GDPR
Chapter III - Rights of the Data Subject

GDPR GDPR-Art.17: Right to erasure (right to be forgotten)

Erase personal data without undue delay where the data is no longer necessary for the purposes it was collected or processed for, where consent is withdrawn and no other legal ground applies, where the data subject objects under Article 21(1) and there are no overriding legitimate grounds or objects to direct marketing under Article 21(2), where the data has been unlawfully processed, where erasure is required by Union or Member State law, or where the data was collected in relation to information society services offered to a child. Where the data has been made public, take reasonable steps including technical measures, allowing for available technology and the cost of implementation, to inform other controllers processing it that erasure of any links to, or copies or replications of, the data has been requested. The obligation does not apply to the extent processing is necessary for freedom of expression and information, for compliance with a legal obligation or a public interest task, for public health reasons, for archiving, research or statistics under Article 89(1) where erasure would seriously impair those objectives, or for the establishment, exercise or defence of legal claims.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

What else in your programme already covers this

This control maps to 58 controls across 38 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

NIST SP 800-53 Rev 5 · 4 controls

CCPA/CPRA · 3 controls

  • 1798.105(c) Delete on a verified request and pass deletion on
  • CCR 7022 Carry out deletion requests completely and explain any denial
  • §1798.105 Right to Delete Personal Information

SOC 2 · 3 controls

  • SOC2-C1.2 C1.2 Disposing of confidential information
  • SOC2-P4.2 P4.2 Retaining personal information
  • SOC2-P4.3 P4.3 Securely disposing of personal information

APPI · 2 controls

  • APPI-A34 Request for Correction, Addition or Deletion
  • APPI-A35 Request for Cessation of Use, Erasure or Cessation of Third Party Provision
  • AUCDR-PS-12 Privacy Safeguard 12 - Security of CDR data and destruction or de-identification of redundant CDR data
  • AUCDR-PS-4 Privacy Safeguard 4 - Dealing with unsolicited CDR data
  • APP-11 APP 11 - Security of personal information
  • APP-4 APP 4 - Dealing with unsolicited personal information
  • 5.2(d) 5.2(d) Delete raw biometric data effectively, on unauthorised access and at the device's end of life
  • 6.2.1 6.2.1 Erasure: erase on request when footage is no longer needed; blurring irreversibly counts
  • s4-5 s 4(5) Delete video data without delay once no longer needed
  • s75 s 75 Rectify and erase, and set time limits for erasure or review

ISO 27701:2019 · 2 controls

  • 7.3.6 Access, correction and/or erasure
  • 7.4.5 PII de-identification and deletion at the end of processing
  • UZB-DPL-10 Data Subject Rights
  • UZB-DPL-15 Retention and Destruction
  • MALABO-Art19 Data Subject Right of Rectification and Erasure
  • AL-DPA-8 Right of Rectification and Erasure
  • AO-PDPL-8 Right of Rectification, Erasure and Blocking
  • 5.1(b) 5.1(b) Recruitment data deleted once no offer is made or it is declined
  • MYHR-GOV-5 Retention, destruction and correction obligations of the System Operator

Bahrain PDPL · 1 control

C5 (Germany) · 1 control

  • C5-OPS-12 Logging and Monitoring - Access, Storage and Deletion
  • SD134-11 Secure Disposal
  • CAYDPA-s14 Rectification, Blocking, Erasure or Destruction (s.14)
  • CL21719-A5c Right of Cancellation/Erasure (Art. 5 lit c)
  • CSL-Art43 Right to Correction and Deletion - Art. 43
  • PIPL-Art47 Right to Deletion
  • AUCDR-OB-5 Deletion or de-identification of redundant data

FedRAMP High · 1 control

  • MP-6 Media Sanitization

FedRAMP Moderate · 1 control

  • MP-6 Media Sanitization
  • UAE-PDPL-Art.11_12_13_14_15_16 Data subject rights (UAE PDPL Articles 11-16)
  • 8.5 8.5 Retain only as long as the purpose justifies

ISO 27001:2022 · 1 control

  • 8.10 Information deletion

ISO 27002:2022 · 1 control

  • 8.10 Information deletion

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in Chapter III - Rights of the Data Subject

You are reading one control. How much of GDPR have you already done?

GDPR GDPR-Art.17 is one control. If you already hold one of the frameworks below, a reviewed crosswalk already says how much of GDPR your existing evidence covers. Hold ISO 27701:2019 and 21 of 41 GDPR controls already carry evidence.

Each report names every control your existing framework evidences, every one it does not, the reasoning behind each claim, and the claims that were argued against and rejected. 0 were rejected on the ISO 27701:2019 pair alone.

Query this from an agent

The graph holds this control, the 58 it maps to, and the evidence behind each claim, over MCP and REST.