You can reduce your online footprint significantly, but you usually cannot erase yourself completely. You can delete unused accounts, remove public information, stop some forms of tracking and marketing, and use privacy rights to request deletion. But public records, legal retention duties, backups, reposts, archives, and information held by other people can remain.
This matters because a digital footprint is not just a record of what someone posted. When data from apps, purchases, websites, location services, public records, and data brokers are combined, it can reveal routines, relationships, interests, health-related inferences, work patterns, and sensitive locations.
What does "deleting yourself" actually mean?
"Deleting yourself online" is a useful phrase, but it covers several different actions. Each has a different outcome.
| Action | What it can achieve | What it does not guarantee |
|---|---|---|
| Delete an account | Removes or deactivates a profile and, in some cases, associated content | Deletion from backups, logs, lawful records, partners, or copies already shared |
| Delete posts and photos | Reduces public visibility of material you control | Removal of screenshots, reposts, archives, or copies held by others |
| Request removal from a website | Removes content from the original publisher if they agree or are legally required to act | Automatic removal from search engines or other websites |
| Request search-result removal | Makes certain results harder to find through a specific search engine | Removal of the original page or removal from every search engine |
| Opt out of marketing or broker lists | Stops a particular organisation using or selling data for certain purposes | Prevention of new collection by unrelated organisations |
| Exercise a legal deletion right | Can require a controller to erase data in specified circumstances | A universal right to erase all historical information about you |
| Improve privacy settings | Reduces future collection and public exposure | Removal of data already collected or shared |
The realistic goal is not perfect disappearance. It is to make data less public, less persistent, less easy to combine, and less valuable for tracking, profiling, fraud, or manipulation.
How far can you go?
The extent to which someone can shrink their digital footprint depends on the type of data, who holds it, why it is held, and whether the data have already been copied or published.
Data you can often remove
You usually have the strongest practical control over information held in accounts you created yourself.
- Old social-media accounts, profiles, posts, comments, photographs, usernames, and bios
- Unused retail, loyalty, delivery, fitness, travel, gaming, dating, and event accounts
- Marketing subscriptions and advertising preferences
- Old public profile pages on forums, communities, or marketplaces
- App permissions, third-party login links, saved payment methods, and contact synchronisation
- Data that are no longer necessary for a service you have left
- Data held only because you previously gave consent, where you withdraw it and no other lawful basis applies
Start with the original source. If an old post sits on a forum, an employer directory, a conference website, or a social platform, contact that publisher first. Search-result removal alone can make material harder to find, but does not normally remove the source page.
Data that are often difficult to remove
Some data are difficult to erase because they are legally required, widely replicated, technically hard to separate, or protected by other rights such as freedom of expression and information.
| Data type | Why it is difficult to delete | What may still help |
|---|---|---|
| Public records | Company registers, property records, court records, licences, insolvency notices, and electoral information may be published or retained under law | Check whether access can be restricted, whether a record is inaccurate, or whether a special safety process applies |
| Tax, payroll, transaction and compliance records | Organisations may have statutory retention obligations and need evidence for audits, fraud prevention, or legal claims | Ask for the specific legal basis, retention period, and restriction of all non-essential uses |
| News reporting and public-interest material | Publishers may rely on freedom of expression and the public interest | Seek correction, context, de-indexing in certain circumstances, or removal of unnecessary sensitive details |
| Reposts, screenshots and archives | You may not control the person or service holding the copy | Make targeted takedown requests and document infringement, harassment, or unlawful disclosure |
| Data-broker profiles | Data can be repeatedly gathered from many public and private sources | Use direct opt-outs, request erasure, and repeat checks periodically |
| Backups and system logs | Organisations may need time to rotate backups or must preserve security and legal records | Ask whether the data are isolated, inaccessible for normal use, and scheduled for deletion |
| Inferences and profiles | A company may infer interests, likely income, health-related categories, or behaviour from other data | Request access, object to profiling where applicable, correct inaccurate input data, and object to marketing |
| Blockchain records | The technical design makes individual records difficult to change or remove | Avoid placing personal data on-chain and use off-chain storage for personal information |
| Data in AI systems | A person's information may have been used in a training or retrieval pipeline, making targeted removal technically and operationally complex | Ask whether personal data were used, seek deletion from source systems, and request details of the controller's remediation process |
The European Data Protection Board's guidance on personal data in blockchain systems explains that storing personal data directly on a blockchain can make erasure and rectification technically difficult. It recommends careful design, including keeping additional personal data off-chain where possible.
What does EU law say?
