Right to Erasure vs Right to Access: Key Differences Explained

GDPR Article 15 vs Article 17 side by side. When each right applies, exemptions, handling combined requests, and a practical workflow for dual requests.

Last updated: 2026-09-13

Two Rights, Different Rules

The right of access and the right to erasure are the two most common DSAR types. They are also the most frequently confused. Both are exercised by individuals against the organizations that hold their personal data, both have the same one-month deadline under GDPR, and both are often submitted in the same request. But the rules governing each are different in important ways — particularly when it comes to exemptions, scope, and how you handle them operationally.

Disclaimer: This article is for informational purposes only and does not constitute legal advice. Privacy regulations are complex and change frequently. Consult a qualified attorney for guidance specific to your business. The information here is based on the GDPR (Articles 15 and 17), the UK GDPR, and ICO guidance as of the date of publication.

This guide puts the two rights side by side, explains when each applies, walks through the exemptions for each, and provides a practical workflow for handling combined access and erasure requests.

Article 15: Right of Access

GDPR Article 15 gives individuals the right to obtain confirmation of whether their personal data is being processed, and if so, access to that data along with specific supplementary information.

What the Individual Gets

When someone exercises their right of access, you must provide:

  1. Confirmation that you process their personal data (or confirmation that you do not)
  2. A copy of the personal data being processed
  3. The purposes of the processing
  4. The categories of personal data concerned
  5. The recipients or categories of recipients to whom data has been or will be disclosed
  6. The retention period or the criteria used to determine it
  7. Information about their other rights — erasure, rectification, restriction, objection
  8. The right to lodge a complaint with a supervisory authority
  9. The source of the data if not collected directly from the individual
  10. Whether automated decision-making (including profiling) is applied, and if so, meaningful information about the logic, significance, and consequences

When It Applies

The right of access is broad. It applies whenever an organization processes personal data about the individual making the request. There is no requirement for the individual to state a reason for their request. Under GDPR Recital 63, the right exists so individuals can be aware of and verify the lawfulness of processing.

Deadline

30 calendar days from receipt of the request (GDPR Article 12(3)). Extendable by up to 60 additional days for complex or numerous requests, provided the individual is informed within the first 30 days.

Article 17: Right to Erasure

GDPR Article 17 gives individuals the right to have their personal data deleted. It is sometimes called the "right to be forgotten," though the GDPR itself uses the term "right to erasure."

When Erasure Must Be Granted

The right to erasure applies when at least one of the following grounds exists:

  1. The data is no longer necessary for the purpose it was collected or processed for
  2. The individual withdraws consent and there is no other legal basis for processing
  3. The individual objects to processing under Article 21(1) and there are no overriding legitimate grounds, or the individual objects to direct marketing processing under Article 21(2) (this is absolute — no balancing test)
  4. The data was unlawfully processed — no valid legal basis ever existed
  5. Erasure is required to comply with a legal obligation under EU or member state law
  6. The data was collected from a child in relation to information society services (Article 8(1))

If none of these grounds apply, the organization can refuse the erasure request.

What Erasure Means in Practice

Erasure means permanently removing the personal data from all active systems. Under Article 17(2), if the data has been made public, the controller must take reasonable steps to inform other controllers processing the data about the erasure request. Under Article 19, you must notify anyone you have disclosed the data to about the erasure.

Backups present a practical complication. If selectively deleting data from encrypted backups is technically infeasible, most regulators accept documenting the backup retention cycle and ensuring the data is not restored from backups. This is not an exemption from erasure — it is a recognized approach to the technical challenge.

Deadline

Same as access: 30 calendar days, extendable by up to 60 days (GDPR Article 12(3)).

Side-by-Side Comparison

ElementRight of Access (Article 15)Right to Erasure (Article 17)
Core entitlementCopy of personal data + supplementary informationDeletion of personal data
Individual must state a reasonNoNo (but one of the six grounds in Art. 17(1) must exist)
Default positionMust provide unless exemption appliesMust delete if grounds are met and no exemption applies
Deadline30 days (extendable to 90)30 days (extendable to 90)
FeeFree for first copy; reasonable fee for further copies (Art. 15(3))Free
Third-party notificationNot requiredRequired under Art. 17(2) and Art. 19
Applies to backupsYes — must search backups if reasonably accessibleYes — but technical infeasibility of selective backup deletion is recognized

Exemptions: Where the Rights Diverge

The exemptions for each right are different, and this is where confusion most commonly arises.

Access Exemptions (Article 15(4) and DPA 2018 Schedule 2)

The GDPR itself provides limited exemptions to the right of access. Article 15(4) states that the right to obtain a copy "shall not adversely affect the rights and freedoms of others." This means you can withhold or redact data where providing it would disclose another person's personal data without their consent, or would reveal confidential information.

