Skip to main content
Category: Supervisory Authorities & Enforcement

Power to Order Rectification or Erasure

Also known as: Corrective power to order rectification or erasure, Supervisory authority power to order rectification or erasure
Simply put

This refers to the authority a data protection regulator can exercise to require an organisation to correct inaccurate personal data or delete personal data. It connects to individuals' rights to have wrong or incomplete data fixed, and in some cases to have their data erased. The exact scope, conditions, and how such a power is exercised depend on the applicable law and should be verified against the current official text.

Formal definition

The power to order rectification or erasure describes a corrective mechanism through which the outcomes underlying the data subject rights of rectification and erasure may be compelled against a controller. Under the UK GDPR, the right to rectification generally entitles individuals to have inaccurate personal data corrected, or incomplete data completed, and the controller is typically required to act without undue delay. The right to erasure ('right to be forgotten') is addressed at Article 17 GDPR, under which a data subject may in defined circumstances obtain erasure of personal data concerning them from the controller without undue delay; EDPB guidance treats rectification, erasure, and restriction of processing as related but distinct rights that a data subject may request from the controller. Note the following limitations: neither the right to rectification nor the right to erasure is absolute, and both are subject to conditions and exceptions that must be assessed against the applicable provisions; the evidence supplied does not specify the precise conditions, exceptions, or the identity and enabling article of the authority exercising an ordering power, and the EU GDPR and UK GDPR positions (as well as member state implementing law) may diverge. Practitioners should verify the relevant article numbers, the scope of any corrective or enforcement power, and applicable exemptions against the current official text.

Why it matters

The power to order rectification or erasure links individuals' data protection rights to concrete enforcement outcomes. While the underlying rights of rectification and erasure operate directly between a data subject and a controller, the ability of a supervisory authority to compel correction or deletion adds a regulatory backstop where an organisation fails to act. This matters because inaccurate personal data can cause ongoing harm to individuals, and personal data retained beyond its lawful basis or purpose can expose organisations to compliance risk. Under the UK GDPR, the ICO describes a right for individuals to have inaccurate personal data rectified, or completed if it is incomplete, and the right to erasure ('right to be forgotten') is addressed at Article 17 GDPR.

For organisations, understanding the potential for a corrective or ordering power to be exercised should inform how requests for rectification and erasure are handled in practice. The EDPB treats rectification, erasure, and restriction of processing as related but distinct rights that a data subject may request from the controller, and controllers are generally required to act without undue delay. Failing to distinguish these rights, or treating them as interchangeable, can lead to incorrect responses and downstream regulatory exposure.

It is important to note the limits of what can be stated with certainty here. Neither the right to rectification nor the right to erasure is absolute; both are subject to conditions and exceptions that must be assessed against the applicable provisions. The evidence supplied does not specify the precise enabling article, scope, or conditions attaching to a supervisory authority's ordering power, and the EU GDPR and UK GDPR positions, as well as member state implementing law, may diverge. Readers should verify the relevant article numbers and the scope of any corrective power against the current official text.

Who it's relevant to

Data protection officers and compliance leads
DPOs and compliance teams need to build processes that correctly distinguish rectification, erasure, and restriction requests and respond within the applicable timeframes. Understanding that these rights are qualified, and that a regulator may seek to compel correction or deletion where a controller fails to act, helps prioritise robust request-handling procedures.
Privacy and data protection lawyers
Legal advisers assessing individual rights requests or enforcement exposure should analyse the specific conditions and exceptions attaching to rectification and erasure, and verify the enabling provisions and scope of any corrective power against the current UK GDPR or EU GDPR text, given that positions may diverge and member state implementing law can vary.
Engineers and data teams
Technical teams implement the systems that make correction and deletion of personal data possible in practice. Because controllers are generally required to act without undue delay, systems should support locating, amending, and erasing personal data reliably so the organisation can meet a request or, where required, comply with an order.
Controllers processing personal data
Organisations acting as controllers bear the direct obligation to respond to rectification and erasure requests and are the parties against whom a corrective outcome may be compelled. They should assess each request against the applicable grounds and exceptions rather than assuming any right applies or is excluded automatically.

Inside Power to Order Rectification or Erasure

Supervisory authority corrective power
This power sits among the corrective measures available to supervisory authorities under the GDPR, allowing an authority to order a controller or processor to bring processing into compliance, which can include ordering the rectification or erasure of personal data. Verify the precise article reference against the current official text before citing it.
Relationship to data subject rights
The power complements, but is distinct from, the data subject's own right to rectification and right to erasure. A data subject may exercise those rights directly against a controller; the ordering power is a supervisory intervention that can compel action, typically following a complaint, investigation, or identified infringement.
Rectification component
An order to rectify concerns personal data that is inaccurate or incomplete. It generally directs the controller to correct or complete the data, and may extend to notifying recipients where applicable, subject to assessment of what is proportionate in the circumstances.
Erasure component
An order to erase directs deletion of personal data, typically where retention or processing is found to lack a valid basis or otherwise infringes the Regulation. The scope of erasure is context dependent and may be qualified by applicable exemptions or overriding grounds for continued processing.
Trigger and procedural context
Such orders generally arise from a supervisory authority's investigatory and enforcement process. The exercise of the power is subject to administrative procedure, the affected party's rights, and, in most cases, the availability of judicial remedy against the authority's decision.
National and cross-border variation
The framing and procedural detail can differ between the EU GDPR, the UK GDPR, and national implementing law, and member state derogations may affect how the power operates. Cross-border cases may involve cooperation and consistency mechanisms among authorities. Confirm the position under the relevant jurisdiction.

