Article 17 GDPR

From GDPRhub
Article 17 - Right to erasure (‘right to be forgotten’)
Gdpricon.png
Chapter 10: Delegated and implementing acts

Legal Text


Article 17 - Right to erasure (‘right to be forgotten’)

1. The data subject shall have the right to obtain from the controller the erasure of personal data concerning him or her without undue delay and the controller shall have the obligation to erase personal data without undue delay where one of the following grounds applies:

(a) the personal data are no longer necessary in relation to the purposes for which they were collected or otherwise processed;
(b) the data subject withdraws consent on which the processing is based according to point (a) of Article 6(1), or point (a) of Article 9(2), and where there is no other legal ground for the processing;
(c) the data subject objects to the processing pursuant to Article 21(1) and there are no overriding legitimate grounds for the processing, or the data subject objects to the processing pursuant to Article 21(2);
(d) the personal data have been unlawfully processed;
(e) the personal data have to be erased for compliance with a legal obligation in Union or Member State law to which the controller is subject;
(f) the personal data have been collected in relation to the offer of information society services referred to in Article 8(1).

2. Where the controller has made the personal data public and is obliged pursuant to paragraph 1 to erase the personal data, the controller, taking account of available technology and the cost of implementation, shall take reasonable steps, including technical measures, to inform controllers which are processing the personal data that the data subject has requested the erasure by such controllers of any links to, or copy or replication of, those personal data.

3. Paragraphs 1 and 2 shall not apply to the extent that processing is necessary:

(a) for exercising the right of freedom of expression and information;
(b) for compliance with a legal obligation which requires processing by Union or Member State law to which the controller is subject or for the performance of a task carried out in the public interest or in the exercise of official authority vested in the controller;
(c) for reasons of public interest in the area of public health in accordance with points (h) and (i) of Article 9(2) as well as Article 9(3);
(d) for archiving purposes in the public interest, scientific or historical research purposes or statistical purposes in accordance with Article 89(1) in so far as the right referred to in paragraph 1 is likely to render impossible or seriously impair the achievement of the objectives of that processing; or
(e) for the establishment, exercise or defence of legal claims.

Relevant Recitals

Recital 39: Principles of Data Processing
Any processing of personal data should be lawful and fair. It should be transparent to natural persons that personal data concerning them are collected, used, consulted or otherwise processed and to what extent the personal data are or will be processed. The principle of transparency requires that any information and communication relating to the processing of those personal data be easily accessible and easy to understand, and that clear and plain language be used. That principle concerns, in particular, information to the data subjects on the identity of the controller and the purposes of the processing and further information to ensure fair and transparent processing in respect of the natural persons concerned and their right to obtain confirmation and communication of personal data concerning them which are being processed. Natural persons should be made aware of risks, rules, safeguards and rights in relation to the processing of personal data and how to exercise their rights in relation to such processing. In particular, the specific purposes for which personal data are processed should be explicit and legitimate and determined at the time of the collection of the personal data. The personal data should be adequate, relevant and limited to what is necessary for the purposes for which they are processed. This requires, in particular, ensuring that the period for which the personal data are stored is limited to a strict minimum. Personal data should be processed only if the purpose of the processing could not reasonably be fulfilled by other means. In order to ensure that the personal data are not kept longer than necessary, time limits should be established by the controller for erasure or for a periodic review. Every reasonable step should be taken to ensure that personal data which are inaccurate are rectified or deleted. Personal data should be processed in a manner that ensures appropriate security and confidentiality of the personal data, including for preventing unauthorised access to or use of personal data and the equipment used for the processing.

Recital 65: Right to Erasure and Rectification
A data subject should have the right to have personal data concerning him or her rectified and a ‘right to be forgotten’ where the retention of such data infringes this Regulation or Union or Member State law to which the controller is subject. In particular, a data subject should have the right to have his or her personal data erased and no longer processed where the personal data are no longer necessary in relation to the purposes for which they are collected or otherwise processed, where a data subject has withdrawn his or her consent or objects to the processing of personal data concerning him or her, or where the processing of his or her personal data does not otherwise comply with this Regulation. That right is relevant in particular where the data subject has given his or her consent as a child and is not fully aware of the risks involved by the processing, and later wants to remove such personal data, especially on the internet. The data subject should be able to exercise that right notwithstanding the fact that he or she is no longer a child. However, the further retention of the personal data should be lawful where it is necessary, for exercising the right of freedom of expression and information, for compliance with a legal obligation, for the performance of a task carried out in the public interest or in the exercise of official authority vested in the controller, on the grounds of public interest in the area of public health, for archiving purposes in the public interest, scientific or historical research purposes or statistical purposes, or for the establishment, exercise or defence of legal claims.

