Right to Erasure (Right to be Forgotten)
Quick Definition
A GDPR right allowing individuals to request deletion of their personal data when it is no longer necessary or they withdraw consent.
What is Right to Erasure (Right to be Forgotten)?
The right to erasure, also known as the "right to be forgotten," is a GDPR Article 17 requirement that gives individuals the right to request deletion of their personal data under certain circumstances. Organizations must delete personal data when it is no longer necessary for the original purpose, when individuals withdraw consent, when they object to processing and there are no overriding legitimate grounds, when data was processed unlawfully, or when deletion is required for legal compliance.
Implementing erasure rights requires organizations to identify all locations where an individual's data exists-across production databases, backups, archives, logs, analytics systems, data warehouses, and third-party processors. This is where data lineage and data cataloging become critical. Organizations must be able to find and delete all personal data for a specific individual within required timeframes (typically 30 days under GDPR).
Right to erasure creates significant challenges for test data. If test environments contain masked or copied production data, erasure requests must extend to those environments. The safest approach is synthetic data that contains no real personal information-there's nothing to erase because no actual individuals' data exists. For masked data, organizations must either implement erasure procedures for test environments or ensure masking is irreversible and unlinkable to real individuals.
Common Use Cases
- GDPR compliance implementation
- Customer data request handling
- Privacy rights management
- Data retention policy enforcement
Learn More
Need help with Right to Erasure (Right to be Forgotten)?
GoMask makes realistic synthetic datasets with the patterns you ask for. Get started in minutes.