When your team receives a GDPR Article 17 deletion request, the clock starts ticking. You have one month to respond, and your answer must be documented, defensible, and technically accurate. This template provides a structured framework for responding to erasure requests, ensuring both the data subject and the regulator are satisfied.
A well-documented response process can be the difference between a warning and a fine. It's not just about compliance; it's about showing you took the request seriously, evaluated it correctly, and acted proportionately.
Purpose of the Template
This response template helps you evaluate a GDPR Article 17 right to erasure request. It guides you through the legal grounds for deletion, applicable exceptions, and the technical steps needed to execute or refuse the request. Use it when a data subject submits a deletion request via email, web form, or any other channel.
The template creates a written record of your decision-making process. If you delete the data, it shows you verified the requestor's identity and acted within the required timeframe. If you refuse, it documents which Article 17(3) exception applies and why.
Prerequisites
Before using this template, confirm:
- You've verified the requestor's identity using your standard authentication process (e.g., two-factor verification, credential matching, or a signed request from a known email address).
- You've located all systems where the individual's personal data is stored (e.g., CRM, marketing automation, analytics platforms, backup systems, third-party processors).
- You understand the legal basis originally used to process this data (e.g., consent, contract, legitimate interest, legal obligation).
- You have access to legal counsel if the request involves ongoing litigation, regulatory investigation, or complex contractual obligations.
Do not proceed with deletion until identity verification is complete. Deleting data for the wrong person creates a new breach.
The Template
GDPR ARTICLE 17 DELETION REQUEST EVALUATION
Request received: [DATE]
Requestor: [NAME / EMAIL / CUSTOMER ID]
Identity verified: [YES/NO] via [METHOD]
Response due: [DATE + 30 DAYS]
---
SECTION 1: DATA INVENTORY
List all systems containing the requestor's personal data:
System/Platform | Data Categories | Legal Basis | Retention Period
----------------|-----------------|-------------|------------------
[Example: CRM] | [Contact info, purchase history] | [Contract] | [7 years]
[Example: Analytics] | [Browsing behavior, device ID] | [Consent] | [2 years]
---
SECTION 2: DELETION ELIGIBILITY ASSESSMENT
Evaluate whether Article 17(1) grounds apply:
☐ (a) Data no longer necessary for the original purpose
☐ (b) Consent withdrawn and no other legal basis exists
☐ (c) Data subject objects under Article 21 and no overriding grounds exist
☐ (d) Data processed unlawfully
☐ (e) Legal obligation requires deletion
☐ (f) Data collected from a child for information society services
If ANY box is checked, proceed to Section 3.
If NO boxes apply, document why and skip to Section 4.
---
SECTION 3: EXCEPTION EVALUATION (Article 17(3))
Evaluate whether any exception prevents deletion:
☐ (a) Exercise of freedom of expression and information
☐ (b) Compliance with legal obligation or public interest task
☐ (c) Public health interest
☐ (d) Archiving, research, or statistical purposes with safeguards
☐ (e) Legal claims (establishment, exercise, or defense)
If ANY exception applies:
- Document the specific legal provision or contractual clause
- Explain why continued processing is necessary
- Specify which data categories the exception covers
- Set a review date for when the exception may no longer apply
---
SECTION 4: TECHNICAL DELETION PLAN
If deletion is required, specify:
1. Primary systems deletion: [List systems and deletion method]
2. Backup systems: [Specify whether backups will be flagged for deletion on next rotation or overwritten immediately]
3. Third-party processors: [List processors notified under Article 19]
4. Pseudonymized data: [Confirm whether re-identification is reasonably likely; if not, document why deletion is impossible]
5. Aggregated data: [Confirm data is truly anonymized and outside GDPR scope]
Deletion execution date: [DATE]
Executed by: [ROLE/NAME]
---
SECTION 5: COMMUNICATION TO DATA SUBJECT
[IF DELETION EXECUTED:]
"We have processed your deletion request received on [DATE]. Your personal data has been erased from [LIST SYSTEMS]. Backup copies will be overwritten during the next scheduled rotation on [DATE]. We have notified [NUMBER] third-party processors of your request under Article 19 GDPR."
[IF DELETION REFUSED:]
"We have reviewed your deletion request received on [DATE]. We are unable to delete your data because [SPECIFIC ARTICLE 17(3) EXCEPTION]. This exception applies to [SPECIFIC DATA CATEGORIES]. We will review this decision on [DATE] to determine whether continued retention remains necessary. You have the right to lodge a complaint with [SUPERVISORY AUTHORITY] if you disagree with this decision."
[IF PARTIAL DELETION:]
"We have processed your deletion request received on [DATE]. We have deleted [DATA CATEGORIES] from [SYSTEMS]. We are retaining [DATA CATEGORIES] because [SPECIFIC EXCEPTION]. You have the right to lodge a complaint with [SUPERVISORY AUTHORITY] if you disagree with this decision."
Response sent: [DATE]
Method: [EMAIL / POSTAL MAIL / SECURE PORTAL]
---
INTERNAL NOTES (not shared with data subject):
[Document any edge cases, legal consultation, or technical limitations encountered]
Customizing the Template
For consent-based processing: If data was collected under Article 6(1)(a) consent, deletion is usually required once consent is withdrawn. Exceptions are rare, such as ongoing legal claims or mandatory retention periods. Your Section 2 evaluation will be straightforward.
For contract-based processing: If data was collected to fulfill a contract (Article 6(1)(b)), you may retain data necessary for warranty claims, payment disputes, or ongoing service delivery. Document the specific contractual clause that requires retention and set a review date for when the contract obligation ends.
For legitimate interest processing: If you relied on Article 6(1)(f) legitimate interest, evaluate whether your interest overrides the individual's rights. If they object under Article 21, you must delete unless you can demonstrate "compelling legitimate grounds." Document your balancing test in Section 3.
For backup systems: Regulators understand that restoring backups solely to delete one record is disproportionate. Flag the record for deletion and document your next backup rotation schedule. If your backup retention exceeds your primary system retention by more than 90 days, address this compliance issue.
For AI training data: If personal data was used to train a machine learning model, evaluate whether the data is still identifiable within model weights. If the model underwent differential privacy, aggregation, or other anonymization, the data may no longer be personal data. If re-identification is likely, consider retraining the model or applying techniques like machine unlearning. Document your technical assessment.
Validation Steps
Before closing the request:
Verify deletion in each system. Don't rely on automated deletion scripts without spot-checking. Query each database to confirm the record no longer exists.
Confirm third-party processor notifications. If you share data with processors under Article 28, inform them of the deletion request unless it's impossible or requires disproportionate effort (Article 19). Log which processors you notified and when.
Review your response for Granularity. Vague language like "we've deleted your data as required" won't satisfy a regulator. Name the systems, explain the timeline, and cite the legal basis.
Archive the completed template. Store it with the original request email and any identity verification records. If a supervisory authority audits your deletion processes, this documentation shows you followed a structured, legally grounded approach.
Update your data inventory. If you discovered systems during this request that weren't in your Article 30 records of processing, add them. Every deletion request is an opportunity to improve your data map.
If you refused the request, set a calendar reminder for your review date. Exceptions don't last forever. When the legal claim resolves or the retention period expires, delete the data without waiting for a second request.



