Footprint · guide

The right to be forgotten, and how a request is actually made

By Alberto Gulotta · Updated · 18 min read

The right to be forgotten is two requests with one name. To the organisation holding your data it is a right to erasure, made verbally or in writing to any part of it, answered within one calendar month. To a search engine it is delisting, which hides results for your name and leaves the page online. Neither is the route for an intimate image published without consent, which has its own law and its own deadline: forty-eight hours, and two free takedown services.

Two different requests share the name: erasure, and delisting A request to the organisation holding the data asks for the data itself to be erased, and if it was made public the organisation must take reasonable steps to tell others to erase links or copies. A request to a search engine asks only for results to be delisted for searches on your name; the page itself stays online and stays findable through other queries. SAME NAME, TWO DIFFERENT THINGS TO ASK FOR To whoever holds the data the data itself is erased and, if it was made public, they must take “reasonable steps” to tell others to erase links or copies one calendar month to answer To the search engine the result is delisted, and only “for queries related to your name” the page stays online, and stays findable by any other search reviewed by hand, case by case Which is why the order matters, in the search engine’s own words “Removing material from the web can be more effective than removing it only from Google on searches for your name.” AI Tools Primer · figure
The left-hand request removes the thing; the right-hand one removes a route to it. Figure drawn by AI Tools Primer.

Two different requests share the name, and mixing them up wastes months

The right to be forgotten is a nickname, and it covers two things that behave differently. The first is erasure by whoever holds the data: the shop, the employer, the forum, the social network. In UK law this is the right to erasure, and the regulator’s own summary is plain — “you can ask an organisation that holds data about you to delete that data. In some circumstances, they must then do so.”

The second is delisting by a search engine, and it is narrower than the name suggests. Google’s own description of the outcome: “We’ll only delist content from search results for queries related to your name. Content that we delist for your name may remain in our results for other queries.” The page stays online. What changes is one route to it.

The order follows from that, and the search engine says so itself: “removing material from the web can be more effective than removing it only from Google on searches for your name”. Where the material is something you published, that route is a setting rather than a legal request — which is what making a Facebook profile private and locking a Facebook profile are for.

How the request is actually made, which is less formal than it sounds

The most useful thing the ICO publishes is how little ceremony is required. A request can be made “verbally or in writing”, it can go to “any part of the organisation” rather than a named privacy officer, and “there are no specific words that you must use”. You do not have to cite Article 17 or use the phrase “right to erasure” at all.

The regulator does recommend writing it down: “we recommend you follow up any verbal request in writing because this will allow you to explain your complaint, give evidence and explain what you want to happen” — and because it gives you proof if the decision has to be challenged later. The ICO publishes a template letter on the same page; it asks for a “full response within one calendar month” and for a date if that is not possible.

Say what you want erased rather than everything. The right applies in named circumstances: the organisation no longer needs the data for the original purpose; you have withdrawn consent you previously gave; you have objected and your interests outweigh theirs; you have objected to direct marketing; the data was collected or used unlawfully; there is a legal obligation to erase it; or the data was collected from you as a child for an online service — and that last one still applies now you are an adult.

Then the clock. The organisation has one calendar month, and may take up to an extra two months for a complicated request provided it tells you inside the first month why. If it needs to check who you are, the month starts when it receives that information. A fee is only possible where the request is “manifestly unfounded or excessive”.

The two regimes side by side, from the regulators that enforce them: the UK Information Commissioner’s Office and the California Attorney General. Both pages read on 9 September 2026.
 UK and EU — right to erasure California — right to delete
How to ask “verbally or in writing”, to “any part of the organisation” through one of the business’s designated methods, of which it must offer “at least two”
Wording required “There are no specific words that you must use”; the ICO publishes a template review the privacy policy, which “must include instructions”
Deadline “one calendar month”, extendable by “up to an extra two months” “45 calendar days”, extendable “by another 45 days (90 days total)”
Fee none, unless the request is “manifestly unfounded or excessive” not mentioned as a charge; the business must verify who you are
Account needed no “Businesses cannot make you create an account just to submit a deletion request”
The two clocks: one calendar month, or forty-five days Under UK data protection law an organisation has one calendar month to respond and may take up to two further months, telling you within the first month. Under the California Consumer Privacy Act a business must respond within forty-five calendar days and may extend by another forty-five, ninety in total, if it notifies you. HOW LONG THEY HAVE, AND WHAT EXTENDS IT United Kingdom and EU one calendar month to respond plus “up to an extra two months”, and they must tell you within the first identity check restarts the clock California 45 calendar days to respond plus another 45 if they notify you, 90 in total verification is required either way If nothing arrives, the first move is the same in both places Check you used the designated method, follow up in writing, then complain to the regulator. AI Tools Primer · figure
Neither deadline is a suggestion, and both regulators publish the follow-up route. Figure drawn by AI Tools Primer.