Under UK law, the Data Protection Act 2018 Schedule 2 adds several exemptions including:

  • Legal professional privilege — data subject to privilege can be withheld
  • Management forecasting — data related to management planning can be withheld if disclosure would prejudice the organization
  • Negotiations — data revealing the organization's negotiation intentions can be withheld
  • Confidential references — references given in confidence do not need to be disclosed
  • Crime and taxation — data processed for crime prevention or tax assessment can be withheld if disclosure would prejudice those purposes

Erasure Exemptions (Article 17(3))

Article 17(3) sets out specific circumstances where the right to erasure does not apply:

  • Freedom of expression and information — journalistic, academic, artistic, or literary purposes
  • Legal obligation — the data must be retained to comply with EU or member state law (e.g., tax records, regulatory retention requirements)
  • Public interest in public health — under specific conditions
  • Archiving, research, or statistics — in the public interest, subject to appropriate safeguards
  • Legal claims — data needed for the establishment, exercise, or defense of legal claims

The legal claims exemption is particularly common in practice. If there is a pending or reasonably anticipated legal dispute involving the data subject, retaining relevant data is justified even if they request erasure.

Key Difference

Access exemptions are primarily about what you can withhold from disclosure — you may still hold the data, you just do not have to show it. Erasure exemptions are about what you can retain — the data stays, and you do not have to delete it. An exemption that applies to access does not automatically apply to erasure, and vice versa.

For a detailed guide to all DSAR exemptions, see our exemptions guide.

When Both Rights Are Exercised Simultaneously

It is common for individuals to submit combined requests: "Tell me what data you hold about me, then delete it." This creates a sequencing challenge.

The Correct Approach

  1. Process the access request first. Compile the data, review it, apply access-specific exemptions, and provide it to the individual.
  2. Then process the erasure request. Delete the data from your systems, applying any erasure-specific exemptions.
  3. Both share the same deadline. The 30-day clock starts when you receive the combined request.

What Not to Do

Do not delete first and then claim you have nothing to disclose. This defeats the purpose of the access right and would likely be viewed by a regulator as a failure to comply with Article 15. The individual is entitled to know what data you held before you delete it.

Do not treat them as two separate requests with two separate deadlines. A combined request is one request exercising multiple rights. The 30-day deadline applies to the entire response.

Do not apply erasure exemptions to the access request. The fact that you can retain data under an Article 17(3) exemption does not mean you can withhold it from an access response. You may need to disclose data that you then continue to retain.

Practical Workflow for Combined Requests

Day 1: Log the request, calculate the deadline (30 days), send acknowledgment.

Days 1-5: Verify identity using proportionate measures.

Days 5-15: Search all systems on your data search checklist. Compile personal data found.

Days 15-20: Review compiled data. Apply access exemptions (redact third-party data, check for privilege). Separately assess which data falls under erasure exemptions.

Days 20-25: Prepare the access response package. Document which data will be disclosed, which will be redacted (and why), which will be deleted, and which will be retained (and why).

Days 25-28: Send the access response. Include a clear explanation of what data will be deleted and what will be retained under exemption.

Days 28-30: Execute the deletion. Notify third parties under Articles 17(2) and 19. Confirm deletion to the requester.

Post-response: File all records in your DSAR audit trail. See our record keeping guide.

Frequently Asked Questions

Can someone make repeated access requests? Yes, but under Article 12(5), if requests are "manifestly unfounded or excessive, in particular because of their repetitive character," you can charge a reasonable fee or refuse. The bar for this is high — the ICO has stated that merely being inconvenient does not make a request excessive.

Can someone request access to data you have already deleted? You can only provide what you currently hold. If data has been legitimately deleted in accordance with your retention policy before the request was received, you are not required to retrieve it.

Does the right to erasure apply under the CCPA? The CCPA provides a "right to delete" (Cal. Civ. Code § 1798.105) with its own set of rules and exemptions that differ from GDPR Article 17. The concepts are similar but not identical. See our guide on CCPA vs GDPR right to delete.

Related Guides

References

  • GDPR Article 15: Right of access by the data subject. Article 15
  • GDPR Article 17: Right to erasure. Article 17
  • GDPR Article 12: Transparent information, communication, and modalities. Article 12
  • ICO: Right of access guidance. ICO guidance
  • ICO: Right to erasure guidance. ICO guidance

Last reviewed: September 2026. Privacy laws change frequently. Verify all statutory references against the current text of the law and consult qualified legal counsel before making compliance decisions for your business.