Recital 66: Informing Controllers of Erasure
To strengthen the right to be forgotten in the online environment, the right to erasure should also be extended in such a way that a controller who has made the personal data public should be obliged to inform the controllers which are processing such personal data to erase any links to, or copies or replications of those personal data. In doing so, that controller should take reasonable steps, taking into account available technology and the means available to the controller, including technical measures, to inform the controllers which are processing the personal data of the data subject's request.

Commentary

Article 17 confers upon the data subject the right to have their personal data erased. Paragraph 1 establishes a standard "right to deletion" of personal data and imposes an obligation on the controller to remove the data when certain conditions are met. To enhance the effectiveness of the right to deletion, especially on the internet (Recital 66), paragraph 2 introduces the so-called "right to be forgotten" which imposes a further obligation on the controller to inform other controllers of the request to delete all links, copies or duplicates of the data, through appropriate technical and cost-effective measures. Paragraph 3 sets out the exceptions to the rules outlined in paragraphs 1 and 2.[1]

(1) Right to erasure

The right to erasure does not constitute an absolute right granted to data subjects. It can be exercised only if one of the following legal grounds applies, which in turn gives rise to a correlated obligation on the controller.[2] Often times, it also requires a balancing exercise among the different interests at stake.

Right to obtain

Article 17 of the GDPR does not contain specific provisions regarding the methods for exercising the right to erasure. These provisions can be found in Article 12, which includes the general obligation to provide information which is accurate and clear (Article 12(1) GDPR), facilitate the data subject (Article 12(2) GDPR), respond and communicate the measures taken (Article 12(3) and (4) GDPR), the principle of freedom from costs (Article 12(5) GDPR) and the identity verification procedure in case of uncertainty (Articles 11 and 12(6) GDPR).

Erasure of personal data

The act of erasing data constitutes a type of processing as defined by Article 4(2) GDPR. The regulation does not provide a definition of "erasure". When it comes to deleting data, the controller has some discretion in choosing means and procedures. In any case, erasure must be effective.[3] Some possible methods for erasing data include physically eliminating the data by overwriting or erasing it, using mechanical or chemical methods such as shredding the paper, burning or otherwise destroying the data carrier, scratching the surface of CDs, and destroying codes or decryption devices without removing the data itself. In general, deleting a link or reference in a file system (logical deletion) typically does not result in the actual erasure of the data, but only makes it more challenging to locate. The requirements for deletion under data protection laws are evolving due to technological advancements. It is crucial to acknowledge the possibility of recovering deleted data through specialized software. The use of such software is generally expected and feasible.[4]

Deletion must be comprehensive but not in absolute terms. it therefore applies to all data and data carriers, including data stored on backup media, as well as those belonging to contractors (e.g., stored in a "cloud") or employees' private data processing devices. However, removing identical data that serves a legitimate and still valid purpose is unnecessary. In certain situations, preservation of backup copies, for instance, may also be justified due to the controller's legitimate interest. The right of erasure in the context of profiling (Article 4(4) GDPR) affects both the input data (i.e., the personal data on which a profile is based) and the output data (i.e., the profile itself).[5] The deletion obligation does not include any copies of the data made by third parties to whom the data has been disclosed. In this respect, there is an obligation to notify the erasure under Article 19 GDPR and the recipient may be subject to independent deletion obligations.

Relation with the "right to be forgotten"

See commentary under Article 17(2) GDPR below.

