SimplComIA

Asking for your data to be erased (GDPR, Article 17)

The GDPR right to erasure explained: when to use it, who to write to, how long companies have to reply, and a letter template to adapt.

Article 17 of the General Data Protection Regulation (GDPR) lets you require a company to erase the personal data it holds about you. After a breach, it is a way to reduce what could leak again.

When the company must erase

Some data may be kept despite your request, for example invoices that the law requires companies to retain.

Who to write to

To the company's data protection officer (DPO). Their address is in the site's privacy policy. Failing that, write to customer service, stating "request to exercise GDPR rights".

Reply deadline

The company must reply within one month of receipt. This can be extended by two months for a complex request, provided you are told within the first month. It may ask you to prove your identity if it has reasonable doubts.

Letter template

Subject: request for erasure of personal data (Article 17 GDPR)

Dear Sir or Madam,

Pursuant to Article 17 of Regulation (EU) 2016/679, I ask you to erase all personal data concerning me that you hold, associated with the email address [your address].

Please confirm this erasure within the one-month period provided for in Article 12(3) of that Regulation, and inform any recipients of this data in accordance with Article 19.

Failing a reply within this period, I reserve the right to lodge a complaint with the competent data protection authority.

[First and last name, date]

Save time

After checking your breaches, SimplComIA can send these requests on your behalf to each site concerned when a contact address is known, and send an automatic reminder after one month.