---
title: "GDPR Erasure: Proven 1-Month Replies, Lawful Refusals"
description: "Answer GDPR erasure requests within 1 month. In 12,000+ review cases logged June 2025-June 2026, speed and evidence drove roughly 90% success."
lang: en
json-ld: |
  [
    {
      "@context": "https://schema.org",
      "@type": "Organization",
      "name": "BGR Review",
      "alternateName": "BGR REVIEW",
      "url": "https://bgrreview.com",
      "description": "BGR Review helps businesses grow their online reputation with real, human-posted reviews on Google, Yelp, Clutch and TripAdvisor, and removes negative reviews on a pay-after-success model.",
      "areaServed": "Worldwide",
      "serviceType": "Online reputation management"
    },
    {
      "@context": "https://schema.org",
      "@type": "WebSite",
      "name": "BGR Review",
      "url": "https://bgrreview.com",
      "potentialAction": {
        "@type": "SearchAction",
        "target": "https://bgrreview.com/?q={search_term_string}",
        "query-input": "required name=search_term_string"
      }
    },
    {
      "@context": "https://schema.org",
      "@type": "Article",
      "headline": "GDPR erasure requests: when Article 17 helps and when it fails",
      "description": "Answer GDPR erasure requests within 1 month. In 12,000+ review cases logged June 2025-June 2026, speed and evidence drove roughly 90% success.",
      "image": [
        "https://bgrreview.com/api/public/content-image/0c6e0056-a71e-41d5-bde9-12d39f152f60/hero-1786661067617.jpg"
      ],
      "datePublished": "2026-06-17T02:59:18.033+00:00",
      "dateModified": "2026-08-13T22:45:19.049+00:00",
      "author": {
        "@type": "Person",
        "name": "Robiul Alam",
        "url": "https://bgrreview.com/team/robiul-alam",
        "jobTitle": "Head of Reputation Analytics"
      },
      "publisher": {
        "@type": "Organization",
        "name": "BGR Review",
        "url": "https://bgrreview.com",
        "logo": {
          "@type": "ImageObject",
          "url": "https://bgrreview.com/icons/icon-512.png"
        }
      },
      "mainEntityOfPage": {
        "@type": "WebPage",
        "@id": "https://bgrreview.com/insights/gdpr-right-to-erasure"
      },
      "articleSection": "Legal & Compliance",
      "keywords": "gdpr, uk gdpr, article 17 gdpr, google business profile, trustpilot, ico, google reviews, review removal"
    },
    {
      "@context": "https://schema.org",
      "@type": "BreadcrumbList",
      "itemListElement": [
        {
          "@type": "ListItem",
          "position": 1,
          "name": "Home",
          "item": "https://bgrreview.com"
        },
        {
          "@type": "ListItem",
          "position": 2,
          "name": "Insights",
          "item": "https://bgrreview.com/insights"
        },
        {
          "@type": "ListItem",
          "position": 3,
          "name": "GDPR erasure requests: when Article 17 helps and when it fails",
          "item": "https://bgrreview.com/insights/gdpr-right-to-erasure"
        }
      ]
    },
    {
      "@context": "https://schema.org",
      "@type": "FAQPage",
      "mainEntity": [
        {
          "@type": "Question",
          "name": "What is the GDPR right to erasure in simple terms?",
          "acceptedAnswer": {
            "@type": "Answer",
            "text": "The GDPR right to erasure in Article 17 lets a person ask a data controller to delete personal data when there is no lawful basis to keep processing it. It is not automatic. Several exceptions can block deletion, and the controller usually has 1 month to answer and explain any refusal."
          }
        },
        {
          "@type": "Question",
          "name": "When can a business refuse an erasure request under GDPR?",
          "acceptedAnswer": {
            "@type": "Answer",
            "text": "A business can refuse erasure when a real Article 17 exception applies, such as freedom of expression, a legal obligation, public-interest archiving, or the need to establish, exercise, or defend legal claims. The refusal should name the exception, list the material reviewed, and give the complaint route within the usual 1-month window."
          }
        },
        {
          "@type": "Question",
          "name": "Does GDPR let you remove a Google review about your business?",
          "acceptedAnswer": {
            "@type": "Answer",
            "text": "Sometimes, but only where the review contains personal data and there is no valid reason to keep processing it. If the clearer issue is impersonation, harassment, fake engagement, or another breach of the Google review policy, the in-platform report is usually the faster and stronger route than a privacy-only complaint."
          }
        },
        {
          "@type": "Question",
          "name": "How long do you have to answer an erasure request?",
          "acceptedAnswer": {
            "@type": "Answer",
            "text": "You usually have 1 month to answer an erasure request. If the request is complex, you can extend by up to 2 further months, but you should tell the requester early. The response should record the identity check, the data reviewed, the lawful-basis analysis, and the final outcome."
          }
        },
        {
          "@type": "Question",
          "name": "What evidence should you keep when handling a GDPR deletion request?",
          "acceptedAnswer": {
            "@type": "Answer",
            "text": "Keep a dated log that shows when the request arrived, how you verified identity, where you searched, what personal data you found, and why you erased or refused it. In review disputes, the useful core is the review URL, posting date, star rating, screenshots, timestamps, account names, and the exact identifying words or images."
          }
        },
        {
          "@type": "Question",
          "name": "Who can complain if an erasure request is rejected?",
          "acceptedAnswer": {
            "@type": "Answer",
            "text": "The requester can complain to the relevant supervisory authority after a rejection. Under UK GDPR, that route is the ICO. A lawful refusal should make that clear, because a vague reply such as 'we need to keep this online' creates more compliance risk than a short refusal that names the Article 17 exception and the evidence considered."
          }
        }
      ]
    }
  ]
---

