Time Limits for Erasure
When someone asks an organisation to delete their personal data, the organisation generally must act on that request quickly, and at the latest within about one month. The clock typically starts when the organisation receives the request. This right to have data erased is not absolute, so a valid request may sometimes be refused or subject to exceptions.
The time limit for responding to a request under the right to erasure (Article 17 UK GDPR / GDPR) requires the controller to act 'without undue delay' and, per ICO guidance, at the latest within one month, with the period commencing on receipt of the request. Requests may be made verbally or in writing, and the controller should take reasonable steps to verify the requester's identity as the data subject. The right is qualified rather than absolute, and separate statutory or regulatory retention obligations (which vary by jurisdiction and data type) may lawfully require continued storage of certain records; practitioners should note that the one-month period may be capable of extension in defined circumstances and should verify the current position and any applicable extension conditions against the official text and current regulator guidance.
Why it matters
The right to erasure under Article 17 is one of the most visible data subject rights, and the time limit for responding to it is where compliance is most often tested in practice. When an individual asks an organisation to delete their personal data, the controller must generally act without undue delay and, according to ICO guidance, at the latest within about one month of receiving the request. Missing that window is not a mere administrative slip; it can convert an ordinary request into a complaint to a supervisory authority and expose the organisation to regulatory scrutiny over its wider handling of individual rights.
The deadline also forces organisations to have operational readiness rather than good intentions. Because requests may be made verbally or in writing, the clock can start without a formal form ever being submitted, and the organisation must still be able to locate, assess, and act on the relevant data within the period. This is complicated by the fact that the right is qualified rather than absolute: a valid request may be refused or narrowed where an exemption applies, and separate statutory or regulatory retention obligations may lawfully require certain records to be kept. Deciding which data must go and which may or must remain is a substantive legal assessment that has to be completed inside the same tight timeframe.
Because the position on when the one-month period may be extended, and the precise scope of exemptions, can vary by jurisdiction and data type, organisations should treat published deadlines as a floor for planning and verify the current position against the official text and current regulator guidance rather than relying on a fixed snapshot.
Who it's relevant to
Inside Time Limits for Erasure
Common questions
Answers to the questions practitioners most commonly ask about Time Limits for Erasure.