What the right to erasure is
Article 17 of UK GDPR gives a data subject "the right to obtain from the controller the erasure of personal data concerning him or her without undue delay", and puts the controller under "the obligation to erase personal data without undue delay" where one of the listed grounds applies. The heading adds the phrase most people use: the right to be forgotten.
Three features shape everything else. The right applies only where one of the grounds in Article 17(1) applies; it is not a general right to have any data deleted on demand. It is subject to the exceptions in Article 17(3), which in schools, charities and care are engaged constantly. And it is exercised through the same machinery as the other rights: a request can be made verbally or in writing, to anyone in the organisation, with no special form, and is normally free.
UK GDPR has been amended by the Data (Use and Access) Act 2025, including the rules on response times that came into force on 5 February 2026; all the Act's data protection provisions have been in force since 19 June 2026, and the ICO, the data protection regulator, says its right to erasure guidance is under review as a result. Check the date on any ICO page you rely on.
When the right to erasure applies
Article 17(1) lists the grounds. The controller must erase personal data without undue delay where:
- the personal data "are no longer necessary in relation to the purposes for which they were collected or otherwise processed";
- the person withdraws consent on which the processing is based, "and where there is no other legal ground for the processing";
- the person objects to processing based on public task or legitimate interests under Article 21(1) and "there are no overriding legitimate grounds", or objects to direct marketing under Article 21(2);
- the personal data "have been unlawfully processed";
- the personal data have to be erased to comply with a legal obligation;
- the personal data were collected in relation to the offer of information society services, meaning online services, to a child; or
- since 31 March 2026 in England and Wales, the data were processed as a result of an allegation made by a "malicious person", which the controller has investigated and decided to take no further action on.
Which grounds are open depends on the lawful basis for processing. Where data is held on the basis of consent, withdrawing consent can end it; where it is held to comply with a legal obligation, the person cannot object at all, and erasure will usually turn on whether the data is still necessary. In practice the common cases are these. A charity supporter who asks to be taken off the mailing list and deleted has objected to direct marketing, and that objection is absolute; most organisations keep a minimal suppression record so that the person is not contacted again, and the ICO's direct marketing guidance explains how. A volunteer who left five years ago asks for their file to be deleted, and the purpose for which it was held has ended. A parent withdraws consent for photographs of their child on the school website, and there is no other basis for publishing them. A former applicant whose details were kept after an unsuccessful application with no retention period asks for them to go. In each, the retention schedule should already have said the data would be deleted; the request is often just the moment somebody checks.
Data the organisation has made public. Where the controller has published the data, a photograph on the school website, a case study in a charity newsletter, a post on social media, and must erase it, Article 17(2) requires it, "taking account of available technology and the cost of implementation", to take reasonable steps to inform other controllers processing it that the person has asked for links, copies or replications to be erased. Removing the post is the start, not the end.
The ICO asks controllers to give "particular weight" to erasure requests about data collected from children where the processing was based on consent the child gave, especially online, and says this remains the case when the person is no longer a child. For schools, youth groups and children's charities this is the ground most likely to arise from an adult looking back.
The new malicious-allegation ground is narrower than its name suggests. It was inserted by the Victims and Prisoners Act 2024, and a "malicious person" is defined by reference to a conviction for specified harassment or stalking offences against the data subject, or a stalking protection order made to protect them. It does not cover every allegation an organisation concludes was false. Schools already have a separate expectation in Keeping children safe in education 2026 (KCSIE 2026): "Details of allegations following an investigation that are found to have been malicious or false should be removed from personnel records unless the individual gives their consent for retention of the information."
When the right to erasure does not apply
Article 17(3) says the right does not apply "to the extent that processing is necessary" for any of five purposes:
- exercising the right of freedom of expression and information;
- "compliance with a legal obligation which requires processing", or "the performance of a task carried out in the public interest or in the exercise of official authority vested in the controller";
- reasons of public interest in the area of public health;
- archiving in the public interest, scientific or historical research, or statistics, where erasure would "render impossible or seriously impair" those purposes; or
- "the establishment, exercise or defence of legal claims".
The ICO adds that for special category data, the right does not apply where processing is necessary for health or social care purposes, including "the provision of health or social care", when the data is processed by or under the responsibility of a professional subject to a legal obligation of professional secrecy. The Data Protection Act 2018 also contains exemptions that can apply to erasure requests; the ICO notes that not all of them apply in the same way, so look at each carefully.
