Skip to main content
Category: Impact Assessments & Documentation

Time Limits for Erasure

Also known as: Erasure Response Deadline, Right to be Forgotten Time Limit, Time Limit to Respond to an Erasure Request
Simply put

When someone asks an organisation to delete their personal data, the organisation generally must act on that request quickly, and at the latest within about one month. The clock typically starts when the organisation receives the request. This right to have data erased is not absolute, so a valid request may sometimes be refused or subject to exceptions.

Formal definition

The time limit for responding to a request under the right to erasure (Article 17 UK GDPR / GDPR) requires the controller to act 'without undue delay' and, per ICO guidance, at the latest within one month, with the period commencing on receipt of the request. Requests may be made verbally or in writing, and the controller should take reasonable steps to verify the requester's identity as the data subject. The right is qualified rather than absolute, and separate statutory or regulatory retention obligations (which vary by jurisdiction and data type) may lawfully require continued storage of certain records; practitioners should note that the one-month period may be capable of extension in defined circumstances and should verify the current position and any applicable extension conditions against the official text and current regulator guidance.

Why it matters

The right to erasure under Article 17 is one of the most visible data subject rights, and the time limit for responding to it is where compliance is most often tested in practice. When an individual asks an organisation to delete their personal data, the controller must generally act without undue delay and, according to ICO guidance, at the latest within about one month of receiving the request. Missing that window is not a mere administrative slip; it can convert an ordinary request into a complaint to a supervisory authority and expose the organisation to regulatory scrutiny over its wider handling of individual rights.

The deadline also forces organisations to have operational readiness rather than good intentions. Because requests may be made verbally or in writing, the clock can start without a formal form ever being submitted, and the organisation must still be able to locate, assess, and act on the relevant data within the period. This is complicated by the fact that the right is qualified rather than absolute: a valid request may be refused or narrowed where an exemption applies, and separate statutory or regulatory retention obligations may lawfully require certain records to be kept. Deciding which data must go and which may or must remain is a substantive legal assessment that has to be completed inside the same tight timeframe.

Because the position on when the one-month period may be extended, and the precise scope of exemptions, can vary by jurisdiction and data type, organisations should treat published deadlines as a floor for planning and verify the current position against the official text and current regulator guidance rather than relying on a fixed snapshot.

Who it's relevant to

Data Protection Officers and Privacy Leads
DPOs and privacy leads are typically responsible for ensuring the organisation can identify an erasure request through any channel, log the receipt date correctly, and complete the assessment and action within the one-month period. They also need to document the reasoning where a request is refused or narrowed because the right is qualified or because a retention obligation applies.
Compliance and Legal Teams
Legal and compliance teams generally advise on whether an exemption applies and how competing statutory or regulatory retention obligations interact with a request, and on whether and when the one-month period may be extended. Because these points can vary by jurisdiction and data type, they should verify the current position against the official text and current regulator guidance.
Customer-Facing and Front-Line Staff
Because a request for erasure can be made verbally as well as in writing, front-line and customer service staff need to recognise such requests when they arise and escalate them promptly, since the response clock generally starts on receipt rather than when the request reaches a specialist team.
Engineers and Data Owners
Engineers and system owners are usually the ones who must locate the relevant personal data across systems and execute deletion within the timeframe, while preserving records that a retention obligation or exemption requires to be kept. Reliable data mapping and the ability to act quickly are typically prerequisites for meeting the deadline.

Inside Time Limits for Erasure

Right to Erasure (Article 17)
The GDPR right, sometimes called the right to be forgotten, allowing a data subject to request deletion of their personal data where one of the grounds in Article 17(1) applies. Erasure is not absolute and is subject to the exemptions in Article 17(3).
One-Month Response Period (Article 12(3))
A controller must generally respond to an erasure request without undue delay and in any event within one month of receipt. This period may be extended by up to two further months where the request is complex or numerous, and the data subject should be informed of any extension and the reasons within the first month.
Without Undue Delay
The overarching standard requiring the controller to act promptly rather than waiting out the full permitted period. What is undue can depend on the circumstances of the request and is subject to assessment.
Retention Limits and Storage Limitation (Article 5(1)(e))
Personal data should be kept in a form permitting identification no longer than necessary for the purposes processed. Erasure timelines interact with defined retention schedules, after which data may need deletion even absent a request.
Grounds Triggering Erasure
Includes data no longer necessary for the original purpose, withdrawal of consent where consent was the legal basis, a valid objection to processing, or unlawful processing, among the grounds listed in Article 17(1). The applicable ground affects whether erasure is required.
Exemptions to Erasure (Article 17(3))
Situations where erasure may be refused or delayed, such as compliance with a legal obligation, exercise or defence of legal claims, freedom of expression, or public interest grounds. These can lawfully justify retaining data beyond a request.

