Do I Have A Right To Be Forgotten? (2026 Updated)

Rowan Gardoce
byRowan Gardoce10 min read

If you run a business in the UK, you've probably had that sinking feeling at least once: someone emails you out of the blue and says, "Please delete all my data."

Sometimes it's a former customer who's had a change of heart. Sometimes it's an ex-employee. Sometimes it's someone who just doesn't want their name in your systems anymore.

This is where the "right to be forgotten" comes in. It's a real legal right (with a very specific scope), and it's one of those GDPR topics that can feel intimidating until you break it down into practical steps.

Below, we'll walk through what the right to be forgotten actually means in the UK, when it applies, when it doesn't, and how to handle requests in a way that protects both the individual and your business.

What Is The "Right To Be Forgotten" In The UK?

In UK data protection law, the "right to be forgotten" is usually referred to as the right to erasure.

It comes from the UK GDPR (and sits alongside the Data Protection Act 2018). In simple terms, it means that in certain circumstances, an individual can ask you to delete personal data you hold about them, and you must do it.

But (and this is the part that trips people up) it's not an automatic right to wipe everything, everywhere, immediately.

Instead, the right to erasure is a qualified right. That means:

  • It applies in certain scenarios (not all scenarios).
  • It can be limited by other legal obligations (like keeping records for tax, employment, or regulatory reasons).
  • You still need to handle the request properly - even if the answer is "no".

What Counts As "Personal Data?"

Personal data is information that identifies a person (directly or indirectly). That can include obvious things like a name and email address, but also things like:

  • customer IDs and account numbers (if they link back to an individual)
  • IP addresses and device identifiers (in many contexts)
  • HR notes about performance or absence
  • call recordings and CCTV footage (if people can be identified)

Even "business contact details" can still be personal data in many cases. If you're unsure where the line is, it's worth getting clarity early - for example, whether work email addresses are treated as personal data in your specific context.

Is This Only About Google And Search Results?

No. The "right to be forgotten" became famous because of search engines and online results, but for most small businesses, the real-world version is much more practical:

  • deleting old customer profiles
  • removing someone from a mailing list
  • erasing a former employee's data that you no longer need
  • clearing out data in SaaS tools (CRM, booking systems, email marketing platforms)

When Can Someone Ask You To Erase Their Data?

Someone can request erasure when one (or more) of the legal grounds for erasure applies. In plain English, the main situations you'll see are below.

1) You No Longer Need The Data For The Original Purpose

If you collected someone's personal data for a specific reason, and you no longer need it for that reason, they may be able to ask you to erase it.

For example:

  • A customer made a one-off purchase years ago and you've kept their details in your marketing database "just in case".
  • A prospective client enquired, didn't proceed, and their details are still sitting in your pipeline indefinitely.

Data retention is a big part of this. If you don't have a clear retention approach, you'll usually end up keeping too much for too long (which increases risk). A sensible retention plan often starts with understanding how long you should keep personal data in different scenarios.

If you relied on consent to process the person's data (for example, email marketing sign-ups), and they withdraw consent, you generally can't keep using that data for the consent-based purpose.

This doesn't always mean you must delete everything immediately (for instance, you may keep a suppression record so you don't accidentally re-market to them), but it does mean you need to stop the consent-based processing and consider what must be erased.

3) They Object To Processing (And You Don't Have A Strong Justification To Continue)

People can object to certain types of processing, particularly direct marketing.

If someone objects to you using their data for marketing, the safest operational approach is usually:

  • stop marketing to them straight away, and
  • keep only the minimum necessary record to ensure they stay opted-out

4) The Data Was Processed Unlawfully

If personal data was collected or used in a way that doesn't comply with UK GDPR (for example, you scraped data without a lawful basis, or you kept it without a proper reason), erasure may apply.

This is also where businesses sometimes discover uncomfortable truths about older datasets, legacy email lists, or "temporary" spreadsheets that became permanent.

Sometimes erasure can be tied to a separate legal obligation. This is less common for many SMEs, but it can come up depending on your industry and the type of data you handle.

When Can A Business Refuse A "Right To Be Forgotten" Request?

