Skip to main content
Erasure and Objection Rights: Your Compliance ChecklistData Subject Rights
7 min readFor Data Governance Leads

Erasure and Objection Rights: Your Compliance Checklist

Your team processes erasure requests. Someone objects to direct marketing. Another person wants their account deleted. You respond within 30 days, document the decision, and move on.

But are you actually compliant?

The EDPB's updated One-Stop-Shop case digest on the rights to object and erasure reveals what supervisory authorities look for when they investigate your processes. This isn't just about responding to requests. It's about whether your internal systems can prove you've met each element of Articles 17 and 21.

This checklist translates those regulatory expectations into actionable steps. Use it to audit your current processes and identify gaps before a supervisory authority does.

What This Checklist Covers

This checklist addresses your organization's compliance with:

  • Article 21 (right to object, including objections to direct marketing under Article 21(2) and objections based on particular situations under Article 21(1))
  • Article 17 (right to erasure, covering all six grounds in Article 17(1))

It focuses on the internal processes supervisory authorities examine during investigations, based on patterns identified in cross-border enforcement decisions.

Prerequisites

Before using this checklist, confirm you have:

Documentation of all processing activities where individuals might exercise these rights. Your Article 30 records of processing activities should identify the lawful basis for each activity. You can't assess an objection or erasure request without knowing why you're processing the data in the first place.

Clear ownership assignments for each processing activity. Someone specific must be accountable for reviewing requests, making decisions, and executing erasure or cessation of processing.

Technical capability to locate personal data across your systems. If you can't find all instances of an individual's data within your response deadline, your process fails at the most basic level.

Checklist Items

1. Request intake is documented and timestamped

□ Every objection or erasure request receives an immediate acknowledgment with a unique reference number
□ You log the date and time of receipt in a central tracking system
□ The acknowledgment confirms your one-month deadline (extendable by two months if complex, with explanation required)

Good looks like: A request arrives at 2:47 PM on March 15. Your system auto-generates reference #2024-OBJ-0847, logs the timestamp, and sends an acknowledgment within minutes. Your team knows the response is due by April 15.

2. Identity verification is proportionate and documented

□ You verify the requester's identity before processing the request
□ Your verification method matches the sensitivity of the data involved
□ You document what verification you performed and why it was sufficient
□ You don't request more information than necessary to confirm identity

Good looks like: For a basic account deletion, you verify the email address used to register. For requests involving sensitive data categories under Article 9, you require additional verification. You document your rationale in each case file.

3. Scope assessment is complete and recorded

□ You identify all processing activities where the individual's data appears
□ You determine which lawful basis applies to each activity
□ For objection requests, you assess whether Article 21(1) or 21(2) applies
□ For erasure requests, you determine which Article 17(1) ground the requester invokes (or should invoke)

Good looks like: Your case file shows you checked customer database, marketing platforms, backup systems, and analytics tools. You noted that marketing uses legitimate interests (Article 6(1)(f)), while order processing uses contract performance (Article 6(1)(b)).

4. Objection assessment follows the correct legal test

□ For direct marketing objections (Article 21(2)): You cease processing immediately with no legitimate interests assessment
□ For Article 21(1) objections: You conduct and document a legitimate interests assessment weighing the individual's interests against your compelling legitimate grounds
□ Your legitimate interests assessment is specific to the individual's particular situation, not a generic template
□ You document the outcome and reasoning in writing

Good looks like: A customer objects to profiling for personalized pricing. You document their specific circumstances (e.g., they're concerned about discrimination), assess whether your legitimate interests override theirs, record your analysis, and communicate the decision with clear reasoning.

5. Erasure assessment addresses all Article 17 exceptions

□ You check whether any Article 17(3) exception applies (compliance with legal obligations, public interest, legal claims, etc.)
□ You document which exception applies or why none apply
□ If you retain data under an exception, you explain this to the requester with specific reference to Article 17(3)
□ You distinguish between data you must erase and data you may retain

Good looks like: A former employee requests erasure. You identify that payroll records must be retained for seven years under tax law (Article 17(3)(b)) but their emergency contact information has no retention obligation. You erase what you can and explain what you're keeping and why.

