Your erasure request is ignored: taking it to the AEPD
Last updated 2026-09-01 · Reviewed by Jaime Piñeira Pardo, registered with the ICAM bar, no. 138826
The short answer
If a month passes from your request with no reply, or the reply arrives late, the breach is already complete. The matter goes to the AEPD for failure to attend to the right: it must decide within six months of telling you the complaint is proceeding, and after that period you may treat it as upheld. Damages are claimed in the civil courts.
Seven weeks ago you wrote to a company asking it to erase your data. You cancelled, you are no longer a customer and you want nothing more from them. You have had no reply at all, not even an acknowledgement. The marketing emails have kept coming, now twice a week, and last week they phoned offering you a renewal. You have written twice more to the customer service inbox and been told the request is being passed to the relevant department.
The case, in five lines
- What is brought
- A rights protection complaint to the AEPD for failure to attend to a request under Articles 15 to 22 of the Regulation, with a parallel civil claim for damages where harm exists.
- Before which court
- The AEPD (the Spanish data protection authority) decides the complaint for failure to attend to the right. Compensation is claimed before the Civil section of the Tribunal de Instancia (the first-instance court), following the referral in Article 82 of the Regulation.
- Deadline
- The controller has one month from receipt of the request, extendable by two more only if it notifies you within that month with the reasons. Once it expires, the complaint to the authority is decided within six months.
- Who can bring it
- The data subject whose data are processed and who made the request. There is no need to be a customer or to have a current relationship with the controller when the complaint is brought.
- Financial risk
- The protection route forces the right to be attended to, but it does not compensate you. If you also sue for damages and fail to prove concrete harm, that claim may be dismissed and you may bear the costs.
The Article 12 month is what turns your complaint into a case
Article 12 of the Regulation requires the controller to give you information on the action taken on a request under Articles 15 to 22 within one month of receiving it. That period may be extended by a further two months on account of complexity or volume of requests, but only if you are told of the extension within the first month and given the reasons for the delay.
And there is a duty that is always forgotten: if the controller does not act on the request, it must inform you without delay and at the latest within one month of the reasons for not acting and of the possibility of lodging a complaint with a supervisory authority and of seeking a judicial remedy. Silence is not a permitted answer, not even where a refusal would have been correct.
That is why the expiry of the month is the border between asking for something and having a case. Before that date you are an applicant waiting. After it you are the holder of a right that has been breached, with an objectively provable deadline and a complaint the authority must decide through a specific procedure. The strategy is to reach that border with the date properly documented.
Asking flatly for erasure is sometimes asking for the wrong thing
Article 17 requires erasure without undue delay where the data are no longer necessary for the purposes, where consent is withdrawn and there is no other basis, where an objection under Article 21 succeeds, where they have been unlawfully processed, where a legal obligation requires it, or where they were collected in relation to the offer of information society services to children.
If the processing rests on legitimate interests, the natural door is not Article 17 but Article 21: you may object at any time on grounds relating to your particular situation, and the controller must stop processing unless it demonstrates compelling legitimate grounds overriding your interests, rights and freedoms, or the establishment, exercise or defence of legal claims.
There is also a case where the law brooks no argument. Where processing is for direct marketing purposes, the data subject has the right to object at any time, including profiling related to it, and the data must no longer be processed for those purposes. No balancing, no compelling grounds and no further arguments from whoever sends the emails.
Article 19 drags the erasure through to whoever received your data
Erasing in the database of whoever was writing to you is not enough if your data had travelled. Article 19 requires the controller to communicate any rectification, erasure or restriction to each recipient to whom the personal data have been disclosed, unless this proves impossible or involves disproportionate effort. It is a chain obligation, not a node obligation.
The same article adds the piece that lets you check it: the controller shall inform the data subject about those recipients if the data subject requests it. It is worth asking for expressly in the initial request, because the list of recipients is what later explains why you kept receiving calls from a company you never gave your data to.
That same block of rights includes an information tool almost nobody uses before complaining: Article 15 lets you obtain confirmation as to whether your data are processed and, if so, access to them and to the purposes, the categories, the recipients, the envisaged retention period, the source where you did not supply them and the existence of automated decision making.
