Compliance decisions
GDPR deletion requests for AI chats and files
Treat an erasure request as a decision across records, not one delete button. Establish the requester’s rights and applicable exceptions, locate relevant copies, instruct the right service owners and document what was deleted or retained. Deleting a ChatGPT conversation does not necessarily remove other stored material.
For DPOs, privacy operations and AI workspace administrators
Conversation, Library, project, source system and exported evidence can have different lifecycles.
Synthetic request ERASURE-TEST-01. No live data has been searched, deleted, retained under a legal hold or sent to a provider.01
Establish the request and the controller’s decision
Article 17 GDPR provides a right to erasure in specified circumstances and includes exceptions. Start with the request’s scope, the person’s identity where needed and why the organisation holds the data. Do not assume that every reference to a person must be removed regardless of legal obligations or claims.
Article 12 generally requires information about action taken without undue delay and within one month. Necessary extensions can add two months because of complexity or number of requests, with notice and reasons within the first month. Track that response obligation separately from a provider’s published technical deletion lifecycle.
Source context: EU GDPR: Regulation (EU) 2016/679
02
Locate the copies created by employee AI use
Trace the original record, text pasted into a conversation, uploaded file, generated response and anything copied into another system. Ask whether the content was saved to a project, a Library, a memory or a local file. Map which controller, processor or internal owner can act on each copy.
OpenAI’s Work Cloud security documentation distinguishes these categories. It says deleting a conversation does not delete a file saved to Library and does not necessarily delete a saved memory. Connected source systems and exported compliance records follow separate rules. Those statements concern the documented Work Cloud context; confirm the actual surface and configuration in use.
Source context: OpenAI: ChatGPT Work Cloud data handling and retention
03
Use the relevant control for each location
After the privacy decision, assign the appropriate owner to each action: a workspace administrator, file owner, source-system team or processor contact. Record the action requested, its scope and the evidence of completion. Removing a connector or revoking access is not the same operation as erasing data already stored elsewhere.
Where relevant under Article 19, communicate erasure or restriction to recipients unless the stated exception applies, and inform the person about recipients if requested. Keep the request record proportionate: retain the evidence needed to demonstrate handling without unnecessarily duplicating the personal information being erased.
Source context: EU GDPR: Regulation (EU) 2016/679 · OpenAI: ChatGPT Work Cloud data handling and retention
04
Resolve retention and preservation conflicts
Article 17 exceptions include processing necessary for certain legal obligations and the establishment, exercise or defence of legal claims. Have the responsible privacy and legal owners assess the actual record and reason; do not use “compliance” as an unexplained label for keeping everything.
Where information must remain, document the scope and applicable basis, access restrictions and review trigger. Where a technical deletion is scheduled rather than immediate, describe that accurately. Do not promise removal from model weights, every backup or all downstream systems without evidence that supports that claim.
Source context: EU GDPR: Regulation (EU) 2016/679
05
Close with a clear, evidenced response
A useful response identifies what action was taken, what remains where relevant, and the reason for any refusal or partial action. It should not report “all data deleted” when only the visible conversation was removed. Keep internal confirmations and unresolved issues linked to the request record.
The synthetic example below separates action status from legal decision and provider lifecycle. It does not claim any live deletion was performed. Use it to practise the handoff between privacy, workspace administration and the owners of the source and destination systems.
Source context: EU GDPR: Regulation (EU) 2016/679
Put it into practice
AI erasure request evidence map
An invented requester’s information appears in a support record and several AI-related copies. Each row identifies a distinct action and the evidence needed.
Synthetic request ERASURE-TEST-01. No live data has been searched, deleted, retained under a legal hold or sent to a provider.
Source
Customer record in its original system
AI
Conversation, saved file, project or memory
Exports
Documents and security evidence
Response
Confirmed actions and explained exceptions
| Location | Action to assess | Evidence and owner |
|---|---|---|
| Original support record | Apply the organisation’s Article 17 decision to the source record. | Privacy decision and source-system action record; support-system owner. |
| ChatGPT conversation | Use the applicable conversation deletion control if erasure is required. | Correct account/conversation and action confirmation; workspace owner. |
| File saved to Library | Assess and remove the saved file separately where required. | File identity and confirmation; file/workspace owner. |
| Project file or saved memory | Review its separate storage and deletion control. | Relevant object and actual action; authorised workspace user or administrator. |
| Draft copied into a document | Assess this separate retained copy. | Document owner’s confirmation and scope; collaboration-system owner. |
| Exported security evidence | Determine necessity, erasure or applicable retention exception. | Reasoned privacy/legal decision and access restriction; security record owner. |
| Request response | Reconcile confirmed actions and explained exceptions. | Clear response and case record; privacy operations. |
Work through your review
Use the checks to organise the evidence you need. Your selections stay in this tab.
