Skip to content
English
By RightEuropean rights, in situation
ODERSA association · Taking Part programmeIndependent educational site. Not an official website of the European Union.

The written walkthrough

The account they refuse to erase: the written walkthrough

An account they refuse to erase is not a technical problem. Erasure is an obligation that rests on them, the request costs nothing, they have one month to tell you what action they took, and it is up to them to prove your request is abusive.

Law as verified onJuly 29, 2026

This walkthrough contains the answers. It is here so you can read the situation without playing it, print it, and so the content stays complete without JavaScript.

Item no. 1 · The only button on offer

Six years of an account on a photo sharing network, 412 photos online, and the urge to be out of it for good. You live in Belgium. The service itself is established in another country of the Union.

In the settings you look for “delete my account”. There is no “delete my account”. There is “deactivate my account”, and one sentence in pale grey under the button.

Account settingsPrivacy and data
Account open for
six years
Photos online
412
Option offered
Deactivate my account
Deletion option
nowhere to be found
Sentence in pale grey
Deactivation hides your profile. Your content is retained.
Article quoted by the service
none

You want that data gone, not asleep. What do you do?

Correct answer · I write to the service asking for erasure, and I name the ground I am relying on.

Erasure is not a menu option, it is an obligation that rests on them The text runs both ways in the same sentence: you have the RIGHT to obtain erasure, and the controller has the OBLIGATION to erase, without undue delay. One of the grounds on the list is enough, and the first two are disarmingly ordinary: the data are no longer necessary in relation to the purposes, or you withdraw the consent the processing was based on. What triggers the right is not a button: it is your request.

“1. The data subject shall have the right to obtain from the controller the erasure of personal data concerning him or her without undue delay and the controller shall have the obligation to erase personal data without undue delay where one of the following grounds applies: (a) the personal data are no longer necessary in relation to the purposes for which they were collected or otherwise processed; (b) the data subject withdraws consent on which the processing is based […] and where there is no other legal ground for the processing; […] (d) the personal data have been unlawfully processed;”

In plain words: finding the right button is not your job, erasing when you ask is theirs. “The obligation to erase” is the wording of the text, not a generous reading of it.

Article 17(1) · Regulation (EU) 2016/679, Article 17 (Right to erasure, 'right to be forgotten'), paragraph 1 · https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:32016R0679

Myth · I click “Deactivate”: the profile disappears, so the data must go with it.

The best established myth in the settings menu: “deactivating is deleting” The sentence in pale grey under the button was telling the truth: deactivation hides the profile, it retains the content. The Regulation, for its part, knows nothing about deactivation. It knows one verb, erase, and it turns it into an obligation resting on the controller. A hidden profile is still a profile whose data are retained.

“The data subject shall have the right to obtain from the controller the erasure of personal data concerning him or her without undue delay and the controller shall have the obligation to erase personal data without undue delay where one of the following grounds applies”

In plain words: the text says “erase”, not “hide”. As long as the data are retained the obligation is not met, whatever state your profile is shown in.

Article 17(1) · Regulation (EU) 2016/679, Article 17 (Right to erasure, 'right to be forgotten'), paragraph 1 · https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:32016R0679

Myth · Erasure is something you get with a serious reason. I have nothing dramatic to point to.

The myth: “you need a good reason” The official EU page sums the condition up in one line, and it asks for no drama at all: data that are no longer needed is enough. The Regulation says the same thing and names a second ground that is just as ordinary, the withdrawal of the consent the processing was based on. What is expected of you is not a justification: it is naming the ground you rely on.

“If your personal data is no longer needed or is being used unlawfully then you can ask for your data to be erased. This is known as "the right to be forgotten".”

In plain words: “no longer needed” is a ground in its own right. You do not have to tell your life story to obtain an erasure.

Section “Deleting your personal data” · Data protection: deleting your personal data (the right to be forgotten) · https://europa.eu/youreurope/citizens/consumers/internet-telecoms/data-protection-online-privacy/index_en.htm

Item no. 2 · First prove that you are you

Four days later a reply arrives. It does not say no. It asks for documents.

The message is signed “compliance team”. It sets out a procedure and quotes no article.

Reply from the serviceRequest No D4K-QX7

Before any processing of your request, please send us: a photograph of your identity card (front and back), a selfie holding that document, a recent proof of address and a bank statement.

A handling fee of 15 € applies to permanent deletion requests. Payment is made from your customer area.

