The Right to Be Forgotten: Balancing Personal Privacy and Public Information in the Digital Age
In today‘s data-driven world, concerns over online privacy and data protection have reached a fever pitch. Internet users are increasingly wary about the vast troves of personal information collected by the websites and online services they use. Once your data is out there, getting it removed can feel like an impossible task.
But thanks to privacy laws like the European Union‘s General Data Protection Regulation (GDPR), consumers now have the power to demand that companies erase their personal data, a concept known as the "right to be forgotten." As a cybersecurity expert with over a decade of experience, I believe the right to be forgotten is a crucial tool for protecting personal privacy in the digital age. However, its application also raises challenging questions about how to balance privacy with freedom of information and the immutable nature of data.
What is the Right to Be Forgotten?
In simple terms, the right to be forgotten refers to an individual‘s ability to request that their personal data be deleted by organizations that have collected it, provided certain conditions are met. The right to be forgotten is specifically outlined in Article 17 of the GDPR, which states that individuals have the right to obtain "erasure of personal data concerning him or her without undue delay."[^1]
Personal data, in the context of GDPR, encompasses a broad range of information relating to an identifiable person, including:[^2]
- Basic identity information (name, address, ID numbers)
- Web data (location, IP address, cookie data)
- Health and genetic data
- Biometric data
- Racial or ethnic data
- Political opinions
- Sexual orientation
There are several scenarios in which the right to be forgotten applies under GDPR. Consumers can request data deletion if:[^1]
- The personal data is no longer necessary for its original purpose
- They withdraw consent for its processing
- They object to the processing and there is no overriding legitimate interest
- The data was unlawfully processed
- Erasure is required to comply with a legal obligation
- The data was collected in relation to offering information society services to a child
However, the right to erasure is not absolute. Organizations can refuse requests in some cases, such as if the data is needed to:[^1]
- Exercise freedom of expression and information
- Comply with a legal obligation
- Perform a task carried out in the public interest
- Exercise official authority vested in the controller
- Reasons of public interest in public health
- Archiving purposes in the public interest, scientific/historical research, or statistical purposes
- Establishment, exercise or defense of legal claims
Landmark Right to Be Forgotten Cases
The right to be forgotten first gained prominence in 2014 with a landmark ruling by the Court of Justice of the European Union (CJEU) in the case of Google Spain SL, Google Inc. v Agencia Española de Protección de Datos, Mario Costeja González. The case involved a Spanish citizen who requested that Google remove links to a 1998 newspaper article about the auction of his foreclosed home, arguing that the matter had been resolved and was no longer relevant.
The CJEU ruled that search engines like Google must consider requests from individuals to remove links to web pages that contain inaccurate, inadequate, irrelevant or excessive information about them.[^3] This decision established that the right to be forgotten could be applied to search engine results, not just the original websites hosting the content.
Since then, Google has received over 1 million requests to delist URLs under the right to be forgotten, approving around 45% of them.[^4] Other landmark cases have further defined the scope and limits of the right to be forgotten:
-
In 2019, the CJEU ruled that the right to be forgotten only applies within the EU and that Google is not required to delist URLs from its search results globally (Google v CNIL).[^5]
-
In 2020, the UK High Court found that the right to be forgotten could apply to news articles in some circumstances, in a case involving a businessman seeking to remove articles about his past criminal conviction (NT1 & NT2 v Google).[^6]
-
In 2022, the CJEU clarified that the right to be forgotten does not require online publishers to delete references to individuals within their articles, only to prevent those articles from appearing in search results when someone searches for the individual‘s name (Biancardi v Italy).[^7]
Challenges of Enforcing the Right to Be Forgotten
From a technical perspective, enforcing the right to be forgotten poses significant challenges, especially when it comes to ensuring that data is fully erased from all systems. Even if a company deletes personal data from its active databases, copies may still exist in backups, caches, or mirror sites beyond the company‘s direct control.
This issue came to a head in 2019 when the European Parliament found that the GDPR‘s right to be forgotten was "impossible to enforce" on the blockchain.[^8] Because blockchains are immutable ledgers where data cannot be deleted once added, they are fundamentally incompatible with the right to erasure. As more organizations explore blockchain-based solutions for identity management, cloud storage, and other applications involving personal data, the tension between the right to be forgotten and the permanence of data on the blockchain will only grow.
Another challenge is the increasing use of AI and machine learning algorithms that are trained on vast quantities of personal data, including data that may be subject to right to be forgotten requests. If an individual‘s data is used to train an AI model, it can be difficult if not impossible to fully "forget" that data, as it may be deeply embedded in the model‘s decision-making processes. This raises questions about whether the right to be forgotten should extend to AI models built using an individual‘s data.
The Right to Be Forgotten and Cybercrime
An often overlooked aspect of the right to be forgotten is its potential application to victims of cybercrime. When hackers breach a company‘s databases and post stolen personal information on the dark web, those affected may wish to exercise their right to have that data erased.
