Definition
The right to erasure, also known as the right to be forgotten under GDPR Article 17, gives subscribers the right to request that an organisation deletes their personal data without undue delay. For email marketers, this means when a subscriber requests erasure, you must delete their personal data including name, email address, engagement history, preferences, and any other identifiable information stored in your email marketing systems. The right is not absolute: it applies only in certain circumstances including when the data is no longer necessary for the original processing purpose, when consent is withdrawn, or when the data has been unlawfully processed.
Exceptions to the right to erasure are important for email operations to understand. You may refuse a erasure request if processing is necessary for exercising the right of freedom of expression and information, for compliance with a legal obligation, for the establishment or defence of legal claims, or for archiving purposes in the public interest. In practice, the most common exception for email marketers is the legal obligation to maintain suppression records: while you must delete the subscriber's personal data upon request, you are permitted to retain a minimal record of their email address and the date of the erasure request to ensure you do not inadvertently email them again.
The erasure process must be completed within one month of receiving the request, extendable by two months for complex requests. The ICO expects organisations to have clear procedures for receiving, verifying, and processing erasure requests. Automated systems that integrate your email platform with your data management processes are strongly recommended. Manual processing of erasure requests across multiple systems (ESP, CRM, analytics, data warehouse) is error-prone and difficult to audit. The interaction between erasure and suppression is a common area of confusion: you delete personal data but you must keep a suppression record, and these two requirements must be managed together.
Best Practices
Maintain a separate suppression list that survives erasure requests. When processing an erasure request, delete all personal data from your active systems, then add the email address to a permanent suppression list that contains only the address, the date of the erasure request, and the fact that deletion was requested. Do not store any additional personal data in the suppression list. This is permitted under GDPR Article 17(3)(e) for legal claims and legal obligation purposes.
Implement automated erasure processing across all integrated systems. A subscriber's data typically exists in your ESP, CRM, analytics platform, data warehouse, and possibly in third-party enrichment tools. Manual processing across these systems is slow and risks missing some copies. Use automated workflows triggered by the erasure request to execute deletions across all systems simultaneously and log completion for audit purposes.
Verify the identity of the requester before processing. You must take reasonable steps to confirm that the person making the erasure request is the data subject. Simple methods include sending a verification email to the registered address or asking for information that only the subscriber would know. Overly burdensome verification requirements may themselves breach GDPR. Strike a balance between security and accessibility.
Document every erasure request and its processing. Maintain a log that records the date of request, verification method, systems searched, data deleted, any exceptions applied, and the date of completion. This documentation is essential for demonstrating compliance if audited by the ICO or a similar regulator. Retention of erasure request logs should follow your data retention policy.
Train all customer-facing staff on erasure request handling. Erasure requests can arrive through any channel: email reply, web form, phone call, social media, or postal mail. Any staff member who might receive a request must know how to recognise it, whom to escalate to, and the response timeframe. A missed erasure request that exceeds the 30-day deadline is a GDPR breach that could result in regulatory action.
Related Glossary Terms
Australia Spam Act
Australia's Spam Act 2003 regulates commercial electronic messages including email. It requires consent, functional unsubscribe mechanisms within 5 working days, and sender identification. Penalties reach AUD $2.22 million per day.
Email B2B Consent
The legal requirements for B2B email marketing consent, covering GDPR legitimate interest, CASL implied consent, CAN-SPAM exemptions, and jurisdiction-specific best practices.
Email CASL
Canada's Anti-Spam Legislation requirements for commercial electronic messages, including consent types, record-keeping, and penalties up to $10 million per violation.
Email CCPA
California Consumer Privacy Act requirements for email marketing, including consumer rights to access, delete, and opt out of data collection and sale.
Email Compliance Automation
Email compliance automation uses automated processes to manage unsubscribe processing, consent record-keeping, data retention enforcement, and regulatory monitoring within required legal timeframes.
Email Consent Age
Age of consent for email marketing across GDPR (16), COPPA (13), CASL, and PIPEDA jurisdictions, with age verification and compliance practices.
Frequently Asked Questions
Yes, and they are distinct rights. Unsubscribing only withdraws consent for future email sending but the organisation retains their personal data. Erasure deletes the data entirely. A subscriber may choose erasure if they do not want their data retained at all, not just if they no longer wish to receive emails. You must respect either choice.
No. There are several exceptions. The most relevant to email marketing is the legal obligation to maintain suppression records to prevent future sending. You can also refuse if the data is needed for legal claims or for the performance of a contract. If you refuse a request, you must inform the individual of the reason and their right to complain to a regulator.
If the email address is also their account login identifier, you may need to retain it for contract performance (providing the service). Consult the individual about whether they want their account closed entirely or only marketing data erased. Finding the right balance often requires case-by-case handling with the subscriber.
After erasure, you must keep a minimal suppression record (email address, date, reason) to ensure you do not accidentally re-add the subscriber or send them emails in the future. This suppression record is not considered personal data for most regulatory purposes as long as it contains no additional biographical or behavioural information. Keep suppression lists separate from active subscriber databases.
Failure to respond within the one-month timeframe is a breach of GDPR and can result in regulatory enforcement action, including fines of up to 4% of annual global turnover or €20 million, whichever is higher. The ICO may issue enforcement notices, reprimands, or fines depending on the circumstances and whether the failure was systemic or a one-off error.