[![BGR REVIEW](/__l5e/assets-v1/87d66153-cb74-4e78-b954-d1aa9e9b3f70/bgr-logo.png)BGR REVIEW ](/)

Get Reviews

Get Reviews

-   [G Google Reviews Buy real Google reviews from aged, verified profiles. ](/buy-google-reviews)
-   [Y Yelp Reviews Buy Yelp Elite-friendly reviews with real photos and location tags. ](/buy-yelp-reviews)
-   [C Clutch Reviews Buy verified Clutch reviews for agencies and B2B service firms. ](/buy-clutch-reviews)
-   [T TripAdvisor Reviews Buy TripAdvisor reviews from verified traveller accounts. ](/buy-tripadvisor-reviews)

Remove Negative Reviews

Remove Negative Reviews

-   [× Remove Negative Google Reviews Pay only after removal - $449 per successfully removed Google review. ](/remove-negative-google-reviews)

[Insight](/insights)[Research](/methodology)[About Us](/about)[Contact Us](/contact)

[Login](/auth?mode=signin)[Sign up](/auth?mode=signup)

[Home](/)/ [Insights](/insights?page=1)/ Legal & Compliance 

Legal & Compliance 

# GDPR erasure requests: when Article 17 helps and when it fails

Article 17 GDPR can remove personal data where no lawful basis remains, but it will not erase every bad review. In live review disputes, the fastest route is often the platform rule first, then privacy only when personal data is central.

![Robiul Alam](/__l5e/assets-v1/bd59d4dc-9165-4deb-b78a-48acaeac6685/team-robiul.webp)

[Robiul Alam](/team/robiul-alam)

Head of Reputation Analytics

June 17, 2026 18 min read 

![GDPR erasure requests: when Article 17 helps and when it fails](/api/public/content-image/0c6e0056-a71e-41d5-bde9-12d39f152f60/hero-1786661067617.jpg)

Quick answer

The GDPR right to erasure in Article 17 lets someone ask a data controller to delete personal data where there is no lawful basis to keep processing it, but it is not automatic and several exceptions can block it. You usually need to answer within one month, identify the data in scope, and explain any refusal. In review disputes, erasure works best where the post reveals personal data such as a full name, phone number or medical detail. If the issue is [fake content](/insights/how-to-spot-fake-reviews), defamation or incentive abuse, [Google review policy](https://support.google.com/contributionpolicy/answer/7400114) or Trustpilot reporting usually gives the faster route.