Without these items your request will be closed with no further action.

An identity card, a selfie, a bank statement and 15 €. What do you do?

Correct answer · I reply from the account address, I ask them which doubt they have about my identity, and I stick to what is necessary.

They may check your identity, but the text sets two limits The Regulation does allow a check, and it frames it with two words nobody reads. There must be REASONABLE doubts concerning your identity, and the information requested must be NECESSARY to confirm it. Meeting that condition is their job, not yours. And “necessary to confirm the identity” is a measure, not a list of documents: nothing stops you from asking how each item meets it.

“6. Without prejudice to Article 11, where the controller has reasonable doubts concerning the identity of the natural person making the request referred to in Articles 15 to 21, the controller may request the provision of additional information necessary to confirm the identity of the data subject.”

In plain words: an identity check yes, a full file no. Ask which doubt they have, supply what clears that doubt, and nothing more.

Article 12(6) · Regulation (EU) 2016/679, Article 12 (Modalities for the exercise of the rights), paragraph 6 · https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:32016R0679

Myth · I pay the 15 €: that is the price of a quiet life.

The myth: “an erasure has to be paid for” The first sentence of the paragraph leaves no room: it shall be provided free of charge. The text does allow an exception, and it is narrow: requests that are manifestly unfounded or excessive, in particular because of their repetitive character. Then it adds the sentence that turns the table over: the controller shall BEAR THE BURDEN of demonstrating that character. So it is not for you to prove your request is legitimate.

“5. Information provided under Articles 13 and 14 and any communication and any actions taken under Articles 15 to 22 and 34 shall be provided free of charge. Where requests from a data subject are manifestly unfounded or excessive, in particular because of their repetitive character, the controller may either: (a) charge a reasonable fee taking into account the administrative costs of providing the information or communication or taking the action requested; or (b) refuse to act on the request. The controller shall bear the burden of demonstrating the manifestly unfounded or excessive character of the request.”

In plain words: the request costs nothing. They may charge or refuse in one case only, and it is for them to establish that you are in it.

Article 12(5) · Regulation (EU) 2016/679, Article 12 (Modalities for the exercise of the rights), paragraph 5 · https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:32016R0679

No effect · I reply “DELETE EVERYTHING” in capitals, with eleven exclamation marks.

The Regulation offers no bonus for emphasis, and something else was free No article rewards the tone. There is one, though, that almost nobody uses BEFORE asking for erasure: the right of access. You can claim a copy of everything they hold about you, free of charge, in an accessible format, with a reply due within one month. That is the piece that makes a later complaint hard to argue with, and it is asked for in the same sentence as the erasure.

“You can request access to the personal data a company or organisation has about you, and you have the right to get a copy of your data, free of charge, in an accessible format. They should reply to you within 1 month and have to give you a copy of your personal data and any relevant information about how the data has been used, or is being used.”

In plain words: ask for the copy before the erasure. It is free of charge, it is due within a month, and it is the only way to know what they held.

Section “Access to your personal data” · Data protection: access to your personal data · https://europa.eu/youreurope/citizens/consumers/internet-telecoms/data-protection-online-privacy/index_en.htm

Item no. 3 · Thirty-eight days of silence

You supplied what was necessary to identify you, and nothing else. Since then, not a word: no confirmed erasure, no refusal, no announced extension.

You open the file note and count the days.

File noteCount

Erasure request received by the service: day zero, automatic acknowledgement on file.

Days elapsed since receipt: 38. Information on action taken: none.

Extension announced: none. Reasons for a delay: none.

Thirty-eight days without a word. What does that change?

Correct answer · The deadline has passed: I write and tell them so, and I announce what comes next.

One month, and a single possible extension, on conditions The Regulation starts the clock at the RECEIPT of your request: information on the action taken is due without undue delay and in any event within one month. The extension exists, but it is fenced in on three sides: two further months at most, justified by the complexity and number of the requests, and announced TOGETHER WITH THE REASONS within the first month. An extension you were never told about does not exist.

“3. The controller shall provide information on action taken on a request under Articles 15 to 22 to the data subject without undue delay and in any event within one month of receipt of the request. That period may be extended by two further months where necessary, taking into account the complexity and number of the requests. The controller shall inform the data subject of any such extension within one month of receipt of the request, together with the reasons for the delay.”

In plain words: one month to answer you. They may take two further months, but only if they warned you, said why, and did so before the first month ran out.

