Right to be forgotten: Europe has it, America doesn't

The right to be forgotten sounds like science fiction, but in Europe, it's been law since 2018. You can ask Google to delist search results about you. You can demand Facebook delete your account data permanently. You can tell a data broker to erase your profile, and they have to comply unless they meet narrow exceptions.
In the United States, no such right exists at the federal level. Some states have passed privacy laws that include deletion rights, but the coverage is inconsistent, the exceptions are broad, and enforcement is weak. If you live in Montana or Alabama, you have no legal right to demand deletion from most companies. If you live in California, you have some rights, but they come with caveats that European law doesn't allow.
This isn't a story about Europe doing everything right and America doing everything wrong. Both systems have tradeoffs. But the comparison reveals a fundamental difference in how each jurisdiction treats personal data: Europe treats it as something you own and control. The U.S. treats it as something companies collect and manage, with your input welcome but not required.
GDPR's right to erasure is broad by design
The General Data Protection Regulation gives EU residents the right to request deletion of their personal data under six specific conditions. The data is no longer necessary for the purpose it was collected. You withdraw consent. You object to processing and there's no overriding legitimate interest. The data was processed unlawfully. Deletion is required to comply with a legal obligation. The data was collected from a child.
When you submit a deletion request under GDPR, the company has one month to respond. They can extend that by two more months if the request is complex, but they have to tell you why. If they refuse, they must explain their legal basis. If you disagree, you can file a complaint with your national data protection authority, which has enforcement power including fines up to 4% of global revenue.
The right applies to any company processing data of EU residents, regardless of where the company is located. Google, Meta, Amazon, and every other U.S. tech giant complies with GDPR deletion requests from Europeans because the penalties for noncompliance are severe and the European Data Protection Board has demonstrated willingness to enforce.
GDPR also includes the right to data portability, which lets you download your data in a structured, machine-readable format and transfer it to another service. This isn't deletion, but it's adjacent: you can leave a platform and take your data with you, which reduces lock-in and makes deletion more practical.
The law has exceptions. Companies can keep data when it's necessary to comply with a legal obligation, defend legal claims, perform a task in the public interest, or exercise freedom of expression. These exceptions are narrower than most people expect. "We might need this data someday" doesn't qualify. The company must demonstrate an active, specific legal requirement.
U.S. privacy laws offer patchwork deletion rights
The United States has no federal right to deletion. What exists instead is a growing collection of state laws, each with different rules, different exceptions, and different enforcement mechanisms.
California's Consumer Privacy Act, passed in 2018 and strengthened in 2020, grants California residents the right to request deletion of personal information a business has collected. The business must comply unless the data is necessary to complete a transaction, detect security incidents, comply with legal obligations, engage in research, or enable internal uses "reasonably aligned with consumer expectations."
That last exception is broad. A company can argue that keeping your data for targeted advertising is "reasonably aligned with consumer expectations" because advertising funds free services. Under GDPR, that argument fails unless you explicitly consented to advertising. Under CCPA, it often succeeds.
Virginia, Colorado, Connecticut, Utah, and several other states have passed privacy laws with deletion rights, but the specifics vary. Some states require businesses to honor deletion requests within 45 days. Others allow 60. Some let businesses charge a fee for "excessive" requests. Others don't. Some give consumers the right to sue. Most don't.
Enforcement in most states falls to the state attorney general, who has limited resources and competing priorities. The FTC enforces privacy at the federal level through Section 5 of the FTC Act, which prohibits unfair or deceptive practices, but that authority doesn't create a right to deletion. The FTC can sue companies that promise to delete data and don't, but it can't force deletion when no promise was made.
Some Americans have functional deletion rights through these state laws. Most don't. And even in states with privacy laws, the exceptions are broad enough that companies can often refuse.
The enforcement gap matters more than the law
GDPR's deletion right works because Europe built enforcement infrastructure. Every EU member state has a data protection authority with investigative power, fining authority, and a mandate to handle consumer complaints. Ireland's Data Protection Commission regulates most U.S. tech companies because they base their European operations in Dublin. France's CNIL, Germany's BfDI, and others enforce GDPR within their borders and coordinate through the European Data Protection Board.