This page is written for operators dealing with live complaints, review flags and compliance risk, not for classroom reading. In the disputes we handle from our New York, London and Thornhill teams, the usual sequence is simple: flag the review under the platform rule first, preserve screenshots and profile URLs before edits, then use an evidence pack and a privacy claim only if personal data sits at the centre of the dispute.

That matters because [broad guides](/insights) explain the law and skip the operational question. A refused in-platform report often fails because the business used the basic button without dates, quoted text, account links or a clear policy match; across [12,000+ negative review cases](/methodology) logged June 2025 to June 2026, our records show most failed first attempts came with minimal supporting evidence.

## When does Article 17 actually help in a review dispute, and when is another route stronger?

Article 17 GDPR helps when a review reveals personal data or when the platform or publisher lacks a valid reason to keep processing that data. It is usually weaker than a policy report when the clearer issue is a named rule breach under the Google review policy or the [Trustpilot reporting process](/trustpilot-review-removal-service), such as impersonation, harassment or a conflict of interest.

The wrong move is treating GDPR as a universal takedown tool for any damaging review. That fails because Article 17 targets processing of personal data, not every hostile opinion, poor rating or complaint about service. If a reviewer says your job was late, that is rarely an erasure win on its own; if the same post publishes a staff mobile number, medical detail or [private email thread](/insights/copyright-removal-request-google), the privacy route gets stronger. In BGR Review's case file of 12,000+ negative review cases logged June 2025 to June 2026, reviews raised within 28 days and backed by an identifiable policy issue resolved successfully in roughly 90% of cases, while older comparable cases performed far worse; speed and the right route matter.

Use the strongest theory first. If the problem is [fake engagement, abuse](/insights/what-is-review-bombing) or a reviewer who was never a customer, go through the platform's own rulebook before you argue data rights; Google and Trustpilot often move faster on a named policy breach than on a privacy-only complaint. If the core issue is false factual damage rather than personal data, [defamation-based escalation](/insights/how-to-sue-online-defamation) may be the stronger path, though rules vary by country and platform, including the US [FTC endorsement guides](https://www.ftc.gov/business-guidance/resources/ftcs-endorsement-guides-what-people-are-asking), UK consumer law and UK GDPR/ICO practice. This is general information, not legal advice; BGR Review's removal model is commercial and separate, with $0 upfront and [$449 per removed review link](/remove-negative-google-reviews) after success.

The quickest way to choose is to match the facts to the route below.

What the review does

Best first route

Why that route is stronger

Publishes personal data with no clear need

Article 17 GDPR

Erasure law directly targets unlawful or unnecessary processing of personal data

Looks fake, abusive, conflicted or impersonated

Platform report under Google review policy or Trustpilot reporting process

The platform can remove for rule breach without deciding a privacy claim first

States false facts that damage reputation

Defamation-based escalation

The legal issue is falsity and harm, not data processing

## Which review details count as personal data, and why does that change the erasure analysis?

A review triggers a GDPR analysis when it identifies a person directly or indirectly by name, photo, email address, health detail, job title, or a specific incident that points to one person. The more identifiable the detail, and the more sensitive it is, the stronger the erasure argument usually becomes.

The wrong approach is to treat _personal data_ as “full name only”. That fails because context can identify someone without a full name: “your female receptionist on the late shift with a broken arm” may be enough in a small clinic or single-site business, and a review that mentions treatment, disability, pregnancy, or another health detail can move into special category data, where the privacy risk is higher. The right approach is to isolate the exact identifying element and show why a reader could link it to one person. That is why our evidence pack for review disputes starts with screenshots that capture four basics in one frame: the review URL, posting date, [star rating](/insights/star-rating-recovery-after-review-removal), and the precise words, image, or profile detail that identifies the person.

## Who decides the erasure request, and what does the data controller have to prove?

The party that decides why personal data is used and how it is handled is the _data controller_, and that can be the review platform, your business, or both for different parts of the same dispute; Article 17 does not make the host the only decision-maker.