Six months at the AEPD, and silence works in your favour
Article 64 of Organic Law 3/2018 reserves a route of its own for these matters. Where the procedure concerns exclusively a failure to attend to a request to exercise the rights in Articles 15 to 22 of the Regulation, the period to decide is six months from notification to the complainant that the complaint is proceeding.
And the next sentence is the one that matters: once that period has passed, the person concerned may treat the complaint as upheld. Administrative silence here does not harm you, it favours you. That completely changes the negotiating position against the controller, which knows that letting time run gains it nothing in this particular procedure.
That route should be distinguished from the penalty one. If the object is to determine whether an infringement exists, the maximum duration is twelve months from the notice of initiation, lapsing and closing on expiry, and there is also the possibility of the authority issuing a warning with corrective measures in a six month procedure. They are different paths with different logics.
The protection route restores the right; the money is elsewhere
The complaint to the authority gets the controller to attend to what it should have attended to and, where appropriate, to answer for an infringement. What it does not do is compensate you. That is what Article 82 of the Regulation is for, giving anyone who has suffered material or non material damage as a result of an infringement the right to compensation from the controller or the processor.
The article allocates the burden demandingly for the infringer. Any controller involved in the processing is liable for the damage caused where the processing does not comply with the Regulation, and is exempt only if it proves that it is not in any way responsible for the event giving rise to the damage. The processor is liable where it breached obligations specifically directed at processors or acted outside the controller's lawful instructions.
That is why the two routes are opened in order and not blindly at once. First the protection complaint, which establishes through an official ruling that the right was not attended to. Then, with that document and with proof of concrete harm, the civil claim for compensation, which is the only one ending in a sum in your favour.
How we run the case, step by step
- 1
Reconstruct the request and its exact date
We retrieve the original submission, the channel used and the acknowledgement, and check whether an extension was notified within the first month with reasons given. Whether there is a breach or merely impatience turns on that date.
- 2
Choose the right that fits, not the loudest one
Depending on the basis for the processing, the right one is erasure under Article 17, objection under Article 21 or, if time must be gained while accuracy is disputed, restriction under Article 18. A final demand is sent on the correct basis with a firm deadline.
- 3
Request access to see the full map
The right of access reveals the purposes, the categories of data, the recipients, the retention period, the source and the existence of automated decision making. Without that map the complaint is just an unanswered email.
- 4
Complain to the AEPD once the month expires
The complaint for failure to attend to the right is lodged with the request, the acknowledgement and the calculation of the period. It must be decided within six months of notification that it is proceeding, and after that period it may be treated as upheld.
- 5
Check the effect on the recipients
We require the erasure or restriction to be communicated to every recipient the data were disclosed to, unless impossible or involving disproportionate effort, and ask for the list of those recipients to verify the chain has been closed.
- 6
Claim compensation where there was harm
With the authority's ruling and proof of concrete harm we bring the Article 82 action in the civil courts, against the controller and, where appropriate, against the processor that acted outside the instructions it had.
The evidence that decides the case
- The original request with its date, the channel used and the acknowledgement or delivery trail.
- The absence of any reply within the month, or the reply that came later, with its date visible.
- The extension notice, if there was one, to check whether it arrived within the first month and with reasons.
- The response to the access request, showing the recipients and the envisaged retention period.
- The marketing messages sent after the request, dated, to prove the processing continued.
- The concrete harm: calls from third parties that never got your data from you, or decisions taken using those data.
What closes the door
- Complaining before the month expires. The authority needs a completed breach, and going early merely hands the controller time.
- Sending the request through a channel that leaves no trail. Without a proven date of receipt there is no period to count and the whole case rests on your word.
- Paying a fee to be answered. The action is free of charge, except for manifestly unfounded or excessive requests, and the burden of proving that lies on the controller.
- Ignoring the identification request. Where it has reasonable doubts the controller may ask for additional information, and leaving that unanswered leaves the request in limbo.
- Asking for erasure when objecting was the right move. Where processing rests on legitimate interests or on direct marketing, Article 21 is the shorter route.