When you file a GDPR complaint, a government agency investigates. The process is slow, bureaucratic, and often frustrating, but it exists and it produces results. Meta, Google, Amazon, and others have paid billions in GDPR fines. The fines aren't always large enough to change behavior, but they're large enough that companies take compliance seriously.
U.S. state privacy laws lack equivalent enforcement. California's attorney general can sue companies for CCPA violations, but the office handles consumer privacy alongside antitrust, criminal prosecution, environmental enforcement, and dozens of other responsibilities. CCPA cases compete for attention with everything else. Most violations go uninvestigated.
The FTC has brought privacy enforcement actions against companies that violated their own privacy policies, but the agency's authority is limited. It can't create new rights. It can't force companies to delete data unless they promised deletion and failed to deliver. It can impose fines and consent decrees, but the fines are often smaller than GDPR penalties and the decrees focus on future compliance, not past harm.
Without strong enforcement, deletion rights exist on paper but not in practice. A company can ignore a deletion request, and the consumer's only recourse is filing a complaint that may never be investigated.
Exceptions reveal the philosophical difference
GDPR allows companies to keep data when deletion would interfere with freedom of expression, legal obligations, public interest tasks, scientific research, or the establishment of legal claims. These exceptions are specific and bounded. A company can't invoke "legitimate interest" as a blanket reason to keep everything.
U.S. state privacy laws include broader exceptions. CCPA lets businesses keep data for "internal uses reasonably aligned with consumer expectations." That phrase is vague enough to cover retention for analytics, product improvement, fraud prevention, and targeted advertising. Virginia's law includes similar language. So do Colorado's and Connecticut's.
The difference reflects a deeper divide. GDPR starts from the premise that personal data belongs to the individual, and companies need legal justification to process it. U.S. privacy law starts from the premise that companies can collect and use data unless a specific law prohibits it. Deletion rights in the U.S. are exceptions to the default rule of corporate control. Deletion rights in Europe are the default, and retention is the exception.
This shows up in how each system handles consent. Under GDPR, consent must be freely given, specific, informed, and unambiguous. Pre-checked boxes don't count. Bundled consent doesn't count. Consent obtained through deceptive design doesn't count. If a company can't demonstrate valid consent, it can't process the data, and you can demand deletion.
U.S. privacy laws generally don't require consent for data collection. They require disclosure. Companies must tell you what they collect and give you the option to opt out of sales or sharing, but they don't need your permission to collect in the first place. That weakens deletion rights because companies can argue they collected data lawfully under disclosure-based rules, even if you never consented.
In The Office, Michael Scott builds his World's Best Boss mug identity around the approval of people who work for him. He doesn't own the identity. The office does. When he leaves, the mug stays behind, a relic of a role that only existed in that context. The same dynamic plays out with your data. In Europe, GDPR says you own it and can take it with you or destroy it when you leave. In the U.S., companies argue they built the profile, they hold the data, and they decide when it goes.
The analogy holds because both systems treat data as identity, but they disagree on who controls it. Michael's mug is meaningless outside Dunder Mifflin. Your data profile is meaningless to you but valuable to the company that built it. GDPR says you still get to decide what happens to it. U.S. law says the company does, within limits.
Search delisting works differently across systems
One of GDPR's most visible applications is the right to delist search results. If a search for your name returns outdated, inaccurate, or irrelevant information, you can ask Google to remove those results from searches conducted in Europe. Google evaluates the request, balances your privacy against public interest, and either delists the URLs or refuses.
This right doesn't exist in the United States. Google has no legal obligation to delist search results about Americans, even if the information is outdated or harmful. Some Americans have successfully argued that certain results violate state laws against revenge porn or doxxing, but there's no general right to be delisted.
The difference creates strange outcomes. A European can request delisting of an embarrassing blog post from 2008. An American cannot, even if the post contains the same information. The blog post still exists. The delisting only affects search results in Europe. But that's often enough to reduce visibility and harm.
Search delisting is controversial even in Europe. Critics argue it enables censorship, lets the powerful hide inconvenient truths, and undermines freedom of expression. Supporters argue it balances privacy against speech, gives individuals control over their digital reputation, and prevents outdated information from defining someone's life.
The debate is real, but the mechanism works. Google has processed millions of delisting requests since 2014. Around 45% are granted. The process isn't perfect, but it gives Europeans a tool Americans don't have.
