Right to be forgotten
The right to be forgotten is the right of an individual to ask that personal information about them be erased or delisted, and to have that request assessed.
The right to be forgotten is the right of an individual to ask that personal information about them be erased or delisted, and to have that request assessed.
In the GDPR it appears as the right to erasure, and it matters because the default state of information online is permanence: something published once tends to stay reachable, and remain the first thing found about a person, long after it stopped being accurate or relevant.
The right exists to balance that against the equally real interest in information remaining available. It is not a delete button, and treating it as one is the most common misunderstanding of it.
What it actually gives
Control over one’s own data. A person can ask an organisation holding information about them to remove it, and the organisation has to answer, on the record, within a defined period.
An assessment, not an outcome. The request is weighed. Data that is out of date, inaccurate or no longer necessary for the purpose it was collected for is a strong case; data an organisation is legally required to keep, or which serves a genuine public interest, is not.
An obligation on whoever holds the data. Being able to honour the right means being able to find every copy of a person’s data, including in backups, in exports and in systems run by processors. That is an engineering requirement dressed as a legal one.
What it does not give
It does not erase the internet. Delisting a result from a search engine does not remove the page it pointed at. The information can remain lawfully published while becoming much harder to find.
It does not always win. Freedom of expression, the public interest, historical and statistical purposes, and legal retention duties are all grounds on which a request is refused, and refusing has to be justified rather than simply decided.
It does not apply the same way everywhere. The right is a European construct. A global platform receives requests under a rule that does not exist in every jurisdiction it operates in, which is why the same request can be honoured in one place and not another.
A worked example
A person who was involved in a legal matter, resolved in their favour, finds that searching their name still returns coverage of it years later.
They ask the search operator to delist those results, on the grounds that the information is no longer relevant to who they are now.
The operator weighs it: how old the matter is, whether the person holds public office, whether there is a continuing public interest in it being easy to find.
It decides to delist. The original articles are still published, still lawful and still readable at their own addresses. What has changed is that they are no longer the answer to that person’s name.
Where this shows up in an audit
The finding is almost never about the legal test. It is that the organisation cannot execute the decision it has made: it can delete the record from the main database and has no idea what else holds a copy, no way to reach the analytics warehouse, and no plan for the backups. A right you cannot technically honour is a compliance gap regardless of how well the policy is drafted, which is why this belongs in a security glossary and not only in a legal one.