When they can lawfully say no, and what a refusal must still contain

The exemptions are published, which is what makes a refusal checkable. An organisation can refuse where keeping the data is necessary for freedom of expression and information — the ICO includes “journalism and academic, artistic and literary purposes” — where it is legally obliged to keep it, where it is carrying out a task in the public interest, where the data is needed for legal claims, or where erasure would prejudice research or public-interest archiving. Health and other special category data carries its own separate list.

Two things are true even when the answer is no. The organisation must still respond: the ICO’s words are that it “must still respond to you”, explain why, and tell you about your right to complain to the ICO or go through the courts. And where it does erase, it must tell others: “if your data has been made public online — such as on social networks, forums or websites — then the organisation must take reasonable steps to inform the people with responsibility for these sites to erase links or copies of that data”. That clause is the one that does the work this right is named for.

If nothing arrives, the sequence is: complain to the organisation first, then to the regulator. The ICO is explicit that you can also enforce the right through the courts, and equally explicit about what to do first: “we strongly advise you to seek independent legal advice”. This page is not that advice.

The search engine is a separate request, judged case by case

Google’s account of where this came from is short and worth having: the right was “first established in May 2014 in the European Union as the result of a ruling by the European Court of Justice”, and in 2018 “Article 17 of the GDPR sets out a ‘right to erasure’ similar to the right that the European Court of Justice had recognised”. Russia, Turkey and Serbia have since established versions of their own.

A delisting request is a form, and Google lists what it must carry: the specific URLs, a description of how the content relates to you and why it should be delisted, the search query — normally your full name — and an email address. Requests can be made on somebody else’s behalf by a person legally authorised to do so.

It is then reviewed by a person, not a rule. Google names the factors its reviewers weigh against the public interest: your role in public life, where the information comes from, how old it is, its effect on users, whether it is true, and whether it is sensitive data. Search engines “must consider if the information in question is ‘inaccurate, inadequate, irrelevant or excessive’”.

And the outcome is bounded twice over. It applies to name queries only, and it is territorial: Google delists “from versions of Google’s search results for countries applying European data protection law” and uses location signals to restrict access in the requester’s country, but “consistent with a 2019 decision of the European Court of Justice, we don’t apply these delistings to services for countries outside the EU”.

The documented reasons a request can be refused Under UK law an organisation can refuse where keeping the data is necessary for freedom of expression and information, where it is legally obliged to keep it, where it is carrying out a task in the public interest, where the data is needed for legal claims, or where erasure would prejudice research or public-interest archiving. In California the common reasons include information exempt from the CCPA such as publicly available information, failure to verify the request, completing a transaction, security practices and legal obligations. WHEN THE ANSWER IS LAWFULLY NO United Kingdom and EU freedom of expression and information, including journalism and research a legal obligation to keep it a task in the public interest legal claims · public-interest archiving — and health data has its own list California information exempt from the CCPA, including publicly available information the request cannot be verified completing a transaction, warranty or recall · security practices legal obligations and legal claims A refusal still has to be answered, in writing, with the reason AI Tools Primer · figure
The refusals are published, which means a refusal that names none of them is worth challenging. Figure drawn by AI Tools Primer.

Does the United States have this? Not federally — California has something else

There is no US equivalent of the European right, and no federal right to be forgotten. What exists is a state right with a different shape, and the office that enforces it describes it directly: under the California Consumer Privacy Act, “you may request that businesses delete personal information they collected from you and to tell their service providers to do the same”.

The mechanics differ from the European ones in ways that matter on the day. A business must offer “at least two methods” to submit the request, and the Attorney General’s advice is to use one of them rather than ordinary customer service. It “cannot make you create an account just to submit a deletion request”. And the deadline is “45 calendar days”, extendable “by another 45 days (90 days total)” with notice — against one month plus two in the UK.

The exception to know before you start is the one that catches people: information that is exempt from the CCPA, which includes “publicly available information (such as your address, which is often in public real estate/property records)”. The state does publish a route for people at particular risk: law enforcement officers, public officials and participants in the Safe at Home programme — available to victims of domestic violence, stalking, sexual assault, human trafficking, and elder and dependent abuse, as well as reproductive health workers — can ask a website not to publish their address.

One more thing sits on that page and is worth taking away from it: California requires data brokers to register, and the register is public. That is the practical starting list for anybody working through what is already findable about them.

Four things people mean by “delete me from the internet”

They have different addressees, different deadlines and different results.

