← Back to blog

The Right to Be Forgotten in the US: What You Can Actually Do

July 20, 2026
The Right to Be Forgotten in the US: What You Can Actually Do

The right to be forgotten does not exist as a federal legal right in the United States. No federal statute gives you the power to erase accurate public information about yourself from the internet, and no US court has recognized such a right. What you do have is a patchwork of state laws that let you request deletion of personal data held by businesses, plus practical tools that can help you manage your digital footprint and even profit from it.

Here is the reality in plain terms:

  • The EU's GDPR right to erasure under Article 17 does not apply to US residents without EU ties.
  • State laws like California's CCPA/CPRA, Colorado's CPA, and Virginia's VCDPA give you limited deletion rights over business-held data, not public internet content.
  • The First Amendment protects publishers from being forced to remove truthful, lawful information.
  • Public records, news articles, and third-party posts generally cannot be compelled off the internet by law.
  • Practical alternatives, including editorial requests, data hygiene, and consent-based monetization platforms, give you more real-world leverage than most people realize.

What US federal and state laws actually give you the right to delete

The federal government has not passed a comprehensive privacy law granting individuals the right to erase personal information. That gap leaves Americans relying on state statutes, each with its own scope and limits.

Man typing at coworking desk with privacy notes

California leads with the CCPA/CPRA, which gives consumers the right to request that a business delete personal data it collected from them. Under California Civil Code 1798.105, a business that receives a verifiable consumer request must delete the data from its records and notify its service providers and contractors to do the same. Colorado's CPA and Virginia's VCDPA follow a similar structure, requiring controllers to respond to deletion requests within 45 days. None of these laws reach independent publishers, news organizations, or third-party websites that republished your information.

The exclusions matter as much as the rights themselves:

  • Businesses may retain data to complete a transaction, comply with a legal obligation, or support security and fraud prevention.
  • Journalistic, scientific, and historical research content is broadly exempt.
  • A GDPR erasure request sent to a US company carries no legal weight unless that company operates under EU jurisdiction.
  • State-level deletion rights compel businesses and their service providers to act, but do not extend to independent publishers or third-party hosts.
  • Sending a data deletion request to a data collector does not guarantee that the information disappears from the broader internet.

Why the First Amendment blocks a true right to be forgotten

The constitutional barrier is the most durable obstacle. The Supreme Court's ruling in Cox Broadcasting Corp. v. Cohn, 420 U.S. 469 (1975), held that a Georgia law allowing a father to sue a TV station for broadcasting his deceased daughter's name violated the First Amendment. That precedent has shaped every subsequent attempt to build a US right to erasure.

"The right to be forgotten represents the biggest threat to free speech on the Internet in the coming decade." — Jeffrey Rosen, Professor of Law at George Washington University, as cited in Georgetown Law Journal analysis of US RTBF frameworks.

Section 230 of the Communications Decency Act adds another layer of protection for platforms. It grants broad immunity to online publishers for third-party content, which makes court-ordered removal of most user-generated or republished material legally impractical. Courts in Garcia v. Google, Inc. (2015) and Manchanda v. Google (2016) explicitly declined to recognize any right to be forgotten in the United States. The result is a legal environment where compelling a platform or publisher to remove truthful information about you is, in almost every case, not an option.

How the US and EU approach privacy so differently

The divergence comes down to foundational values, not just legal drafting.

  • The EU treats privacy as a fundamental human right that can, in specific circumstances, override the public's interest in accessing information.
  • The US Constitution prioritizes the free flow of information, with First Amendment protections that courts have consistently applied to override privacy-based removal claims.
  • GDPR Article 17 gives EU data subjects the right to obtain erasure "without undue delay" when data is no longer necessary, consent is withdrawn, or processing was unlawful, subject to exemptions for free expression and public interest.
  • EU policies apply to data controllers operating within the EU, regardless of where the data subject lives. A US citizen with no EU ties cannot invoke GDPR against a US-based company.
  • Legal scholars describe the US approach as prioritizing "transparency" and "historical accuracy," while critics argue it leaves individuals tethered to past mistakes with no legal exit.

