People can ask you to delete their data, and for direct marketing you usually have to comply, generally within one month.
Key points
- Article 17 of the GDPR gives individuals the right to have their Personal Data erased without undue delay in specific circumstances [1].
- Grounds include data no longer being necessary, withdrawal of Consent, and a successful objection, including any objection to direct marketing [1][2].
- Controllers must respond without undue delay and within one month, extendable by two further months for complex or numerous requests [3].
- The right is not absolute; exceptions include compliance with a legal obligation and the defense of legal claims [1].
- California's CCPA / CPRA gives a similar right to delete in Civil Code 1798.105, subject to its own exceptions [4].
- Keeping a minimal record on a Suppression List after deletion is generally accepted, so you can make sure you never contact the person again [5].
When the right applies
Article 17 lists the situations in which a controller must erase data on request [1]. The data is no longer necessary for the purpose it was collected for. The person withdraws Consent and there is no other lawful basis. The person objects under Article 21 and there are no overriding legitimate grounds, or the objection is to direct marketing, where no balancing is allowed. The data was processed unlawfully, must be erased to meet a legal obligation, or was collected from a child for online services. For Cold Email this matters because most B2B outreach relies on Legitimate Interest, and a request to delete from a prospect usually doubles as an objection to marketing. In practice, a deletion request from a prospect should almost always be honored.
How to handle a request
A request does not need a special form or wording; it can arrive as a reply to an email or a short note asking you to delete their data [2]. You must respond without undue delay and within one month of receipt, and you can extend by two more months only for complex or numerous requests, telling the person why [3]. Confirm the person's identity only when there is reasonable doubt. Erase the data from live systems, including your CRM (Customer Relationship Management) and any Lead List exports, and tell any processors or recipients you shared it with, unless that is impossible or involves disproportionate effort [1]. The ICO notes that keeping just enough information to suppress future contact is appropriate where someone has objected to marketing [5]. Record what you deleted and when.
Erasure versus opt-out and suppression
An Opt-Out stops messages; erasure removes data. The two often come together in outbound, and they can seem to conflict: if you delete someone completely, you could add them back later from a new list and contact them again. That is why a minimal Suppression List entry, such as a hashed email address, is widely used and accepted by regulators as a way to respect an objection [5]. Under the CCPA / CPRA, businesses must also delete on request and direct their service providers to do the same, with exceptions such as completing a transaction or complying with law [4]. Good Data Minimization makes all of this easier, since less stored data means less to find and delete. This is general information, not legal advice.
- Art. 17 GDPR — Right to erasure (right to be forgotten) — gdpr-info.eu
- Right to erasure — Information Commissioner's Office
- Art. 12 GDPR — Transparent information, communication and modalities for the exercise of the rights of the data subject — gdpr-info.eu
- California Civil Code 1798.105 — Consumer's right to delete — California Legislative Information
- Right to object — Information Commissioner's Office
Related terms
Outreach without the busywork.
PineLead finds new B2B prospects every day, qualifies them against your criteria and writes the first email in your voice. You approve — PineLead sends.
Start free with 100 credits →