Boxfish Labs home
Boxfish Labs
  • Solutions
  • Resources
  • About
  • EN
  • DE
  • HU
Book a Call
Boxfish Labs home
Boxfish Labs

Menu

    • By service
      • Information Security Advisory
      • External CISO
      • External DPO
      • Data Residency & Sovereignty
      • Human-Centric Cybersecurity Awareness
      • Security Check for Vibe-Coded Apps
    • By Framework
      • GDPR
      • ISO 27001
      • DORA
      • TISAX
      • EU AI Act
      • Cyber Resilience Act
    • Audience
      • Startups and Scaleups
      • Fintech
      • Technology suppliers
      • Educators
      • Individuals
    • View all solutions
    • Articles
    • Courses and Webinars
    • Downloads
    • Compliance Glossary
    • CRA applicability quiz
    • View all resources
    • About us
    • Pledge
    • Social impact
    • Partnerships
    • Contact
    • View about Boxfish Labs

Featured

Dot-matrix letters CRA on a black grid background

Pass EU Cyber Resilience Act (CRA) applicability assessment test

  • EN
  • DE
  • HU
Book a Call

Can You Delete Yourself From the Internet? A Guide to Digital Erasure

You can shrink your digital footprint, but you usually cannot erase yourself completely. A practical guide to account deletion, GDPR and UK erasure rights, data brokers, and the limits of the right to be forgotten.

Boxfish Labs

September 17, 2026 • 19 min read
Cover graphic for Can You Delete Yourself From the Internet? A Guide to Digital Erasure

You can reduce your online footprint significantly, but you usually cannot erase yourself completely. You can delete unused accounts, remove public information, stop some forms of tracking and marketing, and use privacy rights to request deletion. But public records, legal retention duties, backups, reposts, archives, and information held by other people can remain.

This matters because a digital footprint is not just a record of what someone posted. When data from apps, purchases, websites, location services, public records, and data brokers are combined, it can reveal routines, relationships, interests, health-related inferences, work patterns, and sensitive locations.

What does "deleting yourself" actually mean?

"Deleting yourself online" is a useful phrase, but it covers several different actions. Each has a different outcome.

ActionWhat it can achieveWhat it does not guarantee
Delete an accountRemoves or deactivates a profile and, in some cases, associated contentDeletion from backups, logs, lawful records, partners, or copies already shared
Delete posts and photosReduces public visibility of material you controlRemoval of screenshots, reposts, archives, or copies held by others
Request removal from a websiteRemoves content from the original publisher if they agree or are legally required to actAutomatic removal from search engines or other websites
Request search-result removalMakes certain results harder to find through a specific search engineRemoval of the original page or removal from every search engine
Opt out of marketing or broker listsStops a particular organisation using or selling data for certain purposesPrevention of new collection by unrelated organisations
Exercise a legal deletion rightCan require a controller to erase data in specified circumstancesA universal right to erase all historical information about you
Improve privacy settingsReduces future collection and public exposureRemoval of data already collected or shared

The realistic goal is not perfect disappearance. It is to make data less public, less persistent, less easy to combine, and less valuable for tracking, profiling, fraud, or manipulation.

How far can you go?

The extent to which someone can shrink their digital footprint depends on the type of data, who holds it, why it is held, and whether the data have already been copied or published.

Data you can often remove

You usually have the strongest practical control over information held in accounts you created yourself.

  • Old social-media accounts, profiles, posts, comments, photographs, usernames, and bios
  • Unused retail, loyalty, delivery, fitness, travel, gaming, dating, and event accounts
  • Marketing subscriptions and advertising preferences
  • Old public profile pages on forums, communities, or marketplaces
  • App permissions, third-party login links, saved payment methods, and contact synchronisation
  • Data that are no longer necessary for a service you have left
  • Data held only because you previously gave consent, where you withdraw it and no other lawful basis applies

Start with the original source. If an old post sits on a forum, an employer directory, a conference website, or a social platform, contact that publisher first. Search-result removal alone can make material harder to find, but does not normally remove the source page.

Data that are often difficult to remove

Some data are difficult to erase because they are legally required, widely replicated, technically hard to separate, or protected by other rights such as freedom of expression and information.