Article 12(3) · Regulation (EU) 2016/679, Article 12 (Modalities for the exercise of the rights), paragraph 3 · https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:32016R0679

Myth · The Regulation sets no precise deadline: they will answer when they can.

The myth: “the Regulation gives no deadline” It gives one, and it gives it for EVERY request in the series, from access to objection: one month from receipt. The phrase “without undue delay” does not replace that month, it adds to it. What makes the deadline usable is that it runs from a date you know: the date of their acknowledgement.

“The controller shall provide information on action taken on a request under Articles 15 to 22 to the data subject without undue delay and in any event within one month of receipt of the request.”

In plain words: the deadline exists, it is one month, and it runs from their receipt, not from their goodwill.

Article 12(3) · Regulation (EU) 2016/679, Article 12 (Modalities for the exercise of the rights), paragraph 3 · https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:32016R0679

Myth · Their silence amounts to a refusal, and a refusal is not up for discussion.

The myth: “no reply, so the file is closed” The Regulation treats inaction for what it is, and fences it in three times over. If they do not act, they must inform you of the REASONS for not taking action, at the latest within one month, AND point you to two doors: lodging a complaint with a supervisory authority and seeking a judicial remedy. A silence gives no reasons, keeps to no deadline and points to no door: it meets none of the three.

“4. If the controller does not take action on the request of the data subject, the controller shall inform the data subject without delay and at the latest within one month of receipt of the request of the reasons for not taking action and on the possibility of lodging a complaint with a supervisory authority and seeking a judicial remedy.”

In plain words: a refusal has to be reasoned, and it has to tell you itself where to go next. The text hands you the next step inside the sentence that turns you down.

Article 12(4) · Regulation (EU) 2016/679, Article 12 (Modalities for the exercise of the rights), paragraph 4 · https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:32016R0679

Item no. 4 · Erased at their end, still there elsewhere

The account is deleted at last. The message announcing it adds two sentences that deserve a slow read.

That evening you look your name up in a search engine. Three of your old photos still show up, hosted somewhere else.

Deletion confirmationRequest No D4K-QX7

Your account and your content have been deleted from our servers.

Some of your data was passed on to our partners and to affiliated sites over the past six years. We have no means of acting on those copies.

We also retain your billing data for 10 years, in accordance with our obligations.

They erased their own copy and passed the ball on the rest. What can you demand?

Correct answer · I ask for the list of recipients, and I remind them that they must notify the erasure to each one.

Erasure does not stop at their own servers A whole article, short and overlooked, settles exactly this case. The controller shall COMMUNICATE the erasure to each recipient to whom the personal data have been disclosed, unless this proves impossible or involves disproportionate effort. And it shall inform you about those recipients if you request it. “We have no means of acting” is not in the text: what is in the text is a duty to communicate, and a duty to tell you to whom.

“The controller shall communicate any rectification or erasure of personal data or restriction of processing carried out in accordance with Article 16, Article 17(1) and Article 18 to each recipient to whom the personal data have been disclosed, unless this proves impossible or involves disproportionate effort. The controller shall inform the data subject about those recipients if the data subject requests it.”

In plain words: they have to warn everyone they gave your data to, and tell you who they are if you ask. Ask for both in the same sentence.

Article 19 in full · Regulation (EU) 2016/679, Article 19 (Notification obligation regarding erasure of personal data) · https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:32016R0679

Myth · Once the data has gone to third parties it is lost: nobody can pull it back.

The myth: “gone to a third party, so out of reach” The official EU page says the opposite in one sentence, and it names the other websites the data was shared with: informing them is the company's job. The same page notes in passing that these rules also apply to search engines, which are likewise regarded as data controllers. Sharing does not create a zone outside the law: it creates a list of people to be told.

“These rules also apply to search engines […] as they're also considered to be data controllers. […] If a company has made your personal data available online and you ask for them to be deleted, the company also has to inform any other websites where they've been shared that you've asked for your data and links to them to be deleted.”

In plain words: informing the other websites is the company's job, not yours to track them down one by one.

Section “Deleting your personal data” · Data protection: the other websites the data was shared with · https://europa.eu/youreurope/citizens/consumers/internet-telecoms/data-protection-online-privacy/index_en.htm

Myth · Erasure erases everything, no exceptions. Their 10 years of billing data go too.

