← All GDPR articles

Art.17

Right to erasure ('right to be forgotten')

Data subjects can request deletion of their personal data. A SaaS without a working deletion path is a compliance defect.

Why it matters for SaaS exits

If a buyer discovers the seller has no working data deletion flow, they inherit liability for every user who might request erasure — and there's no way to fulfill it. This is an operational debt that costs real money to fix post-acquisition (engineering time to build deletion pipelines).

What we scan for

We check if the privacy policy documents the right to erasure and if account settings mention deletion. We don't test the actual deletion API (that requires authentication) — but its absence in documentation is a strong signal.

Automated checks (0)

No automated checks map to this article yet.

Buyer due-diligence checklist

  • Ask: 'Can a user delete their account and all associated data? Show me the flow.'
  • Verify the privacy policy mentions 'right to erasure' or 'right to be forgotten'.
  • Check if there's a documented retention period after account closure.

Run this scan on your site

See exactly where your site stands on Art.17 before a buyer asks.

Scan free →