Right to Be Forgotten: What It Means for Your Data
Understand the right to be forgotten — what it covers, how to exercise it, and its implications for data storage and dead man's switches.
What Is the Right to Be Forgotten?
The right to be forgotten (RTBF), formally known as the right to erasure under GDPR Article 17, gives individuals the right to request that organizations delete their personal data under certain circumstances.
You can exercise RTBF when: • The data is no longer necessary for its original purpose • You withdraw your consent (if consent was the legal basis) • You object to processing and there are no overriding legitimate grounds • The data was unlawfully processed • Deletion is required to comply with a legal obligation
The organization must respond within one month and must also inform any third parties to whom the data was shared.
RTBF in Practice
How to exercise your right:
- Identify the organization holding your data
- Submit a deletion request (most organizations have a privacy contact or data subject access request form)
- Provide enough information to identify yourself (but not more than necessary)
- Wait for response (up to one month)
- Escalate to your national Data Protection Authority if the request is denied without valid reason
Exceptions where RTBF doesn't apply: • Freedom of expression and information • Compliance with a legal obligation • Public health purposes • Archiving in the public interest • Establishment, exercise, or defense of legal claims
For search engines: Google and other search engines accept RTBF requests to delist search results (not delete the underlying content). This is especially relevant for outdated or irrelevant personal information appearing in search results.
RTBF and Data Security Services
How does the right to be forgotten interact with services like ZeroLatch?
Account deletion: When you delete your ZeroLatch account, all your data (encrypted vaults, metadata, activity logs) should be permanently deleted.
Pre-release deletion: Before a vault is released, the owner can delete everything. This effectively exercises the right to erasure.
Post-release considerations: Once a vault has been released and recipients have downloaded the files, the data creator cannot unilaterally erase the recipients' copies. The right to erasure applies to the service, not to every person who has received the data.
client-side encryption advantage: With client-side encryption, even if the service retains encrypted data briefly during deletion processing, it's meaningless without the key — providing an additional layer of privacy protection.
ZeroLatch Editorial Team
Published by ZeroLatch to explain future delivery and continuity planning. These guides are not independent reviews of our product. Read our editorial standards and corrections.
Disclaimer: The information provided in this article is for educational and informational purposes only and does not constitute legal, financial, or technical advice. ZeroLatch is a software service, not a law firm. We recommend consulting with qualified professionals regarding your specific estate planning, data privacy, and security needs.
Help someone find what matters if you cannot respond
See a handoff with document locations, trusted contacts and first steps. ZeroLatch releases it to your chosen person after missed check-ins and a safety period. You can also explore business and digital-assets examples.
Write my instructions →Start a free draft without an account or card. Use harmless information. See the example first.