Privacy Rights & Requests
What is Right to Be Forgotten (Right to Delete)?
The right to be forgotten — formally the right to erasure under GDPR Article 17, and the right to delete under the CCPA — is an individual's right to have an organization delete the personal data it holds about them, subject to defined exceptions.
Under GDPR Article 17, individuals can require erasure when the data is no longer necessary for its original purpose, when they withdraw consent and no other legal basis applies, when they object to processing and no overriding grounds exist, when the data was processed unlawfully, or when a legal obligation requires deletion. The organization must respond within one month and, where it has made the data public, take reasonable steps to inform other controllers processing it.
The right is not absolute. GDPR preserves processing needed for freedom of expression, legal compliance, public health, archiving and research, and the establishment or defense of legal claims. The CCPA's right to delete carries its own exceptions — completing the transaction the data was collected for, security and fraud prevention, legal obligations, and certain internal uses reasonably aligned with consumer expectations. Deletion requests are therefore an evaluation, not a reflex: each request is checked against retention obligations before executing.
Execution is the hard part. Deleting a customer means finding them across production databases, marketing platforms, analytics profiles, support systems, data warehouses, and processors — then erasing or de-identifying in each, instructing service providers to do the same, and keeping evidence of completion. A common lawful pattern is suppression-plus-deletion: retaining a minimal hashed record so the person is not re-added by the next data sync, while the substantive profile is destroyed.
The term 'right to be forgotten' predates GDPR — it entered the lexicon through the CJEU's 2014 Google Spain ruling on de-listing search results — but in operational compliance it now means the erasure workflow.
Why it matters for eCommerce
Deletion requests collide with legitimate retention: you may keep order records needed for tax, accounting, fraud, and returns even after deleting the marketing profile. The defensible pattern is documented triage — erase marketing and behavioral data everywhere, retain the transactional minimum under its legal-obligation basis, and log both halves. What is not defensible is deleting from your store while Klaviyo and your ad audiences keep the customer alive.
Frequently asked questions
- Can a business refuse a deletion request?
- Yes, within the exceptions: legal retention obligations, fraud and security, completing a transaction, or defending legal claims, among others. The refusal must be scoped — delete what has no exception, retain only what does, and tell the requester which exception applies.
- Does deletion include data held by our vendors?
- Yes. GDPR controllers must instruct processors to erase, and the CCPA requires businesses to direct service providers and contractors to delete. A deletion that stops at your own database is incomplete.
Related terms
Wondering how this applies to your own site? Get a free compliance scan — see every tracker that fires before consent, graded against CIPA, GDPR, CCPA/CPRA, and MHMD.
Automate deletion across your stack