The Right to be Forgotten, formally known as the "right to erasure" under GDPR Article 17, represents one of the most significant developments in digital privacy law of the 21st century. It grants individuals the fundamental right to request that their personal data be deleted from databases, search engines, and online platforms under specific circumstances. This right acknowledges that in the digital age, where information persists indefinitely and can be easily replicated and disseminated, individuals should have control over their personal information and the ability to have it removed when certain conditions are met.
At its core, the right to be forgotten addresses a fundamental asymmetry in the digital economy: while individuals generate vast amounts of personal data through their online activities, they often have little control over how this data is stored, processed, or shared by companies and organizations. The right to erasure seeks to restore some balance by empowering individuals to request deletion of their personal information, particularly when that information is no longer necessary for the purposes for which it was collected, when consent is withdrawn, or when the data is being processed unlawfully.
The modern conception of the right to be forgotten emerged from a landmark 2014 European Court of Justice (ECJ) decision in the case of Google Spain SL v. Agencia Española de Protección de Datos (AEPD) and Mario Costeja González. The case involved a Spanish citizen, Mario Costeja González, who requested that Google remove links to a newspaper article from 1998 about his home being repossessed for debt. Although the debt had been settled years earlier, the article continued to appear prominently in Google search results for his name.
The ECJ ruled that search engines are data controllers under EU data protection law and that individuals have the right to request removal of links to information about them that is "inadequate, irrelevant, or no longer relevant, or excessive in relation to the purposes of the processing." This landmark decision established that search engines must balance an individual's privacy rights against the public's right to information, with privacy generally taking precedence unless there is a compelling public interest in the information remaining accessible.
The Google Spain judgment sent shockwaves through the tech industry and sparked global debate about privacy, freedom of expression, and the power of search engines. Within weeks of the ruling, Google received hundreds of thousands of delisting requests from European citizens. The case highlighted the tension between the right to privacy and the right to information in the digital age, questions that continue to shape privacy law and policy worldwide.
Building on the principles established in Google Spain and earlier European data protection directives, the European Union codified the right to erasure in Article 17 of the General Data Protection Regulation (GDPR), which took effect on May 25, 2018. GDPR Article 17 goes beyond search engine delisting to establish a comprehensive framework for data deletion across all types of data controllers and processors.
The GDPR's approach to the right to erasure is notable for several reasons. First, it establishes clear grounds under which individuals can request deletion: when data is no longer necessary for its original purpose, when consent is withdrawn, when data is unlawfully processed, when there is a legal obligation to delete, or when data was collected from children. Second, it imposes obligations on data controllers not only to delete data themselves but also to take "reasonable steps" to inform other controllers who are processing the data to delete it as well. Third, it provides specific exceptions where the right to erasure does not apply, such as for exercising freedom of expression, compliance with legal obligations, public health purposes, archiving in the public interest, or establishment of legal claims.
Following GDPR's implementation, the right to erasure has been adopted in various forms across the globe. California's Consumer Privacy Act (CCPA) and its successor, the California Privacy Rights Act (CPRA), grant California residents the right to request deletion of personal information. Brazil's Lei Geral de Proteção de Dados (LGPD) includes similar provisions. Countries from South Africa to Japan to South Korea have incorporated elements of the right to erasure into their privacy frameworks.
This global proliferation reflects a growing recognition that individuals should have meaningful control over their personal data in the digital age. However, implementation varies significantly across jurisdictions, with differences in scope, exceptions, enforcement mechanisms, and the balance struck between privacy rights and other interests such as freedom of expression and innovation.
In the physical world, information fades over time. Newspaper articles yellow and become difficult to find, court records may be sealed or expunged, and people's memories dim. The digital world, by contrast, has nearly perfect memory. Information posted online can persist indefinitely, easily searchable and accessible to anyone with an internet connection. This digital permanence creates significant challenges for individuals seeking to move past mistakes, youthful indiscretions, or outdated information that no longer reflects who they are.
The right to be forgotten recognizes that humans have the capacity for growth, rehabilitation, and change. A person should not be permanently defined by information from years or decades ago, particularly if that information relates to minor infractions, resolved legal matters, or personal circumstances that have significantly changed. The right to erasure provides a mechanism for individuals to advocate for the removal of outdated or irrelevant information, supporting rehabilitation and the possibility of a fresh start.