Obligation to erase personal data

Where one of the following grounds applies

(a) Data No Longer Necessary for the Initial Purposes

The data subject may invoke the right to erasure when the personal data is no longer necessary for the purpose(s) they were initially collected for or otherwise processed. This legal ground reflects the general GDPR principles of "purpose limitation" and “storage limitation” as provided for in Articles 5(1)(b) and (e) GDPR. In this case, if a data controller continues to process the personal data, this processing would beat odds with these provisions, unless the data controller had previously informed the data subject about the change of purpose according to Article 13(3) GDPR and Article 14(4) GDPR, or if it “is necessary for realising another purpose of processing that partially overlaps with or is compatible with the eliminated purpose.”[6] In this sense, Art 6(4) GDPR establishes that, unless the further processing is based on consent or laid out by law, in order for the controller to determine whether processing for another purpose is compatible with the purpose for which the personal data was initially collected, certain elements have to be taken into consideration (inter alia, the link between the former and further purpose, the context or relationship between the data subject and the controller, the nature of the personal data, the possible consequences of further processing, and the existence of appropriate safeguards).

(b) Withdrawal of Consent and No Other Legal Basis

This ground can apply in cases where the legal basis for processing is consent as provided for in Article 6(1)(a) GDPR,or in Article 9(2)(a) GDPR when special categories of personal data are processed. According to Article 7(3) GDPR, the data subject may withdraw their consent at any time, and it must be as easy to withdraw that consent as it was to give it. Further processing of personal data after withdrawal of consent renders that processing operation unlawful and the data controller must erase the personal data upon request. However, if there is another legal basis for lawful processing of the personal data, or a part of it the controller may continue the processing operations and will not be obliged to erase this data.

(c) Objection to Processing and No Overriding Legitimate Grounds

According to this provision, a data subject may request an erasure when they have objected to processing in accordance with Article 21(1) GDPR, which establishes the right to objection based on the data subject’s particular situation, when processing is based on the legal bases in Article 6(1)(e) and (f) GDPR (processing is necessary for the performance of a task in the public interest or legitimate interest of the controller), including profiling based on these provisions. In this case, the controller must grant the data subject’s right to erasure when there are no compelling legitimate grounds for the processing which override the interests, rights and freedoms of the data subject, or for the establishment, exercise or defence of legal claims.

In all cases, the data controller bears the burden of demonstrating whether the overriding legitimate grounds exist. However, the data subject must demonstrate the circumstances that have led to the modified interests at stake. Furthermore, as Voigt and von dem Bussche note, the controller would have “the right to revaluate the situation as its own interests for processing might still prevail and an erasure might not have to take place. This evaluation might require some time, and thus the data subject could exercise its right to restriction of processing in the meantime.[7] When processing is implemented for direct marketing purposes, then, in accordance with Article 21(2) GDPR, further processing will not be lawful (if there is no other legal basis for processing) and a simple objection by the data subject will be enough to exercise the right to erasure.

Direct marketing should be interpreted in a broad sense, and as Carey points out, this right “will extend both to records of marketing communications sent to data subjects and also to any underlying personal data that are held for direct marketing purposes, including personal data used for profiling purposes (i.e. to identify a subject as a marketing target). As direct marketing is considered to include any targeted communications that promote the 'aims and ideals' of an organization, data held for the purposes of political canvassing and for charitable fundraising purposes may therefore be caught by the right of erasure.”[8]

(d) Unlawful Processing

Processing can be unlawful for a number of reasons. Most commonly, processing is unlawful when it lacks any legal basis as prescribed in Article 6 GDPR or Article 9 GDPR, or when it violates the obligations of data controllers under the GDPR as provided for mainly in Chapter 2 and 4. As Voigt and von dem Bussche observe, “this provision can be seen as a sweeping clause, as it grants a right to erasure where processing is unlawful, whether it is for a lacking legal permission for processing or for non-compliance with the Regulation, such as regarding the organisational obligations of the controller”.[9]

(e) Compliance with a Legal Obligation

This provision establishes a legal basis analogous to the legal basis for processing under Article 6(1)(c) GDPR. It contains opening clause by which legal obligations are left to the discretion of Member States Hence, additional cases which would justify the erasure of data can be introduced at a national level.