Data typeWhy it is difficult to deleteWhat may still help
Public recordsCompany registers, property records, court records, licences, insolvency notices, and electoral information may be published or retained under lawCheck whether access can be restricted, whether a record is inaccurate, or whether a special safety process applies
Tax, payroll, transaction and compliance recordsOrganisations may have statutory retention obligations and need evidence for audits, fraud prevention, or legal claimsAsk for the specific legal basis, retention period, and restriction of all non-essential uses
News reporting and public-interest materialPublishers may rely on freedom of expression and the public interestSeek correction, context, de-indexing in certain circumstances, or removal of unnecessary sensitive details
Reposts, screenshots and archivesYou may not control the person or service holding the copyMake targeted takedown requests and document infringement, harassment, or unlawful disclosure
Data-broker profilesData can be repeatedly gathered from many public and private sourcesUse direct opt-outs, request erasure, and repeat checks periodically
Backups and system logsOrganisations may need time to rotate backups or must preserve security and legal recordsAsk whether the data are isolated, inaccessible for normal use, and scheduled for deletion
Inferences and profilesA company may infer interests, likely income, health-related categories, or behaviour from other dataRequest access, object to profiling where applicable, correct inaccurate input data, and object to marketing
Blockchain recordsThe technical design makes individual records difficult to change or removeAvoid placing personal data on-chain and use off-chain storage for personal information
Data in AI systemsA person's information may have been used in a training or retrieval pipeline, making targeted removal technically and operationally complexAsk whether personal data were used, seek deletion from source systems, and request details of the controller's remediation process

The European Data Protection Board's guidance on personal data in blockchain systems explains that storing personal data directly on a blockchain can make erasure and rectification technically difficult. It recommends careful design, including keeping additional personal data off-chain where possible.

What does EU law say?

The EU General Data Protection Regulation gives people a right to request erasure under Article 17. It is often called the "right to be forgotten," although it is more accurate to describe it as a conditional right to have personal data deleted.

An organisation must erase personal data without undue delay in defined situations, including where the data are no longer necessary for the purpose for which they were collected, consent has been withdrawn and no other lawful basis applies, processing is unlawful, or the person has successfully objected to processing. The European Commission's GDPR guidance for individuals also notes that data collected from someone as a child in an online service can be subject to erasure.

The GDPR does not require deletion where the organisation needs the data for:

  • Freedom of expression and information
  • A legal obligation to retain the data
  • A task carried out in the public interest or exercise of official authority
  • Public-health, archiving, scientific, historical research, or statistical purposes in specified circumstances
  • Establishing, exercising, or defending legal claims

When data were made public, a controller may also have to take reasonable steps, taking account of available technology and cost, to inform other controllers processing links or copies that the person has requested erasure. This is not a guarantee that every copy across the internet will disappear.

The right to erasure works alongside other GDPR rights:

RightWhy it matters when reducing a digital footprint
AccessHelps identify what an organisation holds, where it came from, who receives it, and how long it is kept
RectificationHelps correct false records, profiles, addresses, or data that create harmful inferences
Restriction of processingCan limit use of contested data while an organisation assesses accuracy, an objection, or a deletion request
ObjectionStops direct marketing when you object and can challenge processing based on legitimate interests or public tasks
Data portabilityLets you obtain certain data you provided before closing or changing a service
Withdrawal of consentStops processing that depends on consent, though it does not automatically invalidate earlier lawful processing

For search engines, the European Data Protection Board's right-to-be-forgotten guidance explains how requests to de-reference results should be assessed. De-referencing means a result is removed from name-based search queries. It does not necessarily mean that the original web page is deleted.

What does UK law say?

The UK GDPR and Data Protection Act 2018 retain a closely comparable right to erasure. The UK Information Commissioner's Office guidance on the right to erasure describes it as the right to have personal data erased, also known as the "right to be forgotten."

A UK organisation must assess the request on its facts. It may need to erase data where, for example, the data are no longer necessary, consent has been withdrawn, or the person has objected and the controller has no overriding grounds to continue. Like the EU regime, the UK right is subject to exceptions, including legal obligations, legal claims, public-interest functions, and freedom of expression.

