protection, especially online, because they may be less aware of the risks and consequences of giving their data to organisations. Even if you are now an adult, you have a right to have your data erased if it was collected from you as a child.
You should contact the organisation and let them know what personal data you want them to erase. You don’t have to ask a specific person – you can contact any part of the organisation with your request.
You can make your request verbally or in writing. We recommend you follow up any verbal request in writing because this will allow you to explain your complaint, give evidence and explain what you want to happen. You will also have clear proof of your actions, if you decide to challenge the organisation’s response.
There are no specific words that you must use, but you may find it useful to use the template below to help you exercise your right to erasure.
[Your full address]
[Your phone number]
[The date]
[Name and address of the organisation]
[Reference number (if provided within the initial response)]
Dear [Sir or Madam / name of the person you have been in contact with]
Right to erasure
[Your full name and address and any other details such as account number to help identify you]
I wish to exercise my right of erasure under data protection law.
[Give details of what personal data you want erased/deleted.]
You can find guidance on your obligations under information rights legislation on the website of the Information Commissioner’s Office (www.ico.org.uk) as well as information on their regulatory powers and the action they can take.
Please send a full response within one calendar month confirming if you will comply with my request. If you cannot respond within that timescale, please tell me when you will be able to respond.
If there is anything you would like to discuss, please contact me.
The organisation should delete your data, unless an exemption in data protection law applies (see below).
They should also tell anyone else they have shared your data with about the erasure. They can only refuse to do this if it would be impossible or involve disproportionate effort. If you ask, they must also tell you that they have shared your data with other organisations.
If your data has been made public online – such as on social networks, forums or websites – then the organisation must take reasonable steps to inform the people with responsibility for these sites to erase links or copies of that data.
The organisation can refuse to erase your data in the following circumstances:
Also, the right to erasure does not apply to special category data in the following circumstances:
If an exemption applies, the organisation can either fully or partly refuse to comply with your request.
The organisation can also refuse your request if it is, as the law states, ‘manifestly unfounded or excessive’.
There is no set definition of what makes a request ‘manifestly unfounded or excessive’. It depends on the particular circumstances of your request. For example, an organisation may consider a request to be ‘manifestly unfounded or excessive’ if it is clear that it has been made with no real purpose except to cause the organisation harassment or disruption.
In such circumstances the organisation can:
In either case they will need to tell you and justify their decision.
If, having considered your request, the organisation decides it does not need to erase your data, they must still respond to you. They should explain why they believe they don’t have to erase your data, and let you know about your right to complain about this decision to the ICO, or through the courts.
An organisation has one calendar month to respond to your request. In certain circumstances they may need extra time to consider your request and can take up to an extra two months. If they are going to do this, they should let you know within one month that they need more time and the reasons why. For more on this, see our guidance on time limits.
The organisation might need you to prove your identity. However, they should only ask you for just enough information to be sure you are the right person. If they do this, then the one-month time period to respond to your request begins from when they receive this additional information.
In most circumstances, no. An organisation can only charge a fee if the request is ‘manifestly unfounded or excessive’. They may then ask for a reasonable fee for administrative costs associated with your request.
If you are unhappy with how the organisation has handled your request, you should first raise a complaint with them and give them the opportunity to resolve the matter
Having done so, if you remain dissatisfied you can make a complaint to the ICO.
You can also seek to enforce your rights through the courts. If you decide to do this, we strongly advise you to seek independent legal advice first.