You must erase personal data when a person asks and at least one of the grounds in Article 17(1) GDPR applies, most commonly: the data is no longer needed for its purpose, the person has withdrawn consent and there is no other basis, the person objects and your grounds do not override, or the processing is direct marketing, or the data is processed unlawfully. You may refuse to the extent that processing is still necessary, for example to comply with a legal obligation or to defend legal claims (Article 17(3)(b) and (e) GDPR). You must answer without undue delay and within one month at the latest. In complex cases the period may be extended by two further months if, within the first month, you tell the person of the extension and the reasons for the delay (Article 12(3) GDPR).
In practice a request is almost never “all or nothing”. The right answer is usually partial: the account, the marketing list and the correspondence are erased, while the accounting records of the purchase are kept until the retention period ends. Below: how to tell what to erase and what to keep, and what this means for backups, processors and recipients.
When erasure is mandatory
Article 17(1) GDPR lists six grounds. Four usually matter to an organisation:
- The data is no longer needed for the purpose for which it was collected (point (a)). For example, the account is closed, the contract was performed long ago and the retention period you set has ended.
- Consent has been withdrawn and there is no other legal ground (point (b)). What remains lawful after withdrawal is covered in our article on consent under the GDPR.
- The person objects to the processing (point (c)). Where the data is processed on the basis of legitimate interest, you have to assess whether your grounds override. Where it is processed for direct marketing, there is nothing to assess: the data is no longer processed for that purpose (Article 21(3) GDPR).
- The data is processed unlawfully (point (d)).
Requests arrive in any form: one sentence in an email, a website form, sometimes a general mailbox or even the wrong one, often with no reference to any article. But a broad request to “erase everything” does not mean that everything must be erased. You erase to the extent that one of these grounds applies.
Where the data was published online, additional rules apply. We cover them in Personal data published without consent: what to do.
When you may refuse
The right to erasure does not apply where processing is necessary, among other things:
- to comply with a legal obligation which requires processing by law applicable to the organisation (Article 17(3)(b) GDPR);
- for the establishment, exercise or defence of legal claims (Article 17(3)(e) GDPR).
The key word here is “necessary”. The exception covers only the data needed to meet the obligation or defend the claim, and only for as long as it is needed. Data may not be kept longer than necessary for the purposes for which it is processed (Article 5(1)(e) GDPR).
The legal claims exception is not a licence to keep everything “just in case”. It is justified by an actual dispute, a claim received, an unpaid debt, or a period set in advance and linked to the limitation period. The general limitation period is ten years (Article 1.125(1) of the Civil Code, CK), but the law sets shorter periods for many claims (Article 1.125(2) CK). So the period is best linked to a specific claim, not automatically to the longest one.
Accounting documents and “erase everything”
One company received a letter from a buyer demanding the immediate erasure of all data about him. The letter already stated that no exception under Article 17(3) GDPR applied and demanded that all recipients be notified. A check showed that the company held data on one purchase. Our lawyer replied that the purchase data forms part of the accounting records. It is processed to comply with a legal obligation (Article 6(1)(c) GDPR), so it cannot be erased before the retention period ends, and it will be erased once the period ends. The answer also set out the right to complain to the State Data Protection Inspectorate (VDAI).
What the law says:
- business transactions are supported by accounting documents (Article 3(1) of the Law on Financial Accounting, FAĮ);
- accounting documents and accounting registers are kept in the manner set by the head of the entity, in accordance with the Law on Documents and Archives (Article 10(1) FAĮ);
- FAĮ sets no specific periods: they follow from laws and other legal acts (Article 13(1) of the Law on Documents and Archives, DAĮ), and retention schedules for mandatory internal administration documents are approved by the Chief Archivist of Lithuania (Article 13(2) DAĮ);
- until the period ends the documents must be kept (Article 12(1)(2) DAĮ), and they may be destroyed, after an appraisal of their value, once the periods set by law have expired (Article 14(1) DAĮ);
- accounting documents supporting business transactions carried out in money may not be corrected. If an error is made, a new accounting document is prepared and the erroneous one is kept with the other documents of the reporting period (Article 7(5) FAĮ). In our view, this also means a buyer’s name cannot be removed from an invoice already issued.
What this exception does not cover. The duty to keep covers only what supports the business transaction. It does not cover marketing consents, the newsletter list, a loyalty account, browsing or correspondence history. That data is erased in the ordinary way. Also, a buyer’s name does not always appear on an accounting document: it is not required where tax law does not require it (Article 7(1)(6) FAĮ). The buyer’s identity may then not be recorded in the accounts at all, and “we keep it for accounting” does not work for data that the accounts do not contain.