One of the core principles of modern data protection law is data minimization—the idea that organizations should only collect and retain personal data that is necessary for specific, legitimate purposes. Related to this is purpose limitation: data collected for one purpose should not be repurposed without consent. The right to erasure operationalizes these principles by requiring organizations to delete personal data when it is no longer needed for its original purpose.
This approach contrasts sharply with the business models of many technology companies, which have historically been built on collecting as much data as possible and retaining it indefinitely for potential future uses. The right to be forgotten challenges this "data hoarding" mentality and forces organizations to think more carefully about what data they truly need and for how long.
The digital economy is characterized by significant power imbalances. Large technology platforms, data brokers, and digital advertisers possess vast troves of personal information about billions of people. Individuals, by contrast, often have little knowledge of what data has been collected about them, limited understanding of how it's being used, and even less ability to control or delete it.
The right to erasure represents an attempt to rebalance this power dynamic. By granting individuals the legal right to request deletion of their data, privacy laws give individuals a tool to assert control over their personal information. While the effectiveness of this tool depends heavily on implementation and enforcement, it represents a significant shift from a regime where companies had nearly unlimited discretion over personal data to one where individuals have enforceable rights.
Outdated or inaccurate personal information can cause real harm to individuals. A person might be denied employment because of a criminal record that was later expunged, or because of negative reviews or social media posts from years ago that no longer reflect their character or competence. Someone might face discrimination based on health information that is no longer accurate, or experience harassment due to old personal information that has become publicly accessible.
The right to be forgotten provides a legal mechanism to address these harms. By enabling individuals to request removal of information that is no longer relevant, accurate, or fair, the right to erasure can help prevent reputational damage, discrimination, and other negative consequences that might flow from the persistence of outdated digital information.
Young people today grow up with digital technology from birth. They create digital footprints—through social media, educational technology, gaming platforms, and countless other online activities—long before they have the maturity to understand the implications. Photos, videos, comments, and personal information posted during childhood and adolescence can persist online indefinitely, potentially causing embarrassment or harm in adulthood.
GDPR and other privacy laws provide enhanced protections for children's data, including strengthened rights to erasure. The rationale is that children deserve special protection because they may not fully understand the consequences of sharing personal information online, and they should have the opportunity to control or remove data created during their youth once they reach adulthood.
The right to be forgotten is not absolute. It must be balanced against other fundamental rights and important societal interests. Freedom of expression and information, for instance, may override privacy rights when information is newsworthy or of legitimate public concern. Legal and regulatory compliance requirements may necessitate retention of certain data even when a deletion request is made. Scientific research, statistical purposes, and public health objectives may justify continued processing of personal data despite erasure requests.
This balancing act is one of the most challenging aspects of implementing the right to be forgotten. Organizations must evaluate each deletion request individually, considering the specific circumstances, the nature of the data, the reasons for the request, and applicable legal exceptions. This requires significant legal expertise and careful judgment, as getting the balance wrong can result in either violating individuals' privacy rights or improperly suppressing legitimate information.
The right to erasure is inherently contextual. Whether a deletion request should be granted depends on factors such as: Why was the data collected originally? Is it still needed for that purpose? How old is the data? Has the data subject's situation changed? Is there a public interest in retaining the information? What is the potential harm from continued retention versus deletion?
This contextual nature means that the same piece of information might be subject to deletion in one context but protected from deletion in another. For example, information about a person's criminal conviction might be properly retained by law enforcement and court systems but might need to be delisted from search engine results after a certain period of time.
While privacy laws impose strong obligations to comply with deletion requests, they also recognize practical and technical limitations. GDPR, for instance, requires controllers to take "reasonable steps" to inform other parties processing the data, rather than guaranteeing that every copy of data everywhere will be deleted. This acknowledges that in distributed systems, with data replicated across multiple databases, backups, and third parties, complete erasure may be technically impossible or unreasonably burdensome.
The question of what constitutes "reasonable" effort is an evolving area of law and practice. As technology advances and data deletion becomes more feasible through improved tools and practices, expectations for what organizations should do to comply with deletion requests will likely increase. Organizations implementing the right to be forgotten must stay current with both legal requirements and technical best practices.