This is the part many business owners want to know: yes, you can refuse an erasure request in some circumstances.

But you need to refuse it the right way - with clear reasoning and good record-keeping - because refusal is exactly the type of response that can escalate into a complaint.

Common Reasons You Can Keep Data (Even If They Ask You To Delete It)

Some of the most practical, day-to-day reasons you might be able (or required) to keep certain personal data include:

  • Legal obligations (for example, keeping certain records for HMRC, payroll, statutory payments, or regulatory compliance).
  • Contract necessity (where you still need the data to perform or manage an ongoing contract).
  • Legal claims (you may need to keep evidence to establish, exercise, or defend legal claims).
  • Employment record-keeping (there are often legitimate reasons to retain ex-employee information for a defined period).

Employment data is a particularly common flashpoint. Ex-employees will sometimes ask you to delete everything immediately, but employers often have valid reasons to retain certain records (for example, relating to tax, pensions, or potential disputes). That's why it's useful to have a clear internal approach to ex-employee records rather than dealing with requests ad hoc.

Erasure Doesn't Always Mean "Delete Every Trace"

In practice, erasure is often more like:

  • deleting what you don't need, and
  • securely retaining what you genuinely must keep (and only for as long as necessary)

It can also include anonymisation (where the data is changed so the person is no longer identifiable), but be careful here: "anonymised" is a higher bar than many people expect, and if you can still re-identify the person, it's probably still personal data.

What About Backups?

Backups are a classic operational headache.

You don't necessarily need to rebuild your entire backup architecture because of a single erasure request, but you do need a sensible plan. Many businesses handle this by:

  • ensuring backups are protected and access-controlled
  • having defined backup retention periods
  • ensuring that if a backup is restored, the erased data is re-erased where feasible

Your cloud setup matters here too. If you're storing data in common tools and you're not sure what "good" looks like, it may help to sense-check your processes against questions like whether Google Drive is GDPR compliant for your use case (it often can be, but only if you configure and manage it properly).

How Long Do You Have To Respond And What Process Should You Follow?

When you receive a right to be forgotten request, treat it as a formal data rights request - even if it arrives in an informal message like "Hey, can you remove me from your system?".

Most of the time, you'll have one month to respond (with some limited options to extend in complex cases). Timing and process mistakes are one of the easiest ways to create risk, so it helps to build an internal workflow that you can repeat every time.

If you're juggling deadlines (and who isn't), it's worth getting familiar with SAR response timescales - even though a SAR (subject access request) isn't the same as an erasure request, the operational discipline is very similar.

Step 1: Confirm Who You're Dealing With

Before you delete anything, you should take reasonable steps to make sure the person is who they say they are.

This is especially important if:

  • the request comes from a different email address than the one you have on file
  • the request relates to sensitive information
  • you hold large amounts of data on the person

Be careful not to request excessive ID documents. The goal is to reduce fraud risk without collecting even more personal data unnecessarily.

Step 2: Clarify What They Want Deleted (If Needed)

Sometimes requests are broad ("delete everything"). Sometimes they're specific ("delete my marketing profile").

If it's unclear, you can ask follow-up questions so you can respond properly. The clock doesn't stop just because you asked questions, so keep things moving internally while you wait for clarification.

Step 3: Identify Your Lawful Basis And Whether Erasure Applies

This is where you work through:

  • What data you hold (and where it lives)
  • Why you collected it
  • What lawful basis you relied on (contract, legal obligation, legitimate interests, consent, etc.)
  • Whether you still need it
  • Whether any legal exceptions apply

If your team doesn't have a consistent way to document this, you'll end up reinventing the wheel for every request - which increases the chance of errors.

Step 4: Delete, Anonymise, Or Restrict Processing

If erasure applies, delete the data from the systems where it's held (CRM, mailing list, support platform, finance software, HR platform), and document what you did.

