The Right to be Forgotten on Google, AI, and Beyond: How Companies Implement Deletion Requests

- The right to be forgotten protects against reputational damage caused by negative online information.
- Article 17 of the GDPR defines the requirements and exceptions for erasure requests.
- Companies are required to process legitimate erasure requests within one month.
- To respond to erasure requests quickly and accurately, those responsible should develop deletion concepts and data protection policies in good time.
What is meant by the right to be forgotten under the GDPR?
With the right to be forgotten, the General Data Protection Regulation (GDPR) strengthens the rights of EU citizens and natural persons whose personal data is processed within the EU: It gives them the option to have personal data erased, for example, data stored by companies or appearing in search results on Google and similar platforms.
Legal basis: What does Article 17 of the GDPR say?
Article 17 of the GDPR regulates the conditions under which erasure requests must be honored, and which exceptions apply.
The article also distinguishes between the right to erasure and the right to be forgotten – strictly speaking, these are two different things:
- If customers no longer want their personal data to be processed by your company or if the statutory retention periods for the data have expired, there is a right to erasure.
- The right to be forgotten concerns the traces your data leaves behind on the internet. It involves, for example, removing links or copies of published personal data.
Example of the right to be forgotten in practice
A case from 2014 illustrates exactly when the right to be forgotten applies: Back then, private citizen Mario Costeja González from Spain fought to have an old 1998 newspaper article deleted that reported on his debts at the time, which resulted in damage to his reputation. While the local newspaper relied on freedom of the press regarding the article, Google was required to remove the link to the article.
Does the right to be forgotten also apply to companies?
Companies can also request deletion or to be forgotten. This is useful, for example, if false negative reviews on Google threaten their reputation or misinformation is being spread about them that could lead to economic damage.
H2: Requirements: When must personal data be deleted under the GDPR?
For data subjects to be able to enforce the right to erasure or the right to be forgotten, certain requirements must be met:
- The personal data is no longer necessaryfor the original purpose for which it was collected.
- The data subject withdraws their consent and there is no other legal basis for the processing of the data.
- The data subject objects to the processing of the data and there are no overriding legitimate grounds for (continued) processing.
- The data is being processed unlawfully.
- Erasure is required under Union law, for example, because another European legal provision applies.
When is it not necessary to delete personal data?
There are exceptions to the right to erasure under Art. 17 (3) GDPR. As a rule, there is no right to erasure if the processing of the datais necessary
- for exercising the right of freedom of expression and information
- for reasons of public interest in the area of public health
- for statistical or research purposes
- for the establishment, exercise or defence of legal claims.
How can customers request that their data be deleted?
Any person whose personal data is collected, processed, or stored by a company can submit a request for information to find out what data is stored. Subsequently, data subjects can a deletion request submit.
How do you delete data in compliance with the GDPR?
Data subject to a deletion request must be deleted without undue delay, meaning "without culpable hesitation." Once the request is received, the requester must be notified within one month regarding the measures taken.
If a deletion request is denied, those responsible must explain the reasons for the refusal and inform the requester of their right to lodge a complaint with a supervisory authority and the possibility of judicial remedy .
Checklist: How to be prepared for deletion requests
To be able to respond to deletion requests at short notice and reduce the effort involved in deleting data, the utmost care is required from the moment of collection :
- Ensure that your privacy policy is up-to-date and accurate and contains all relevant information regarding deletion.
- Document the purpose of data collection or data processing from the very beginning and the legal basis for processing and consent of the data subject.
- Determine the deletion and retention periods for the data – document these as well and set reminders for the deadlines.
- Clearly identify which data must be deleted and which data are exempt from the deletion obligation . Exceptions may apply, for example, to scientific data.
- Document the transfer of data to third parties.
- If the data is published, the publications must also be documented.
The easiest way to manage documentation is with a Data protection software: Software gives you an overview at all times of where in the company and in which systems data is stored and who it may have been shared with.
Never overlook data again
Implementing data protection is even easier if you rely on an external data protection officer who already has software in place.
To the external data protection officer
How should data disposal be managed?
Digital data must be destroyed in such a way that it cannot be restored. Specialized service providers can assist you with this. You can find out what applies to physical documents containing personal data in our blog post on GDPR-compliant document shredding.
H2: What is a deletion concept according to the GDPR – and is it mandatory?
A deletion concept governs how data is deleted within a company. While not explicitly mandatory under the GDPR, it is, alongside an up-to-date privacy policy, an important prerequisite for quickly and securely meeting deletion obligations, making it virtually indispensable.
Learn more about the deletion concept – including a checklist of what it must contain.
H2: Right to be forgotten in Google and AI tools
While the right to erasure is generally easy for companies to manage, the right to be forgotten presents several challenges – especially in the context of AI. Search results on Google can be removed quite easily. But what happens when personal data enters AI-based tools like chatbots?
Data that a model has "learned" is stored in the system as knowledge and used to generate responses. Even if the original data is deleted, the learned information often remains, making a complete "forgetting" technically difficult to implement .
For companies, this means they must not only establish secure deletion processes for internal data but also develop new strategies for handling AI toolsto reliably fulfill their deletion obligations. An important step is building AI expertise and establishing AI governance.
How your teams can work securely with AI
Establish clear AI guidelines and train your employees on how to use LLMs. We provide the expertise to help you save resources and stay productive!
H2: Conclusion: Take the right to erasure and the right to be forgotten seriously and build trust
Whether you work in e-commerce, finance, or healthcare, the right to erasure belongs in every data protection concept. Collect and process data in a GDPR-compliant and transparent manner from the start, and even a one-month deadline will no longer be a problem.
If you have questions about the GDPR and the right to erasure or the right to be forgotten our data protection experts are happy to help.
Do you have further questions on this topic? Our experts will be happy to advise you free of charge.