Data you keep is not hidden from the person. The EDPB Guidelines 01/2022 state that data a controller keeps only to comply with a legal obligation must be provided if the person asks for access (Example 18, paragraph 109). How to answer such a request is covered in our article on subject access requests.
Backups, processors and recipients
Backups. The EDPB, discussing the right of access, notes that in some cases data erased in the live system is reflected in the backup set only when a later backup is made, and that if the person asks for access in the meantime the controller must be open about this (paragraph 110 of Guidelines 01/2022). In our view, this is enough if backups are overwritten within a set time, erased data is not restored from them into the live system, and the answer to the person states honestly how long it will take for the data to disappear from the backups too.
Processors. An IT provider, a CRM or a sales system vendor processes data only on your documented instructions (Article 28(3)(a) GDPR) and helps you respond to people’s requests (Article 28(3)(e) GDPR). In the case above, the data in the vendor’s system was deleted before any legal assessment. For the part that did not need to be kept, that may be right. But the decision on what to erase must be taken by the controller, having assessed the whole request, not by the vendor on its own.
Recipients. Once data is erased under Article 17(1), each recipient to whom it was disclosed must be told, unless this proves impossible or involves disproportionate effort. If the person asks, you tell them who those recipients are (Article 19 GDPR).
What happens when you get it wrong
Too much erased. An accounting document is gone, and it was mandatory. A breach of the rules governing financial accounting leads to a warning or a fine of forty to one hundred and forty euros (Article 205(1) of the Code of Administrative Offences, ANK). If a dispute arises, you lack the evidence you would have needed to defend your own position.
Too little erased. You replied that the data was erased, but it remained in the marketing system, with a vendor or in a colleague’s mailbox. Or you refused entirely, although the exception covered only part of the data. Infringing data subject rights under Articles 12–22 can lead to fines of up to twenty million euros or, for an undertaking, up to 4 % of its total worldwide annual turnover of the preceding financial year, whichever is higher (Article 83(5)(b) GDPR). A person who has suffered damage has the right to compensation (Article 82(1) GDPR).
Refusal without reasons. If you do not act on the request, within one month you must give the reasons and tell the person about the possibility of complaining to a supervisory authority and seeking a judicial remedy (Article 12(4) GDPR). A bare “we can’t” does not meet this duty.
An answer based on wrong facts. In the case above, the purchase date was corrected later. Before writing what you keep and why, check what you actually hold about the person, and where.
When to call a lawyer
- when the request is broad, cites articles and threatens a complaint;
- when you want to keep part of the data and need to justify which part and for how long;
- when there is or may be a dispute, a debt or a claim with the person;
- when the data sits with several vendors or has been passed to other recipients;
- when the request reached you late or at the wrong address.
Frequently asked questions
Can we refuse erasure if the person owes us money?
In part. Data needed to recover the debt or for a dispute may be kept, because it is needed for the establishment and exercise of legal claims (Article 17(3)(e) GDPR). This does not cover marketing or other data unrelated to the debt. Erase that, and state in your answer what is kept, why and until when.
Do we have to erase data from backups too?
Yes, but usually not on the same day. The EDPB notes that in some cases erasure is reflected in backups only when a later backup is made (paragraph 110 of Guidelines 01/2022). What matters is that backups are overwritten within a set time and that erased data is not restored from them. It is worth saying this honestly in your answer to the person.
Can a phone number or email address stay on a block list when a person deletes their account?
Yes, if it is genuinely needed to prevent abuse, for example so that a removed user does not register again. The basis is legitimate interest (Article 6(1)(f) GDPR), and the Regulation names fraud prevention as an example of a legitimate interest (Recital 47). Keep as little as possible, ideally not the number itself but a pseudonymised value, use it only for this purpose, set a period and say so in your privacy policy.
Do we have to tell the person that the data has been erased?
Yes. Within one month of receiving the request, the person is given information on the action taken (Article 12(3) GDPR). If they ask, you also name the recipients you notified of the erasure (Article 19 GDPR). The request and your answer are usually kept as evidence that the request was dealt with.
How to start
List where data about a customer may sit: the sales and accounting system, the CRM, the marketing tool, mailboxes, vendors. For each place, mark what is kept because of the law, what because of a possible dispute, and what only for convenience. Send us the request you received and this list – we will tell you what to erase, what to keep and how to explain it to the person.
You can check whether your organisation needs a record of processing activities with the Privacio tool, built by Linden (in Lithuanian).
Email: info@linden.lt
More about this service: External data protection officer services.