The EU General Data Protection Regulation gives people a right to request erasure under Article 17. It is often called the "right to be forgotten," although it is more accurate to describe it as a conditional right to have personal data deleted.
An organisation must erase personal data without undue delay in defined situations, including where the data are no longer necessary for the purpose for which they were collected, consent has been withdrawn and no other lawful basis applies, processing is unlawful, or the person has successfully objected to processing. The European Commission's GDPR guidance for individuals also notes that data collected from someone as a child in an online service can be subject to erasure.
The GDPR does not require deletion where the organisation needs the data for:
- Freedom of expression and information
- A legal obligation to retain the data
- A task carried out in the public interest or exercise of official authority
- Public-health, archiving, scientific, historical research, or statistical purposes in specified circumstances
- Establishing, exercising, or defending legal claims
When data were made public, a controller may also have to take reasonable steps, taking account of available technology and cost, to inform other controllers processing links or copies that the person has requested erasure. This is not a guarantee that every copy across the internet will disappear.
The right to erasure works alongside other GDPR rights:
| Right | Why it matters when reducing a digital footprint |
|---|---|
| Access | Helps identify what an organisation holds, where it came from, who receives it, and how long it is kept |
| Rectification | Helps correct false records, profiles, addresses, or data that create harmful inferences |
| Restriction of processing | Can limit use of contested data while an organisation assesses accuracy, an objection, or a deletion request |
| Objection | Stops direct marketing when you object and can challenge processing based on legitimate interests or public tasks |
| Data portability | Lets you obtain certain data you provided before closing or changing a service |
| Withdrawal of consent | Stops processing that depends on consent, though it does not automatically invalidate earlier lawful processing |
For search engines, the European Data Protection Board's right-to-be-forgotten guidance explains how requests to de-reference results should be assessed. De-referencing means a result is removed from name-based search queries. It does not necessarily mean that the original web page is deleted.
What does UK law say?
The UK GDPR and Data Protection Act 2018 retain a closely comparable right to erasure. The UK Information Commissioner's Office guidance on the right to erasure describes it as the right to have personal data erased, also known as the "right to be forgotten."
A UK organisation must assess the request on its facts. It may need to erase data where, for example, the data are no longer necessary, consent has been withdrawn, or the person has objected and the controller has no overriding grounds to continue. Like the EU regime, the UK right is subject to exceptions, including legal obligations, legal claims, public-interest functions, and freedom of expression.
Most requests should receive a response without undue delay and normally within one month. The organisation may ask for additional information only where it has reasonable doubts about identity. It should explain what action it has taken, or clearly explain the reason for any refusal.
For a person using a service with both EU and UK operations, it is sensible to state which law applies to their situation. For example, an EU resident may rely on EU GDPR rights when dealing with an organisation established in the EU, while UK GDPR rules may apply to processing connected with a UK establishment or UK market activity.
What does international law say?
There is no single worldwide right to erase personal information. Privacy law is fragmented, and the strength of deletion rights varies significantly by country, sector, and type of organisation.
The OECD Privacy Guidelines are an important international foundation. They have influenced many national privacy frameworks and recognise an individual's ability to challenge personal data and, where a challenge succeeds, to have data erased, corrected, completed, or amended. However, the Guidelines are principles rather than a directly enforceable global deletion law.
Several jurisdictions provide deletion or similar rights:
| Jurisdiction | General position |
|---|---|
| European Union | GDPR Article 17 creates a conditional right to erasure, supported by data-protection authorities and judicial remedies |
| United Kingdom | UK GDPR provides a closely similar conditional right to erasure, regulated by the ICO |
| Brazil | The LGPD provides rights to anonymise, block, or delete unnecessary, excessive, or unlawfully processed data, and to delete data processed with consent in defined circumstances |
| California | The CCPA gives consumers a right to request deletion of personal information a business collected, subject to substantial exceptions |
| Many other countries | Rights may focus on access and correction, may apply only in certain sectors, or may not provide a broad deletion right at all |
California's official CCPA guidance makes the limits clear. A business may have to delete personal information it collected and instruct service providers to do the same, but it can retain information for reasons such as completing a transaction, maintaining security, complying with legal obligations, defending legal claims, or where information is publicly available or otherwise exempt.
This is a useful international lesson: even strong privacy laws generally support controlled deletion, not historical amnesia.
Is the right to erasure well implemented?
The legal right is established, but implementation remains uneven. The practical barriers are often organisational and technical rather than simply legal.
In 2025, European data-protection authorities coordinated enforcement work focused specifically on how controllers implement the right to erasure. The European Data Protection Board's coordinated enforcement report identified seven recurring challenges. These included weak internal procedures, insufficient information for people making requests, inconsistent practices, uncertainty around retention periods, difficulties deleting data in backups, and reliance on ineffective anonymisation as an alternative to deletion.
