Obtainer
Blog / Templates 11 min read

GDPR Right to Erasure Response Template: Copy, Adapt, Send

Last updated July 2026 · Obtainer

Request Studio
Requester
Compiled the manifest and drafted the response - illustrative sample request
0
records found
0
systems scanned
Data manifest
Response draft

Assembling the cover letter from the template...

You approve what is disclosed before anything ships

Helps you comply, not legal advice

A GDPR right to erasure response template is the letter you send back when someone asks you to delete their personal data. There are only three versions you ever need: erasure confirmed, erasure partly refused, and erasure refused. Each has to say what you did, what you kept, why you kept it, and how the person can challenge you. This page gives you all three, plus the Article 17 wording worth keeping.

This is general information, not legal advice. Adapt the language to your organization, your lawful bases, and the advice of your own counsel.

What every erasure response has to contain

Whatever the outcome, a compliant reply carries the same skeleton. If a paragraph in your draft does not serve one of these jobs, cut it.

ElementWhy it is there
Confirmation you received the request and whenAnchors the one-month clock and shows you did not sit on it
Confirmation of identity checkShows you did not act on an unverified request
What you erasedThe substance of the response
What you retained, and the ground for itA refusal without a stated reason reads as non-compliance
Whether you told other recipientsArticle 19 requires it unless it is impossible or disproportionate
Right to complain to a supervisory authorityRequired, and its absence is a common finding against controllers
A named contactGives the person somewhere to go other than the regulator

Send it in writing, keep a copy, and record the date. The record matters as much as the letter, because the burden of showing you complied sits with you, not with the requester.

Template 1: erasure confirmed

Use this when you erased everything the request covered and you are keeping nothing.

Dear [Name],

We received your request to erase the personal data we hold about you on [date received]. We confirmed your identity on [date verified].

We have now erased the personal data we held about you across our systems. This includes [describe the categories in plain terms, for example: your account record, your contact details, your order history, and your support correspondence].

Where your data had been shared with other recipients, we have communicated your erasure request to them, as required by Article 19 of the GDPR.

[If applicable] Copies of your data may persist in secure backups for a limited period. These backups are not used for any live processing, your data has been excluded from restoration, and the copies will be overwritten in the normal backup cycle, which completes within [period].

If you are unhappy with how we handled your request, you can contact us at [contact], and you have the right to lodge a complaint with your supervisory authority, [name the authority if known].

Yours sincerely,
[Name, role]

The backup paragraph is the one most teams leave out, and it is the one most likely to prevent a follow-up complaint. Do not claim a clean total wipe if data is still sitting in a nightly snapshot. Say what is true.

Template 2: erasure partly refused

This is the most common response in practice. You delete most of it, and you keep a defined slice because the law lets you or requires you to.

Dear [Name],

We received your request to erase the personal data we hold about you on [date received], and we confirmed your identity on [date verified].

We have erased [describe what was deleted, for example: your marketing profile, your contact preferences, and your support correspondence].

We have retained a limited set of your personal data, and we are not able to erase it at this time. Specifically:

[Data category], retained because [ground, for example: we are required to keep transaction records for [period] to comply with a legal obligation under [law]]. We will erase this data when that obligation ends, which we expect to be [date or trigger].

This retained data is not used for any other purpose, including marketing or profiling.

Where your erased data had been shared with other recipients, we have communicated your request to them under Article 19 of the GDPR.

If you disagree with our decision to retain this data, you can contact us at [contact]. You also have the right to lodge a complaint with your supervisory authority, [authority], and to seek a judicial remedy.

Yours sincerely,
[Name, role]

Two details make this letter defensible. First, you name the specific ground rather than gesturing at "legal reasons." Second, you say when the retention ends. A retention with no end date looks like a refusal dressed up as a delay.

Template 3: erasure refused

Full refusals are rare, and they attract scrutiny, so the reasoning has to be explicit.

Dear [Name],

We received your request to erase the personal data we hold about you on [date received], and we confirmed your identity on [date verified].

We have considered your request and we are not able to erase your personal data. The right to erasure under Article 17 of the GDPR does not apply where processing is necessary for [state the exception you rely on, for example: compliance with a legal obligation to which we are subject, or the establishment, exercise, or defence of legal claims].

