Right to Erasure
Data & TrackingAlso: Right to be Forgotten · Data Deletion Request
Quick definition
Right to erasure is a person's ability to ask an organisation to delete the personal data it holds about them. It comes from the European Union's General Data Protection Regulation (GDPR) and is sometimes called the right to be forgotten. Australian businesses encounter it when they hold data on European Union residents or when local privacy reform mirrors the concept.
How it varies across Australia
Most Australian businesses have no formal deletion workflow at all, relying on ad hoc manual removal when someone complains. Businesses with mature data and tracking practices tend to have this built into their customer relationship management (CRM) and email platforms from the start rather than bolted on after a request arrives.
See data and tracking maturity across Australian industries →What it actually means
Right to erasure sounds like a single button. In practice it's a scavenger hunt through every system that ever touched a person's data.
The request usually starts simple. Someone emails asking you to delete everything you hold on them. The complexity shows up in the follow-through. Their record sits in your CRM, your email marketing platform, your analytics tool, a spreadsheet someone exported eighteen months ago, and probably a backup that runs on its own schedule regardless of what you promise a customer.
This is where erasure connects to consent and to first-party data more broadly. If you never mapped where personal data flows in the first place, you can't credibly claim you've deleted it everywhere. Attribution systems and customer relationship management (CRM) tools are the two places businesses most often forget to check, because both were built for marketing convenience, not privacy compliance.
Australia doesn't have a direct legal equivalent to GDPR's right to erasure baked into the Privacy Act the same way, but that gap is closing. Businesses serving European Union residents already owe this obligation regardless of where the business is based. Treating erasure as a GDPR-only problem is a bet that local law won't catch up. It's catching up.
A right to erasure request is a stress test for your data map. Most businesses fail it because they never drew the map in the first place.
How it shows up
Erasure shows up as a support ticket, a privacy officer email, or a formal complaint if it's ignored. It also shows up in your data audit trail, or the absence of one, when you try to prove a deletion actually happened across every system rather than just the one someone remembered to check first.
The Australian context
Australia's Privacy Act reform, driven partly by recommendations following high-profile data breaches, is moving toward stronger individual rights over personal information, though it hasn't fully mirrored GDPR's erasure right yet. The Office of the Australian Information Commissioner (OAIC) already expects businesses to have reasonable processes for handling deletion requests, particularly for sensitive information. Businesses that already serve European Union customers are ahead of the curve simply because they had to build the muscle for GDPR compliance already.
Where people get this wrong
Related terms
Common questions
Does the right to erasure apply to Australian businesses?
It applies if you hold data on European Union residents, regardless of where your business is based. Australia's own Privacy Act doesn't yet have an identical provision but is moving toward stronger individual data rights, so treating this as irrelevant locally is a short-term bet.
How long do I have to respond to an erasure request?
Under GDPR, generally one month, extendable in complex cases. There's no fixed Australian equivalent yet, but the Office of the Australian Information Commissioner expects a reasonable response time when handling any privacy request.
Do I have to delete data from backups too?
Under GDPR, yes, though backups are often handled with documented exceptions if immediate deletion isn't technically feasible. The expectation is that the data is deleted or made inaccessible within a reasonable cycle, not indefinitely retained.
What happens if I ignore a legitimate erasure request?
Under GDPR, this can result in regulatory penalties and reputational damage. In Australia, ignoring a reasonable privacy request can still trigger a complaint to the Office of the Australian Information Commissioner even without an identical erasure provision in law.
Debrief
Get the next one
No spam. No fluff. Just the next article, straight to your inbox.
Keep exploring
About New Rebellion
New Rebellion is a marketing intelligence consultancy. We build tools, score Australian businesses on how their marketing actually performs, and publish Debrief every day. This dictionary is part of how we work in the open.
How we think →