Perhaps the most significant controversy surrounding the right to be forgotten is its potential tension with freedom of expression and the free flow of information. Critics argue that allowing individuals to request removal of information about themselves from search engines and online platforms creates opportunities for powerful individuals to suppress legitimate journalism, hide inconvenient facts, or rewrite their public histories.
There have been documented cases of public figures, politicians, and business leaders using the right to be forgotten to request removal of articles about past scandals, legal proceedings, or controversial business dealings. While some of these requests are denied based on public interest exceptions, the existence of the right creates ongoing tension between individual privacy and the public's right to know.
Defenders of the right to be forgotten argue that these concerns can be addressed through properly calibrated exceptions and careful case-by-case adjudication. They point out that the right does not require deletion of information at its source—the original news articles, court records, or other documents remain accessible—but only removal of links from search results or deletion from databases where there is no legitimate need for retention.
Another major challenge is determining the geographic scope of deletion obligations. When a European citizen requests that Google delist links about them, should those links be removed only from Google's European domains (google.fr, google.de, etc.), or from Google's global index, including google.com? Should a deletion request under GDPR result in data being deleted from servers located outside the EU?
These questions have significant implications for both individual rights and the global flow of information. The ECJ initially held that delisting should apply to all EU domains but not necessarily to google.com or other non-EU domains. However, the French data protection authority (CNIL) argued for global delisting, leading to further legal battles. As of 2025, the consensus leans toward territorial application—delisting or deletion applies within the jurisdiction where the law applies, but not necessarily globally, unless the data controller voluntarily extends compliance.
Modern data systems are highly distributed, with information replicated across multiple databases, data centers, content delivery networks, backup systems, and third-party processors. Ensuring complete deletion of personal data across all these systems is technically complex. Data may exist in active databases, log files, backup tapes, cached copies, and analytical databases. Each of these may require different deletion procedures.
Moreover, some systems—particularly blockchain and other distributed ledger technologies—are designed to be immutable, making traditional deletion impossible. This creates fundamental tensions between the technical architecture of modern systems and legal requirements for data deletion, leading to innovative solutions such as encryption key destruction and off-chain data storage.
As we progress through this comprehensive guide to the right to be forgotten, we will explore these challenges in depth and examine practical solutions. Subsequent chapters will cover the legal framework in detail, technical implementation strategies, specific challenges like blockchain and search engine delisting, verification and certification methods, real-world case studies, and future developments in privacy rights.
The right to be forgotten represents a profound shift in how we think about privacy, data ownership, and individual rights in the digital age. It reflects a broader movement toward data sovereignty—the idea that individuals should have meaningful control over their personal information. While implementation remains complex and controversial, the right to erasure has already changed how organizations handle personal data and will continue to evolve as technology and law co-develop.
Korea operates its industrial ecosystem and standardization system through the following core infrastructure. Korea Top 5 Groups: Samsung, Hyundai Motor, LG, SK, Lotte. Each group operates standardization committees and ISO/IEC TC Korean secretariats. Samsung Electronics (semiconductors, displays, home appliances, telecom)·Hyundai Motor (automobiles, mobility)·LG Electronics (home appliances, displays, OLED)·SK hynix (memory)·LG Energy Solution·Samsung SDI (batteries)·POSCO Future M (materials)·Hyundai Mobis (parts). Korean IT Big Tech: NAVER (search, cloud, AI HyperCLOVA)·Kakao (messenger, payment, mobility, banking)·Coupang (e-commerce, logistics)·Karrot Market·Toss·Woowa Brothers. Korea Telcos: SK Telecom·KT·LG U+. 