Common questions

Answers to the questions practitioners most commonly ask about Power to Order Rectification or Erasure.

Does the right to erasure mean a controller must always delete personal data on request?
No. The so-called right to be forgotten is not absolute. Erasure applies only where one of the grounds in the relevant GDPR provision is met, and it is subject to exceptions, for example where processing is necessary for compliance with a legal obligation, for the performance of a task carried out in the public interest, or for the establishment, exercise, or defence of legal claims. A controller may lawfully refuse or limit an erasure request where such an exception applies, subject to assessment of the specific facts. You should verify the applicable grounds and exceptions against the current official text.
Is the power to order rectification or erasure the same as the data subject's own right to rectification or erasure?
They are related but distinct. The data subject exercises rights directly against the controller. Separately, a supervisory authority has a corrective power to order a controller or processor to bring processing into compliance, which can include ordering rectification or erasure. The individual right and the regulator's ordering power arise from different provisions and operate through different mechanisms, so they should not be conflated. Where an authority issues an order, its scope and enforceability derive from that authority's decision rather than from the data subject request alone.
How should a controller decide whether rectification or erasure is the appropriate response to a request?
This turns on what the data subject is asserting and the state of the data. Rectification is generally appropriate where personal data is inaccurate or incomplete and can be corrected or completed. Erasure is generally appropriate where the data should no longer be processed under an applicable ground, such as where it is no longer necessary for the original purpose or where consent has been withdrawn and no other legal basis applies. Where accuracy is disputed, restriction of processing may be a relevant interim measure pending verification. The correct response is fact-specific and should be documented.
What steps should a controller take when third parties or recipients also hold the affected data?
Where personal data has been disclosed to recipients, the controller generally has an obligation to communicate a rectification or erasure to each recipient, unless this proves impossible or involves disproportionate effort. In the case of erasure of data that has been made public, there are additional obligations to take reasonable steps, including technical measures, to inform other controllers that the data subject has requested erasure of links, copies, or replications, taking account of available technology and cost. What is reasonable or disproportionate is a matter of assessment in the circumstances, and this should be recorded.
How should a controller document its handling of a rectification or erasure request or a supervisory authority order?
Maintain a record of the request or order, the identity verification performed, the grounds and any exceptions relied on, the decision reached, the actions taken across relevant systems and backups, and the communications sent to recipients. Where a request is refused in whole or in part, record the reasons and, where required, inform the data subject of the refusal and of their available remedies. This documentation supports the accountability principle and helps demonstrate the basis for the controller's decision if it is later challenged.
How should erasure obligations be reconciled with retention required by other laws or with backup systems?
Where retention is necessary to comply with a legal obligation, an erasure request may be lawfully refused or narrowed to the extent of that obligation, subject to assessment. For backups and archived environments, immediate deletion from every copy may not be technically feasible; a common approach is to remove data from live systems and apply measures so that backed-up data is not restored into active use and is overwritten in the normal backup cycle. The specific approach should be assessed case by case and documented, and practice may vary between regulators, so you should verify current guidance.

Common misconceptions

An order to erase always means all copies of the data must be permanently and totally deleted.
The scope of an erasure order is context dependent and can be qualified by exemptions, legal retention obligations, or overriding grounds for continued processing. What is required is determined by assessment of the specific circumstances rather than an absolute rule of total deletion.
Only the data subject can bring about rectification or erasure of their data.
While data subjects can exercise their own rights directly against a controller, a supervisory authority holds a separate power to order rectification or erasure as a corrective measure, typically following a complaint, investigation, or finding of infringement.
A supervisory authority's order is the final word with no possibility of challenge.
Such orders are generally subject to administrative procedure and, in most cases, to a judicial remedy against the authority's decision. Controllers and processors typically retain avenues to challenge an order, subject to the applicable jurisdiction's rules.

Best practices

Distinguish clearly in your compliance documentation between responding to a data subject's own rectification or erasure request and complying with an order issued by a supervisory authority, as the trigger, timeline, and procedural posture differ.
When served with an order, assess its precise scope, including whether it concerns rectification, erasure, or both, and whether applicable exemptions or overriding retention grounds qualify what must be done.
Confirm the applicable jurisdiction and instrument (EU GDPR, UK GDPR, or national implementing law) and check for member state derogations before determining your obligations, rather than assuming a uniform position.
Maintain records of processing and data flows that let you locate affected personal data and identify recipients, so that any ordered rectification or erasure and related notifications can be actioned and evidenced.
Verify the specific article references, procedural deadlines, and remedy options against the current official text and the relevant authority's guidance before acting, and take advice on whether to comply, seek clarification, or pursue an available challenge.