What Is the Right to Be Forgotten?

The right to be forgotten (RTBF), formally known as the right to erasure under GDPR Article 17, gives individuals the right to request that organizations delete their personal data under certain circumstances.

You can exercise RTBF when: • The data is no longer necessary for its original purpose • You withdraw your consent (if consent was the legal basis) • You object to processing and there are no overriding legitimate grounds • The data was unlawfully processed • Deletion is required to comply with a legal obligation

The organization must respond within one month and must also inform any third parties to whom the data was shared.

RTBF in Practice

How to exercise your right:

  1. Identify the organization holding your data
  2. Submit a deletion request (most organizations have a privacy contact or data subject access request form)
  3. Provide enough information to identify yourself (but not more than necessary)
  4. Wait for response (up to one month)
  5. Escalate to your national Data Protection Authority if the request is denied without valid reason

Exceptions where RTBF doesn't apply: • Freedom of expression and information • Compliance with a legal obligation • Public health purposes • Archiving in the public interest • Establishment, exercise, or defense of legal claims

For search engines: Google and other search engines accept RTBF requests to delist search results (not delete the underlying content). This is especially relevant for outdated or irrelevant personal information appearing in search results.

RTBF and Data Security Services

How does the right to be forgotten interact with services like ZeroLatch?

Account deletion: When you delete your ZeroLatch account, all your data (encrypted vaults, metadata, activity logs) should be permanently deleted.

Pre-release deletion: Before a vault is released, the owner can delete everything. This effectively exercises the right to erasure.

Post-release considerations: Once a vault has been released and recipients have downloaded the files, the data creator cannot unilaterally erase the recipients' copies. The right to erasure applies to the service, not to every person who has received the data.

Zero-knowledge advantage: With zero-knowledge encryption, even if the service retains encrypted data briefly during deletion processing, it's meaningless without the key — providing an additional layer of privacy protection.