Skip to main content
DPAs Keep Rejecting Erasure Requests: What Changed?Laws and Regulations
5 min readFor Compliance Managers

DPAs Keep Rejecting Erasure Requests: What Changed?

Over the past year, your team has likely dealt with more right-to-erasure and right-to-object requests than in all of 2022 combined. If you're concerned about whether your processes will withstand scrutiny, the EDPB's updated One-Stop-Shop case digest on these rights offers a reality check.

The digest now includes hundreds of new cross-border decisions, providing a clear picture of where organizations fail in handling Article 17 and Article 21 requests. These aren't theoretical gaps; they're the documented reasons DPAs issued corrective measures against controllers who thought their DSAR workflows were adequate.

Here's what compliance managers are asking after reviewing the updated digest and what the enforcement patterns reveal.

Understanding the Source of These Questions

The EDPB's Support Pool of Experts developed this digest to help DPAs coordinate enforcement across member states. It draws from the public register of Article 60 decisions, categorizing common infringements, corrective measures, and procedural failures.

If you're managing data subject requests for users in multiple EU countries, these patterns determine whether your next erasure denial results in a formal complaint.

Do You Have to Delete Data if the User Agreed to It?

Not if you have another legal basis for processing. This is where many teams stumble.

Valid consent under Article 6(1)(a) can be withdrawn at any time, triggering erasure under Article 17(1)(b). However, if you're processing the same data under Article 6(1)(b) (contract performance) or Article 6(1)(f) (legitimate interests), withdrawal of consent doesn't automatically require deletion.

The digest shows DPAs consistently reject erasure requests when the controller demonstrates an ongoing legal basis independent of consent. For example, you can't demand erasure of transaction records needed for tax retention obligations under Article 17(3)(b), even if you initially consented to marketing uses of that data.

Where organizations fail is in their response letters. If you deny an erasure request, you must cite the specific legal basis you're relying on and explain why Article 17(3) exceptions apply. Generic responses like "we need this data for business purposes" don't meet the Article 12(4) requirement to inform the data subject of the reasons for not taking action.

Responding to an Object Request Under Article 21

You have one month from receipt to respond, extendable by two months if the request is complex, according to Article 12(3).

The digest reveals that DPAs don't accept "we're still reviewing" as a valid reason for delay. If you invoke the two-month extension, notify the data subject within the first month and explain the specific complexity justifying the delay.

A common failure is treating objection requests like erasure requests. Under Article 21(1), when a data subject objects to processing based on legitimate interests or public interest tasks, you must stop processing unless you can demonstrate "compelling legitimate grounds" that override the individual's interests. The digest shows controllers frequently fail to document these grounds adequately.

For direct marketing under Article 21(2), there's no balancing test. If someone objects to direct marketing, you stop. No exceptions, no "compelling grounds" analysis required.

Recognizing a Valid Erasure Request

Any communication clearly expressing the data subject's wish to have their personal data deleted is valid, regardless of whether they cite "Article 17" or use the phrase "right to erasure."

The digest confirms DPAs expect you to recognize erasure requests even when users say "delete my account," "remove my data," or "I want everything gone." If the intent is clear, the request is valid.

Your obligation under Article 12(2) is to facilitate the exercise of rights, not to require data subjects to use specific legal terminology. Teams that reject requests because the user didn't fill out the official DSAR form or didn't reference the correct GDPR article are setting themselves up for enforcement action.

One procedural detail: if you can't verify the requester's identity using the information provided, you can ask for additional information under Article 12(6). But you can't demand government-issued ID as a default requirement if less intrusive verification methods would work.

Charging for Repeated Erasure Requests

You can charge only if the requests are "manifestly unfounded or excessive," and you'll need to demonstrate that clearly.

Article 12(5) allows you to charge a reasonable fee or refuse to act on requests meeting this threshold, but the digest shows DPAs interpret "manifestly unfounded or excessive" narrowly. Repeated requests aren't automatically excessive if circumstances have changed or if the initial response was inadequate.

What triggers the excessive standard: a data subject who submits near-identical erasure requests every week after you've already deleted the requested data and provided evidence of deletion. The pattern must show bad faith or an obvious intent to harass, not just persistence.

If you're going to refuse a request as excessive, document your reasoning thoroughly. DPAs expect you to show why the specific request meets the Article 12(5) standard, not just assert that the data subject is "being difficult."

Missing the One-Month Deadline

If you miss the deadline, you're in violation of Article 12(3), and the data subject can file a complaint with their supervisory authority.

The digest doesn't specify penalty amounts, but it shows that procedural failures around response timing are among the most frequent infringements identified in OSS decisions. DPAs view timely responses as fundamental to making rights effective, not as an administrative nicety you can skip when you're short-staffed.

If you genuinely need more time, invoke the two-month extension properly: notify the data subject within the first month, explain the complexity, and provide a specific timeline for when you'll complete the review. "We're working on it" doesn't satisfy Article 12(3).

Corrective Measures Issued by DPAs

The digest provides an overview of corrective measures, showing that DPAs are ordering organizations to bring their request-handling processes into compliance, not just to fix individual cases.

Typical corrective measures include orders to implement proper verification procedures, establish documented processes for assessing Article 17(3) exceptions, train staff on recognizing valid requests regardless of phrasing, and revise response templates to include specific legal reasoning rather than boilerplate language.

The enforcement trend is toward systemic fixes. If your erasure denial process failed once, the DPA wants assurance it won't fail the same way for the next hundred requesters.

Where to Go for More

The updated digest is available on the EDPB website as part of the Support Pool of Experts program resources. It's organized by infringement type and includes anonymized case summaries that show how DPAs analyzed specific fact patterns.

If your organization handles cross-border processing and you're subject to the One-Stop-Shop mechanism under Article 56, this digest is effectively a preview of how your lead supervisory authority will evaluate your DSAR processes. The corrective measures issued in past cases set the compliance baseline for future enforcement.

For teams building or auditing erasure workflows, the digest offers something more valuable than abstract guidance: it shows you exactly where other controllers failed and what DPAs expect you to do differently.

You Might Also Like