Advertisement

The Delete Button That Doesn't Always Delete: What Really Happens When You Ask Companies to Erase Your Data

The Delete Button That Doesn’t Always Delete: What Really Happens When You Ask Companies to Erase Your Data

Imagine discovering that a company you’ve never heard of knows your home address, your estimated income, your political affiliation, the names of your relatives, and the fact that you once filed for bankruptcy. Now imagine learning you have the legal right to make them erase all of it — and then spending three months, eleven emails, two formal complaints, and a regulatory filing trying to make that actually happen.

This is not a hypothetical. It’s the routine experience of consumers who attempt to exercise one of the most consequential rights in modern data privacy law: the right to erasure. Sometimes called the “right to be forgotten,” this legal mechanism was enshrined in the European Union’s General Data Protection Regulation in 2018, later adopted in various forms by California’s Consumer Privacy Act, and subsequently echoed in legislation across dozens of jurisdictions. On paper, it is elegant and powerful. In practice, it is a labyrinthine ordeal that reveals the profound gap between what privacy law promises and what the data economy delivers.

The right to erasure under GDPR, codified in Article 17, is sweeping in its language. EU residents can demand that any organization delete their personal data when it is no longer necessary for the purpose it was collected, when they withdraw consent, when they object to processing and there is no overriding legitimate interest, or when the data was unlawfully processed. Companies have one month to comply — extendable to three months in complex cases — and must respond even if they ultimately decline the request.

California’s CCPA, which took effect in January 2020 and was strengthened by the California Privacy Rights Act (CPRA) in 2023, grants California residents similar powers. Businesses subject to CCPA must delete personal information upon request within 45 days, notify any service providers or contractors to do the same, and explain their reasoning if they refuse. The law applies to for-profit businesses that collect consumer personal information and meet threshold criteria: annual gross revenues over $25 million, data on 100,000 or more consumers or households, or deriving 50% or more of revenues from selling personal information.

By 2024, at least 20 U.S. states had passed comprehensive consumer privacy legislation with deletion rights, according to the International Association of Privacy Professionals (IAPP). The global picture is similarly expansive: Brazil’s LGPD, Japan’s Act on the Protection of Personal Information, South Korea’s PIPA, and Canada’s proposed Bill C-27 all contain erasure or correction rights of varying strength.

The regulatory penalties for non-compliance are real, at least in Europe. Under GDPR, fines can reach €20 million or 4% of global annual turnover, whichever is higher. Meta has been fined over €1.2 billion under GDPR as of 2023. Google was hit with a €50 million penalty by France’s CNIL in 2019 partly for failing to adequately inform users about data processing. The machinery of enforcement exists. The question is whether it functions.

The Mechanics of Making a Request — and Why They Often Fail

Most people who attempt a data deletion request quickly discover that the process is designed, whether intentionally or through negligence, to frustrate them.

The first hurdle is simply finding the right place to ask. Major platforms like Google, Apple, Meta, and Amazon have built relatively accessible privacy dashboards, where users can download their data or submit deletion requests with a few clicks. But the overwhelming majority of companies holding your data — the insurance company, the retail loyalty program, the app you downloaded in 2017 and forgot about, the data broker who bought your information from seventeen other companies — have no such infrastructure. Many bury their deletion request processes in lengthy privacy policies, require requests to be submitted by postal mail, or use web forms that generate auto-responses and then go silent.

Data brokers are a particular problem. Companies like Acxiom, LexisNexis, Oracle Data Cloud, and hundreds of smaller operations compile extraordinarily detailed profiles on hundreds of millions of individuals, yet most consumers have no idea these companies exist, let alone that they hold their data. Submitting deletion requests to each one individually is, by design, a full-time job. The website DeleteMe, a subscription service that submits opt-out requests to data brokers on consumers’ behalf, estimates that a single individual’s information appears on 40 to 50 data broker sites on average — and that data often reappears within months of deletion, scraped from public records or repurchased from other sources.