0 of 3 reviewed
Example files for this task
Keep the source material and the instructions together. You can also download the complete worksheet or matrix as CSV.
ai-chat-erasure-evidence-map.mdInspect
# AI erasure request evidence map
Synthetic request ERASURE-TEST-01. No live data has been searched, deleted, retained under a legal hold or sent to a provider.
An invented requester’s information appears in a support record and several AI-related copies. Each row identifies a distinct action and the evidence needed.
| Location | Action to assess | Evidence and owner |
| --- | --- | --- |
| Original support record | Apply the organisation’s Article 17 decision to the source record. | Privacy decision and source-system action record; support-system owner. |
| ChatGPT conversation | Use the applicable conversation deletion control if erasure is required. | Correct account/conversation and action confirmation; workspace owner. |
| File saved to Library | Assess and remove the saved file separately where required. | File identity and confirmation; file/workspace owner. |
| Project file or saved memory | Review its separate storage and deletion control. | Relevant object and actual action; authorised workspace user or administrator. |
| Draft copied into a document | Assess this separate retained copy. | Document owner’s confirmation and scope; collaboration-system owner. |
| Exported security evidence | Determine necessity, erasure or applicable retention exception. | Reasoned privacy/legal decision and access restriction; security record owner. |
| Request response | Reconcile confirmed actions and explained exceptions. | Clear response and case record; privacy operations. |
## Review steps
- Map all relevant copies: Use the actual account, surface, feature and saved locations rather than assuming one conversation contains everything.
- Separate legal and technical status: Record the erasure decision, any justified exception and whether the action is requested, completed or scheduled.
- Reconcile before replying: Check recipient communications, provider responses and the Article 12 response timeline.
## Example case record
Reference: ERASURE-TEST-01
Requester: fictional customer Example Person
Receipt date: not a real request
Legal assessment: illustrative only; no live Article 17 determination
Action status: not performed
Response: not sent
## Practice response outline
Identify the request scope, explain the action actually taken, describe any justified retained records and reasons, and give the relevant rights information. Do not claim every copy was removed when confirmations cover only selected locations.
## Source and scope
Guide: https://aona.ai/resources/guides/gdpr-ai-chat-deletion-requests/
Source check: 21 September 2026. General information; no professional approval or installed-product result is represented.
- EU GDPR: Regulation (EU) 2016/679: https://eur-lex.europa.eu/eli/reg/2016/679/oj/eng
- OpenAI: ChatGPT Work Cloud data handling and retention: https://learn.chatgpt.com/docs/enterprise/chatgpt-work-cloud-security#data-handling-and-retention
Download ai-chat-erasure-evidence-map.mdai-chat-erasure-evidence-map.csvInspect
Location,Action to assess,Evidence and owner
Original support record,Apply the organisation’s Article 17 decision to the source record.,Privacy decision and source-system action record; support-system owner.
ChatGPT conversation,Use the applicable conversation deletion control if erasure is required.,Correct account/conversation and action confirmation; workspace owner.
File saved to Library,Assess and remove the saved file separately where required.,File identity and confirmation; file/workspace owner.
Project file or saved memory,Review its separate storage and deletion control.,Relevant object and actual action; authorised workspace user or administrator.
Draft copied into a document,Assess this separate retained copy.,Document owner’s confirmation and scope; collaboration-system owner.
Exported security evidence,"Determine necessity, erasure or applicable retention exception.",Reasoned privacy/legal decision and access restriction; security record owner.
Request response,Reconcile confirmed actions and explained exceptions.,Clear response and case record; privacy operations.
Download ai-chat-erasure-evidence-map.csvBefore you proceed
Keep these distinctions clear
- Access removal is not erasure
- Disconnecting a service does not establish deletion of previously stored copies.
- A provider lifecycle is not the response deadline
- Track GDPR request communications separately from technical deletion timing and exceptions.
Apply it to employee AI use
Bring your actual data path.
Supported employee-AI activity evidence can help a team identify an application and input route relevant to an investigation.
Aona does not execute erasure requests in third-party services or establish the controller’s Article 17 decision. Its own records need a separate handling review.
Use the fictional request to identify what scoped activity evidence is available and who owns each follow-up action.
Review your use caseFAQ
Questions for this decision
Does deleting a ChatGPT chat delete uploaded files and memories?
Must every request result in complete deletion?
Can we promise deletion from model weights?
Is the response deadline always the provider’s deletion period?
Evidence behind the guide
Sources and scope
Prepared by Aona. Sources checked 2026-09-21. The cited material supports the specific points below; it does not certify a product or your use case.
- EU GDPR: Regulation (EU) 2016/679
Articles 5, 6, 9, 12, 17, 19, 28, 32, 35 and 36 establish the relevant processing, rights, processor and risk-assessment requirements.
law · checked 2026-09-21 - OpenAI: ChatGPT Work Cloud data handling and retention
Work Cloud conversations, Library files, project files, saved memories, connected content and exported compliance records have distinct retention/deletion behaviours; API ZDR is not a universal ChatGPT Work rule.
vendor · checked 2026-09-21