For the organisations this guide is written for, the exceptions settle most of the hard cases:
- Safeguarding and child protection records. A school must keep child protection files and pass them on when a pupil moves, under KCSIE 2026; a local authority, a school or a children's charity recording a concern is acting under legal duties or in the public interest. A parent who asks for a safeguarding record about their child to be deleted will almost always be refused, with reasons. Our guide on what KCSIE requires you to record covers those files.
- Care records. A care provider must "maintain securely an accurate, complete and contemporaneous record in respect of each service user" under Regulation 17 of the 2014 Regulated Activities Regulations, and keep it for the periods in the Records Management Code of Practice. A resident or relative cannot have a care record erased because they dislike an entry; if the entry is wrong, the remedy is rectification, or a note of their disagreement. Our guide to CQC record keeping requirements sets out the periods.
- Staff and recruitment records. Pay, tax and pension records, right-to-work checks, the single central record in a school, and, in a school, records of allegations found substantiated, unfounded or unsubstantiated, which KCSIE 2026 says should be kept on the file of the person accused. A former employee can ask; the organisation keeps what the law requires, for as long as it requires, and deletes the rest. Our guide to DBS record keeping covers what should never have been kept in the first place.
- Records that may be needed in a claim. A complaint, a grievance or an incident that could lead to a legal claim can be retained while the claim is possible, under Article 17(3)(e), but only while that remains realistic and only what is needed.
- Charity records. Gift Aid declarations and the records behind them have to be kept for HMRC, and a trustee's details appear in the charity's statutory records.
An exception applies "to the extent" processing is necessary. It rarely covers everything the person asked about. A school that must keep a child protection file does not need to keep the same child's photographs from a trip in a shared drive; a care provider that must keep the care record may have no reason to keep a relative's old correspondence about parking. The right answer is usually a partial erasure with a clear explanation of what is kept and why.
How to respond to an erasure request, and the one-month clock
Article 12(3) requires the controller to tell the person what action it has taken "without undue delay and in any event before the end of the applicable time period". Since 5 February 2026 that period is defined in Article 12A: one month beginning with "the relevant time", which is the latest of when the controller receives the request, when it receives any information it asked for to confirm the person's identity, and when any fee is paid. The controller can extend by "two further months" where that is necessary because of the complexity or number of the person's requests, but only by notice given within the first month, stating the reasons. The pause for clarifying the scope of a request applies only to subject access requests under Article 15, not to erasure.
- Recognise it. A request does not have to mention Article 17 or use the word erasure. "Take my details off your system" said to a receptionist is a request. Log it the day it arrives, including verbal requests.
- Confirm identity if you have reasonable doubts, and only then; the clock starts when you have what you need.
- Find the data. Every system the person's data is in: the management information system or care record, email, shared drives, the fundraising database, paper files, backups, and messages held on staff phones.
- Decide ground by ground and record by record. Which Article 17(1) ground applies, and whether an Article 17(3) exception or a Data Protection Act exemption applies to each category of data.
- Erase what must go, including from processors such as software suppliers. The ICO says backups must be put "beyond use" if they cannot be overwritten immediately, and that you must be "absolutely clear with individuals" about what will happen to data in backups.
- Tell recipients. Article 19 requires the controller to communicate an erasure to each recipient the data was disclosed to, "unless this proves impossible or involves disproportionate effort", and to tell the person who those recipients are if they ask.
- Reply in writing, saying what has been erased, what has been kept, the reason for each part kept, and how long it will be kept.
If the organisation refuses in whole or in part, Article 12(4) requires it to give its reasons and to tell the person about their right to complain. Since 19 June 2026 that means telling them they can complain to the controller itself, under the new section 164A of the Data Protection Act 2018, as well as to the ICO, and that they can seek a judicial remedy. A request can also be refused, or a reasonable fee charged, where it is "manifestly unfounded or excessive", but the controller bears the burden of showing that, and the ICO is clear it is not a tick-list exercise.
Keep a record of every erasure request and decision. It is the only evidence that the one-month deadline was met, and an organisation that erases data and keeps no note of having done so cannot show it complied.

