UK law gives people a right to erasure, and most organisations meet that right with a promise. A member of staff presses delete, a supplier confirms the action, and nobody can show what happened. A personal value survives a delete in six places. This article names them, explains how erasure and retention law conflict, and describes what turns deletion into a provable act.
Connect with us about provable erasure · · Replies within 24 hours
A person may ask you to erase their personal data, and you must respond within one month in most cases. The right is not absolute, and several exemptions apply.
The Information Commissioner's Office sets out the detail in its guidance on the right to erasure. The Data Protection Act 2018 carries the provisions into UK law.
Two obligations follow from a request, and organisations usually meet the first. You must erase the data, and you must be able to demonstrate that you did.
A delete removes a row from a table, and the value persists elsewhere.
| Place | Why it survives |
|---|---|
| Backups | Nightly copies hold the value for the whole retention period. |
| Audit logs | The log records the value that changed, so it holds the value. |
| Search indexes | An index rebuilds from the data, and a stale index keeps the old term. |
| Reporting copies | A warehouse or extract holds a copy nobody counted. |
| Integrations | Another system received the value and has its own retention. |
| Documents | A letter, a report or an attachment contains the value as text. |
Rows two and six defeat most processes. An audit log exists to record change, so it holds the value it recorded. A document holds the value inside prose, and no field-level delete reaches it.
Other law requires you to keep some records. A care provider keeps care records for a set period. A school keeps safeguarding records far longer. A financial firm keeps transaction records for its regulator.
An erasure request against a retained record therefore meets a competing duty, and the ICO guidance covers the exemptions. Your answer is a refusal with a stated reason, rather than a deletion.
Two abilities are needed to answer such a request correctly.
Most estates hold retention as a policy document and not as a property of a record. The policy then depends on a person applying it correctly, every time, across every system.
The right of access requires you to supply all personal data you hold about a person.
Erasure asks you to remove what you can find. Access asks you to find everything. An organisation that cannot list every place a value exists cannot answer either request with confidence, and access exposes the gap first.
The practical test is therefore one question. Take a name and list every record in your estate that mentions that person, with sources. Time the exercise.
Three properties, and each one is a design decision rather than a process.
The ICO's guidance on encryption treats it as a core security measure, and key destruction turns it into an erasure mechanism.
We build your system on engage.re, and erasure is a property of your records.
Sense Future built engage.re, and it has run in production since December 2025.
A council receives an erasure request from a former tenant. The person appears in housing, revenues, a repairs system and two reporting copies. Five systems, four suppliers, and one month to respond. The council deletes what it finds and cannot state what it missed.
A care home group receives the same request from a family. Care records carry a statutory retention period, so the correct answer is a partial refusal with a stated reason. The group must know which records fall under the rule, and the answer usually rests on one manager's knowledge.
The care home software and school software pages set out the sector detail. Our guides to CQC digital records and safeguarding records under KCSIE cover the retention periods that apply.
A person may ask you to erase their personal data, and you must respond within one month in most cases. The right is not absolute, and several exemptions apply. Two obligations follow a request: you must erase the data, and you must be able to demonstrate that you did.
In six places. Backups hold the value for the whole retention period. Audit logs record the value that changed. Search indexes keep a stale term. Reporting copies hold a copy nobody counted. Integrated systems received the value and apply their own retention. Documents contain the value as text.
No. Other law requires you to keep some records, and the ICO guidance covers the exemptions. Your answer is a refusal with a stated reason rather than a deletion. Answering correctly needs a retention class on each record and a legal hold that resists deletion during an investigation.
Three properties make it provable. Encrypt each record under its own key, so destroying the key destroys access to every copy including backups. Write an erasure event into a log nobody can alter. Hold one estate to search, rather than one request per supplier.
Erasure asks you to remove what you can find, and access asks you to find everything. An organisation that cannot list every place a value exists cannot answer either request with confidence, and an access request exposes the gap first.
We build your system on engage.re. Each record is encrypted separately, so destroying a key destroys access everywhere including backups. Erasure writes an event into a signed chain, every record carries a retention class, legal hold is enforced by the platform, and one query answers a subject access request.
Connect with us about provable erasure · · Replies within 24 hours