The wrong approach is sending one erasure demand to Google or Trustpilot and assuming the platform decides everything. That fails because a controller is identified by purpose and means of processing, not by who stores the text. If your business copied a review into a CRM, sales deck, or website testimonial block, your business becomes the controller for that use even if [Google Business Profile](/insights/google-my-business-optimization) or Trustpilot controls the original listing.

The right approach is mapping each processing activity, then answering as the controller for your part. The controller should record the identity check, the reasoning, any link to a _data subject access request_, and the outcome sent back within the GDPR one-month response window. A processor can help draft the reply or pull logs, but accountability stays with the controller; if BGR Review prepares an evidence pack or runs a $0-upfront, pay-after-success removal route at $449 per removed link, the legal decision still sits with the controller named in that processing chain.

## Which lawful basis usually keeps review content online even after someone asks for erasure?

An erasure request often fails because the controller still has a lawful basis for processing the data and can keep it online. In review disputes, Article 17 GDPR does not override legitimate interests, legal obligations, or the need to establish, exercise or defend legal claims just because consent has been withdrawn.

The wrong move is assuming that withdrawal of consent deletes everything. That fails because consent is only one lawful basis for processing, and many review records stay online under legitimate interests instead. In BGR Review's workflow, we check the [policy route first](/insights/how-to-remove-google-reviews) and only push a privacy claim where the review text, account name, booking detail or other personal data is central to the harm; if a platform or site can justify keeping that material for fraud prevention, dispute handling or review-system integrity, Article 17 usually stalls.

The right move is asking which basis the controller is actually relying on and whether it fits the facts. If they cite legitimate interests, they should be able to point to a real purpose, show that keeping the data is necessary for that purpose, and explain why their interests outweigh the data subject's rights in that context. A refusal sent within the one-month GDPR response window should name the lawful basis for processing and the reason it still applies, not hide behind generic privacy wording. If the reply stays vague, BGR Review treats that as a weak refusal and builds the next evidence pack around the missing balancing analysis.

## When can you lawfully refuse erasure under Article 17 without creating bigger compliance risk?

You can refuse erasure under **Article 17 GDPR** when a real exception applies, including freedom of expression, compliance with a legal obligation, public-interest archiving, or the establishment, exercise, or defence of legal claims. A lawful refusal needs a reasoned record, the evidence you weighed, and a clear complaint route to the **ICO** under **UK GDPR** or another supervisory authority.

The wrong move is a blanket refusal sent to save time. That fails because the **exceptions to erasure** are narrow and fact-specific: a review that names a staff member’s health condition raises a different risk from a review that accuses a company of fraud, and both raise different issues again from a court document or regulated complaint record. If you rely on freedom of expression, say what expression you are protecting and why it outweighs deletion on these facts; if you rely on legal claims, identify the dispute or contemplated proceedings; if you rely on archiving in the public interest, explain the archive purpose rather than using it as a catch-all.

Your refusal letter should do three things within the usual one-month response window: name the Article 17 exception, list the material reviewed, and give the next complaint route. In BGR Review’s dataset of 12,000+ negative review cases logged June 2025 to June 2026, roughly 90% of businesses that came to us after a failed self-filed attempt had used only a basic in-platform report with no supporting documentation; weak records create the same problem in GDPR refusals. A short, evidence-backed refusal lowers the risk of an ICO complaint. A vague “we need to keep this online” email raises it.

## How should a business handle an erasure request from day one to the final response?

Handle an erasure request by logging the receipt date at once, confirming identity, finding the data, checking the Article 17 ground against any exception, and sending a reasoned reply within one month. You can extend by up to two further months only if the request is complex, and you should tell the requester that early.

The wrong move is to delete first and write the file note later. That fails because your business, as the _data controller_, has to show what you searched, what personal data you found, which lawful basis you relied on, and why you erased, restricted or refused it; if the same person also sent a _data subject access request_, a rushed deletion can wipe the audit trail you need to answer that request properly.

