Skip to main content
ExplainerData PrivacyExplainerSep 1, 2026, 1:20 PM· 5 min read· in perspectives

The Mechanics of the 'Right to Be Forgotten': Why the Global Internet Renders Absolute Privacy Logistically Impossible

The GDPR's flagship privacy mandate assumes data can be cleanly deleted, but the distributed, immutable architecture of the modern internet makes absolute erasure a mathematical impossibility.

By Ling Zhou

Systems Engineers 40%Privacy Fundamentalists 35%Global Harmonizers 25%
Systems Engineers
Maintain that distributed databases, immutable backups, and AI models make absolute data deletion mathematically and physically impossible.
Privacy Fundamentalists
Argue that the right to privacy is absolute and that technical challenges are merely excuses for corporate non-compliance.
Global Harmonizers
Focus on the jurisdictional impossibility of enforcing regional privacy laws on a borderless, global internet.

The short answer

  1. The Right to Be Forgotten assumes data is centralized, but the internet relies on distributed, redundant storage.
  2. Immutable backups, designed for cybersecurity, make permanent deletion of user data technically unfeasible.
  3. The borderless nature of the internet creates jurisdictional clashes that limit the enforcement of regional privacy laws.
  4. Emerging technologies like AI and blockchain are fundamentally incompatible with the concept of absolute data erasure.

The popular consensus regarding the "Right to Be Forgotten" is that tech giants are simply too greedy or too lazy to delete user data when asked. We imagine a central server where a single button press could wipe a digital footprint clean, if only a corporation would comply. But this fundamentally misunderstands how the modern internet is built. The evidence shows that absolute data erasure is not a matter of corporate compliance; it is a logistical and mathematical impossibility dictated by the architecture of distributed systems.[4]

To understand why the European Union’s General Data Protection Regulation (GDPR) struggles to enforce its core privacy mandate, we must look past the legal text and into the server racks. The internet was designed for redundancy and persistence, not targeted amnesia. When a user requests erasure, they are asking a decentralized, fragmented network to perform an action it was explicitly engineered to resist.

The mechanics of data storage explain the friction. When you submit personal information to a platform, it does not sit in a single, neat folder. It is instantly replicated across multiple databases for load balancing, cached in content delivery networks to reduce latency, and baked into unstructured data logs used for system diagnostics. Finding every instance of a user's data is like trying to extract a specific drop of water after it has been stirred into the ocean.[2]

This technical reality is what makes the GDPR's Article 17—the right to erasure—so difficult to execute in practice. As enterprise data management analyses highlight, the sheer volume of unstructured data and the complexity of legacy backup systems create an environment where complete deletion is a forensic nightmare. Companies often do not even know where all the data resides, let alone how to surgically remove it without corrupting the surrounding datasets.[2]

How a single piece of user data is instantly fragmented across multiple storage environments.

Backups present a particularly intractable problem. Best practices in cybersecurity and disaster recovery require immutable backups—snapshots of data that cannot be altered or deleted, specifically to protect against ransomware. If a company deletes a user's profile from its active database, that profile still exists in encrypted backups stored off-site. If the system is ever restored, the "forgotten" data is resurrected with it.

The European Data Protection Board (EDPB) has openly acknowledged these hurdles. In its assessments of the right to erasure, the EDPB identifies significant challenges hindering full implementation, noting that the technical realities of modern data processing often clash with the rigid expectations of the law. The board's findings suggest a growing recognition that compliance cannot be absolute.[1]

Beyond the technical constraints of a single company, the Right to Be Forgotten collides with the borderless nature of the internet. The GDPR is a European law, but data flows globally. When a French citizen demands their data be erased, that data might be hosted on a server in Singapore, processed by a vendor in India, and cached on devices in the United States.

Beyond the technical constraints of a single company, the Right to Be Forgotten collides with the borderless nature of the internet.

This jurisdictional clash creates what foreign policy analysts call the illusion of global data privacy standards. While the EU attempts to project its privacy values extraterritorially, it lacks the enforcement mechanisms to compel compliance across sovereign borders. A search engine might delist a result on its European domains, but the information remains freely accessible on its American or Asian counterparts.[3]

The extraterritorial reach of the GDPR often clashes with the physical location of global servers.

The logistical impossibility is further compounded by the rise of artificial intelligence and large language models (LLMs). LLMs are trained on vast scrapes of the public internet. Once personal data is ingested and its statistical weights are adjusted within a neural network, the original data ceases to exist in a recognizable form.

You cannot simply "delete" a person from a trained AI model. The information is baked into the billions of parameters that dictate how the model predicts text. To remove a specific individual's influence, researchers often have to retrain the model entirely—a process that costs millions of dollars and months of computing time. The GDPR was written for databases, not neural networks.[4]

Blockchain technology and immutable ledgers introduce another fatal flaw in the Right to Be Forgotten. By definition, a blockchain is an append-only database. Once a transaction or piece of data is recorded on a public ledger, it cannot be altered or erased without destroying the integrity of the entire chain.

This creates a direct, unresolvable conflict between the legal right to erasure and the mathematical reality of cryptographic persistence. Regulators are increasingly forced to accept "anonymization" or "pseudonymization" as a substitute for actual deletion, quietly conceding that true erasure is impossible in these environments.[1][4]

Data packets are routed globally in milliseconds, complicating efforts to track and erase specific information.

We must also consider the tension between privacy and the public record. The Right to Be Forgotten was originally established to allow individuals to move past outdated or irrelevant information, such as old bankruptcies or minor criminal offenses. But when applied broadly, it risks becoming a tool for censorship, allowing public figures to scrub their histories and rewrite the past.

The internet's memory is a feature, not a bug. It democratizes access to information and preserves the historical record against those who would seek to sanitize it. By demanding that this memory be selectively erased, privacy frameworks are asking the network to perform a function that undermines its core utility.[3][4]

Ultimately, the debate over the Right to Be Forgotten reveals a profound disconnect between lawmakers and engineers. We are attempting to govern a 21st-century distributed network using 20th-century concepts of centralized filing cabinets. Until privacy legislation aligns with the architectural realities of the internet, absolute data erasure will remain a legal fiction rather than a technical reality.[4]

Jargon, explained

Right to Erasure
Article 17 of the GDPR, which grants individuals the right to request the deletion of their personal data by a data controller.
Distributed Database
A database in which data is stored across multiple physical locations or servers to ensure redundancy and fast access.
Immutable Backup
A copy of data that cannot be altered, deleted, or overwritten, typically used to recover systems after a cyberattack.
Extraterritoriality
The application of a country's laws outside its own physical borders, such as the EU attempting to enforce GDPR on foreign websites.

Sources

Source coverage

4 outlets

3 viewpoints surfaced

Systems Engineers 40%Privacy Fundamentalists 35%Global Harmonizers 25%
  1. [1]European Data Protection BoardPrivacy Fundamentalists

    EDPB identifies challenges hindering the full implementation of the right to erasure

    Read on European Data Protection Board
  2. [2]K2viewSystems Engineers

    GDPR right to be forgotten – what makes it tough?

    Read on K2view
  3. [3]Council on Foreign RelationsGlobal Harmonizers

    The Illusion of Global Data Privacy Standards (Technology Policy Brief #165)

    Read on Council on Foreign Relations
  4. [4]Factlen Editorial TeamGlobal Harmonizers

    Synthesis by Factlen editorial team

    Read on Factlen Editorial Team

Comments

Stay informed

Every angle. Every day.

Get perspectives stories with full source coverage and perspective breakdowns delivered to your inbox.