The Conventional Wisdom
Many privacy teams treat AI prompt logs like toxic waste. When someone submits a deletion request, they search every prompt, purge every mention, and document the destruction. This approach stems from a fear of GDPR Article 17, which gives individuals the right to erasure. Nobody wants to explain to a regulator why they kept personal data after a deletion request.
The logic seems straightforward: you processed someone's data through an AI system, they want it gone, so you delete it. Privacy forums and vendor guidance reinforce this view. Some CMP providers even suggest integrating prompt-scanning tools into your DSAR workflow. The assumption is that keeping any record of a prompt containing personal data after a deletion request is non-compliant by default.
Why This Approach Is Incomplete
This blanket approach misunderstands how Article 17 actually works. The right to erasure isn't absolute; it's conditional. You're only required to delete data when specific circumstances apply, depending on your Legal Basis for Processing.
If you processed personal data in an AI prompt based solely on consent, you'll likely need to honor the deletion request. But if you have another permissible legal basis and haven't violated any other GDPR requirement, you can decline the request. Article 17 doesn't say "delete on request." It says delete when one of six enumerated conditions is met.
Here's what's often missed: most enterprise AI use cases don't rely on consent as the sole legal basis. You might be processing employee data to manage performance reviews, analyzing customer service transcripts to improve response times, or feeding contract clauses into a model to identify risk. These scenarios typically rest on contract performance, legitimate interest, or legal obligation, not consent.
The Evidence
Article 6(1) establishes six lawful grounds for processing. Consent is just one. When you process data under legitimate interest (Article 6(1)(f)), an individual can request deletion, but you don't have to comply if your interest is "demonstrably overriding." If you're processing to fulfill a contract (Article 6(1)(b)), the individual's deletion request doesn't override your need to maintain records necessary for that contract.
The GDPR states that erasure requests must be honored when processing is based "solely on consent" or when legitimate interest is outweighed by individual rights. Notice the qualifier: solely. If you have an additional permissible purpose beyond consent, Article 17(1) doesn't automatically require deletion.
Article 17(3) provides explicit exceptions. You can decline an erasure request if honoring it would interfere with a legal obligation to maintain the data, or if the data is needed to establish, exercise, or defend a legal claim. Consider an AI system that analyzes HR complaints for patterns of discrimination. Even if a complainant requests deletion, you may have a legal obligation to retain those records for employment law compliance.
The provision requiring deletion of unlawfully processed data is almost redundant. If you're processing lawfully under one of the Article 6 bases, this condition doesn't apply. If you're processing unlawfully, you already have a compliance problem that exists independent of any deletion request.
What to Do Instead
Start by documenting your legal basis for each AI processing activity. Don't default to consent just because it feels simpler. If you're using AI to fulfill a contract, improve a service, or comply with a legal requirement, document that basis in your Records of Processing Activities.
When a deletion request arrives, evaluate it against your documented legal basis:
Consent-only processing: If consent was your sole basis and you kept prompt logs, you'll need to search and delete (unless an Article 17(3) exception applies).
Legitimate interest: Conduct a balancing test. Can you demonstrate that your interest in retaining the prompt data overrides the individual's rights? Document this analysis. If you're retaining prompts for model training, audit trails, or quality assurance, articulate why that interest is compelling and proportionate.
Contract or legal obligation: If you need the prompt data to perform a contract or comply with law, you can decline the request. Document the specific obligation.
Legal claims: If the prompt data is relevant to defending against a discrimination claim, a regulatory inquiry, or litigation, Article 17(3)(e) permits retention.
For prompt logs you do retain, implement retention schedules tied to your processing purpose. Don't keep everything forever just because you can. If your legitimate interest was improving a specific model and that work is complete, delete the prompts even without a request.
Build a decision tree for your DSAR team. When they receive a deletion request mentioning AI systems, the first question shouldn't be "which prompts do we search?" It should be "what was our legal basis for that processing?"
When the Conventional Wisdom Is Right
If you're processing personal data in AI prompts based solely on consent, particularly in consumer-facing applications, the conventional approach is correct. You should maintain searchable prompt logs and honor deletion requests promptly.
The same applies if you can't articulate a legitimate interest that survives a balancing test. "We might want it later" isn't a legitimate interest. "We use it for ongoing fraud detection as part of our contract performance obligation" is.
If your processing has become unlawful (you exceeded the stated purpose, you lost your legal basis, or you violated another GDPR requirement), you're required to delete regardless of the original basis. Don't wait for a deletion request; fix the unlawful processing immediately.
And if you're handling data from children under 16 collected through information society services, Article 17(1)(f) requires deletion on request. No balancing test, no legitimate interest override.
The key distinction: evaluate each deletion request against your specific legal basis and processing context. Don't treat AI prompts as categorically different from other processing activities. The same Article 17 framework applies; you just need to apply it correctly.