(f) Information Society Services to Children

This provision is meant to ensure a more thorough protective scheme for children, who enjoy increased protection under the GDPR. According to Article 8(1) GDPR, a child is anyone below the age of 16, though Member States have the discretion to establish a lower age for those purposes (the age of 13 is the minimum permitted age according to the GDPR). According to Article 4(25) GDPR “‘information society service’ means a service as defined in point (b) of Article 1(1) of Directive (EU) 2015/1535 of the European Parliament and of the Council.” Recital 65 GDPR establishes a reason for this provision, stating that where the data subject has given their consent as a child, and are not fully aware of the risks involved in the processing operations, they may want to remove such personal data, especially on the internet. The aforementioned Recital 65 also offers the possibility of exercising this right even when the data subject is no longer a child. According to Voigt and von dem Bussche, “it is unclear whether this right to erasure equals a withdrawal of consent and, thus, this provision would not have a separate scope of application as it would be a sub-part of Art. 17 Sec. 1 lit. a GDPR. Given the legislator’s aim to increase the protection of children and the otherwise lacking additional benefit, the provision should allow a request for erasure of selective personal data (where possible) without a withdrawal of the consent for processing altogether.[10]

(2) Obligation to Inform Other Controllers

This paragraph establishes an additional obligation for controllers who have made personal data public, to take reasonable steps to inform other controllers (including employees of the controller), processors, and third parties, which are processing this data, that its erasure has been requested by a data subject. . Article 17(2) GDPR is read together with Article 19 GDPR, which foresees the communication of any erasure of personal data to each recipient to whom the personal data had been disclosed (unless this proves impossible or entails disproportionate effort), as well as informing the data subject about those recipients if requested. Recital 66 GDPR clearly states that this addition is meant to "strengthen the right to be forgotten in the online environment", although it is not limited to this kind of processing. This paragraph is a clear reflection of the ruling in Google Spain.[11]

Rucker and Kugler note that to be able to comply with the requirements set out in Article 19 GDPR, “controllers should document and keep track of the organisations they transfer personal data to and the categories of personal data transferred.[12] In this regard, Voigt and von dem Bussche suggest the implementation of technical and organisational measures to be able to record the recipients of personal data, including records of processing activities, as well as Data Protection Management Systems where feasible.[13]

This obligation in general has been criticised as conferring an excessive burden on controllers, which is moderated only by the non-defined notion of "reasonable steps", although there is also the view that the constitute an adequate leverage for the data controllers to ensure that they are not obliged to make disproportionate efforts. In fact, in Kranenborg’s opinion, “this obligation has actually been softened in comparison with the Commission’s initial proposal, according to which the controller was ‘considered responsible’ for a publication made by a third party if they had ‘authorised’ it, and had to take ‘all’ reasonable steps to inform those third parties of the erasure request.”[14] It is not entirely clear whether the reasonableness of these measures depends on the controller’s subjective situation, or whether objective criteria should be used. According to Voigt and von dem Bussche, “the former should be the case, as otherwise the obligation would be too much of a burden for micro, small and medium-sized enterprises whose interests have received special consideration under the GDPR.”[15]

Furthermore, as Kelleher and Murray highlight, “it seems that this amounts only to an obligation to inform other controllers that such links should be erased, the GDPR does not provide that controllers have to require such erasure and does not provide a specific mechanism by which controllers could require such erasure.”[16] Additionally, it is also important to keep in mind that third parties might be in a different position when processing the data which they have obtained through the controller. In this sense Carey notes, that “it is also entirely possible that a third party controller that has obtained personal data as a result of their having been made public by another controller will process those data on the basis of processing grounds that do not allow for erasure requests, or will be able to rely on exemptions to the right of erasure that are not available to the controller that made the data public.”[17]

Additionally, it is important to mention that according to the EDPB, this obligation of information does not apply to search engine providers when they find information containing personal data published or placed on the internet by third parties, index it automatically, store it temporarily and make it available to internet users according to a particular order of preference. In addition, "it does not require search engine providers, who have received a data subject’s delisting request, to inform the third party which made public that information on the internet. Such obligation seeks to give greater responsibility to original controllers and try to prevent from multiplying data subjects’ initiatives.”[18] Moreover, according to the Board, it is planning to issue specific Guidelines on Article 7(2) GDPR in the future.

(3) Exceptions

The exceptions here are not absolute, and a necessity test will be required. The refusal of the erasure is only allowed "to the extent that processing is necessary" for the reasons below. This means that a data subject may exercise the right to erasure when the processing is no longer necessary, or when it is carried out at a level beyond what is necessary. In any case, the data controllers bear the burden of demonstrating and proving that any exception that they may rely on is applicable.

