Skip to content

Right to be Forgotten

What is Right to be Forgotten?

The right of individuals to request the erasure of their personal data under certain circumstances. Established under GDPR Article 17, also known as the right to erasure, it applies when data is no longer necessary, consent is withdrawn, or processing is unlawful.

Privacy

Each of these is named in at least one of the same controls as right to be forgotten. The number is how many controls name both.

What the standards actually require on right to be forgotten

Requirements naming right to be forgotten across 6 standards, quoted from the control text.

GDPR1 control

Erase personal data without undue delay where the data is no longer necessary for the purposes it was collected or processed for, where consent is withdrawn and no other legal ground applies, where the data subject objects under Article 21(1) and there are no...

GDPR-Art.17 · Right to erasure (right to be forgotten)

Per LOPDGDD Title X: digital rights including right to digital education + right to be forgotten + digital workplace rights.

SPAINLOPDGDD-2 · Digital Rights, Spanish Specifics

Art.24 right to be informed; Art.25 right of access; Art.26 exceptions to the right of access (national security, criminal investigation, etc.); Art.27 right to rectification; Art.28 right to erasure ('right to be forgotten').

ETH-PDPP-Art.24-28 · Right to be informed, access, rectification and erasure

Articles 11-16 establish the DATA SUBJECT RIGHTS regime. Each right is exercisable through a request to the controller + the controller must respond within reasonable time (Data Office guidance suggests 30 days).

UAE-PDPL-Art.11_12_13_14_15_16 · Data subject rights (UAE PDPL Articles 11-16)

Chapter II Sections 14-23 establish data subject rights and transparency obligations. Section 14 (Right to Information) requires controller to provide privacy notice at or before collection covering: identity + contact of controller + processor + DPO + purpose...

HU-INFOTV-Chap2-Transparency-DataSubject-Rights-Sections-14-23 · HU Infotv Chap II - Transparency + Data Subject Rights to Information, Access, Rectification, Erasure, Restriction (Sections 14-23)

Questions people ask about right to be forgotten

What is Right to be Forgotten?
The right of individuals to request the erasure of their personal data under certain circumstances. Established under GDPR Article 17, also known as the right to erasure, it applies when data is no longer necessary, consent is withdrawn, or processing is unlawful.
Why is Right to be Forgotten important for compliance?
Right to be Forgotten is a key concept in Privacy. Understanding right to be forgotten helps organizations meet regulatory requirements, reduce risk, and demonstrate due diligence during audits. Our compliance platform maps 686 frameworks with 311K cross-framework control mappings.
Which compliance frameworks address Right to be Forgotten?
Right to be Forgotten appears in the requirement text of GDPR, Jamaica Data Protection Act 2020, Spain Organic Law 3/2018 on Data Protection and Digital Rights (LOPDGDD), Ethiopia Personal Data Protection Proclamation (No. 1321/2024), Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data (UAE PDPL). Across these standards we have identified 8 controls that name it directly, each linked to the control text on the compliance platform.
Where can I learn more about Right to be Forgotten?
Explore our compliance framework pages to see how right to be forgotten applies across different standards and regulations. Our implementation guides provide step-by-step guidance, and the compliance platform offers AI-powered analysis of how this concept maps across 686 frameworks.

See how Right to be Forgotten applies across compliance frameworks

Our platform maps 686 frameworks with 311K cross-framework control mappings. Explore how this concept is addressed across standards.

Written and maintained by Gerard Blokdyk, The Art of Service.