In this case, [explain concretely, for example: we are required to retain your transaction records for seven years under [law], and the retention period ends on [date]].

We will erase your data once that period ends. In the meantime, your data is not used for [marketing, profiling, or any other secondary purpose].

You may also have other rights that we can act on now, such as the right to restrict processing or to object to it. If you would like us to consider either, tell us.

If you disagree with this decision, you can contact us at [contact], lodge a complaint with [supervisory authority], or seek a judicial remedy.

Yours sincerely,
[Name, role]

Notice the offer at the end. When you refuse erasure, pointing the person to restriction or objection is both good practice and good sense: it often resolves what they actually wanted without you deleting a record you are obliged to keep.

The exceptions you are allowed to rely on

You can only refuse on a ground the regulation gives you. Under Article 17(3), the right to erasure does not apply where processing is necessary for freedom of expression and information, compliance with a legal obligation or a task carried out in the public interest, reasons of public interest in public health, archiving in the public interest or scientific, historical, or statistical research, or the establishment, exercise, or defence of legal claims.

Two of those do nearly all the work in a commercial setting: the legal obligation ground, for tax and accounting records, and the legal claims ground, for anything you may need if a dispute lands. If you find yourself reaching for public interest or research to justify keeping a customer's marketing profile, the ground almost certainly does not fit, and the exemption question is worth a closer read in the guide on DSAR exemptions.

How long do I have to respond?

You must act without undue delay and at the latest within one month of receiving the request. You can extend that by two further months where the request is complex or where you have received a number of requests, but you have to tell the person within the first month and explain why. The clock starts when the request arrives, not when you get around to verifying identity, so a slow verification eats your own time.

If your organization tracks erasure alongside a stack of other regulatory duties, it helps to keep those obligations and their deadlines in one register rather than scattered across owners' calendars, in the same way you would map every obligation to the control that satisfies it. For the erasure clock specifically, deadline tracking that starts the moment the request lands is the cheapest insurance you can buy.

Do I have to confirm in writing that the data was deleted?

Yes, in substance. The GDPR requires you to inform the person of the action taken on their request, and doing that in writing is the only version you can later prove. A short letter naming what you erased, what you kept, and why is enough. You do not have to produce a technical deletion log or a screenshot of an empty database, but you should be able to show internally what was erased and when.

What if the data is in our backups?

Regulators accept that you cannot surgically pull one person's record out of an immutable backup the day a request arrives. The accepted approach is to put the data beyond use: delete it from live systems, flag it so it is not restored if you ever roll back, and let the backup age out on its normal cycle. Say this plainly in your response, give the person a rough timeframe, and make sure the data really does not return. A restore that quietly resurrects an erased record is the failure this paragraph is meant to prevent.

Can we charge for an erasure request?

Almost never. Erasure requests are free. You can charge a reasonable fee, or refuse, only where a request is manifestly unfounded or excessive, for example where the same person submits repetitive requests. That bar is high and it is on you to justify it, so treat a fee as an exception you will rarely use rather than a standard policy.

Turning the template into a repeatable process

The letter is the easy part. The work sits underneath it: finding every system that holds the person's data, deciding what falls under an exception, actually erasing the rest, notifying the recipients you shared it with, and keeping proof. Do that by hand across a CRM, a help desk, a warehouse, and a mailing list, and the one-month clock disappears fast.

That is the workflow data deletion request software exists to run. Obtainer verifies the requester, discovers where the person's data lives across your systems, flags the records that a statutory exception covers, routes the rest for erasure, and produces a dated record of what was deleted and what was kept. Nothing is erased automatically, because deletion cannot be undone: a person approves every erasure at the review gate. If you want the background on the right itself before you write the letter, start with the guide to the right to erasure and the GDPR right to be forgotten, and if the request is Californian rather than European, the rules differ, so read the CCPA right to delete instead.

Run a data subject access request end to end

Obtainer finds where a person's data lives across your systems, compiles it into one manifest, drafts the deadline-safe response, and tracks the GDPR and CCPA clock. You review, redact, and approve what gets disclosed. Helps you comply; not legal advice.