Pypo.ai logoPypo.ai
    Back to blog
    Privacy

    GDPR Right to Erasure: How to Force Any Company to Delete Your Data

    By Maria Chen, Privacy & Data Protection Specialist·10 min read

    In March 2025, the European Data Protection Board (EDPB) launched its Coordinated Enforcement Framework action focused specifically on the Right to Erasure. This wasn't an academic exercise — it was a signal that data protection authorities across Europe were about to start auditing how organizations handle deletion requests in earnest.

    Meanwhile, personal data breaches in Europe increased by 22% in 2025 according to DLA Piper's annual report. More data is being collected, more data is being breached, and individuals are increasingly demanding the right to make it disappear.

    Article 17 of the GDPR — the Right to Erasure, commonly known as the "Right to be Forgotten" — gives individuals the power to demand that organizations delete their personal data. It's one of the most powerful privacy rights ever enacted into law. But like any powerful tool, its effectiveness depends entirely on how you wield it.

    When the Right to Erasure Applies

    Article 17 isn't a blanket "delete everything" button. It applies in specific circumstances: when the data is no longer necessary for the purpose it was collected, when you withdraw consent and there is no other legal basis for processing, when you object to processing and there are no overriding legitimate grounds, when the data has been unlawfully processed, when the data must be erased to comply with a legal obligation, or when the data was collected in relation to the offer of information society services to a child.

    In practice, the most commonly invoked grounds are withdrawal of consent and the "no longer necessary" basis. If you signed up for a service, used it, and stopped — your data is arguably no longer necessary for the original purpose. If you consented to data processing and now withdraw that consent, the organization must delete unless they can demonstrate another legal basis for keeping it.

    There are exceptions. Organizations can refuse erasure if the data is needed for exercising the right of freedom of expression, compliance with a legal obligation, public health purposes, archiving in the public interest, or the establishment, exercise, or defense of legal claims. But these exceptions are narrower than most organizations pretend.

    How to Submit an Effective Erasure Request

    An effective erasure request should include: clear identification of yourself (so the organization can locate your data), specific identification of the data you want deleted (or a statement that you want all data deleted), the legal basis for your request (which Article 17 ground applies), a reference to Article 17 of the GDPR and the organization's obligations, and a reminder that the organization must respond within one month.

    Tone matters more than you might think. A request that is clear, specific, and cites the correct legal provisions gets processed faster than an angry, vague complaint. Data protection officers are more responsive to requests that demonstrate the requester understands their rights — because it signals that non-compliance will likely lead to an escalation they want to avoid.

    Send your request to the organization's Data Protection Officer (DPO) or designated privacy contact. Under GDPR, certain organizations are required to appoint a DPO, and their contact details should be publicly available, typically in the privacy policy.

    Tired of navigating this alone? Let Pypo's AI agent handle it.

    What to Do When Companies Say No

    Organizations must respond to erasure requests within one month. If they refuse, they must explain the specific legal basis for the refusal. Vague responses like "we need to keep your data for business purposes" are not compliant — the organization must cite a specific exception under Article 17(3).

    If you receive an inadequate response or no response at all, you have the right to lodge a complaint with your local Data Protection Authority (DPA). Every EU member state has one: the CNIL in France, the ICO in the UK (which maintains a GDPR-equivalent regime post-Brexit), the BfDI in Germany, and so on.

    DPA complaints are free to file and surprisingly effective. Data protection authorities have the power to investigate, issue binding orders, and impose fines of up to €20 million or 4% of annual global turnover — whichever is higher. Organizations know this, which is why a well-drafted escalation letter that mentions the DPA often produces results that the initial request did not.

    The Right to Erasure for Non-EU Residents

    GDPR applies to organizations that process data of individuals in the EU, regardless of where the organization is based. But what if you're not in the EU? Many jurisdictions have enacted similar rights. California's CCPA/CPRA provides a right to deletion for California residents. Brazil's LGPD includes erasure rights. Several other countries and US states have followed suit.

    Even without a specific legal right, many organizations will honor deletion requests simply to reduce data liability and maintain customer trust. A clearly written deletion request citing your jurisdiction's applicable privacy law — even if it's not GDPR — signals that you understand your rights and are prepared to escalate.

    The global trend is unmistakable: the right to control your personal data, including the right to demand its deletion, is becoming a universal standard. Organizations that ignore this trend risk both legal penalties and reputational damage.

    Ready to Put Your AI Agent to Work?

    Pypo's AI agent builds GDPR-compliant erasure requests with automatic escalation paths built in.

    Disclaimer: This article is for informational and educational purposes only and does not constitute legal advice. Pypo is not a law firm. For specific legal matters, consult a qualified attorney in your jurisdiction.

    GDPR
    right to erasure
    data deletion
    privacy
    EU law