(a) Freedom of Expression and Information

This exception reflects one of the most common balancing tests that not only courts but also many data protection authorities have been called upon to implement. When attempting to strike a balance, the following two factors need to be taken into consideration: first, the nature of information in question and its sensitivity for the data subject’s private life, and second, the public’s interest in accessing the information, which may vary depending on the data subject’s role in public life. Results may vary from case to case, but when the data is about a public figure or about the professional life of a data subject, the argument for refusing erasure in favour of freedom of expression and information usually prevails. Article 85(1) GDPR is relevant here, according to which "Member States shall by law reconcile the right to the protection of personal data pursuant to this Regulation with the right to freedom of expression and information, including processing for journalistic purposes and the purposes of academic, artistic or literary expression."

It is important to take into consideration that according to Recital 153 GDPR, “in order to take account of the importance of the right to freedom of expression in every democratic society, it is necessary to interpret notions relating to that freedom, such as journalism, broadly.” According to Voigt and von dem Bussche, “this exception might become highly relevant in practice as this right cannot only be invoked by the press but also by any entity”, as well as any individual.[19] Voigt and von dem Bussche also note that “under this exception, an erasure of opinions should be excluded. However, the distinction between personal data and opinion can be difficult where an opinion is based on personal data. In such a case, it needs to be balanced out whether the underlying personal data is still necessary for forming an opinion. The older the personal data is, the more improbable is their necessity for forming an opinion.”[20]

(b) Compliance with a Legal Obligation, Public Interest, Official authority

These situations refer to the grounds of processing contained in Article 6(1)(c) and (e). A common instance of such compliance with a legal obligation is compliance with national commercial or tax laws which may require the retention and processing of personal data.

(c) Public Health

This section establishes an exception based on public health reasons, making specific references to provisions in Article 9 GDPR related to the processing of special categories of personal data.

Specifically, Article 9(2)(h) GDPR which refers to a broad exception based on processing necessity for the provision of health and social care. According to Georgieva and Kuner, the latter should be interpreted broadly to include assistance granted by social security authorities.[21] Besides health and social care services, it also includes other related purposes, such as the assessment of employee working capacities or the management of health or social care systems. For this exception to apply, the sensitive data must be processed by a professional subject to the obligation of professional secrecy, as established by an explicit complementary provision in Article 9(3) GDPR, also referenced in this section.

The other provision mentioned is Article 9(2)(i) GDPR, which is an exception for processing based on public interest considerations in the area of public health. It gives some examples, such as protection against serious cross-border threats, or ensuring adequate standards for health products and devices.

According to Recital 54 GDPR, the interpretation of “public health” corresponds to Regulation (EC) No 1338/2008,[Regulation (EC) No 1338/2008 of the European Parliament and of the Council of 16 December 2008 on Community statistics on public health and health and safety at work (available here).] which includes “namely all elements related to health, namely health status, including morbidity and disability, the determinants having an effect on that health status, health care needs, resources allocated to health care, the provision of, and universal access to, health care as well as health care expenditure and financing, and the causes of mortality.”

(d) Archiving, Scientific, Historical Research, Statistical Purposes

This section (which mirrors Article 9(2)(j) GDPR) contains a processing exception for archiving purposes in the public interest, scientific or historical research purposes or statistical purposes in accordance with Article 89(1) GDPR, which in turn establishes that these processing purposes must be subject to appropriate safeguards for the rights and freedoms of data subjects. Among those safeguards, this article places an emphasis on data minimisation, and mentions pseudonymisation as a possible measure. This exception will apply when the right to erasure will have a considerable effect on these purposes, either rendering them impossible, or seriously impairing them.

(e) Legal Claims

This provision (which also partly mirrors Article 9(2)(f) GDPR) establishes an exception which prevents data subjects from demanding an erasure of their personal data that might be relevant for the establishment, exercise or defense of legal claims, which should be interpreted broadly to include both public and private law claims. It should also be noted that these legal claims bust be either already filed and underway, or at the very least imminent or impending, and not just a hypothetical possibility.