However, cybercriminals are unlikely to comply with right to be forgotten requests, and the decentralized nature of the dark web makes it virtually impossible to fully remove data once it has been posted. In these cases, the right to be forgotten may be more useful as a means for pressuring companies to notify affected individuals and take swift action to minimize the damage of a breach.
Interestingly, the right to be forgotten has also been invoked by cybercriminals seeking to remove evidence of their past misdeeds. In 2021, a Russian national convicted of operating a cybercrime forum sued a Russian news site demanding the removal of an article about his conviction under Russia‘s right to be forgotten law.[^9] While this request was denied, it demonstrates how the right to be forgotten could potentially be abused by bad actors.
The Future of the Right to Be Forgotten
Looking ahead, the right to be forgotten is likely to remain a key battleground in the fight over online privacy. As more nations mull privacy legislation, the ability to request erasure of personal data will become an increasingly standard provision.
One notable example is India‘s proposed Personal Data Protection Bill, which includes a right to be forgotten that would allow individuals to request the deletion of their personal data from both data fiduciaries and third parties if it is no longer necessary, was illegally processed, or if consent is withdrawn.[^10] If passed, this law would apply to over 1.4 billion people, greatly expanding the global reach of the right to be forgotten.
At the same time, there will likely be more legal challenges testing the limits of the right to be forgotten as companies and free speech advocates push back on perceived overreach. Laws attempting to balance the right to erasure with freedom of expression, such as the EU‘s Digital Services Act, may provide a model for a compromise approach.[^11]
The growing push for a digital "right of inheritance" or "data death" could add a new dimension to the right to be forgotten. Some argue that individuals should have the ability to designate what happens to their personal data after death, including the right to have it permanently erased.[^12] However, this raises complex legal and ethical questions around posthumous privacy rights and the historical record.
Balancing Privacy and Public Information
The benefits of the right to be forgotten are clear: it gives individuals greater control over their personal data, allowing them to limit its spread and curtail invasive data collection practices. In an age of data breaches, identity theft, and reputational damage, the ability to request erasure of one‘s personal information is a vital privacy safeguard.
However, the right to be forgotten also has significant potential drawbacks if applied too broadly or without sufficient safeguards for freedom of expression and the public interest.
Critics argue that it could enable the censorship or whitewashing of public information, such as news reports about a person‘s criminal history or past misconduct.[^13] In several controversial cases, the right to be forgotten was invoked to delist articles about public figures‘ past wrongdoing, leading some to accuse it of erasing or rewriting history.
There are also concerns that the right to be forgotten could make the internet less useful as an archival and research tool by allowing individuals to shape their digital footprint to include only flattering information. For people-centric investigations and due diligence, the widespread scrubbing of personal data from the web could make it much harder to uncover key facts.
Clearly, a balance must be struck between protecting individual privacy and ensuring the free flow of information in the public interest. This is why most right to be forgotten laws include exemptions for newsworthy content, freedom of expression, and archival purposes. The challenge is defining where to draw the line.
Conclusion
The right to be forgotten is a crucial tool for protecting personal privacy in the digital age, giving individuals the power to control their data and combat exploitative data collection practices. However, its application also raises challenging questions about how to balance privacy with transparency, free speech, and the permanence of online data.
As someone who has spent my career studying and defending against cyber threats, I believe that a robust right to be forgotten is an indispensable layer of defense against the mass harvesting and misuse of personal data. At the same time, I recognize that it is a blunt instrument that must be used judiciously to avoid censorship and abuse.
Policymakers and courts around the world will continue to grapple with the nuances of the right to be forgotten in the years to come as its legal and technical implications evolve. Like any privacy right, it must be carefully calibrated to empower users without unduly burdening companies or undermining democratic values.
With well-crafted and sensibly enforced right to be forgotten laws, we can give individuals meaningful control over their digital footprint while preserving the public square of the internet. The road ahead is sure to be contentious, but the price of getting it wrong is too high. In an era of surveillance capitalism and ubiquitous data collection, the right to oblivion may be our last line of defense.
[^1]: Art. 17 GDPR – Right to erasure (‘right to be forgotten‘) | General Data Protection Regulation [^2]: What is considered personal data under the EU GDPR? | GDPR.eu [^3]: Google Spain SL v. AEPD and Mario Costeja González | Global Freedom of Expression [^4]: Requests to delist content under European privacy law | Google Transparency Report [^5]: Google wins landmark right to be forgotten case | The Guardian [^6]: Right to be forgotten will apply to some news articles, court rules | Financial Times [^7]: CJEU ruling clarifies right to be forgotten but gaps remain [^8]: GDPR Impossible to Enforce on Blockchain, EU Parliament Says [^9]: Cybercriminal loses bid to have news article about his crimes erased [^10]: Data Protection Bill 2021: Exclusive Rights, Duties, and Way Forward [^11]: Digital Services Act: Commission welcomes political agreement on rules [^12]: What Happens to Your Data When You Die? [^13]: Right to Be Forgotten: Asserting Control Over Our Digital Identity