The foundation: engage.re
Data Protection 30 July 2026 9 min read

Can You Prove You Deleted Someone's Data?

UK law gives people a right to erasure, and most organisations meet that right with a promise. A member of staff presses delete, a supplier confirms the action, and nobody can show what happened. A personal value survives a delete in six places. This article names them, explains how erasure and retention law conflict, and describes what turns deletion into a provable act.

Connect with us about provable erasure · · Replies within 24 hours

6
places a personal value survives a delete
1
month, the usual deadline to respond to a request
1
key per record, so destroying a key destroys access

What does the right to erasure require?

A person may ask you to erase their personal data, and you must respond within one month in most cases. The right is not absolute, and several exemptions apply.

The Information Commissioner's Office sets out the detail in its guidance on the right to erasure. The Data Protection Act 2018 carries the provisions into UK law.

Two obligations follow from a request, and organisations usually meet the first. You must erase the data, and you must be able to demonstrate that you did.

The six places a value survives

A delete removes a row from a table, and the value persists elsewhere.

Place Why it survives
BackupsNightly copies hold the value for the whole retention period.
Audit logsThe log records the value that changed, so it holds the value.
Search indexesAn index rebuilds from the data, and a stale index keeps the old term.
Reporting copiesA warehouse or extract holds a copy nobody counted.
IntegrationsAnother system received the value and has its own retention.
DocumentsA letter, a report or an attachment contains the value as text.

Rows two and six defeat most processes. An audit log exists to record change, so it holds the value it recorded. A document holds the value inside prose, and no field-level delete reaches it.

The count is the problem, not the deletion. A person can delete a record in one system in a minute. Nobody can state how many copies of that value exist across six categories and several suppliers.

How do erasure and retention conflict?

Other law requires you to keep some records. A care provider keeps care records for a set period. A school keeps safeguarding records far longer. A financial firm keeps transaction records for its regulator.

An erasure request against a retained record therefore meets a competing duty, and the ICO guidance covers the exemptions. Your answer is a refusal with a stated reason, rather than a deletion.

Two abilities are needed to answer such a request correctly.

  • A retention class per record. Each record must state which rule governs it, so the answer is a lookup rather than a discussion.
  • A legal hold. Where litigation or an investigation is live, a record must resist deletion, including a deletion somebody requests in good faith.

Most estates hold retention as a policy document and not as a property of a record. The policy then depends on a person applying it correctly, every time, across every system.

Why is a subject access request the harder test?

The right of access requires you to supply all personal data you hold about a person.

Erasure asks you to remove what you can find. Access asks you to find everything. An organisation that cannot list every place a value exists cannot answer either request with confidence, and access exposes the gap first.

The practical test is therefore one question. Take a name and list every record in your estate that mentions that person, with sources. Time the exercise.

What makes deletion provable?

Three properties, and each one is a design decision rather than a process.

  1. Encryption per record. Where each record holds its own key, destroying the key destroys access to every copy at once, including the copies in backups.
  2. An erasure event. The deletion writes a record of itself, into a log nobody can alter, so you can show what you destroyed and when.
  3. One estate to search. One query covers your data, rather than one request per supplier.

The ICO's guidance on encryption treats it as a core security measure, and key destruction turns it into an erasure mechanism.

Key destruction reaches the copies a delete cannot. A backup taken last March holds ciphertext. Destroy the key today, and that backup holds ciphertext nobody can read, without anybody restoring or rewriting it.

What ESRE Media offers

We build your system on engage.re, and erasure is a property of your records.

  • Each record is encrypted separately. Destroying a record's key destroys access to that record everywhere, including in backups.
  • Erasure writes an event. The event joins a signed chain, so you can demonstrate the act rather than assert it.
  • Every record carries a retention class. The rule that governs a record is data, so the answer to a request is a lookup.
  • Legal hold is enforced. A held record resists deletion, and the platform refuses the operation.
  • One estate answers the question. One query lists every record about a person, so a subject access request does not become a project.

Sense Future built engage.re, and it has run in production since December 2025.

The same duty at two sizes

A council receives an erasure request from a former tenant. The person appears in housing, revenues, a repairs system and two reporting copies. Five systems, four suppliers, and one month to respond. The council deletes what it finds and cannot state what it missed.

A care home group receives the same request from a family. Care records carry a statutory retention period, so the correct answer is a partial refusal with a stated reason. The group must know which records fall under the rule, and the answer usually rests on one manager's knowledge.

The care home software and school software pages set out the sector detail. Our guides to CQC digital records and safeguarding records under KCSIE cover the retention periods that apply.

What we do not claim

  • Key destruction does not reach data held outside your estate. A value another organisation received stays with that organisation.
  • We do not give legal advice. The obligations here come from ICO guidance and legislation, and your data protection officer applies them to your case.
  • Provable erasure is not free. It is a design decision, and it must be made before your data exists.

What to do next

  1. Take one name and list every record about that person across your estate. Time the exercise.
  2. Count the copies of one value across the six categories above.
  3. Ask what happens to your backups when you delete a record.
  4. Check whether any record in your systems states its own retention rule.
  5. Then decide whether you can demonstrate a deletion, or only assert one.

Common questions

What does the right to erasure require?

A person may ask you to erase their personal data, and you must respond within one month in most cases. The right is not absolute, and several exemptions apply. Two obligations follow a request: you must erase the data, and you must be able to demonstrate that you did.

Where does deleted data survive?

In six places. Backups hold the value for the whole retention period. Audit logs record the value that changed. Search indexes keep a stale term. Reporting copies hold a copy nobody counted. Integrated systems received the value and apply their own retention. Documents contain the value as text.

Do we have to delete a record if other law says keep it?

No. Other law requires you to keep some records, and the ICO guidance covers the exemptions. Your answer is a refusal with a stated reason rather than a deletion. Answering correctly needs a retention class on each record and a legal hold that resists deletion during an investigation.

How can you prove data was deleted?

Three properties make it provable. Encrypt each record under its own key, so destroying the key destroys access to every copy including backups. Write an erasure event into a log nobody can alter. Hold one estate to search, rather than one request per supplier.

Why is a subject access request harder than an erasure request?

Erasure asks you to remove what you can find, and access asks you to find everything. An organisation that cannot list every place a value exists cannot answer either request with confidence, and an access request exposes the gap first.

What does ESRE Media build?

We build your system on engage.re. Each record is encrypted separately, so destroying a key destroys access everywhere including backups. Erasure writes an event into a signed chain, every record carries a retention class, legal hold is enforced by the platform, and one query answers a subject access request.

Connect with us about provable erasure · · Replies within 24 hours

Sources and further reading