30 Days Gen AI Risk Trial -Start Now
Skip to main content

Compliance decisions

GDPR deletion requests for AI chats and files

Treat an erasure request as a decision across records, not one delete button. Establish the requester’s rights and applicable exceptions, locate relevant copies, instruct the right service owners and document what was deleted or retained. Deleting a ChatGPT conversation does not necessarily remove other stored material.

For DPOs, privacy operations and AI workspace administrators

Aona field notesC10
One person, several copies
Map before deleting

Conversation, Library, project, source system and exported evidence can have different lifecycles.

Synthetic request ERASURE-TEST-01. No live data has been searched, deleted, retained under a legal hold or sent to a provider.

01

Establish the request and the controller’s decision

Article 17 GDPR provides a right to erasure in specified circumstances and includes exceptions. Start with the request’s scope, the person’s identity where needed and why the organisation holds the data. Do not assume that every reference to a person must be removed regardless of legal obligations or claims.

Article 12 generally requires information about action taken without undue delay and within one month. Necessary extensions can add two months because of complexity or number of requests, with notice and reasons within the first month. Track that response obligation separately from a provider’s published technical deletion lifecycle.

Source context: EU GDPR: Regulation (EU) 2016/679

02

Locate the copies created by employee AI use

Trace the original record, text pasted into a conversation, uploaded file, generated response and anything copied into another system. Ask whether the content was saved to a project, a Library, a memory or a local file. Map which controller, processor or internal owner can act on each copy.

OpenAI’s Work Cloud security documentation distinguishes these categories. It says deleting a conversation does not delete a file saved to Library and does not necessarily delete a saved memory. Connected source systems and exported compliance records follow separate rules. Those statements concern the documented Work Cloud context; confirm the actual surface and configuration in use.

Source context: OpenAI: ChatGPT Work Cloud data handling and retention

03

Use the relevant control for each location

After the privacy decision, assign the appropriate owner to each action: a workspace administrator, file owner, source-system team or processor contact. Record the action requested, its scope and the evidence of completion. Removing a connector or revoking access is not the same operation as erasing data already stored elsewhere.

Where relevant under Article 19, communicate erasure or restriction to recipients unless the stated exception applies, and inform the person about recipients if requested. Keep the request record proportionate: retain the evidence needed to demonstrate handling without unnecessarily duplicating the personal information being erased.

Source context: EU GDPR: Regulation (EU) 2016/679 · OpenAI: ChatGPT Work Cloud data handling and retention

04

Resolve retention and preservation conflicts

Article 17 exceptions include processing necessary for certain legal obligations and the establishment, exercise or defence of legal claims. Have the responsible privacy and legal owners assess the actual record and reason; do not use “compliance” as an unexplained label for keeping everything.

Where information must remain, document the scope and applicable basis, access restrictions and review trigger. Where a technical deletion is scheduled rather than immediate, describe that accurately. Do not promise removal from model weights, every backup or all downstream systems without evidence that supports that claim.

Source context: EU GDPR: Regulation (EU) 2016/679

05

Close with a clear, evidenced response

A useful response identifies what action was taken, what remains where relevant, and the reason for any refusal or partial action. It should not report “all data deleted” when only the visible conversation was removed. Keep internal confirmations and unresolved issues linked to the request record.

The synthetic example below separates action status from legal decision and provider lifecycle. It does not claim any live deletion was performed. Use it to practise the handoff between privacy, workspace administration and the owners of the source and destination systems.

Source context: EU GDPR: Regulation (EU) 2016/679

Put it into practice

AI erasure request evidence map

An invented requester’s information appears in a support record and several AI-related copies. Each row identifies a distinct action and the evidence needed.

Synthetic request ERASURE-TEST-01. No live data has been searched, deleted, retained under a legal hold or sent to a provider.

Follow the copies
01

Source

Customer record in its original system

02

AI

Conversation, saved file, project or memory

03

Exports

Documents and security evidence

04

Response

Confirmed actions and explained exceptions

AI erasure request evidence map
LocationAction to assessEvidence and owner
Original support recordApply the organisation’s Article 17 decision to the source record.Privacy decision and source-system action record; support-system owner.
ChatGPT conversationUse the applicable conversation deletion control if erasure is required.Correct account/conversation and action confirmation; workspace owner.
File saved to LibraryAssess and remove the saved file separately where required.File identity and confirmation; file/workspace owner.
Project file or saved memoryReview its separate storage and deletion control.Relevant object and actual action; authorised workspace user or administrator.
Draft copied into a documentAssess this separate retained copy.Document owner’s confirmation and scope; collaboration-system owner.
Exported security evidenceDetermine necessity, erasure or applicable retention exception.Reasoned privacy/legal decision and access restriction; security record owner.
Request responseReconcile confirmed actions and explained exceptions.Clear response and case record; privacy operations.

Work through your review

Use the checks to organise the evidence you need. Your selections stay in this tab.

0 of 3 reviewed

Example files for this task

Keep the source material and the instructions together. You can also download the complete worksheet or matrix as CSV.

ai-chat-erasure-evidence-map.mdInspect
# AI erasure request evidence map

Synthetic request ERASURE-TEST-01. No live data has been searched, deleted, retained under a legal hold or sent to a provider.

