The right to erasure, also known as the 'right to be forgotten', is one of the most important rights granted to data subjects under the General Data Protection Regulation (GDPR). In essence, it allows an individual to request the deletion of their personal data where, for example, the data are no longer necessary for the purpose for which they were collected, consent has been withdrawn, or the processing was unlawful. In these situations, the controller is under an obligation to erase the data without undue delay.
In practice, this obligation has long been understood in fairly straightforward terms: locating the individual's data within the company's databases, deleting it from operational systems, and documenting the response sent to the data subject. However, the rapid development of artificial intelligence systems significantly complicates this logic.
The problem arises when personal data have not merely been stored, but have been used to train, fine-tune, or evaluate an AI model. In such cases, the data no longer necessarily exist as an individual, easily identifiable and deletable record. They may instead be reflected indirectly in the model's parameters, statistical weights, or behaviour. In other words, the information has been absorbed into the model, and removing the contribution of a single person's data becomes, from both a technical and a legal standpoint, considerably more difficult — at times impossible.
This is the central tension: the GDPR proceeds on the assumption that personal data can be identified, controlled and, where appropriate, deleted. AI models, by contrast, typically function by generalising patterns extracted from large volumes of data. If a person today requests the deletion of their data, the question is no longer simply whether the data have been removed from the CRM, the marketing platform, or the user account. The question becomes: what happens to the model that has already been trained on that data?
This question is all the more important given that European data protection authorities have begun expressly examining the relationship between the GDPR and AI models. In Opinion 28/2024, the European Data Protection Board (EDPB) addressed three relevant aspects:
- The anonymous nature of the AI model: an AI model can only be regarded as anonymous following a case-by-case assessment. The model must not allow the direct or indirect identification of the individuals whose data were used in its development, nor should it allow personal data to be extracted by querying the model.
- Legitimate interest as a legal basis: legitimate interest can justify the processing of data for the development or use of an AI model only if three conditions are met: the existence of a legitimate interest, the strict necessity of the processing, and a balancing of that interest against the rights and freedoms of the data subjects. It also matters whether the individuals concerned could reasonably have expected their data to be used for this purpose.
- Unlawfully processed personal data: if an AI model has been developed using personal data that were processed unlawfully, this may affect the lawfulness of the model's subsequent use. An exception may exist only where the model has been properly anonymised.
For organisations, the message is clear: simply affirming that a model 'contains no personal data' is not enough. Such a conclusion must be backed by a robust, documented analysis. In certain situations, a model may allow personal information to be extracted, re-identified, or reproduced, particularly if it was trained on sensitive, limited, or insufficiently cleaned datasets. In other cases, the risk may be lower, but it should never be automatically assumed that a model is anonymous simply because the data are no longer visible in a conventional format.
The practical risk for companies is that of achieving only apparent compliance. An organisation may respond to a deletion request, remove the data from its core systems, and confirm to the data subject that the request has been resolved. Yet if that data was previously used to develop an AI model, and this aspect was never examined, the company may still be exposed. When faced with an investigation, the authority's question will not simply be 'did you delete the record?', but also 'where else was this data used, and what effect did the deletion have on the AI systems built with it?'
This issue must also be viewed in the broader context of the AI Act. Regulation (EU) 2024/1689 establishes a harmonised European framework for artificial intelligence and seeks to promote human-centric, trustworthy AI while ensuring a high level of protection for health, safety, and fundamental rights. Although the AI Act does not replace the GDPR, the two frameworks must be applied together. An AI system may comply with the AI Act's technical requirements and yet still raise serious concerns if the personal data used in its development were not processed lawfully, transparently, and with careful documentation.
What should organisations that develop or use AI systems do?
First, they must know what data were used, for what purpose, on what legal basis, and at which stage of the AI system's life cycle. Maintaining an inventory of datasets is no longer a mere administrative exercise, but an essential precondition for being able to respond to data subjects' requests.
Second, internal procedures governing the right to erasure must be updated to also cover scenarios where data have been used to train or fine-tune a model. A procedure that only checks operational databases is incomplete once a company uses AI.
Third, organisations must document whether the resulting model can still be regarded as anonymous or whether there is a risk that personal data could be extracted, inferred, or reproduced. This analysis must be carried out on a case-by-case basis, taking into account the type of model, the nature of the data, the size of the training dataset, and the technical measures implemented.
Fourth, where actual deletion from the model is not technically feasible or would entail disproportionate costs, alternative measures must be considered: excluding the data from future training sets, retraining the model, fine-tuning it, restricting its use, or implementing risk-mitigation mechanisms. What matters is that the organisation does not ignore the issue, but is able to demonstrate that it has genuinely assessed it.
In the age of artificial intelligence, compliance no longer means simply knowing where data are stored. It also means knowing how they were used, what systems were developed on their basis, and what effects that use produces over time.
The right to be forgotten does not disappear in the face of artificial intelligence. On the contrary, it becomes a test of organisational maturity. Companies that use AI must be prepared to answer not only the question 'did we delete the data?', but also the harder one: 'what did the system learn from that data, and can we demonstrate that we have addressed this issue in a compliant manner?'