Rectification, restriction and the requests that are really about something else
Many erasure requests in schools, charities and care are not really about deletion. A parent who wants a behaviour record deleted usually disputes what it says. A family who wants a care note removed usually thinks it is unfair to their mother. A former member of staff who wants their file erased may be preparing a claim. Recognising which it is helps the response.
- Rectification (Article 16). If personal data is inaccurate, the person has the right to have it corrected. An opinion recorded as an opinion is not inaccurate because the person disagrees with it, but the record can note their view.
- Restriction (Article 18). Where accuracy is contested, or processing is unlawful but the person would rather it were restricted than erased, or the controller no longer needs the data but the person needs it for a legal claim, processing can be restricted instead of the data being deleted.
- Objection (Article 21). Where processing relies on public task or legitimate interests, the person can object, and the controller must stop unless it has compelling legitimate grounds.
The worst response to an erasure request about a disputed record is to delete it. A safeguarding concern, an incident report or a care note that is deleted on request, and later turns out to have mattered, is a failure of the duty that required it to be kept, and the deletion itself will be read as concealment.
The messages that can be neither kept nor deleted
An erasure request is a good test of whether an organisation knows where its information is, because it has to find every copy. The systems are usually manageable. The staff group chat is not. A parent asks a school to delete everything about their family except what it is legally required to keep; the family has been discussed for two years in a staff WhatsApp group, in direct messages between the head and the deputy, and in a text to a teaching assistant's personal number. A former care worker asks for her data to be erased; the provider's rota and every conversation about her attendance live in a senior carer's phone.
Those messages are the organisation's personal data about the person, and within the request. The organisation cannot erase them, because they are on phones it does not control, and it cannot reliably say what they contain, so it cannot tell the person what has been kept and why, and cannot tell Article 19 recipients anything. Where some of the messages are part of a record the organisation is obliged to keep, such as the first mention of a safeguarding concern, it cannot keep those properly either. The same conversation fails the retention duty and the erasure duty at once.
An end-to-end-encrypted consumer app cannot solve that by configuration, because it keeps content on the handsets of the people in the conversation. ComplyChat replaces the work group with channels the organisation controls: everyone added is told the channel is on the record and can object or leave, messages are recorded on the server as they are sent, and a mobile number verified by SMS is an identity on it, so parents, volunteers and bank staff with no work account can be included. On paid plans the lasting record files into the organisation's own Microsoft 365 once the tenant is connected, under its own rules for keeping, holding and searching. Erasure is a request the organisation makes to ComplyChat, which carries it out across the working copy in a single transaction, hard-deletes the staged media and issues an erasure certificate. Before it runs, every message of the person still waiting to be filed is filed, and each affected archive folder then receives a dated, append-only amendment recording the erasure; nothing already filed is edited. ComplyChat cannot reach or erase anything in staff members' existing WhatsApp groups; those remain a question for the organisation's own policy and records process.
A question for the next board or leadership meeting: if a parent, a supporter or a former member of staff asked us tomorrow to delete everything we hold about them, could we find all of it, including what staff have said about them in messages, and explain in one letter what we deleted and what we kept?
Official guidance and your next step
The primary sources are Article 17 of UK GDPR with Articles 12, 12A and 19, the Data Protection Act 2018 for the exemptions, and the ICO's guidance on the right to erasure, which is under review following the Data (Use and Access) Act. Schools should read KCSIE 2026 on records of allegations against staff. Quotations here are from those sources as published on 25 September 2026.
This guide is a practical starting point for organisations in the UK, not legal advice about a particular request. Where a request touches a safeguarding file, a live complaint or a possible claim, ask your data protection officer or adviser before replying.
Then do one thing: check that your retention schedule names every category of personal data you hold, including staff messages, with a period and a reason. An erasure request can only be answered quickly by an organisation that has already decided what it keeps.
We build ComplyChat for the work conversations organisations need to keep. An erasure request asks an organisation to find every copy of someone's data, and the copies held in staff messages are the ones it most often cannot find, keep or delete. Explore Free personal messaging, or compare the paid plans if your organisation needs a lasting Microsoft 365 archive under its own retention rules.
Sources
Every document this guide quotes or links to, in the order it first cites them.
- Article 17 of UK GDPR legislation.gov.uk
- Right to erasure guidance ico.org.uk
- Keeping children safe in education 2026 gov.uk
- Data Protection Act 2018 legislation.gov.uk