This does not mean the right is ineffective. It means the right often works best where an organisation has a clear data inventory, defined retention schedules, accountable teams, and systems designed to find and delete data across operational databases, processors, and backups.
A 2026 enforcement decision by France's data-protection authority, CNIL, illustrates the gap between having a policy and applying it. CNIL fined EXTIA €300,000 after finding problems with transparency and individuals' rights. It reported that, of 265 erasure requests received in 2024, more than three quarters were not handled or were not handled satisfactorily, and 166 people had not been informed what happened to their request.
The European Commission's 2024 GDPR application report also found that businesses reported increasing use of the right to erasure. It noted that this right is used more often than rectification or objection rights.
The balanced conclusion is that the right to erasure is real, enforceable, and often useful. But its effectiveness depends on the facts, the controller's data governance, the quality of its systems, the legal grounds for retention, and whether the individual is prepared to follow up or complain.
How can a digital footprint be misused?
A digital footprint can create harm when organisations, criminals, abusive individuals, or state and commercial actors combine data that appears harmless in isolation.
Identity theft and account takeover
Personal details such as name, address, date of birth, phone number, email address, employment history, family links, and social-media posts can help criminals impersonate someone, answer account-recovery questions, craft convincing phishing messages, or take over accounts.
A breached email address may be only one piece of the puzzle. Combined with public professional information, old addresses, and reused credentials, it can support sophisticated social engineering.
Stalking, harassment and physical risk
Location information can reveal a home, workplace, routine, religious practice, medical appointment, political activity, travel pattern, or the location of a child's school.
In 2024, the US Federal Trade Commission took action against Mobilewalla over allegations that it collected and sold sensitive location data. The FTC said the data included visits to health clinics and places of worship and could expose people to discrimination, physical violence, emotional distress, and other harms. The complaint alleged that the company collected more than 500 million unique advertising identifiers paired with precise location data between 2018 and 2020.
The issue is not limited to the United States. The EDPB's data-broker market study describes brokers as businesses that collect personal data from public and private sources, analyse and aggregate it, and monetise detailed profiles, often without the knowledge or direct control of the people concerned. It warns that AI-driven profiling and analysis can enrich or expose personal data even where the raw data are not directly sold.
Discrimination and exclusion
Profiles may be used to segment people by apparent income, health interests, location, ethnicity, religion, employment status, debt risk, consumer behaviour, political interest, or vulnerability. A person may not know they have been placed in a category, why it was inferred, or how it affects the advertisements, offers, prices, credit decisions, insurance treatment, recruitment exposure, or opportunities they see.
Not every form of segmentation is unlawful. But the more opaque and sensitive the profiling, the greater the risk of unfairness, exclusion, manipulation, or discrimination.
Reputational and professional harm
Old posts, photographs, comments, public disputes, inaccurate databases, or out-of-date professional pages can be taken out of context. Search engines make historical material discoverable long after its relevance has faded.
This is one reason de-referencing can matter. It may reduce the prominence of information in name-based searches even where a publisher has a legitimate reason to retain the original record.
Political influence and manipulation
Behavioural data can be used to identify likely interests, fears, preferences, and voting-related concerns. Targeted messaging may then exploit emotional triggers or vulnerabilities. The underlying issue is not only political advertising. It is the ability to make different people see different messages with little transparency about who was targeted, why, and on what evidence.
Espionage, blackmail and organisational risk
Location, device, and professional data can affect more than personal privacy. Investigative reporting on commercially traded advertising data has shown how device identifiers and movement records can be used to reconstruct likely home and work locations and identify visits to sensitive places. This can create risks of surveillance, blackmail, and espionage, particularly for people in public office, critical infrastructure, security-sensitive roles, or positions with access to valuable information.
What are the best practical steps?
The most effective approach combines clean-up, legal requests, security controls, and a change in day-to-day habits.
1. Audit what exists
Search your name, previous names, usernames, email addresses, phone numbers, and image results. Search in more than one engine. Look for social profiles, old forum accounts, company bios, speaker pages, event listings, directories, marketplaces, and data-broker profiles.
Make a simple record of:
- The organisation or website
- The data visible or held
- Whether the source is public
- Whether you need the account
- The deletion or opt-out method
- The request date and follow-up date
- The result and any retention explanation
2. Secure accounts before deleting them
Start by protecting your primary email account, because it is the recovery route for many other accounts.