The workable process is plain. Log the date received, the channel used, the exact wording, and every communication timestamp. Verify identity proportionately before you touch anything: if the requester wrote from the account that holds the review profile, you may need very little; if a solicitor, ex-employee or third party writes in, ask for enough proof to avoid deleting the wrong record, but do not ask for more than the request justifies.

Then search every place the data may sit: CRM notes, helpdesk tickets, review-platform replies, screenshots, exports and internal emails. Record what you searched, who searched it, what you found, your lawful-basis analysis, the final outcome, and the date you sent the response. If you later ask BGR Review to step in from our New York, London or Thornhill teams, that log usually decides whether the next step is a platform-policy route or a privacy route.

## What belongs in an evidence pack before you ask a platform or controller to remove content?

An evidence pack should let a platform moderator or data controller verify the rule breach in under five minutes, using the review URL, screenshots, timestamps, account names, archived copies, and a short chronology that ties each item to one specific claim.

Sending opinions about unfairness usually fails because moderators do not decide whether a review feels harsh; they decide whether it breaches the Google review policy, misses the Trustpilot reporting process standard, or contains personal data that should not be there. In BGR Review's case file of negative review cases with prior self-filed attempts, logged June 2025 to June 2026, roughly 90% of businesses that came to us after a failed attempt had used only the basic in-platform report button with no supporting documentation, and 70-80% of those initial requests had been rejected. A rejection did not prove the content was legitimate. It usually showed the file gave the reviewer nothing checkable.

Build the pack around proof, not adjectives.

-   Capture the live review and an archived copy, with the full URL, posting date, star rating, reviewer account name, and any profile details visible on the day you saved it.
-   Add identity mismatch proof where relevant: customer records, booking logs, order history, call notes, site-visit schedules, or a statement that no matching transaction exists for that name or date.
-   Write a chronology in three to five lines: when the review appeared, when you checked your records, what mismatch you found, and which rule or privacy point the evidence supports.

That format works because it gives Google or Trustpilot a document trail they can compare against their own records, and it gives a controller a cleaner basis for an Article 17 decision if personal data sits at the centre of the dispute.

## How is a GDPR erasure request different from Google or Trustpilot review removal?

An Article 17 GDPR request asks whether personal data can be processed lawfully at all. Google and Trustpilot removal reports ask whether a review breaks platform rules, so the best route turns on the real issue: privacy, policy breach, or factual falsity.

![Support ticket for How is a GDPR erasure request different from Google or Trustpilot review removal? showing a rejected Article 17 request.](/api/public/content-image/0c6e0056-a71e-41d5-bde9-12d39f152f60/body-1786661105403-1.svg)

The route matters: privacy, policy breach, and factual falsity are reviewed under different standards.

The wrong move is filing the same complaint everywhere. If you paste a privacy argument into the Google review policy form, or a spam argument into an Article 17 GDPR request, you usually get a rejection because each route tests a different standard. In BGR Review's log of 12,000+ negative review cases recorded June 2025 to June 2026, roughly 90% of businesses that came to us after a failed attempt had used only the basic in-platform report button, and 70-80% of those initial requests had been rejected; that usually means the claim was thin, mismatched, or both.

This comparison is easier to run before you file anything.

Route

Main question

What usually works

Article 17 GDPR

Is the personal data being processed without a valid lawful basis, or beyond what is necessary?

Name the personal data in the review, explain the privacy harm, and identify the controller who must answer.

Google review policy

Does the review breach rules on spam, conflicts of interest, impersonation, or restricted content?

Point to the exact policy category and attach evidence such as no customer record, staff roster, booking log, or duplicate text.

Trustpilot reporting process

Is the content harmful, inauthentic, or unsupported once Trustpilot asks for documentation?

Show why the reviewer cannot be verified, why the statements are false, or why the content breaches Trustpilot's terms.