6. Third-party notification is executed where required

□ If you've disclosed the data to other controllers, you inform them of the erasure or objection (Article 19)
□ You document which controllers you notified and when
□ If notification is impossible or involves disproportionate effort, you document why
□ You inform the requester about which third parties you notified, if they ask

Good looks like: You shared a customer's complaint with a processor and a joint controller. You notify both about the erasure request. You log confirmation emails from each party. When the requester asks who you told, you provide the list.

7. Technical erasure is complete and verifiable

□ You erase data from live production systems
□ You erase or anonymize data in backups according to your documented backup retention policy
□ You document what you erased, when, and from which systems
□ You can demonstrate that erasure occurred (through logs, deletion certificates, or audit trails)

Good looks like: Your deletion process touches production databases, CRM, email archives, and analytics platforms. Your backup policy states that backups are overwritten on a 90-day cycle. You document the deletion in each system and note that backup copies will be overwritten by June 30.

8. Response is substantive and timely

□ You respond within one month (or your extended deadline if you notified the requester)
□ Your response explains your decision with specific legal references
□ If you refuse the request, you explain the reasons and inform the requester of their right to complain to a supervisory authority and seek judicial remedy
□ You document the date you sent the response

Good looks like: Your response says "We have erased your data from [systems] as of [date]. We are retaining [specific data] under Article 17(3)(b) because [specific legal obligation]. You have the right to lodge a complaint with [supervisory authority] if you disagree with this decision."

9. Edge cases have documented procedures

□ You have a documented process for handling objections to processing based on legitimate interests where you believe you have compelling grounds
□ You have a process for erasure requests where Article 17(3) exceptions apply
□ You have a process for requests that are manifestly unfounded or excessive (Article 12(5))
□ Your team knows when to escalate unusual requests

Good looks like: Your procedures include decision trees for common edge cases. When someone requests erasure of data you need for a pending legal claim, your team follows the documented process, involves legal counsel, and documents the decision rationale.

10. Monitoring and review mechanisms are active

□ You track response times and identify requests that might breach the deadline
□ You review a sample of decisions quarterly to ensure consistency
□ You update your procedures when supervisory authorities issue new guidance
□ You train staff on changes to procedures

Good looks like: Your monthly metrics show an average response time of 18 days. Your quarterly review identified inconsistent application of Article 17(3)(e) (legal claims exception). You updated the procedure and retrained the team. When the EDPB published the updated case digest, you reviewed your processes against the common infringements identified.

Common Mistakes

Treating all objections the same. Direct marketing objections (Article 21(2)) require immediate cessation. Objections under Article 21(1) require a legitimate interests assessment. Confusing these leads to either processing you should have stopped or wrongful cessation of lawful processing.

Generic balancing tests. Article 21(1) requires you to assess the individual's "particular situation." A template response that doesn't address their specific circumstances won't satisfy supervisory authorities.

Incomplete erasure. Deleting data from your CRM but leaving it in analytics platforms, backup systems, or third-party processors isn't erasure. Supervisory authorities examine whether you erased data everywhere it existed.

Inadequate documentation. You might have made the right decision, but if you can't show your reasoning during an investigation, you can't prove compliance. Document your analysis, not just your conclusion.

Ignoring Article 19 notification obligations. If you shared the data with other controllers and don't tell them about the erasure or objection, you've failed a specific GDPR requirement even if you processed the request correctly yourself.

Next Steps

Run this checklist against your last 20 objection and erasure requests. If you find gaps, they're probably systemic. Fix the process, not just the individual cases.

Review your procedures against the common infringements identified in the EDPB case digest. Supervisory authorities see the same failures repeatedly. Don't be one of them.

Train your team on the distinction between Article 21(1) and 21(2), and between Article 17(1) grounds and Article 17(3) exceptions. Most compliance failures stem from confusion about which legal test applies.

Your compliance isn't measured by whether you respond to requests. It's measured by whether you can prove you applied the correct legal test, made a defensible decision, and executed it completely. This checklist gives you the framework to do that.

You Might Also Like