A 2021 study by researchers at University College London found that only 40.5% of email-based deletion requests to companies actually resulted in confirmed deletion. The researchers sent test requests to 150 companies across multiple sectors and found significant variation: financial services companies were among the more compliant, while gaming and entertainment companies were among the worst performers. Many companies simply did not respond at all.

The identity verification problem compounds the difficulty. To prevent malicious actors from deleting someone else’s data, companies require requestors to prove who they are — which, paradoxically, sometimes means providing more personal data before any can be deleted. Some companies have been found to retain the identity verification data submitted with deletion requests longer than any other data, creating a perverse loophole in which the act of asking for privacy generates a new privacy problem.

The Exceptions That Swallow the Rule

Even a technically compliant response to a deletion request may erase far less than the consumer expects. Privacy laws contain significant exceptions, and companies have become adept at invoking them.

Under GDPR, companies are not required to delete data that is necessary for “the performance of a task carried out in the public interest,” for the establishment, exercise, or defense of legal claims, or for compliance with a legal obligation. CCPA similarly exempts data retained to complete a transaction, detect security incidents, exercise free speech, comply with legal obligations, or conduct research in the public interest.

The “legal compliance” exception is particularly elastic. A credit card company may argue it must retain your transaction history for seven years to comply with anti-money laundering regulations. A healthcare provider may retain your records indefinitely under HIPAA. An employer may keep your personnel file for years after termination for litigation purposes. These are often legitimate reasons. But companies also invoke legal exceptions expansively, as a catch-all for data they simply prefer not to delete.

More troubling are the architectural realities of modern data infrastructure. Even when a company genuinely attempts to delete your data, it may exist in dozens of backup systems, data warehouses, and third-party integrations that the company cannot easily modify. “The fundamental problem,” explains Caitlin Fennessy, Chief Knowledge Officer at IAPP, “is that many organizations were never built with deletion in mind. Their databases are optimized for adding data, not removing it. Deletion is technically difficult and expensive.”

Derived data presents another complication. If a company has used your personal data to train a machine learning model, is that model “your data”? Current regulatory guidance is inconsistent on this point. In the EU, data protection authorities have suggested that personal data embedded in AI models may need to be excised through techniques like machine unlearning, but the technical methods for doing so reliably are still immature. The implications for large language models and other AI systems trained on scraped internet data are profound and largely unresolved.

Who Actually Gets Results — and Why

Not all erasure requests fail. Consumer advocates and privacy researchers have identified patterns in which requests succeed.

Requests made through formal, written channels — citing specific legal provisions, referencing the company’s obligations under GDPR or CCPA, and setting clear deadlines — are substantially more likely to generate substantive responses than informal requests. Organizations like the Electronic Frontier Foundation (EFF) and Privacy Rights Clearinghouse publish template letters that consumers can adapt for this purpose.

Regulatory complaints dramatically increase compliance rates. In the UK, the Information Commissioner’s Office (ICO) receives tens of thousands of data rights complaints annually. A formal complaint to the ICO — or to France’s CNIL, Germany’s BfDI, Ireland’s Data Protection Commission, or California’s state Attorney General — typically prompts a far more serious response from the company in question than a direct request alone. “The threat of regulatory scrutiny is the primary enforcement mechanism in practice,” says Paul Bernal, a professor of IT, IP, and media law at the University of East Anglia. “Most companies would rather comply than explain themselves to a regulator.”

Consumers in the European Union generally enjoy stronger practical protections than their American counterparts, not because EU law is inherently better drafted, but because GDPR enforcement is better resourced and more active. Irish DPC enforcement actions against Meta, for example, have led to substantial changes in how the company processes EU user data. No comparable enforcement infrastructure exists at the federal level in the United States, where there is no national privacy law and the FTC’s enforcement authority over privacy is constrained by its statutory mandate.