Common questions

Answers to the questions practitioners most commonly ask about Time Limits for Erasure.

Does the GDPR set a fixed number of days within which a controller must erase personal data on request?
No. The GDPR does not prescribe a single fixed deadline expressed in days specifically for erasure. Requests to exercise data subject rights, including the right to erasure under Article 17, are generally handled within the timeframe the GDPR sets for responding to data subject requests, which can be extended in certain circumstances where the request is complex or where a controller receives a number of requests. You should verify the exact response period and the conditions for any extension against the current official text of the Regulation, and note that national implementing law or regulator guidance may affect practical expectations.
Does the right to erasure mean personal data must always be deleted whenever someone asks?
No. The right to erasure under Article 17 is not absolute. It applies in defined situations and is subject to exceptions, for example where processing is necessary for compliance with a legal obligation, for the establishment, exercise, or defence of legal claims, or for other grounds recognised in the Regulation. Whether erasure is required in a given case is subject to assessment, and a controller may be entitled or obliged to retain data despite a request. Retention periods driven by other legal duties can also delay or prevent erasure.
How should a controller calculate when the response period for an erasure request begins?
Generally, the response period runs from receipt of the request, though identity verification steps may affect the practical starting point where the controller has reasonable doubts about the identity of the requester. Because the precise calculation and any permitted extension are governed by the Regulation text and may be affected by national procedural rules, you should confirm the exact starting point and duration against the current official source rather than relying on a fixed assumption.
What should a controller do if it cannot complete erasure within the applicable response period?
In most cases the controller should still respond within the applicable period, informing the data subject of the position, and where an extension applies, of the extension and the reasons for it. If erasure is refused in whole or in part, the controller should typically explain the grounds relied upon and inform the individual of their ability to complain to a supervisory authority and to seek a judicial remedy. The specific information obligations should be verified against the current Regulation text.
How do retention schedules interact with erasure time limits?
Retention schedules and erasure obligations operate together rather than in isolation. Where a controller has a lawful basis and a defined retention period for data, that period may justify continued storage and delay erasure until it expires. When responding to an erasure request, a controller should typically assess whether an applicable retention requirement or another Article 17 exception applies before deciding whether and when data can be deleted. This assessment is context dependent.
Should controllers inform processors and third parties when personal data must be erased?
Generally, where a controller uses processors, the arrangement governing that relationship should address deletion of personal data, and controllers typically instruct processors to erase or return data as appropriate. Where data has been disclosed to, or made public for, other recipients, the Regulation contemplates that controllers take steps, subject to available technology and cost, to inform relevant parties of an erasure request. The precise scope of these obligations should be verified against the current Regulation text and relevant guidance.

Common misconceptions

Erasure must always be completed immediately upon request.
The standard is without undue delay and generally within one month, which may be extended by up to two further months for complex or numerous requests, provided the data subject is informed. Immediate deletion is not a fixed universal requirement.
The right to erasure is absolute and every request must be granted.
Erasure applies only where an Article 17(1) ground is met and is subject to the exemptions in Article 17(3), such as legal obligations or the establishment or defence of legal claims. Whether a request must be granted is context and assessment dependent.
The time limits only start once the organisation decides the request is valid.
The response period generally runs from receipt of the request, not from an internal validity determination. Any permitted extension must still be communicated to the data subject within the first month.

Best practices

Log the date each erasure request is received and calculate the one-month deadline from receipt, tracking any decision to extend within the initial month.
Assess each request against the Article 17(1) grounds and the Article 17(3) exemptions before responding, documenting the reasoning for granting, refusing, or partially actioning it.
Where an extension is applied for complex or numerous requests, notify the data subject of the extension and the reasons within the first month.
Maintain defined retention schedules aligned with storage limitation so that data is deleted at the end of its necessary period, independent of any incoming request.
Establish a workflow to propagate erasure to backups, downstream systems, and processors, and verify what obligations flow to processors under the relevant processing arrangements.
Verify the current position against the official GDPR text and applicable regulator guidance, and account for possible divergence under the UK GDPR or national implementing law before finalising any procedure.