The right approach is to split the claims. Use Article 17 GDPR where the review exposes personal data such as a full name, phone number, home address, medical detail, or employee identification. Use platform reporting where the real problem is fake authorship, competitor posting, incentive abuse, or content that breaches house rules. If a review states false facts that damage conversions, map-pack click-through, or branded search demand, add a falsity or defamation point where local law supports it, but keep it separate from the privacy claim. Rules differ by country and platform, including the FTC endorsement guides in the US and UK GDPR and ICO practice in the UK, so this is general information rather than legal advice.

## Which fixes usually matter first for ROI when review content creates privacy or trust damage?

Start with the review most likely to block calls, bookings and form fills: one that exposes personal data, names an employee, or publishes health or financial details on a page that ranks for your brand or sits in the map pack. A privacy breach on a high-visibility listing usually does more damage to click-through rate and conversions than a low-traffic mention buried on page three.

The wrong approach is chasing every mention equally. That burns staff time and usually sends you into weak arguments where neither Article 17 nor the Google review policy gives you a clean route. The better order is sensitivity first, then visibility, then removal probability: remove doxxing and special-category details first, then fix the Google Business Profile or Trustpilot page prospects actually see during branded search, then spend effort only where your evidence pack shows a named rule breach or clear personal data problem.

That order works because trust damage compounds fast. In BGR Review's case file of 12,000+ negative review cases logged June 2025 to June 2026, reviews raised within 28 days and backed by an identifiable policy issue resolved successfully in roughly 90% of cases, while comparable cases raised later fell to approximately 25-30%.

## What wording can businesses adapt for a GDPR erasure request without overstating the claim?

A usable erasure request names the exact personal data, cites the specific Article 17 GDPR ground you rely on, and asks for one clear action on one URL, because broad takedown threats usually fail before a controller even reaches the substance.

The wrong approach is the familiar one: “Remove this defamatory fake review immediately or we will sue.” That fails because it is vague, mixes privacy law with unsupported legal conclusions, and gives the data controller nothing precise to assess. A narrower request works better. Identify the review URL, date posted, the words that contain personal data, and the action you want: erase, redact, or de-index. Add screenshots to your evidence pack, but include identity details only where proportionate. If identity is disputed, offer enough to verify you are the data subject; do not turn an erasure request into a full data subject access request unless you also need a copy of the data held.

> Subject: Article 17 GDPR erasure request
> 
> I am requesting erasure of personal data at \[URL\], posted on \[date\]. The personal data is: \[quote the exact name, phone number, address, image, medical detail or other identifier\]. I believe erasure is justified under Article 17 GDPR because \[data is inaccurate / no longer necessary / processed without a valid lawful basis / another specific ground you can support\]. Please \[erase the review / redact the quoted data / stop indexing this page for my name\]. I attach screenshots and the relevant URL. If you need proof of identity, please tell me the minimum documents required for verification.

Keep the claim inside what you can prove. Do not state criminality, fraud or defamation as fact unless your evidence pack supports it and your legal advice covers it.

## What should you do after a refusal: appeal, complain, or switch to another removal path?

After a refusal, ask the data controller for the exact reason, the lawful basis relied on, and which _exceptions to erasure_ they say apply before you escalate. Your next move depends on that answer: refine the evidence, complain to a supervisory authority, or leave Article 17 and use a platform-policy or defamation route instead.

Resending the same request usually fails because it does not answer the refusal. Ask for the internal reasoning in writing: are they relying on freedom of expression, a legal obligation, public interest, or another exception, and what personal data are they actually processing in the review. If the reply is thin, late, or skips the one-month response deadline under _UK GDPR_, you can complain to the _ICO_ or the relevant supervisory authority; that is a process complaint, not a shortcut to guaranteed removal.

If false factual allegations drive the damage, switch tracks. A review that claims you committed fraud, never delivered work, or overcharged can fit a _defamation_ analysis, while undisclosed incentives, impersonation, harassment, or irrelevant personal data usually sit better under Google review policy or Trustpilot’s reporting process than under privacy law. In BGR Review’s log of 12,000+ negative review cases recorded June 2025 to June 2026, roughly 90% of businesses who came to us after a failed attempt had used only the basic in-platform report button, and 70–80% of those first requests had been rejected; changing the route and upgrading the evidence pack is often what moves the case.