The myth: “the right to be forgotten erases everything” The article that creates the right sets its own limits, in its third paragraph, and it names them: exercising the right of freedom of expression and information, compliance with a legal obligation which requires processing, the establishment or defence of legal claims. What your country requires to be kept does not fall under the same regime as your profile, and this site never covers national law. Knowing the limit of a right is what makes the rest of the request credible.

“3. Paragraphs 1 and 2 shall not apply to the extent that processing is necessary: (a) for exercising the right of freedom of expression and information; (b) for compliance with a legal obligation which requires processing by Union or Member State law to which the controller is subject […] (e) for the establishment, exercise or defence of legal claims.”

In plain words: erasure stops where another rule requires keeping. Ask for the erasure of what can be erased, and the file stands up.

Article 17(3) · Regulation (EU) 2016/679, Article 17 (Right to erasure), paragraph 3 · https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:32016R0679

Item no. 5 · File closed, at their end

Last message. It is shorter than the others, and it closes the door while showing you a map.

Final decision of the serviceRequest No D4K-QX7

Your successive requests are repetitive and excessive within the meaning of the Regulation. We will take no further action on them.

We consider this file closed and will not reply further on the subject.

Should you wish to contest this, we invite you to bring the matter before the competent court of the country of our registered office.

They are sending you to a foreign court. Is that really the only door?

Correct answer · I lodge a complaint with the data protection authority of my own country.

The complaint is lodged where you live, not where they are The article names three places to choose from, and the first is your habitual residence. The other two are your place of work and the place of the alleged infringement. Nothing sends you to the company's registered office. And the authority you turn to then owes you the progress and the outcome of your complaint, including the possibility of a judicial remedy.

“1. Without prejudice to any other administrative or judicial remedy, every data subject shall have the right to lodge a complaint with a supervisory authority, in particular in the Member State of his or her habitual residence, place of work or place of the alleged infringement if the data subject considers that the processing of personal data relating to him or her infringes this Regulation. 2. The supervisory authority with which the complaint has been lodged shall inform the complainant on the progress and the outcome of the complaint including the possibility of a judicial remedy pursuant to Article 78.”

In plain words: you complain at home, to the authority of your own country. The company's registered office does not decide your geography.

Article 77(1) and (2) · Regulation (EU) 2016/679, Article 77 (Right to lodge a complaint with a supervisory authority) · https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:32016R0679

Myth · They write that my request is excessive. So it is up to me to prove otherwise.

The myth: “it is written in their letter, so it is established” The paragraph that allows a refusal ends with a sentence refusals never quote: the controller shall bear the burden of demonstrating the manifestly unfounded or excessive character of the request. Writing the word “excessive” is not demonstrating it. And the text says “manifestly”: it is for them to establish that you are there, request by request.

“Where requests from a data subject are manifestly unfounded or excessive, in particular because of their repetitive character, the controller may either: (a) charge a reasonable fee […] or (b) refuse to act on the request. The controller shall bear the burden of demonstrating the manifestly unfounded or excessive character of the request.”

In plain words: the proof is on their side, not yours. You do not have to justify having followed up.

Article 12(5) · Regulation (EU) 2016/679, Article 12 (Modalities for the exercise of the rights), paragraph 5 · https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:32016R0679

Myth · A written refusal can only be fought in court, and I am not going to court.

The myth: “after their refusal there is only the courtroom” The official EU page puts the two routes side by side. It presents a complaint to the national data protection authority as a DIRECT route, with an investigation and a response within three months, and it writes that the court stays open without any obligation to go through that authority first. In other words: two doors, and you are required to take neither of them first. The same page adds that material or non-material damage may entitle you to compensation.

“If you think your data protection rights have not been respected, you can make a complaint directly to your national data protection authority which will investigate your complaint and give you a response within 3 months. […] to file a case directly in court against the company or organisation concerned instead of first going to your national data protection authority. You may be entitled to compensation if you suffer material damage, such as financial loss, or non-material damage, such as psychological distress, due to a company or organisation not respecting EU data protection rules.”

In plain words: you have two doors and you pick one. The authority of your country answers within three months; the court stays open with or without it.

Section “Making a complaint” · Data protection: making a complaint · https://europa.eu/youreurope/citizens/consumers/internet-telecoms/data-protection-online-privacy/index_en.htm

Verdict · What a button that did not exist was worth

A settings page with no erasure option, one identity document too many, thirty-eight days of silence, seven recipients never disclosed, and eight rights the contact form mentioned nowhere.