Article 17 GDPR gives you a right to erasure: you can ask an organisation to delete the personal data it holds about you where the legal conditions apply. The controller normally has one month to reply.
This differs from Google delisting, which hides a search result. Erasure targets the source: a website, broker or directory. Our guide explains which personal data can be removed and where to act. To find where you appear and send requests, start with a free scan, then Remove my data.
Here are the grounds, who to contact and what to do when a request is ignored or refused.
What is the right to erasure?
The right to erasure, sometimes called the “right to be forgotten” in public debate, lets you ask a data controller to delete your personal information. It is defined by Article 17 of the GDPR. Delisting is different: it concerns search engines and asks them to stop showing a link when someone searches for your name. Erasure concerns the organisation processing the data, such as a website or data broker.
In France, the CNIL is the supervisory authority. The GDPR applies throughout the European Union. You can exercise the right with any organisation processing your data that is subject to the GDPR.
When can you request erasure?
You can request erasure in particular where:
- The data is no longer necessary for the purposes for which it was collected.
- You withdraw consent and there is no other legal basis.
- You object to processing and the applicable conditions are met.
- The data was processed unlawfully.
- Erasure is required to meet a legal obligation.
- The data was collected in connection with offering information society services to a child.
Exceptions include freedom of expression, certain archiving grounds and legal claims. The controller may refuse erasure in those circumstances. For everyday websites, brokers and directories, erasure grounds often arise after withdrawal of consent or when the original purpose no longer exists.
Who should receive the request, and in what form?
Send a personal data erasure request to the controller, the organisation deciding the purposes and means of processing. Many websites and brokers provide an address or dedicated form labelled DPO, privacy contact or exercise your rights. You can write by post or email, state that you are exercising Article 17 GDPR and specify the data or processing concerned.
The controller must normally reply within one month, with a possible two-month extension for complex requests. It may ask you to confirm your identity through its own procedures outside Data Knight. To act after a free scan, see Remove my data.
What if the organisation refuses or does not reply?
If the controller refuses erasure, it must explain why and tell you about your right to complain to the CNIL. If there is no reply within one month, you can also complain. In parallel, you can address other sources, such as additional brokers, to reduce your footprint.
To centralise requests, you can use a service such as ours. After a free scan covering the public web, brokers and breaches, you choose what to remove and we send the requests for you. Our method explains the steps. For an unresponsive broker, see GDPR requests: follow-up and CNIL complaints. The digital footprint and removal guide connects scanning, rights and the practical process.
Want to know who holds your data and request removal? Run a free scan, choose what to remove and track your requests in your account.
See also: Digital footprint and GDPR removal guide · Check for leaked data in three minutes · Have I Been Pwned: what to know · Data brokers: remove your information · Unanswered broker requests and the CNIL.