The law that applies
- Art. 12 RGPD. It requires information to be given concisely, transparently, intelligibly and in an easily accessible form, and information on action taken on a request under Articles 15 to 22 within one month of receipt, extendable by two more for complexity or volume if notified within the first month with reasons. If the request is not acted on, the reasons and the possibility of complaining to a supervisory authority and seeking a judicial remedy must be given within that month. Everything is free of charge except manifestly unfounded or excessive requests, which the controller must prove, and the controller may request additional information where it has reasonable doubts about identity. 32016R0679
- Art. 17 RGPD. It requires erasure without undue delay where the data are no longer necessary for the purposes, consent is withdrawn with no other basis, an Article 21 objection succeeds, they were unlawfully processed, a legal obligation requires it or they were collected in relation to information society services offered to children. Whoever made them public must take reasonable steps to inform other controllers of the request to erase links and copies. It does not apply where processing is necessary for freedom of expression and information, legal obligations or public tasks, public health, archiving, research or statistical purposes, or the establishment, exercise or defence of legal claims. 32016R0679
- Art. 21 RGPD. It allows objection at any time, on grounds relating to the person's particular situation, to processing based on a public interest task or on legitimate interests, including profiling, and the controller must stop processing unless it demonstrates compelling legitimate grounds that override or the establishment, exercise or defence of legal claims. Against direct marketing the objection is unconditional and the data must no longer be processed for those purposes. The right must be brought to the person's attention explicitly and separately at the latest at the time of the first communication. 32016R0679
- Art. 18 RGPD. It gives the right to obtain restriction of processing where the accuracy of the data is contested, for a period allowing verification; where the processing is unlawful and the person prefers restriction to erasure; where the controller no longer needs the data but the person needs them for legal claims; and while it is verified whether the controller's legitimate grounds override following an objection. Once restricted, the data may only be stored or processed with consent, for legal claims, to protect another person or for important public interest, and the person must be informed before the restriction is lifted. 32016R0679
- Art. 19 RGPD. It requires the controller to communicate any rectification, erasure or restriction of processing carried out under Articles 16, 17.1 and 18 to each recipient to whom the personal data have been disclosed, unless this proves impossible or involves disproportionate effort, and to inform the data subject about those recipients if the data subject requests it. 32016R0679
- Art. 64 LOPDGDD. It reserves a procedure of its own for failure to attend to a request under the rights in Articles 15 to 22 of the Regulation: the period to decide is six months from notification to the complainant that the complaint is proceeding, and after that period the person may treat it as upheld. Where the object is to establish an infringement, the maximum duration is twelve months from the notice of initiation, lapsing and closing on expiry, and six months if the matter is steered towards a warning with corrective measures. The periods are suspended where an opinion must be sought from Union bodies or other supervisory authorities. BOE-A-2018-16673
Each article checked against the consolidated text published in the BOE (the Spanish official gazette).
Frequently asked questions
How long does the company have to reply to me?
One month from receipt of the request. That period can only be extended by two further months on account of complexity or volume, and only if you are told within the first month with the reasons for the delay stated. If they also decide not to act on the request, they must inform you within that same month of the reasons and that you may complain to a supervisory authority.
What if the AEPD does not decide either?
In this particular procedure silence favours you. Where the complaint concerns exclusively a failure to attend to a right under Articles 15 to 22, the period to decide is six months from notification that it is proceeding, and after that period the person may treat the complaint as upheld. That is not the same as the penalty procedure, which lapses after twelve months.
They ask for my ID to deal with my request. Is that lawful?
It can be. Where the controller has reasonable doubts about the identity of the person making the request, it may ask for the additional information needed to confirm it. What is not allowed is using that request as an indefinite barrier or demanding disproportionate documents. If you are asked to identify yourself, do it at once and in writing, because refusing leaves the request unresolved and weakens the later complaint.
Can they charge me for handling the request?
As a rule, no: every communication and any action taken under Articles 15 to 22 is free of charge. Only where requests are manifestly unfounded or excessive, in particular because of their repetitive character, may the controller charge a reasonable fee based on administrative costs or refuse to act. And the burden of demonstrating that character lies on the controller, not on you.
Other companies keep calling me. Is any of this any use?
Yes, and there is an article designed for that. The controller must communicate the erasure or restriction to each recipient to whom your data were disclosed, unless this proves impossible or involves disproportionate effort, and must inform you who those recipients are if you ask. Requesting that list turns a vague problem into a concrete list of controllers to address.
This guide explains how the action works in general. It does not replace the study of your own case: deadlines depend on when things happened and on what you have done since.