The landmark Google Spain case (2014) illustrated the EU model: a Spanish citizen successfully compelled Google to de-reference links to an old newspaper article about his debt. That outcome is not replicable under US law.

Practical strategies to manage your privacy and monetize your data now

Since legal compulsion is largely off the table, the more productive path is active data management combined with tools that put you in control.

Start with the basics:

  • Submit deletion requests to data brokers and people-search sites under applicable state laws. California, Colorado, and Virginia residents have the clearest statutory standing.
  • Send editorial removal requests directly to news organizations and websites. Many news sites respond to privacy-based requests under their own editorial guidelines, even without legal obligation.
  • Set strict privacy controls on social media accounts and audit what personal information is publicly visible.
  • Monitor your digital footprint regularly using personal data scanning tools.

The more forward-looking move is turning your data into an asset rather than just a liability. Gdcs, operating as Tethra, offers a consent-based data brokerage platform where you earn royalties when brokers purchase your information with your explicit consent. The Leak Sweep tool scans data broker databases and people-search sites for exposed personal information, then generates legal removal notices you can send directly. The Oracle feature pays you for providing rare data insights, while the Multiplier connects multiple data streams to increase your payout. The wallet system tracks your earnings and keeps your data under your control throughout.

Pro Tip: Combine a state-law deletion request with a Tethra Leak Sweep scan. The deletion request removes your data from business records; the scan catches what slipped through to broker databases and generates the removal letters for you.

Infographic outlining five key privacy management steps

Emerging ideas that could reshape US data privacy law

The legal landscape is not static, even if federal progress has been slow. Federal legislation on a right to be forgotten has repeatedly stalled due to First Amendment concerns and corporate lobbying, but the policy debate continues as data breaches and surveillance concerns grow.

The most discussed alternative framework is reputation bankruptcy, a concept drawn from Georgetown Law Journal scholarship. Legal scholar Edward J. George argues that reputation bankruptcy is "quintessentially American" because it mirrors how bankruptcy law already lets individuals escape the financial consequences of past mistakes. Under this model, a person could petition to have outdated or irrelevant personal information made less accessible, raising the cost to obtain it without erasing it entirely. Jonathan Zittrain has similarly proposed a system modeled on the Fair Credit Reporting Act, which already limits how long negative financial information can follow you.

Key developments to watch:

  • State legislatures continue introducing privacy bills; New York's 2017 attempt to require removal of "inaccurate or irrelevant" online statements was an early signal of the direction.
  • Cultural pressure from high-profile data breach coverage is shifting public opinion toward stronger individual privacy rights.
  • Consent-based data tools are filling the gap that legislation has not yet closed, giving individuals practical control without waiting for Congress.
  • Scholars broadly expect incremental, state-by-state progress rather than a sweeping federal right to erasure.

Gdcs

Gdcs's Tethra platform exists precisely in this gap between what the law provides and what individuals actually need. You can start managing your data exposure and earning from your information at gdcs.me/data-hub while the legal framework catches up.

Key Takeaways

The right to be forgotten does not exist federally in the US, but state laws, editorial requests, and consent-based data tools give individuals real, practical options for controlling their personal information.

PointDetails
No federal erasure rightNo US court has recognized a right to remove accurate public information; state laws fill only part of the gap.
State laws have real limitsCalifornia's CCPA/CPRA, Colorado's CPA, and Virginia's VCDPA cover business-held data, not public internet content.
First Amendment blocks compulsionCox Broadcasting Corp. v. Cohn (1975) and Section 230 make court-ordered removal of truthful content legally impractical.
Editorial requests workMany news sites and platforms respond to privacy-based removal requests under their own guidelines, without legal obligation.
Monetization fills the gapConsent-based platforms like Tethra let you earn royalties from your data while scanning for and removing exposed personal information.

Article generated by BabyLoveGrowth