Most requests should receive a response without undue delay and normally within one month. The organisation may ask for additional information only where it has reasonable doubts about identity. It should explain what action it has taken, or clearly explain the reason for any refusal.

For a person using a service with both EU and UK operations, it is sensible to state which law applies to their situation. For example, an EU resident may rely on EU GDPR rights when dealing with an organisation established in the EU, while UK GDPR rules may apply to processing connected with a UK establishment or UK market activity.

What does international law say?

There is no single worldwide right to erase personal information. Privacy law is fragmented, and the strength of deletion rights varies significantly by country, sector, and type of organisation.

The OECD Privacy Guidelines are an important international foundation. They have influenced many national privacy frameworks and recognise an individual's ability to challenge personal data and, where a challenge succeeds, to have data erased, corrected, completed, or amended. However, the Guidelines are principles rather than a directly enforceable global deletion law.

Several jurisdictions provide deletion or similar rights:

JurisdictionGeneral position
European UnionGDPR Article 17 creates a conditional right to erasure, supported by data-protection authorities and judicial remedies
United KingdomUK GDPR provides a closely similar conditional right to erasure, regulated by the ICO
BrazilThe LGPD provides rights to anonymise, block, or delete unnecessary, excessive, or unlawfully processed data, and to delete data processed with consent in defined circumstances
CaliforniaThe CCPA gives consumers a right to request deletion of personal information a business collected, subject to substantial exceptions
Many other countriesRights may focus on access and correction, may apply only in certain sectors, or may not provide a broad deletion right at all

California's official CCPA guidance makes the limits clear. A business may have to delete personal information it collected and instruct service providers to do the same, but it can retain information for reasons such as completing a transaction, maintaining security, complying with legal obligations, defending legal claims, or where information is publicly available or otherwise exempt.

This is a useful international lesson: even strong privacy laws generally support controlled deletion, not historical amnesia.

Is the right to erasure well implemented?

The legal right is established, but implementation remains uneven. The practical barriers are often organisational and technical rather than simply legal.

In 2025, European data-protection authorities coordinated enforcement work focused specifically on how controllers implement the right to erasure. The European Data Protection Board's coordinated enforcement report identified seven recurring challenges. These included weak internal procedures, insufficient information for people making requests, inconsistent practices, uncertainty around retention periods, difficulties deleting data in backups, and reliance on ineffective anonymisation as an alternative to deletion.

This does not mean the right is ineffective. It means the right often works best where an organisation has a clear data inventory, defined retention schedules, accountable teams, and systems designed to find and delete data across operational databases, processors, and backups.

A 2026 enforcement decision by France's data-protection authority, CNIL, illustrates the gap between having a policy and applying it. CNIL fined EXTIA €300,000 after finding problems with transparency and individuals' rights. It reported that, of 265 erasure requests received in 2024, more than three quarters were not handled or were not handled satisfactorily, and 166 people had not been informed what happened to their request.

The European Commission's 2024 GDPR application report also found that businesses reported increasing use of the right to erasure. It noted that this right is used more often than rectification or objection rights.

The balanced conclusion is that the right to erasure is real, enforceable, and often useful. But its effectiveness depends on the facts, the controller's data governance, the quality of its systems, the legal grounds for retention, and whether the individual is prepared to follow up or complain.

How can a digital footprint be misused?

A digital footprint can create harm when organisations, criminals, abusive individuals, or state and commercial actors combine data that appears harmless in isolation.

Identity theft and account takeover

Personal details such as name, address, date of birth, phone number, email address, employment history, family links, and social-media posts can help criminals impersonate someone, answer account-recovery questions, craft convincing phishing messages, or take over accounts.

A breached email address may be only one piece of the puzzle. Combined with public professional information, old addresses, and reused credentials, it can support sophisticated social engineering.

Stalking, harassment and physical risk

Location information can reveal a home, workplace, routine, religious practice, medical appointment, political activity, travel pattern, or the location of a child's school.

