GDPR data erasure: the right to erasure explained
GDPR gives people a right to have their data deleted. For storage, that means erasing it beyond recovery — and being able to prove you did.
Under Article 17 of the UK GDPR and EU GDPR, individuals have a right to erasure — commonly called the "right to be forgotten." When it applies, an organisation must delete the personal data it holds, and take reasonable steps to ensure anyone it shared the data with does the same.
What this means for storage media
"Deleting" a file isn't enough. A file that's been deleted from a filesystem still exists on the disk until it's overwritten — and anyone with recovery tools can often get it back. Under GDPR, erasure of personal data means rendering it unrecoverable.
When a device holding personal data is decommissioned — resold, recycled, or returned — the appropriate action is to sanitise the media, typically to a Purge-level outcome for anything leaving your control.
The accountability principle
GDPR doesn't just require you to erase; it requires you to be able to demonstrate compliance. The accountability principle (Article 5(2)) means the burden of proof is on you. An erasure report that shows which drives, when, and how — tied to serial numbers — is the practical way to meet that burden.
How tScrub supports GDPR erasure
- Purge-level erasure for drives leaving your control, recorded per drive.
- A chain-of-custody report with serial numbers, method, and final status.
- A certificate of destruction you can generate and file as evidence.
FAQ
Does the right to erasure always apply?
No — there are exemptions (legal obligations, public interest, and others). But where it applies, it's absolute: you must delete the data and demonstrate you did.
Is a signed report enough evidence for the ICO?
There's no single prescribed format, but a verifiable, tamper-evident report that ties erasure to specific devices is exactly the kind of evidence a regulator expects to see.