An invented requester’s information appears in a support record and several AI-related copies. Each row identifies a distinct action and the evidence needed.

| Location | Action to assess | Evidence and owner |
| --- | --- | --- |
| Original support record | Apply the organisation’s Article 17 decision to the source record. | Privacy decision and source-system action record; support-system owner. |
| ChatGPT conversation | Use the applicable conversation deletion control if erasure is required. | Correct account/conversation and action confirmation; workspace owner. |
| File saved to Library | Assess and remove the saved file separately where required. | File identity and confirmation; file/workspace owner. |
| Project file or saved memory | Review its separate storage and deletion control. | Relevant object and actual action; authorised workspace user or administrator. |
| Draft copied into a document | Assess this separate retained copy. | Document owner’s confirmation and scope; collaboration-system owner. |
| Exported security evidence | Determine necessity, erasure or applicable retention exception. | Reasoned privacy/legal decision and access restriction; security record owner. |
| Request response | Reconcile confirmed actions and explained exceptions. | Clear response and case record; privacy operations. |

## Review steps

- Map all relevant copies: Use the actual account, surface, feature and saved locations rather than assuming one conversation contains everything.
- Separate legal and technical status: Record the erasure decision, any justified exception and whether the action is requested, completed or scheduled.
- Reconcile before replying: Check recipient communications, provider responses and the Article 12 response timeline.

## Example case record

Reference: ERASURE-TEST-01
Requester: fictional customer Example Person
Receipt date: not a real request
Legal assessment: illustrative only; no live Article 17 determination
Action status: not performed
Response: not sent

## Practice response outline

Identify the request scope, explain the action actually taken, describe any justified retained records and reasons, and give the relevant rights information. Do not claim every copy was removed when confirmations cover only selected locations.

## Source and scope

Guide: https://aona.ai/resources/guides/gdpr-ai-chat-deletion-requests/

Source check: 21 September 2026. General information; no professional approval or installed-product result is represented.

- EU GDPR: Regulation (EU) 2016/679: https://eur-lex.europa.eu/eli/reg/2016/679/oj/eng
- OpenAI: ChatGPT Work Cloud data handling and retention: https://learn.chatgpt.com/docs/enterprise/chatgpt-work-cloud-security#data-handling-and-retention
Download ai-chat-erasure-evidence-map.md
ai-chat-erasure-evidence-map.csvInspect
Location,Action to assess,Evidence and owner
Original support record,Apply the organisation’s Article 17 decision to the source record.,Privacy decision and source-system action record; support-system owner.
ChatGPT conversation,Use the applicable conversation deletion control if erasure is required.,Correct account/conversation and action confirmation; workspace owner.
File saved to Library,Assess and remove the saved file separately where required.,File identity and confirmation; file/workspace owner.
Project file or saved memory,Review its separate storage and deletion control.,Relevant object and actual action; authorised workspace user or administrator.
Draft copied into a document,Assess this separate retained copy.,Document owner’s confirmation and scope; collaboration-system owner.
Exported security evidence,"Determine necessity, erasure or applicable retention exception.",Reasoned privacy/legal decision and access restriction; security record owner.
Request response,Reconcile confirmed actions and explained exceptions.,Clear response and case record; privacy operations.
Download ai-chat-erasure-evidence-map.csv

Before you proceed

Keep these distinctions clear

Access removal is not erasure
Disconnecting a service does not establish deletion of previously stored copies.
A provider lifecycle is not the response deadline
Track GDPR request communications separately from technical deletion timing and exceptions.

Apply it to employee AI use

Bring your actual data path.

Supported employee-AI activity evidence can help a team identify an application and input route relevant to an investigation.

Aona does not execute erasure requests in third-party services or establish the controller’s Article 17 decision. Its own records need a separate handling review.

Use the fictional request to identify what scoped activity evidence is available and who owns each follow-up action.

Review your use case

FAQ

Questions for this decision

Does deleting a ChatGPT chat delete uploaded files and memories?
Do not assume so. OpenAI’s Work Cloud documentation says files saved to Library and saved memories have separate controls, and project files have their own lifecycle. Confirm where the material is actually stored.
Must every request result in complete deletion?
Article 17 has specific grounds and exceptions. Assess the actual purpose and obligations, explain any justified refusal or partial action, and keep a proportionate record of the decision.
Can we promise deletion from model weights?
Only make claims supported by the provider’s applicable process and evidence. A conversation-delete action does not establish removal from every model, backup or downstream copy.
Is the response deadline always the provider’s deletion period?
No. Article 12’s request-response obligations and a provider’s technical lifecycle are different. Generally respond within one month, with any lawful extension explained within that month.

Evidence behind the guide

Sources and scope

Prepared by Aona. Sources checked 2026-09-21. The cited material supports the specific points below; it does not certify a product or your use case.

  1. EU GDPR: Regulation (EU) 2016/679

    Articles 5, 6, 9, 12, 17, 19, 28, 32, 35 and 36 establish the relevant processing, rights, processor and risk-assessment requirements.

    law · checked 2026-09-21
  2. OpenAI: ChatGPT Work Cloud data handling and retention

    Work Cloud conversations, Library files, project files, saved memories, connected content and exported compliance records have distinct retention/deletion behaviours; API ZDR is not a universal ChatGPT Work rule.

    vendor · checked 2026-09-21
GDPR deletion requests for AI chats and files | Aona