Practical guide

How to draft a GDPR erasure request (right to be forgotten) with AI

4 min read · Updated June 2026 · Editorial oversight: Avv. Federico Papa

The erasure request, embodying the right to be forgotten, is the primary remedy provided by Art. 17 GDPR enabling the data subject to obtain the removal of personal data from the controller's database. This request forms part of the broader framework of data subject rights under EU Regulation 2016/679, designed to ensure individual control over personal information. The remedy aims to restore privacy when processing is no longer justified by lawful purposes or when the necessity requirements have ceased. To ensure the request is granted, the practitioner must correctly qualify the specific case under one of the exhaustive grounds set out in the regulation.

In brief

Drafting erasure requests under Art. 17 GDPR via AI enables removal of personal data when processing purposes cease or consent is withdrawn. Practitioners must verify the applicant's identity under Art. 12 GDPR and confirm the absence of legal exceptions. The request requires analytical specification of data categories or URLs and reference to notification obligations toward third parties per Art. 19 GDPR. Controllers must respond within one month, extendable by two for complexity. Inaction justifies a complaint to the Data Protection Authority or court action.

The steps

  1. 1.

    Identification of the legal ground

    The practitioner must first ascertain the existence of one of the exhaustive grounds set out in Art. 17 GDPR, such as the cessation of processing purposes or the withdrawal of consent. It is essential to verify that no legal exceptions apply, such as compliance with a legal obligation or the exercise of the right of defense in legal proceedings, which override the erasure request. Proper qualification of the legal basis prevents pretextual rejections by the data controller.

  2. 2.

    Verification of the data subject's identity

    Although Art. 12 GDPR requires the controller to facilitate the exercise of data subject rights, it also requires certainty regarding the applicant's identity. The practitioner must provide suitable documentation to prove legal standing, especially when the request is submitted through non-certified channels. In the absence of such proof, the controller may legitimately refuse to act on the request by invoking reasonable doubt regarding identity.

  3. 3.

    Analytical specification of data to be removed

    A generic request for the erasure of all data often proves ineffective or excessively burdensome for the controller, causing delays. It is necessary to precisely list the categories of data or specific information, such as web page URLs or search strings, requiring permanent removal. Technical precision in defining the scope of the request facilitates the material execution of the erasure and minimizes grounds for dispute.

  4. 4.

    Reference to notification obligations towards third parties

    Pursuant to Art. 19 GDPR, the controller is obliged to communicate the erasure to each recipient to whom the personal data have been disclosed. The request must explicitly highlight this duty to ensure that the effects of the right to be forgotten extend beyond the single controller addressed. The practitioner must request confirmation of the notification sent to third parties to ensure full protection of the client's privacy.

  5. 5.

    Monitoring response deadlines

    Under Art. 12 GDPR, the data controller must provide information on action taken without undue delay and at least within one month of receipt of the request. This period may be extended by two months in complex cases, subject to a timely and reasoned communication. The practitioner must monitor the expiration of the deadline to promptly activate remedies before the Data Protection Authority or the courts.

  6. 6.

    Preservation of proof of sending and delivery

    To ensure the effectiveness of the remedy in case of controller inaction, it is essential to retain reliable proof of receipt of the request via PEC or registered mail. Proof of dispatch and delivery constitutes an essential procedural requirement for subsequent legal actions. The practitioner must also archive all correspondence to document any evasive responses or unreasoned refusals.

Legal basis: art. 12 GDPRart. 17 GDPRart. 19 GDPR

The template structure

The standard sections that make up the document. The full template can be opened and completed directly on edit.legal.

  1. Sender

    Full identification details of the data subject exercising the right to erasure.

  2. Data Controller

    Indication of the addressee controller and contact details of the Data Protection Officer (DPO), if appointed.

  3. Subject: right to erasure

    Formal exercise of the right to be forgotten with explicit reference to Art. 17 GDPR.

  4. Grounds for the request

    Factual and legal reasons falling under the exhaustive grounds justifying erasure.

  5. Erasure request

    Formulation of the data removal request and explicit reference to the notification obligation toward third parties under Art. 19 GDPR.

  6. Place, date, signature

    Signature of the data subject and list of attachments establishing identity.

Mistakes to avoid

  • Failure to attach a valid identity document, allowing the controller to legitimately suspend processing of the request under Art. 12 GDPR.
  • Requesting erasure of data necessary for compliance with a legal obligation, which constitutes an explicit exception to the right to be forgotten.
  • Omitting the reference to the notification obligation toward third-party recipients under Art. 19 GDPR, thereby limiting the scope of protection.
  • Using generic grounds without specifying which of the exhaustive grounds set out in Art. 17(1) GDPR applies to the specific case.

Frequently asked questions

What is the maximum deadline for receiving a response from the controller?

The controller must respond within one month of receipt, which may be extended by a further two months in complex cases. Exceeding the deadline without a reasoned response justifies recourse to the Data Protection Authority or the court.

Does exercising the right to erasure involve costs or fees?

Exercising the right is free of charge pursuant to Art. 12 GDPR. Only in the case of manifestly unfounded or excessive requests may the controller charge a reasonable fee or refuse to act on the request.

What can be done if the controller unjustifiably refuses erasure?

The data subject may lodge a complaint with the Data Protection Authority or initiate proceedings before the ordinary courts. Both actions require proof of the prior unsatisfied request.

Avv. Federico Papa
Editorial oversight: Avv. Federico Papa·ICAM

What edit.legal automates

  • Automated verification of the legal grounds under Art. 17 GDPR to minimize the risk of rejection.
  • Instant generation of notification clauses for third-party recipients under Art. 19 GDPR based on input data.
  • Intelligent monitoring of the one-month deadline established by Art. 12 GDPR with alerts for the practitioner.

Put edit.legal to the test on actual cases

Try edit.legal for free on an active case. No credit card required.

Try edit.legal for free