5G·5G dedicated networks·B2B cloud·AI businesses operating. Korea Top 7 Research Universities: Seoul National University·KAIST·POSTECH·Yonsei University·Korea University·UNIST·DGIST·GIST. All serve as standardization R&D bases and ISO/IEC/IEEE Korean chairs. Korea Government-affiliated National Research Institutes (26): KIST, KAERI, KIMM, KIER, KFRI, KRICT, KRIBB, KARI, KASI, KIGAM, KICT, KISTI, KETI, ETRI, NIMS, KIMS, KISDI, KOTRA, STEPI, KOEN, KICCE, KIET, KIPF, KIHASA, KICJ, KLRI. Korea Industrial Complexes / Tech Valleys: Pangyo Techno Valley·Dongtan·Gwanggyo·Songdo IBD·Yeouido·Gangnam·Sihwa·Banwol·Gumi·Ulsan·Changwon·Geoje·Yeosu·Onsan·Cheongju·Iksan·Gwangyang·POSCO Gwangyang Steel Mill·Asan Bay·Seosan·Songdo·Incheon Airport·Sejong·Cheongna·Geomdan. Korea Trade and Finance Infrastructure: Korea International Trade Association (KITA)·Korea Trade-Investment Promotion Agency (KOTRA)·Export-Import Bank of Korea (KEXIM)·Bank of Korea·Kookmin Bank·Shinhan·Hana·Woori·NH Nonghyup·IBK Industrial Bank·SC First Bank·Citi Bank Korea·HSBC Korea·DBS Korea — 14 Korean major banks and foreign banks. Korea K-POP / K-Content: HYBE·SM·YG·JYP 4 major entertainment companies·CJ ENM·tvN·MBC·KBS·SBS·EBS·YTN·Yonhap News TV·JTBC Korean broadcasting·NETFLIX Korea·Disney Plus·TVING·Wavve·Watcha·Coupang Play. Korea Gaming Industry: Nexon·NCsoft·Krafton·Netmarble·Kakao Games·Pearl Abyss·Com2uS·Gamevil·NHN·Smilegate·Webzen. Korea Automotive / Battery: Hyundai Motor·Kia·Genesis·LG Energy Solution·Samsung SDI·SK On·POSCO Future M·EcoPro·L&F battery cathode material suppliers. Korea Semiconductor: Samsung Electronics (HBM3E·HBM4)·SK hynix (HBM3E 12-Hi)·DB HiTek·SK siltron·SK Enpulse·Dongjin Semichem·Seoul Semiconductor·Simmtech·Samsung Display·LG Display.
Korea operates a comprehensive standards governance system through inter-ministerial cooperation. National Standards Council (under Prime Minister's Office, per Framework Act on National Standards Article 5) coordinates KATS (Korean Agency for Technology and Standards), MFDS (Ministry of Food and Drug Safety), MOTIE (Ministry of Trade, Industry and Energy), MSIT (Ministry of Science and ICT), MOIS (Ministry of the Interior and Safety), MOE (Ministry of Environment), MOHW (Ministry of Health and Welfare), MND (Ministry of National Defense), MCST (Ministry of Culture, Sports and Tourism), MOFA (Ministry of Foreign Affairs), MOJ (Ministry of Justice), and FSC (Financial Services Commission). Accreditation and Testing: KOLAS (Korea Laboratory Accreditation Scheme) accredits 800+ testing laboratories. KAS (Korea Accreditation System) accredits 50+ certification bodies. KTC (Korea Testing Certification), KTR (Korea Testing & Research Institute), KTL (Korea Testing Laboratory), and KCL (Korea Conformity Laboratories) provide conformance testing. Telecom and Cyber: KCC (Korea Communications Commission), KCA (Korea Communications Agency), TTA (Telecommunications Technology Association), IITP (Institute for Information & Communications Technology Planning & Evaluation), NIPA (National IT Industry Promotion Agency), KISA (Korea Internet & Security Agency), KCMVP (Korea Cryptographic Module Validation Program), NIS (National Intelligence Service), NSR (National Security Research Institute), and NCSC (National Cyber Security Center). National R&D Centers: KIST, ETRI, KAIST, Seoul National University, Yonsei University, Korea University, POSTECH, UNIST, GIST, DGIST, KISTI, KIER, KIMM, KRICT, KFRI, KRIBB. International Standards Cooperation: ISO TC/SC Korean secretariats, IEC TC/SC Korean secretariats, ITU-T Study Group Korean chairs, 3GPP RAN/SA Korean chairs, IEEE 802 Korean chairs, W3C Korea office, OASIS Korea office, IETF Korea cooperation, OECD CSTP, UN ESCAP, APEC SCSC Korean cooperation. Korean Industrial Standards (KS) Catalog: KS X (Information) 25,000+, KS A (Basic) 15,000+, KS B (Machinery) 25,000+, KS C (Electrical) 18,000+, KS D (Metallurgy) 12,000+, KS E (Mining) 5,000+, KS F (Construction) 18,000+, KS H (Food) 8,000+, KS I (Environment) 5,000+, KS J (Biology) 3,000+, KS K (Textile) 15,000+, KS L (Ceramics) 7,000+, KS M (Chemistry) 12,000+, KS P (Medical) 5,000+, KS Q (Quality Mgmt) 4,000+, KS R (Transport) 12,000+, KS S (Service) 3,000+, KS T (Packaging) 4,000+, KS V (Shipbuilding) 5,000+, KS W (Aerospace) 3,000+ — totaling 220,000+ Korean Industrial Standards. Key Acts: Personal Information Protection Act (Act 19234, effective Sept 15, 2024), Electronic Government Act, Electronic Signature Act, Act on Promotion of Information and Communications Network Utilization and Information Protection, Information and Communications Infrastructure Protection Act, Data Industry Act, Public Data Act, AI Framework Act (Act 20212, effective July 2026), Industrial Technology Innovation Promotion Act, Framework Act on Science and Technology — 70+ Korean standardization-related laws.
