Right to be Forgotten: GDPR rights explained

This blog post is part of our Rights Under GDPR explainer series, looking at the right to be forgotten.

About the Author
Michael has many years’ experience supporting, developing and improving effective data protection and GDPR compliance systems. He has worked in this field in the public, private and charity sectors including at Board level. This experience has made him the ideal lead trainer for WuDo Solutions’ five-star rated GDPR training course.

What is the Right to be Forgotten?

The right to be forgotten, also known as the right to erasure under the GDPR, allows individuals to request that organisations delete their personal data. It’s not absolute though. They can only request erasure in certain situations. Examples include if the data is no longer needed or if they withdraw consent.

What Does the GDPR Say?

Article 17 of the GDPR reads that:

  1. The data subject shall have the right to obtain from the controller the erasure of personal data concerning him or her without undue delay and the controller shall have the obligation to erase personal data without undue delay where one of the following grounds applies:
    1. the personal data are no longer necessary in relation to the purposes for which they were collected or otherwise processed;
    2. when the data subject withdraws consent on which the processing is based according to point (a) of Article 6(1), or point (a) of Article 9(2), and where there is no other legal ground for the processing;
    3. if the data subject objects to the processing pursuant to Article 21(1) and there are no overriding legitimate grounds for the processing, or the data subject objects to the processing pursuant to Article 21(2);
    4. the personal data have been unlawfully processed;
    5. when the personal data have to be erased for compliance with a legal obligation to which the controller is subject;
    6. the personal data have been collected in relation to the offer of information society services referred to in Article 8(1).

Publication

  1. Where the controller has made the personal data public and is obliged pursuant to paragraph 1 to erase the personal data, the controller, taking account of available technology and the cost of implementation, shall take reasonable steps, including technical measures, to inform controllers which are processing the personal data that the data subject has requested the erasure by such controllers of any links to, or copy or replication of, those personal data.

Exemptions

  1. Paragraphs 1 and 2 shall not apply to the extent that processing is necessary for:
    1. exercising the right of freedom of expression and information;
    2. compliance with a legal obligation which requires processing by Union or Member State law to which the controller is subject or for the performance of a task carried out in the public interest or in the exercise of official authority vested in the controller;
    3. reasons of public interest in the area of public health in accordance with points (h) and (i) of Article 9(2) as well as Article 9(3);
    4. archiving purposes in the public interest, scientific or historical research purposes or statistical purposes in accordance with Article 89(1) in so far as the right referred to in paragraph 1 is likely to render impossible or seriously impair the achievement of the objectives of that processing; or
    5. the establishment, exercise or defence of legal claims.

What Does This Mean?

Like most GDPR rights this right is not absolute. It does not apply in certain circumstances. Also, how and when it applies depends on the lawful basis for data processing. For example, the right to be forgotten can apply if someone withdraws consent. However the right will not apply if the data processing is required by law. Requests can also be refused if data is needed to deliver a contract.

It is also important to note data must be erased if it has been published or otherwise put in the public domain.

 

children looking at a tablet

 

The Right to be Forgotten and Children

All rights given to people under the GDPR also apply to children. However, the Right to be Forgotten is unusual because is applies to children more than most.

The reason for this is that the GDPR introduces greater restrictions on the use of children’s data than for adults. This makes it more important that their data are erased if they or their parent/guardian wishes it.

Children are deemed to be less aware of the risks and consequences of sharing their data. This means they have an enhanced right to be forgotten.

It is also important to note that if the data was provided by parents/guardians on behalf of a child, they will inherit the right to control their data as soon as they are competent to do so.

Getting it Right

When you are dealing with a child a request for erasure carries many pitfalls.

It may be tempting to dismiss the request because the person making it is a child and doesn’t understand. However, you must have ways of explaining to a child the uses of their data, and how to exercise their rights to control this in a way they will understand. Also, if you do decide not to comply with their request you must be able to explain why in ways they would understand.

Also, children can be more sensitive about some types of data than others. They are more likely to object to a photograph of them being shared over data that could have a longer term impact like those about health or academic performance. Just because the expectations and priorities of a child are different to an adult does not overrule their right to control their data.

Finally, there is a risk that because children merit special protection under GDPR, organisations will instinctively over-bureaucratise and inadvertently create hurdles that children who want to exercise their rights find difficult to clear. To enhance  their protection the correct route is to reduce barriers and engage.

Enjoying this content?
Get articles like this direct to your inbox with our free newsletter. Full of articles, news and resources with all our content accessible in one place. Plus subscribers get exclusive content, priority access to events, and exclusive special offers. You can unsubscribe any time and we won;t use your data for anything else.

Sign Up Here:

 

Exemptions to the Right to be Forgotten

Under the Regulations data must be erased when someone asks you to unless there is a compelling reason not to. Reasons not to comply include when you are using the data to:

  • exercise the right of freedom of expression and information. That protects journalism and allows some data to be kept and shared in the wider public interest.
  • comply with a legal obligation;
  • perform a task carried out in the public interest or in the exercise of official authority. That means, for example, people can’t have their health or education records deleted.
  • explore the establishment, exercise or defence of legal claims. This allow people and organisations to protect themselves from legal action.
  • archive scientific or historic research and erasing the data would impair that research;
  • for broad public health or personal medical circumstances.

You can also refuse a request to erase someone’s data if your legitimate reason for doing so demonstrably overrides their interests in exercising their rights.

Data Protection Principles

Linked to the Right to Be Forgotten is the GDPR principle on Storage Limitation. This requires data controllers to delete data that they no longer need.

We recommend always deleting data that you no longer need on a regular basis. Regardless of people’s rights you should only have the minimum necessary data. You should always delete data that are out of date or obsolete.

If you have disclosed the data to others, or others have seen it/have access to it due to it being on an online forum or similar then you must contact each recipient and inform them of the erasure request, unless this proves impossible or involves disproportionate effort. If asked to, you must also inform the individuals about these recipients.

Where personal data has been made public reasonable steps should be taken to inform other controllers who are processing the personal data to erase links to, copies or replication of that data. When deciding what steps are reasonable you should take into account available technology and the cost of implementation.

Top tips:

  • Have a clear child friendly privacy policy.
  • If you use legitimate interests as your basis for keeping data be clear what that interest is.
  • It may be that you can delete some data, but not all. Don’t consider data to exist in a state where you must have all of it, or none of it.
  • Even if you are dealing with a child you should record their wish for their data to be deleted and share that wish with any organisation you have passed the relevant data to.
  • If you do decide to delete data you must erase it from your back-up systems as well.
  • Email and local/personal drives are a weak link in data management. People must search their own systems to ensure no data that should be deleted is overlooked.
  • People can exercise their right verbally as well as in writing. It is important to be able to recognise requests when they are made.

Learn About the GDPR

Gain the practical skills you need to identify and manage data protection and GDPR with this five-star rated training course.

Available in person, online or in-house the focus on practical skills and unique post-course support you get by learning with us will ensure you and your organisation can tackle this key governance activity with confidence.

Five star training testimonial