Right to Erasure

Data & Tracking

Also: Right to be Forgotten · Data Deletion Request

What it meansA person can ask you to delete their data
Where it comes fromGDPR, not Australian law by default
Response windowReasonable time, not indefinite
Applies toCRM, email lists, ad platforms, backups

Quick definition

Right to erasure is a person's ability to ask an organisation to delete the personal data it holds about them. It comes from the European Union's General Data Protection Regulation (GDPR) and is sometimes called the right to be forgotten. Australian businesses encounter it when they hold data on European Union residents or when local privacy reform mirrors the concept.

How it varies across Australia

Most Australian businesses have no formal deletion workflow at all, relying on ad hoc manual removal when someone complains. Businesses with mature data and tracking practices tend to have this built into their customer relationship management (CRM) and email platforms from the start rather than bolted on after a request arrives.

See data and tracking maturity across Australian industries

What it actually means

Right to erasure sounds like a single button. In practice it's a scavenger hunt through every system that ever touched a person's data.

The request usually starts simple. Someone emails asking you to delete everything you hold on them. The complexity shows up in the follow-through. Their record sits in your CRM, your email marketing platform, your analytics tool, a spreadsheet someone exported eighteen months ago, and probably a backup that runs on its own schedule regardless of what you promise a customer.

This is where erasure connects to consent and to first-party data more broadly. If you never mapped where personal data flows in the first place, you can't credibly claim you've deleted it everywhere. Attribution systems and customer relationship management (CRM) tools are the two places businesses most often forget to check, because both were built for marketing convenience, not privacy compliance.

Australia doesn't have a direct legal equivalent to GDPR's right to erasure baked into the Privacy Act the same way, but that gap is closing. Businesses serving European Union residents already owe this obligation regardless of where the business is based. Treating erasure as a GDPR-only problem is a bet that local law won't catch up. It's catching up.

A right to erasure request is a stress test for your data map. Most businesses fail it because they never drew the map in the first place.

How it shows up

Erasure shows up as a support ticket, a privacy officer email, or a formal complaint if it's ignored. It also shows up in your data audit trail, or the absence of one, when you try to prove a deletion actually happened across every system rather than just the one someone remembered to check first.

The Australian context

Australia's Privacy Act reform, driven partly by recommendations following high-profile data breaches, is moving toward stronger individual rights over personal information, though it hasn't fully mirrored GDPR's erasure right yet. The Office of the Australian Information Commissioner (OAIC) already expects businesses to have reasonable processes for handling deletion requests, particularly for sensitive information. Businesses that already serve European Union customers are ahead of the curve simply because they had to build the muscle for GDPR compliance already.

Where people get this wrong

Deleting from the CRM and calling it done.Email platforms, ad audience lists, analytics tools and backups usually still hold the record. A partial deletion is not a completed erasure request.
Assuming Australian law doesn't require this at all.If any customer or user is based in the European Union, GDPR applies regardless of where the business operates. Local law reform is also narrowing this gap over time.
Ignoring third-party ad platforms in the deletion.Custom audiences and retargeting lists uploaded to Meta or Google often retain the data separately from your own systems. Deletion there requires a separate request to the platform.

Related terms

Common questions

Does the right to erasure apply to Australian businesses?

It applies if you hold data on European Union residents, regardless of where your business is based. Australia's own Privacy Act doesn't yet have an identical provision but is moving toward stronger individual data rights, so treating this as irrelevant locally is a short-term bet.

How long do I have to respond to an erasure request?

Under GDPR, generally one month, extendable in complex cases. There's no fixed Australian equivalent yet, but the Office of the Australian Information Commissioner expects a reasonable response time when handling any privacy request.

Do I have to delete data from backups too?

Under GDPR, yes, though backups are often handled with documented exceptions if immediate deletion isn't technically feasible. The expectation is that the data is deleted or made inaccessible within a reasonable cycle, not indefinitely retained.

What happens if I ignore a legitimate erasure request?

Under GDPR, this can result in regulatory penalties and reputational damage. In Australia, ignoring a reasonable privacy request can still trigger a complaint to the Office of the Australian Information Commissioner even without an identical erasure provision in law.

Debrief

Get the next one

No spam. No fluff. Just the next article, straight to your inbox.

Keep exploring

About New Rebellion

New Rebellion is a marketing intelligence consultancy. We build tools, score Australian businesses on how their marketing actually performs, and publish Debrief every day. This dictionary is part of how we work in the open.

How we think →