No data deletion or erasure mechanism visible on the page
The right to erasure (also called the "right to be forgotten") is a legal requirement under GDPR and similar laws. This check looks for a visible, easy-to-find way for users to request that their personal data be deleted. If a user has to dig through your site or send a generic contact form to ask for deletion, regulators may view that as a barrier to exercising their rights. Providing a clear mechanism reduces legal risk and builds trust. Add a "Delete my data" link or form to your privacy policy and account settings pages. If you do not have a self-serve option, a dedicated privacy@ email address that is clearly labelled for deletion requests is a compliant alternative.
Why this matters
If a user has to dig through your site or send a generic contact form to ask for deletion, regulators may view that as a barrier to exercising their rights. Providing a clear mechanism reduces legal risk and builds trust.
How to fix it
Add a "Delete my data" link or form to your privacy policy and account settings pages. If you do not have a self-serve option, a dedicated privacy@ email address that is clearly labelled for deletion requests is a compliant alternative.