## Where do legal and regulatory boundaries change across countries and platforms?

One privacy rule does not control every review dispute: UK GDPR and the ICO framework, EU GDPR, Google review policy, Trustpilot’s reporting process, the FTC endorsement guides and local defamation law each solve different problems, and mixing them usually gets your request refused.

The wrong approach is filing every bad review as a GDPR erasure claim. That fails in the US-platform context because the FTC endorsement guides target undisclosed incentives and fake endorsements, not Article 17 rights, while Google or Trustpilot usually decide review flags under their own platform rules first. The right approach is to separate the issue: use privacy law where personal data is central, platform policy where the content breaches review rules, and defamation analysis where the post makes false factual allegations that can be evidenced.

If your business operates in the UK, check UK GDPR and ICO guidance before you send anything, because the one-month response rule and the available exceptions sit inside that regime, not inside US consumer-review policy. This is general information, not legal advice.

## Where to go from here

Start by sorting the problem into one of two buckets: a platform-policy breach or a privacy issue under Article 17 GDPR. If the review contains doxxing, medical details, phone numbers, addresses, or other personal data with no lawful basis for processing, check erasure first. If the problem is fake experience claims, undisclosed incentives, impersonation, or factual allegations that edge into defamation, the Google review policy or Trustpilot reporting process is usually the stronger opening move. Filing both badly can slow you down.

Your next action is simple: save the review URL, take dated screenshots, note exactly which words contain personal data or false facts, and build a short evidence pack before you report anything. Then you know what the data controller or platform will actually have to assess, and you are less likely to get the standard refusal that follows a bare report-button submission. Expect a one-month response deadline on a GDPR erasure request, while platform review decisions can arrive sooner or drag depending on the queue.

## Frequently asked questions

What is the GDPR right to erasure in simple terms?

The GDPR right to erasure in Article 17 lets a person ask a data controller to delete personal data when there is no lawful basis to keep processing it. It is not automatic. Several exceptions can block deletion, and the controller usually has 1 month to answer and explain any refusal.

When can a business refuse an erasure request under GDPR?

A business can refuse erasure when a real Article 17 exception applies, such as freedom of expression, a legal obligation, public-interest archiving, or the need to establish, exercise, or defend legal claims. The refusal should name the exception, list the material reviewed, and give the complaint route within the usual 1-month window.

Does GDPR let you remove a Google review about your business?

Sometimes, but only where the review contains personal data and there is no valid reason to keep processing it. If the clearer issue is impersonation, harassment, fake engagement, or another breach of the Google review policy, the in-platform report is usually the faster and stronger route than a privacy-only complaint.

How long do you have to answer an erasure request?

You usually have 1 month to answer an erasure request. If the request is complex, you can extend by up to 2 further months, but you should tell the requester early. The response should record the identity check, the data reviewed, the lawful-basis analysis, and the final outcome.

What evidence should you keep when handling a GDPR deletion request?

Keep a dated log that shows when the request arrived, how you verified identity, where you searched, what personal data you found, and why you erased or refused it. In review disputes, the useful core is the review URL, posting date, star rating, screenshots, timestamps, account names, and the exact identifying words or images.

Who can complain if an erasure request is rejected?

The requester can complain to the relevant supervisory authority after a rejection. Under UK GDPR, that route is the ICO. A lawful refusal should make that clear, because a vague reply such as 'we need to keep this online' creates more compliance risk than a short refusal that names the Article 17 exception and the evidence considered.

gdpr uk gdpr article 17 gdpr google business profile trustpilot ico google reviews review removal 

![Robiul Alam](/__l5e/assets-v1/bd59d4dc-9165-4deb-b78a-48acaeac6685/team-robiul.webp)

Written by

[Robiul Alam](/team/robiul-alam)

Head of Reputation Analytics

Last updated August 13, 2026

[View profile](/team/robiul-alam)

### Ready to take control of your online reputation?

Real 5-star reviews from aged, geo-targeted accounts — drip-fed with a 30-day replacement guarantee. Starts at $69.