Data brokers operate with near-impunity in the U.S.
Data brokers collect, aggregate, and sell personal information about millions of people. They scrape public records, buy data from other companies, infer details from behavior, and build profiles used for marketing, credit decisions, employment screening, and surveillance.
Under GDPR, data brokers must allow Europeans to access their data, correct errors, and request deletion. The brokers can refuse deletion if they have a legitimate interest, but that interest must be specific and documented. In practice, many brokers comply because the cost of fighting individual requests exceeds the value of retaining the data.
In the United States, data brokers face no federal deletion requirement. California and a few other states require brokers to honor deletion requests, but enforcement is weak and brokers often ignore requests or claim exemptions. The brokers argue they're protected by the First Amendment because they're compiling and selling factual information, which courts have sometimes treated as speech.
The result is that Americans appear in dozens of broker databases with no practical way to remove themselves. You can submit manual opt-out requests to individual brokers, but new brokers appear constantly, old brokers re-add your data from new sources, and the process never ends. Services like Incogni automate broker removal, but even automated tools can't keep up with the scale of the industry.
Europeans face data brokers too, but GDPR gives them leverage. A single complaint to a data protection authority can force a broker to delete data across its entire operation. That leverage doesn't exist in the U.S., where brokers operate in a regulatory gray zone with minimal oversight.
Some U.S. companies extend GDPR rights globally
A handful of companies have decided that maintaining separate data policies for Europe and the rest of the world isn't worth the complexity. Apple, Microsoft, and a few others now offer GDPR-style deletion rights to users worldwide, even in jurisdictions where no law requires it.
This isn't altruism. It's operational simplicity. Building one global privacy system is easier than maintaining different systems for different regions. It also creates competitive advantage: companies that offer strong privacy protections can market themselves as trustworthy, especially when competitors don't.
But most companies don't extend GDPR rights globally. Meta offers deletion to Europeans but not to most Americans. Google complies with GDPR in Europe and CCPA in California but offers weaker protections elsewhere. Amazon, Netflix, and most other platforms do the same.
The result is a two-tier system where your privacy rights depend on where you live. A Californian has more rights than a Texan. A European has more rights than either. The data is the same. The company is the same. The difference is legal jurisdiction.
What you can actually do depends on where you live
If you live in the EU, you have the right to request deletion from any company processing your data. Submit the request through the company's privacy contact or online form. If they refuse, file a complaint with your national data protection authority. The process is slow, but it works.
If you live in California, Virginia, Colorado, Connecticut, or another state with a privacy law, you have limited deletion rights. Submit a request through the company's online form or privacy email. The company has 45-60 days to respond, depending on the state. If they refuse, you can file a complaint with your state attorney general, but enforcement is inconsistent.
If you live in a state without a privacy law, you have no legal right to deletion. You can ask companies to delete your data, and some will comply as a courtesy, but they're not required to. Your best option is to stop using services that don't respect your preferences and support companies that offer strong privacy protections voluntarily.
For everyone, regardless of location: close accounts you no longer use. Request deletion from data brokers manually or through a service. Use privacy-focused tools that minimize data collection in the first place. The legal right to deletion matters, but behavior matters more. The less data you create, the less you need to delete.
The gap isn't closing
Europe passed GDPR in 2016, and it took effect in 2018. In the eight years since, the U.S. has not passed federal privacy legislation. Congress has debated multiple bills. None have become law. The political will doesn't exist, the lobbying pressure is intense, and the ideological divide over government regulation prevents compromise.
State laws are filling the gap, but state-by-state regulation creates fragmentation. A company operating in all 50 states must comply with California's rules, Virginia's rules, Colorado's rules, and the absence of rules everywhere else. The complexity favors large companies that can afford compliance teams and disadvantages small businesses that can't.
Some experts argue that the U.S. will eventually pass federal privacy legislation that preempts state laws and creates a national standard. Others argue that the current patchwork is permanent, and Americans will continue to have privacy rights that depend on geography.
Europe's system isn't perfect. GDPR compliance is expensive, enforcement is uneven across member states, and some companies use dark patterns to discourage deletion requests. But the right exists, it's enforceable, and it gives individuals leverage they didn't have before.
The U.S. system gives some people some rights in some states under some conditions. That's better than nothing. It's not the same as a right to be forgotten.