In 2024, the US Federal Trade Commission took action against Mobilewalla over allegations that it collected and sold sensitive location data. The FTC said the data included visits to health clinics and places of worship and could expose people to discrimination, physical violence, emotional distress, and other harms. The complaint alleged that the company collected more than 500 million unique advertising identifiers paired with precise location data between 2018 and 2020.

The issue is not limited to the United States. The EDPB's data-broker market study describes brokers as businesses that collect personal data from public and private sources, analyse and aggregate it, and monetise detailed profiles, often without the knowledge or direct control of the people concerned. It warns that AI-driven profiling and analysis can enrich or expose personal data even where the raw data are not directly sold.

Discrimination and exclusion

Profiles may be used to segment people by apparent income, health interests, location, ethnicity, religion, employment status, debt risk, consumer behaviour, political interest, or vulnerability. A person may not know they have been placed in a category, why it was inferred, or how it affects the advertisements, offers, prices, credit decisions, insurance treatment, recruitment exposure, or opportunities they see.

Not every form of segmentation is unlawful. But the more opaque and sensitive the profiling, the greater the risk of unfairness, exclusion, manipulation, or discrimination.

Reputational and professional harm

Old posts, photographs, comments, public disputes, inaccurate databases, or out-of-date professional pages can be taken out of context. Search engines make historical material discoverable long after its relevance has faded.

This is one reason de-referencing can matter. It may reduce the prominence of information in name-based searches even where a publisher has a legitimate reason to retain the original record.

Political influence and manipulation

Behavioural data can be used to identify likely interests, fears, preferences, and voting-related concerns. Targeted messaging may then exploit emotional triggers or vulnerabilities. The underlying issue is not only political advertising. It is the ability to make different people see different messages with little transparency about who was targeted, why, and on what evidence.

Espionage, blackmail and organisational risk

Location, device, and professional data can affect more than personal privacy. Investigative reporting on commercially traded advertising data has shown how device identifiers and movement records can be used to reconstruct likely home and work locations and identify visits to sensitive places. This can create risks of surveillance, blackmail, and espionage, particularly for people in public office, critical infrastructure, security-sensitive roles, or positions with access to valuable information.

What are the best practical steps?

The most effective approach combines clean-up, legal requests, security controls, and a change in day-to-day habits.

1. Audit what exists

Search your name, previous names, usernames, email addresses, phone numbers, and image results. Search in more than one engine. Look for social profiles, old forum accounts, company bios, speaker pages, event listings, directories, marketplaces, and data-broker profiles.

Make a simple record of:

  • The organisation or website
  • The data visible or held
  • Whether the source is public
  • Whether you need the account
  • The deletion or opt-out method
  • The request date and follow-up date
  • The result and any retention explanation

2. Secure accounts before deleting them

Start by protecting your primary email account, because it is the recovery route for many other accounts.

  • Use unique passwords stored in a password manager
  • Enable multi-factor authentication
  • Change reused or weak passwords
  • Remove unknown devices and active sessions
  • Review connected apps and third-party account access
  • Check whether old email addresses have appeared in known data breaches

Harvard Privacy and Security guidance recommends avoiding unnecessary accounts, using separate contact details for different contexts where practical, reviewing privacy settings, and using multi-factor authentication to reduce account-takeover risk.

3. Delete accounts and content at the source

Close unused accounts, rather than merely uninstalling the app. Before doing so, download invoices, records, or content you may need. Then remove payment methods, connected accounts, public profile information, and unnecessary personal data before submitting a deletion request.

For content you did not post, contact the original publisher or platform. Be specific about the URL, the information concerned, why it creates a risk or is inaccurate, and the action requested.

4. Use your legal rights strategically

A strong first request should ask for more than deletion. Ask the organisation to explain what it holds and why.

Subject: Request for access, objection and erasure of personal data

Dear [organisation or Data Protection Officer],

I am exercising my rights under the GDPR / UK GDPR.

Please confirm whether you process personal data relating to me and provide details of the data held, its source, purposes, lawful basis, recipients, retention period, and any profiling or automated decision-making.

I request erasure of personal data that are no longer necessary, unlawfully processed, or processed solely on the basis of consent that I now withdraw.