Korea operates digital transformation through a comprehensive governance system. Digital Government: Digital Platform Government Committee (established September 2022, under the President)·Ministry of the Interior and Safety Digital Government Bureau·e-Government Support Center·Gov.kr·National Citizen Service·KDIS (Korea Digital Information Society)·NIA (National Information Society Agency)·MOIS (Ministry of the Interior and Safety). K-DNS Infrastructure: Korea Internet & Security Agency (KISA) Korea Internet Center·KISA DNS Root Server·KRNIC (Korea Network Information Center)·BGP Korea·National Cyber Security Center (NCSC)·KCC (Korea Communications Commission)·MSIT (Ministry of Science and ICT)·NIA·NIPA. Korean Cloud Infrastructure: KT Cloud·NAVER Cloud (NCloud)·Samsung SDS Cloud·LG U+ Cloud·NHN Cloud·Kakao Enterprise Cloud·SK Telecom Cloud·KISA Cloud Security Assurance Program (CSAP)·KCMVP-validated cloud·ISMS-P (Information Security & Personal Information Management System). Korean Security Certifications: KISA ISMS-P certification·KCMVP (Korean Cryptographic Module Validation Program)·NIS (National Intelligence Service) "National Cryptographic Technology Operation Standards"·NCSC "National Cyber Security Strategy 2024-2028"·CC (Common Criteria) Korean evaluation bodies·EAL4·EAL5·KS X ISO/IEC 15408·19790·24759 Korean Profile. Korean Data Standards: NIA AI Hub·National Data Standardization Committee·Statistics Korea (KOSTAT)·MyData 4 Designated Combination Specialists (Samsung SDS, KICI, KOSTAT, KFTC)·National Institute of Korean Language·National Law Information Center·National Spatial Information Platform·National Spatial Data Center·Korean Spatial Information Standards. Finance and Fintech Standards: FSC (Financial Services Commission)·FSS (Financial Supervisory Service)·FIU (Financial Intelligence Unit)·BOK (Bank of Korea)·FSEC (Financial Security Institute)·KFTC (Korea Financial Telecommunications)·KSD (Korea Securities Depository)·KRX (Korea Exchange) 8-agency cooperation. 5G/6G Communications Infrastructure: 5G subscribers 35 million (2024)·5G base stations 350,000·6G commercialization target 2028·5G dedicated networks 16 operators·6G Acceleration Council (MSIT, 2024). K-Content: KOCCA (Korea Creative Content Agency)·MCST (Ministry of Culture, Sports and Tourism)·KCA (Korea Communications Agency)·Korea Culture Information Service Agency·Korean Film Archive·Korea Publishing Industry Promotion Agency. Data 3 Acts (Personal Information Protection Act·Credit Information Act·Telecommunications Network Act, 2020 enforcement)·Data Industry Act (2021)·Public Data Act (2013)·AI Framework Act (2026)·Digital Platform Government Framework Act (2024 proposed) — Korea digital transformation core legislation.