
Right to Erasure: GDPR, KVKK & Backup Compliance Explained
Intro: What Is the Right to Erasure?
The “Right to Erasure” (often called the Right to be Forgotten) is one of the most important data subject rights under privacy law, helping individuals maintain control over their personal data. Under Article 17 of the GDPR, individuals can request that organizations erase their personal data when specific conditions are met. This right is not only a procedural request but reflects deeper compliance requirements linked to data lifecycle management and records retention.
1. GDPR Overview — Who Can Ask for Data Deletion?
Under the GDPR, a person may request erasure if:
🔹 Personal data is no longer necessary
🔹 Consent is withdrawn
🔹 Processing was unlawful
🔹 The person objects and no overriding interest justifies processing
🔹 The data must be erased by law
These rules ensure individuals have meaningful control over digital traces about them — but the right is not absolute. Exceptions include freedom of expression, public interest, legal obligations, and scientific research exemptions.
2. How the Right to Erasure Works in Turkish Law (KVKK)
Turkish Personal Data Protection Law (KVKK) does not have a separate clause titled “Right to Erasure.” Instead, the right is derived from:
🔹 Article 11 — Data subject rights
🔹 Article 7 — Data erasure, destruction, or anonymization
Under KVKK, individuals can request that their personal data be removed, and data controllers must erase or destroy data when processing grounds no longer exist — even without a specific request. This dual approach means in Türkiye, erasure is both a right and a controller obligation.
3. Why Back-Up Compliance Matters
A major GDPR compliance challenge highlighted by the European Data Protection Board (EDPB) is managing erasure in back-up systems. Many organizations satisfy erasure obligations in live systems but leave data in backups indefinitely.
However:
✔ Back-ups are part of personal data processing
✔ Erasure obligations extend to backups
✔ If erased data is restored later, it must be erased again
Organizations may not have to instantly purge backups, but they must control them, define retention periods, and prevent unauthorized reuse — otherwise, the right to erasure becomes ineffective.
4. Common Compliance Issues in Practice
According to the EDPB report, common problems include:
🔸 Missing documented erasure procedures
🔸 Lack of staff training
🔸 Poor communication to data subjects
🔸 Undefined retention periods
🔸 Misapplication of legal exceptions
🔸 Treating account closure as actual deletion
These all point to one conclusion: the right to erasure is not a ticket-based task; it’s a data governance and compliance program issue.
5. Best Practices for Organizations
An effective erasure regime should include:
✔ Written erasure policy and procedures
✔ Centralized request tracking
✔ Defined retention matrices by data category
✔ Backup retention schedules
✔ Automated re-erasure mechanisms after restores
✔ Access restriction on backup environments
Aligning these practices with ISO 27001 and ISO 27701 strengthens compliance by integrating privacy into information security and risk management.
Conclusion
The Right to Erasure is more than a checkbox — it represents a core privacy principle: personal data should not be stored indefinitely when its legal basis disappears. Companies that treat this right as a governance function — not just a ticket resolution — will significantly reduce compliance risk and build trust with users.