I also object to direct marketing and associated profiling. Please stop these activities and confirm that my details have been added to your suppression list.

If you retain any data, please identify the specific data retained, the legal basis and relevant exemption, the retention period, and whether the processing can be restricted.

Please respond within the applicable statutory timeframe.

Kind regards,
[Name]
[Account email, username or other identifier]

Do not send more identity documents than necessary. If a controller asks for identification, ask why it is needed and whether a less intrusive method will be sufficient.

5. Opt out of brokers and reduce new tracking

Submit opt-outs to people-search sites and data brokers. Repeat this work periodically because data can reappear.

Then reduce future collection:

  • Use email aliases for newsletters, trials, shopping, and different life areas
  • Provide only information that is required
  • Disable unnecessary application permissions, especially location, contacts, microphone, photo library, Bluetooth, and background activity
  • Turn off ad personalisation where possible
  • Reject non-essential cookies and review browser privacy controls
  • Keep personal, professional, and public-facing accounts separate where practical
  • Avoid using a social-media login for unrelated services unless there is a clear benefit
  • Treat a VPN as a network-privacy tool, not as a guarantee of anonymity

6. Keep evidence and escalate where necessary

Save screenshots, confirmation emails, request forms, correspondence, and dates. If an organisation ignores a request, responds vaguely, or continues direct marketing after you object, send one clear follow-up.

If that does not resolve the issue:

  • In the EU, complain to the relevant national data-protection authority.
  • In the UK, complain to the ICO.
  • Where you face immediate danger, doxxing, stalking, intimate-image abuse, credible threats, or impersonation, prioritise platform reporting, preservation of evidence, account security, and appropriate emergency or legal support.

FAQs

No. You can request removal of certain search results in appropriate circumstances, but a search engine's removal process generally affects discoverability, not the original publisher's page. To remove the source material, you normally need to contact the website or publisher that hosts it.

Not always. The organisation may retain a limited set of data for legal, fraud-prevention, security, accounting, or dispute-resolution purposes. It should be able to explain what it keeps, why it keeps it, and for how long.

Yes. You can make an access request to identify the source of the data and request erasure where the legal conditions apply. You can also object to direct marketing. However, deletion from one organisation does not automatically remove the same data from every broker, advertiser, or partner.

No. Proper anonymisation means data can no longer identify a person, directly or indirectly, using reasonably available means. If the data are only pseudonymised, hashed, encrypted, or linked to an identifier that can still be reconnected to a person, they may remain personal data. The EDPB has identified ineffective anonymisation as a recurring problem when organisations handle erasure requests.

Usually only in limited circumstances. Public authorities and official registers may have legal duties to publish or retain records. Check whether the record is inaccurate, outdated, improperly disclosed, or eligible for restricted access, but do not assume a general privacy request will override a statutory publication duty.

The bottom line

The right to erasure is valuable, but it is not a right to rewrite history or to become invisible online. It works best as part of a broader privacy strategy: find what exists, remove what you control, challenge unnecessary processing, restrict future collection, secure accounts, and repeat the process over time.

For individuals, this creates a smaller and less exploitable digital footprint. For organisations, it reinforces a central principle of modern data protection: collect less, retain less, explain more, and make deletion possible in practice rather than only in a privacy policy.

This article is general information, not legal advice. The exact outcome of a request depends on the data, the organisation's role, the lawful basis it relies on, applicable retention obligations, and the country involved.

Share this article

Need help with privacy and data-deletion requests?

Boxfish Labs helps individuals and teams understand erasure rights, reduce unnecessary data exposure, and build practical privacy habits.

Book a discovery call
  • What does "deleting yourself" actually mean?
  • How far can you go?
  • What does EU law say?
  • What does UK law say?
  • What does international law say?
  • Is the right to erasure well implemented?
  • How can a digital footprint be misused?
  • What are the best practical steps?
  • FAQs
  • The bottom line
Boxfish Labs

Human-centred security for teams that need to move fast.

LinkedInInstagramYouTubeFacebook

Explore

  • Solutions
  • Resources
  • About

Legal

  • Privacy Policy
  • Impressum

© 2026 Boxfish Labs