Blog

Understanding the Right to Erasure

A customer sends an email asking your business to delete their personal information. It might be a former client, a past employee, someone who signed up for a newsletter years ago. 

The request is simple. What your business is legally required to do next is less straightforward and most businesses are not prepared for it.

 

The right to erasure is one of the most important individual rights under Australian privacy law. It is also one of the most misunderstood.

 

What the Right to Erasure Means

The right to erasure, sometimes called the right to be forgotten, gives individuals the ability to request that a business deletes the personal information it holds on them.

 

Under the Australian Privacy Act, businesses are required to take reasonable steps to destroy or de-identify personal information that is no longer needed for the purpose it was collected.

 

When an individual makes a formal erasure request, that obligation becomes specific and time-bound. The business must assess the request, locate the relevant data across its systems and take appropriate action. Ignoring the request or providing an inadequate response is a privacy compliance failure.

 

It is worth understanding what erasure actually means in practice. Deleting a customer record from a CRM does not constitute full erasure. Personal data exists across multiple systems: email platforms, backup files, third party tools, archived records. 

 

A compliant erasure response requires locating and removing personal data from every system where it exists, not just the most obvious one.

 

When It Applies and When It Does Not

The right to erasure is not absolute. There are circumstances where a business can lawfully retain personal information despite a deletion request:

 

  • Legal obligations: data required to be kept under Australian law, such as financial records or employment documents
  • Contractual requirements: information necessary to fulfil an existing contract or agreement
  • Legitimate business purposes: data still actively needed for the purpose it was originally collected
 

Outside of these exceptions, a valid erasure request carries a legal obligation to act. Businesses that cannot demonstrate a lawful reason for retaining data are required to delete or de-identify it. And the threshold for what counts as a lawful reason is higher than most businesses assume, “we might need it one day” does not qualify.

 

Understanding where the exceptions apply,  and where they do not, is what separates a compliant response from a compliance failure.

 

Responding to an Erasure Request

Handling an erasure request correctly starts with knowing what personal data your business holds and where it lives. Without that foundation, a complete and accurate response is not possible.

 

Acknowledging the request promptly, locating the data across all systems, assessing whether any lawful retention grounds apply and confirming the outcome to the individual are the steps every business needs to have in place.

 

The right exists. The obligation is real. The preparation starts now.

Share:
More Blog Posts