If erasure doesn't fully apply (because you need to keep some records), consider whether you should:

  • delete what you can, and
  • restrict access to what you must keep (for example, limiting it to finance or HR only)

Step 5: Tell Them What You've Done (And Be Clear If You Refused Anything)

Your response should be easy to understand and should cover:

  • what you erased
  • what you didn't erase (if relevant) and why
  • what happens next (for example, timeframes for backups to cycle out)
  • their right to complain to the ICO if they disagree

This isn't about being defensive - it's about being transparent and organised.

What Does "Right To Be Forgotten" Mean For Your Day-To-Day Business Systems?

Most businesses don't struggle with the legal concept of erasure - they struggle with the reality of where personal data ends up.

Think about the typical SME stack. Personal data often exists in:

  • your CRM
  • your email marketing platform
  • inbox history (threads and attachments)
  • invoices and accounting software
  • Slack / Teams messages
  • shared drives and "temporary" spreadsheets
  • third-party booking tools

So the practical question becomes: can you actually find and remove the data when you need to?

Build A Simple Erasure Workflow (So You're Not Scrambling Later)

If you want to be "protected from day one", a workable approach for many SMEs is:

  1. Map your data: document the main systems where customer and employee personal data is stored.
  2. Set retention rules: decide how long you keep different types of data and why.
  3. Limit "shadow files": reduce ad hoc spreadsheets and duplicated lists where possible.
  4. Create request templates: standard responses and internal checklists save time and reduce mistakes.
  5. Train your team: make sure staff know that "delete my data" isn't just a casual ask - it's a legal rights request.

Where possible, it's also smart to have formal documentation in place that matches what you actually do in practice, including a properly drafted Privacy Policy that explains what data you collect, why you collect it, and how long you keep it.

Don't Forget About Subject Access Requests (They Often Come First)

In real life, many people don't start with "delete my data". They start with "what data do you have about me?"

That's a subject access request, and it can quickly become an erasure request depending on what the person sees.

Having a consistent process and an Access Request Form can make it easier to route requests properly and avoid missing deadlines.

Common Mistakes We See (And How To Avoid Them)

  • Deleting data too quickly: if you erase records you legally need (for example, tax records), you can create a compliance problem for yourself.
  • Refusing without explanation: "We can't delete it" isn't enough - you need a clear, plain-English reason.
  • Only deleting in one system: if you remove someone from Mailchimp but keep them in your CRM, you may not have actually honoured the request.
  • Keeping data "just in case": if you don't have a retention reason, it's often safer not to keep it.
  • Not logging the request: if the ICO ever asks what happened, you want a clear paper trail.

And if you're thinking, "This sounds like a lot," you're not alone. The trick is to treat this as an operational habit - not a one-off panic response.

Key Takeaways

  • The UK "right to be forgotten" is the right to erasure under the UK GDPR, but it is a qualified right (it doesn't apply in every situation).
  • People can often request erasure where you no longer need their data, where they withdraw consent, where processing was unlawful, or where they successfully object to certain processing.
  • You can refuse an erasure request in certain circumstances, including where you need to keep data to comply with a legal obligation or to defend legal claims - but you must respond properly and transparently.
  • Most "right to be forgotten" risk for SMEs comes from systems and process gaps (not knowing where data is stored, inconsistent retention, and incomplete deletion across platforms).
  • Having a clear retention approach, documented processes, and customer-facing privacy documentation makes erasure requests much easier to manage (and reduces the chance of mistakes).

If you'd like help reviewing how your business handles erasure requests, retention periods, and GDPR compliance more broadly, you can reach us at 08081347754 or team@sprintlaw.co.uk for a free, no-obligations chat.

Get your customer-facing terms right

When should you formalise this?

If you collect customer data, sell online or run marketing campaigns, your public terms and privacy documents should match the real customer journey.

Rowan Gardoce
Rowan GardoceMarketing Coordinator

Rowan is the Marketing Coordinator at Sprintlaw. She is studying law and psychology with a background in insurtech and brand experience, and now helps Sprintlaw help small businesses

Get your customer-facing terms right

Get in touch with our team

Tell us what you need and we'll come back with a fixed-fee quote - no obligation, no surprises.

Need support?

Need help with your business legals?

Speak with Sprintlaw to get practical legal support and fixed-fee options tailored to your business.