Erasure by the organisation Ask whoever holds the data. One calendar month in the UK, 45 days in California. This is the only one of the four that removes the data itself.
Delisting by the search engine Ask Google. Removes a route, for name queries, in the applicable territory. The page itself stays exactly where it is.
Changing what you published No request needed, because it is yours: a settings change, and the fastest of the four. It is also the one the search engine asks you to do first.
Paying somebody to file requests for you The subscriptions send data broker opt-outs on your behalf. It is the same right, filed by an agent, and it is worth knowing that the broker register is public before deciding whether to pay for it.

Where the facts on this page came from. Three sources, all primary and independent of one another: the Information Commissioner’s Office, which enforces the right in the United Kingdom; the California Attorney General, who enforces the CCPA; and Google Legal Help, which is the party a delisting request is made to. All three were read in full on 9 September 2026 and are listed under Sources. The ICO states on its own page that its guidance is under review following the Data (Use and Access) Act, so the UK detail here is accurate to that date and may move.

What this page is not. It is not legal advice, and where a request is refused the ICO itself recommends taking independent legal advice before going to court.

Where to start

Three ways in.

“How do I actually ask?”
The request itself — how to ask
“They said no”
The published grounds — when no
“I am in the United States”
What exists instead — the us

What is public about you now

Before making a request about somebody else’s copy, the parts you control yourself.

When the data got out on its own

The cases where a request to one organisation is not the whole answer.

Questions people also ask

How do I apply for the right to be forgotten?

To the organisation holding the data, and it is informal: the ICO says a request can be made “verbally or in writing”, to “any part of the organisation”, and that “there are no specific words that you must use”. Put it in writing anyway, and say what you want erased.

Does the US have right to be forgotten?

Not as a federal right. California has a right to delete under the CCPA: you can ask a business to delete personal information it collected from you, it must offer at least two ways to ask, and it has 45 calendar days, extendable by another 45.

How long does an organisation have to reply?

One calendar month in the UK, and it may take up to an extra two months for a complicated request if it tells you within the first month. In California it is 45 calendar days, or 90 with notice. An identity check restarts the UK clock.

Can they refuse to delete my data?

Yes, on published grounds: freedom of expression and information, a legal obligation to keep it, a task in the public interest, legal claims, or public-interest archiving and research. They must still respond, explain why, and tell you how to complain.

Does delisting from Google delete the page?

No. Google delists results “for queries related to your name” only, and content delisted for your name “may remain in our results for other queries”. The page stays online. Google itself says removing the material at source is more effective.

Is a right to be forgotten request free?

In the UK, yes in almost all cases. A fee is only possible where the request is “manifestly unfounded or excessive”, and the organisation has to tell you and justify that decision.

Not covered here. It is not legal advice. It reports what three regulators and one search engine publish about their own procedures, with the dates they were read.

It covers the United Kingdom, the European Union and California, because those are the three whose enforcing bodies were read in full. Other countries have their own versions and their own deadlines.

And it does not remove you from data brokers. California requires them to register and the register is public, which is where that job starts. What holds instead is simple: every deadline, exemption and procedural step comes from the regulator that enforces it rather than from a law firm’s summary or a 2018 explainer, the search-engine section is quoted from the party the request is made to, the ICO’s own note that its guidance is under review is reproduced rather than hidden, and the page says plainly that it is not legal advice.

Sources

  1. Information Commissioner’s Office — Your right to get your data deleted: that a request can be made verbally or in writing to any part of an organisation with no specific wording, the template letter, the six circumstances in which the right applies, the one calendar month deadline and the two-month extension, the fee rule, the published grounds for refusal, and the duty to inform others where the data was made public online — ico.org.uk, read 9 September 2026.
  2. California Attorney General — California Consumer Privacy Act (CCPA), updated 28 August 2026: the right to delete personal information collected from you, the requirement that a business designate at least two methods for submitting a request and cannot require an account, the 45 calendar day deadline and the 45-day extension, the verification requirement, the exceptions including publicly available information, and the public data broker register — oag.ca.gov, read 9 September 2026.
  3. Google Legal Help — Right to be forgotten overview: the 2014 European Court of Justice ruling and its relationship to Article 17 of the GDPR, what a delisting request must contain, the factors Google’s reviewers weigh, that delisting applies only to queries related to your name, the territorial scope following the 2019 Court of Justice decision, and its advice that removing material at source is more effective — support.google.com, read 9 September 2026.

Written by Alberto Gulotta

Founder and editor of AI Tools Primer, writing from Palermo, Italy. Thirty-five years of taking computers apart, starting with a Commodore 64 — the long version is on the about page.

Something wrong on this page? Write to aitoolsprimer@gmail.com and it gets fixed.

Written on 9 September 2026 · last checked 10 September 2026.

Independence and limits

No affiliate links and no paid placements anywhere on this site. Nobody pays to appear here, and no company has seen this page before you did.

This is general information, not professional advice. Where a page touches money, health, safety or the law, it names its source and the date it was read — and your situation may still differ. See the privacy page and the cookie policy.