- Use unique passwords stored in a password manager
- Enable multi-factor authentication
- Change reused or weak passwords
- Remove unknown devices and active sessions
- Review connected apps and third-party account access
- Check whether old email addresses have appeared in known data breaches
Harvard Privacy and Security guidance recommends avoiding unnecessary accounts, using separate contact details for different contexts where practical, reviewing privacy settings, and using multi-factor authentication to reduce account-takeover risk.
3. Delete accounts and content at the source
Close unused accounts, rather than merely uninstalling the app. Before doing so, download invoices, records, or content you may need. Then remove payment methods, connected accounts, public profile information, and unnecessary personal data before submitting a deletion request.
For content you did not post, contact the original publisher or platform. Be specific about the URL, the information concerned, why it creates a risk or is inaccurate, and the action requested.
4. Use your legal rights strategically
A strong first request should ask for more than deletion. Ask the organisation to explain what it holds and why.
Subject: Request for access, objection and erasure of personal data
Dear [organisation or Data Protection Officer],
I am exercising my rights under the GDPR / UK GDPR.
Please confirm whether you process personal data relating to me and provide details of the data held, its source, purposes, lawful basis, recipients, retention period, and any profiling or automated decision-making.
I request erasure of personal data that are no longer necessary, unlawfully processed, or processed solely on the basis of consent that I now withdraw.
I also object to direct marketing and associated profiling. Please stop these activities and confirm that my details have been added to your suppression list.
If you retain any data, please identify the specific data retained, the legal basis and relevant exemption, the retention period, and whether the processing can be restricted.
Please respond within the applicable statutory timeframe.
Kind regards,
[Name]
[Account email, username or other identifier]
Do not send more identity documents than necessary. If a controller asks for identification, ask why it is needed and whether a less intrusive method will be sufficient.
5. Opt out of brokers and reduce new tracking
Submit opt-outs to people-search sites and data brokers. Repeat this work periodically because data can reappear.
Then reduce future collection:
- Use email aliases for newsletters, trials, shopping, and different life areas
- Provide only information that is required
- Disable unnecessary application permissions, especially location, contacts, microphone, photo library, Bluetooth, and background activity
- Turn off ad personalisation where possible
- Reject non-essential cookies and review browser privacy controls
- Keep personal, professional, and public-facing accounts separate where practical
- Avoid using a social-media login for unrelated services unless there is a clear benefit
- Treat a VPN as a network-privacy tool, not as a guarantee of anonymity
6. Keep evidence and escalate where necessary
Save screenshots, confirmation emails, request forms, correspondence, and dates. If an organisation ignores a request, responds vaguely, or continues direct marketing after you object, send one clear follow-up.
If that does not resolve the issue:
- In the EU, complain to the relevant national data-protection authority.
- In the UK, complain to the ICO.
- Where you face immediate danger, doxxing, stalking, intimate-image abuse, credible threats, or impersonation, prioritise platform reporting, preservation of evidence, account security, and appropriate emergency or legal support.
FAQs
No. You can request removal of certain search results in appropriate circumstances, but a search engine's removal process generally affects discoverability, not the original publisher's page. To remove the source material, you normally need to contact the website or publisher that hosts it.
Not always. The organisation may retain a limited set of data for legal, fraud-prevention, security, accounting, or dispute-resolution purposes. It should be able to explain what it keeps, why it keeps it, and for how long.
Yes. You can make an access request to identify the source of the data and request erasure where the legal conditions apply. You can also object to direct marketing. However, deletion from one organisation does not automatically remove the same data from every broker, advertiser, or partner.
No. Proper anonymisation means data can no longer identify a person, directly or indirectly, using reasonably available means. If the data are only pseudonymised, hashed, encrypted, or linked to an identifier that can still be reconnected to a person, they may remain personal data. The EDPB has identified ineffective anonymisation as a recurring problem when organisations handle erasure requests.
Usually only in limited circumstances. Public authorities and official registers may have legal duties to publish or retain records. Check whether the record is inaccurate, outdated, improperly disclosed, or eligible for restricted access, but do not assume a general privacy request will override a statutory publication duty.
The bottom line
The right to erasure is valuable, but it is not a right to rewrite history or to become invisible online. It works best as part of a broader privacy strategy: find what exists, remove what you control, challenge unnecessary processing, restrict future collection, secure accounts, and repeat the process over time.
For individuals, this creates a smaller and less exploitable digital footprint. For organisations, it reinforces a central principle of modern data protection: collect less, retain less, explain more, and make deletion possible in practice rather than only in a privacy policy.
This article is general information, not legal advice. The exact outcome of a request depends on the data, the organisation's role, the lawful basis it relies on, applicable retention obligations, and the country involved.
