Right to be Forgotten - Satori

Right to be Forgotten

Although the EU is not the only regulatory body that gives citizens the right to be forgotten, the GDPR is by far the most comprehensive data privacy regulation that contains the right to be forgotten. Essentially, the right to be forgotten gives EU and UK citizens the right to request an organization to delete their personal data. But, organizations do not always need to comply.

In this article we explore the obligations when individuals exercise their right to be forgotten; this article covers the following topics:

What is the Right to be Forgotten?

The right to be forgotten, also known as the right to erasure, is a fundamental right under the General Data Protection Regulation (GDPR). It gives individuals the right to have their personal data erased from the records of a controller (an organization that processes personal data) and from the records of any processors (organizations that process personal data on behalf of a controller).

With the right to be forgotten, individuals can request that their personal data be erased from the records of a controller and any processors. They can also request that their personal data be erased from any online sources, such as social media platforms or search engines.

The right to be forgotten applies when:

Under the GDPR, the right to be forgotten aims to protect individuals’ privacy while giving them more control over their personal data. Organizations need to have processes in place to handle right to be forgotten requests and to respect the rights of individuals.

Where Do People Have the Right to be Forgotten?

Individuals within the EU and EEA have the right to be forgotten under the GDPR. This right also extends to organizations outside of the EU and EEA that process the personal data of individuals within the EU and EEA. The right to be forgotten applies to the processing of personal data by controllers and processors, regardless of where the processing takes place.

Obligations When a Data Subject Exercises Their Right to be Forgotten

Under the General Data Protection Regulation (GDPR), a data controller (an organization that processes personal data) has several obligations when an individual exercises their right to be forgotten, also known as the right to erasure. These obligations include:

By fulfilling these obligations, data controllers can ensure that they are respecting the rights of individuals under the GDPR and protecting their privacy.

When Can an Organization Decline a Right to be Forgotten Request?

An organization may decline a right to be forgotten request if the personal data is necessary to:

In addition, an organization may also decline a right to be forgotten request if the personal data is being processed for scientific, historical, statistical, or archival purposes, provided that the processing is necessary for these purposes. However, in these cases, the organization must implement appropriate safeguards to protect the rights and freedoms of the individual, such as pseudonymizing personal data or limiting access to personal data.

Best Practices for Complying with the Right to be Forgotten

Complying with a right to be forgotten request can cause disruptions in business processes. Data you thought you had can disappear at a moment’s notice. So, here are a few best practices for complying with a right to be forgotten request while minimizing disruptions to your processes:

Conclusion

The right to be forgotten is a crucial right established within the GDPR. Although it can cause disruptions to business workflows, it provides citizens with more control over the use of their personal data. However, some circumstances allow organizations to decline a right to be forgotten request.