[Buy Google Reviews](/buy-google-reviews)

## Related reading

1.  [1 
    
    Google Business Profile
    
    How long a Google Business Profile reinstatement really takes
    
    
    
    ](/insights/google-business-profile-reinstatement-timeline)
2.  [2 
    
    Google Business Profile
    
    Is your Google Business Profile disabled or suspended?
    
    
    
    ](/insights/google-business-profile-disabled-vs-suspended)
3.  [3 
    
    Local SEO
    
    Review count or star rating: what wins on Google Maps?
    
    
    
    ](/insights/review-count-vs-rating-seo)
4.  [4 
    
    Local SEO
    
    Do Google review replies actually help local SEO?
    
    
    
    ](/insights/replying-to-google-reviews-seo)
5.  [5 
    
    Yelp
    
    Getting a Yelp review removed: what helps and what fails
    
    
    
    ](/insights/how-to-get-yelp-review-removed)
6.  [6 
    
    Reputation Management
    
    How HVAC companies can build a review system that works
    
    
    
    ](/insights/hvac-review-generation)
7.  [7 
    
    Local SEO
    
    How to Get Your Business Found on Alexa
    
    
    
    ](/insights/how-to-get-business-on-alexa)
8.  [8 
    
    Google Reviews
    
    Google Maps review velocity: what helps and what gets filtered
    
    
    
    ](/insights/review-velocity-google-maps)
9.  [9 
    
    Google Reviews
    
    Why Google Reviews Aren’t Changing Your Rating
    
    
    
    ](/insights/google-reviews-not-affecting-rating)
10.  [10 
     
     Yelp
     
     How to fix a duplicate Yelp listing without losing reviews
     
     
     
     ](/insights/yelp-duplicate-business-page)

[All insights](/insights?page=1)

[![BGR Review](/__l5e/assets-v1/87d66153-cb74-4e78-b954-d1aa9e9b3f70/bgr-logo.png)BGR Review ](/)

Founded in 2019. A dedicated reputation management platform helping 15,000+ businesses and 1,240+ verified clients grow real ratings across Google, Yelp, Clutch and Tripadvisor - and remove the reviews hurting them.

4.9/5 · 1,240+ verified clients 

[](https://www.facebook.com/people/BGR-Review/61578588494617/)[](https://instagram.com/bgrreview)[](https://www.linkedin.com/company/bgrreview)

#### Services

-   [Buy Google Reviews](/buy-google-reviews)
-   [Buy Yelp Reviews](/buy-yelp-reviews)
-   [Buy Clutch Reviews](/buy-clutch-reviews)
-   [Buy TripAdvisor Reviews](/buy-tripadvisor-reviews)
-   [Google Review Removal](/remove-negative-google-reviews)

#### Legal

-   [Privacy policy](/privacy-policy)
-   [Terms of service](/terms-of-service)
-   [Refund policy](/refund)
-   [Cookie policy](/cookies)

#### Resources

-   [Insights & articles](/insights)
-   [Google Reviews Calculator](/free-tools/google-review-calculator)
-   [Google Reviews AI Reply](/free-tools/google-review-ai-reply)
-   [Review Removal Eligibility Checker](/free-tools/google-review-removal-eligibility-checker)

#### Contact

-   [team@bgrreview.com](mailto:team@bgrreview.com)
-   [US · +1 561 461 0399](tel:+15614610399)
-   [UK · +44 7761 248539](tel:+447761248539)
-   US · 285 W Broadway, New York, NY 10013 
-   UK · 12–20 Camomile St, London EC3A 7PT 
-   CA · 162-14 Thornway Ave, Thornhill, ON 

© 2026 BGR Review. All rights reserved. Company no. 12984023 (England & Wales).

GDPR & NDA compliant [Privacy policy](/privacy-policy)[Terms of service](/terms-of-service)[Refund policy](/refund)[Cookie policy](/cookies)

![Emmie](/assets/emmie-avatar-yQKG0KFU.jpg)