High-profile individuals, journalists, and public figures have also had notable success using right-to-be-forgotten requests against search engines specifically. Google has received over six million de-indexing requests since 2014, when the Court of Justice of the European Union ruled in the landmark Google Spain case that individuals could request search engines remove links to outdated or irrelevant personal information. Google grants approximately 50% of these requests. The right applies to de-indexing from search results, not to deletion of the underlying source material — a distinction that matters enormously in practice.

The Business of Non-Compliance

Understanding why deletion requests fail so frequently requires understanding the economic incentives at stake. Personal data is not a byproduct of the modern internet economy. It is the currency. The global market for data brokers alone was valued at $345 billion in 2023, according to Statista, and is projected to exceed $700 billion by 2030. Every data point deleted is, in this framing, money removed from circulation.

This creates a structural incentive not merely to ignore deletion requests, but to design compliance processes that appear legitimate while delivering as little actual deletion as possible. Privacy researchers have a term for this: “privacy theater.” Companies create deletion portals that are technically accessible but practically impenetrable, or that delete surface-level account data while retaining behavioral profiles and inferred attributes in separate systems.

The practice of data “anonymization” is frequently used to sidestep deletion obligations. A company may claim that once it strips obvious identifiers like your name and email address from a dataset, the remaining information is no longer “personal data” subject to deletion requirements. But research consistently demonstrates that re-identification of supposedly anonymized data is not merely possible but routine. A landmark 2019 study published in Nature Communications found that 99.98% of Americans could be re-identified in any dataset using just 15 demographic attributes. “Anonymization” as currently practiced is often not anonymization at all.

Small and medium enterprises face a different kind of problem. Unlike large corporations, many SMEs lack the legal and technical infrastructure to process deletion requests competently, not out of bad faith but out of limited capacity. A 2022 survey by the UK ICO found that 40% of small businesses were unsure how to handle data subject access and erasure requests. This regulatory complexity disproportionately burdens smaller organizations while the largest, most data-hungry companies have compliance teams capable of managing requests in ways that technically comply while practically preserving the maximum amount of data.

What Better Looks Like — and Where This Is Heading

The next generation of privacy regulation is attempting to address these failures structurally, rather than relying solely on individual consumers to enforce their own rights.

California’s CPRA created a dedicated California Privacy Protection Agency, the first of its kind in the United States, with independent rulemaking and enforcement authority. The agency has begun issuing regulations that specify the technical and operational standards companies must meet — not merely requiring deletion, but requiring that companies maintain systems capable of locating and deleting data reliably across their infrastructure.

The EU’s Digital Services Act and the proposed ePrivacy Regulation are adding additional layers of obligation. The EU’s AI Act, finalized in 2024, includes provisions addressing the use of personal data in AI systems, though enforcement of AI-specific data rights remains an evolving frontier.

In the United States, the American Privacy Rights Act (APRA), which advanced through Congressional committee in 2024, would establish a federal floor for data rights including deletion — potentially creating a national standard to replace the current patchwork. Whether it will pass in its current form remains uncertain, but the political momentum behind federal privacy legislation is stronger than at any point in the past decade.

Technology, too, may ultimately help close the gap between legal right and practical reality. Privacy-enhancing technologies (PETs) including differential privacy, federated learning, and cryptographic deletion methods are maturing to the point where building deletability into data systems is becoming technically tractable rather than prohibitively expensive. Some researchers argue that privacy by design — engineering systems from the ground up with deletion as a core function rather than an afterthought — is the only way to make the right to erasure meaningful at scale.

The broader lesson of the first decade of erasure rights is this: legal rights without technical and institutional infrastructure to support them are aspirational fictions. The right to erasure is not a broken idea — it reflects a genuine and important principle about individual autonomy and the limits of corporate data collection. But the distance between the principle and the practice is measured in missing enforcement resources, misaligned economic incentives, and infrastructure built to accumulate data rather than to release it. Closing that distance is not primarily a legal challenge. It is an engineering challenge, an institutional challenge, and ultimately a political one about what kind of data economy we are willing to accept. Every unanswered deletion request is a small, concrete answer to that question — and so far, it is not a flattering one.

Advertisement