Someone Has Asked Me to Delete Their Data

Someone Has Asked Me to Delete Their Information. Do I Have To?

A helpful guide

💭 Ask yourself...

"Why am I still keeping this information?"

If you can answer that question clearly...

You're already halfway to making the right decision.

 

Short answer

If someone asks you to delete their personal information, don't panic—and don't start deleting records immediately.

The Right to Erasure is an important right under UK GDPR, but it isn't absolute.

In many situations, organisations have a legal, contractual or regulatory obligation to keep certain information, even when someone asks for it to be deleted.

The key is understanding why you're keeping the information and whether that reason still applies.

 

Why is this important?

One of the biggest mistakes organisations make is assuming that every request to delete information must be granted immediately.

In reality, deleting information too quickly can sometimes create more risk than retaining it.

For example, you may destroy information that you:

  • are legally required to keep; 
  • need to defend a legal claim; 
  • require for tax or employment purposes; 
  • must retain for regulatory reasons. 

Good data protection isn't about deleting information at the first opportunity.

It's about keeping information only for as long as you genuinely need it—and no longer.

 

When should I delete personal information?

You should consider deleting personal information when:

  • It is no longer needed for the purpose it was collected. 
  • Consent has been withdrawn and there is no other lawful basis for keeping it. 
  • The information has been processed unlawfully. 
  • The applicable retention period has expired. 

 

When might I need to keep it?

There are many situations where you may be justified—or legally required—in retaining information.

Examples include:

  • Tax and accounting records. 
  • Employment records. 
  • Ongoing complaints or disputes. 
  • Actual or anticipated legal claims. 
  • Regulatory investigations. 
  • Fraud prevention and detection. 
  • Anti-money laundering obligations. 
  • Other legal obligations that require records to be retained. 

The question isn't simply:

"Has someone asked me to delete this?"

It's also:

"Do I still have a lawful reason—or a legal obligation—to keep it?"

 

Practical examples

Example 1

A customer withdraws consent to receive marketing emails.

You should usually stop marketing to them and remove them from your marketing list.

However, you may still need to retain limited information so you can ensure they aren't contacted again. This is often called a suppression list.

 

Example 2

A former employee asks you to delete all of their HR records immediately after leaving.

Not necessarily.

Many employment and tax records must be retained for specific periods to comply with legal obligations and protect both the employer and employee.

 

Example 3

A customer makes a complaint and then asks you to delete all of their information.

Usually not immediately.

You may need to retain relevant information while the complaint is being investigated or in case legal proceedings arise.

 

Common Misconceptions

"If someone asks me to delete their information, I have to delete everything immediately."

No.

The Right to Erasure isn't absolute. Always consider whether you have a legal or regulatory reason to retain the information before deleting it.

 

"Deleting information is always the safest option."

Not necessarily.

Deleting information you are legally required to retain can create significant legal, regulatory and operational risks.

 

"Once a customer relationship ends, I should delete everything."

Not always.

Many records should be retained for a period after a relationship ends to comply with legal obligations or defend potential legal claims.

 

"If I don't need the information anymore, I should keep it just in case."

Usually not.

Keeping information "just in case" is rarely a good reason to retain personal information. If you no longer need it and there is no other lawful reason to keep it, it should usually be securely deleted or anonymised.

 

"Deleting a file means it's gone forever."

Not always.

Depending on your systems, copies may still exist in backups, archives or other locations. Your retention and deletion processes should take account of where personal information is stored.

 

Practical steps

  1. Understand exactly what the individual is asking you to delete. 
  2. Identify the information you hold. 
  3. Ask why you are keeping that information. 
  4. Check whether any legal, contractual or regulatory obligations require you to retain it. 
  5. Delete information that is no longer required. 
  6. Explain your decision clearly to the individual. 

 

🤝 Need a little support?

Requests to delete personal information often involve balancing individual rights with legal and regulatory obligations. Taking a little time to understand why the information is held before making a decision can help prevent unnecessary risk.

If you're unsure whether information should be retained or deleted, or you're reviewing your retention schedule, we're here to help.

Sometimes a short conversation can prevent a well-intentioned decision from creating a much bigger problem.

Information icon

We need your consent to load the translations

We use a third-party service to translate the website content that may collect data about your activity. Please review the details in the privacy policy and accept the service to view the translations.