EDPB Guidelines: on this Article there are EDPB Guidelines 5/2019 on the criteria of the Right to be Forgotten in the search engines cases under the GDPR (part 1)

Decisions

→ You can find all related decisions in Category:Article 17 GDPR

References

  1. In the below commentary we will use the definition put forward by some authors according to which the "right to erasure" is made of two different elements, the classic "right of deletion" under paragraph 1 and the "right to be forgotten" (in the strict sense) under paragraph 2. See, Kamann, Braun in Ehmann, Selmayr, Datenschutz-Grundverordnung, Article 17 GDPR, margin number 1-3 (C.H. Beck 2018, 2nd Edition).
  2. As Voigt and von dem Bussche note, “the right of the data subject shall only help to enforce the controller’s obligation to erase personal data that would exist anyway under any of the grounds of Art. 17 Sec. 1 GDPR.” See, Voigt, von dem Bussche, The EU General Data Protection Regulation (GDPR): A Practical Guide, p. 159 (Springer 2017).
  3. Deletion must be effective but does not have to be irreversible. It is adequate that the processing and use of the data in question is no longer feasible in its previous form. The fact that at some point a reconstruction of the data (such as restoring a shredded paper) using technical aids (such as cache and metadata or other programs) becomes possible, does not invalidate the effectiveness of the deletion. See, Kamann, Braun in Ehmann, Selmayr, Datenschutz-Grundverordnung, Article 17GDPR, margin number 35 (C.H. Beck 2018, 2nd Edition).
  4. Dix, in Simitis, Hornung, Spiecker, Datenschutzrecht, Article 17 GDPR, margin numbers 5 (NOMOS 2019).
  5. See, Kamann, Braun in Ehmann, Selmayr, Datenschutz-Grundverordnung, Article 17GDPR, margin number 35 (C.H. Beck 2018, 2nd Edition).
  6. Voigt, von dem Bussche, The EU General Data Protection Regulation (GDPR): A Practical Guide, p. 157 (Springer 2017), citing Laue et al., Datenschutzrecht, Rechte der betroffenen Person (2016), margin number 41.
  7. Voigt, von dem Bussche, The EU General Data Protection Regulation (GDPR): A Practical Guide, p. 157 (Springer 2017).
  8. Carey, Data Protection: A Practical Guide to UK and EU Law, p. 144 (Oxford University Press, 2018, 5th Edition).
  9. Voigt, von dem Bussche, The EU General Data Protection Regulation (GDPR): A Practical Guide, p. 158 (Springer 2017).
  10. Voigt, von dem Bussche, The EU General Data Protection Regulation (GDPR): A Practical Guide, p. 158 (Springer 2017).
  11. CJEU, Case C-131/12, Google Spain, 13 May 2014 (available here).
  12. Schrey, in Rücker, Kugler, New European General Data Protection Regulation, A Practitioner's Guide: Ensuring Compliant Corporate Practice, p. 142 (C.H. Beck 2018).
  13. Voigt, von dem Bussche, The EU General Data Protection Regulation (GDPR): A Practical Guide, p. 163 (Springer 2017).
  14. Kranenborg, in Kuner, Bygrave, Docksey, The EU General Data Protection Regulation (GDPR): A Commentary, Article 7 GDPR, p. 483 (Oxford University Press 2020).
  15. Voigt, von dem Bussche, The EU General Data Protection Regulation (GDPR): A Practical Guide, p. 163 (Springer 2017).
  16. Kelleher, Murray, EU Data Protection Law, p. 214 (Bloomsbury Professional 2018).
  17. Carey, Data Protection: A Practical Guide to UK and EU Law, p. 146 (Oxford University Press 2018. 5th Edition).
  18. EDPB, ‘Guidelines 5/2019 on the criteria of the Right to be Forgotten in the search engines cases under the GDPR (part 1)’, 7 July 2020 (Version 2.0), p. 6 (available here).
  19. Voigt, von dem Bussche, The EU General Data Protection Regulation (GDPR): A Practical Guide, p. 159 (Springer 2017).
  20. Voigt, von dem Bussche, The EU General Data Protection Regulation (GDPR): A Practical Guide, pp. 159-160 (Springer 2017).
  21. Georgieva, Kuner, in Kuner, Bygrave, Docksey, The EU General Data Protection Regulation (GDPR): A Commentary, Article 7 GDPR, p. 380 (Oxford University Press 2020).