The Right to Be Forgotten: Getting Search Engines to Delist Your Old Tweets
Search delisting is the part of "delete my old tweets" that most guides skip. Deleting a tweet removes it from X, but the search result, the archive snapshot, and the scraper copy can all survive. In the EU and UK, the right to be forgotten is the legal lever that reaches those copies. Outside those regions it is mostly a policy request with no obligation attached, which changes the tactics completely.
This guide separates the three layers of a footprint and shows which lever moves each one.
What the right actually covers
The right to erasure sits in Article 17 of the GDPR. It binds data controllers processing your personal data in the EU, and the same right exists in the UK under the UK GDPR. Two limits matter in practice.
- It binds controllers, not the whole internet. Google is a controller for search results about you.
- It carries carve-outs: freedom of expression, journalistic purposes, public interest, legal claims.
That is why the Court of Justice in Google Spain (2014) built a delisting remedy rather than a take-down remedy. Google does not have to erase the underlying page from the publisher's site. It has to stop surfacing that page for searches built on your name. Getting this backwards is the most common way people waste a month on forms.
The three layers of a footprint
| Layer | What lives there | Lever that works | Typical time |
|---|---|---|---|
| 1. Source | The live tweet or profile | Delete on X, or account deletion | Minutes to 30 days |
| 2. Index | Search results for your name | Delisting request (GDPR Art. 17 / Google form) | 2 weeks to 3 months |
| 3. Copies | Web archive, scraper sets, people-search sites | Data-subject requests and opt-out forms | Days to months |
Most people start at layer 3, because that layer looks like the real problem. Start at layer 1 instead. Dead source pages make every later request easier, and a delisted URL that still resolves to a live page tends to creep back into results.
Layer 1: kill the source first
If the tweet is still live, delete it before anything else. Deletions on X propagate within minutes, though search engines may hold a cached copy for several days.
Then keep records: the URL, the date you deleted it, and a screenshot of the confirmation. Delisting requests ask you to show harm, and "I already removed it, here is the receipt" is the strongest form of that.
If someone else posted the content and only mentioned you, layer 1 does not apply to you. Skip straight to layer 2 for the search side, and use the platform's report flow for the content itself.
Layer 2: how to write the delisting request
Google runs a dedicated form for EU and UK residents. A few specifics decide whether it works.
- One URL per request. Bundling ten links into a single submission makes a partial grant impossible to track.
- Give your name exactly as it appears in the search, plus every variant you want covered. For Chinese names, include both the characters and the pinyin spelling.
- State the specific harm. "This is old" is weak. "This page lists my home address and my employer" is strong.
- Supply identity proof, usually a photo ID. It is used for verification only.
- Name the jurisdiction you are claiming under. The EU and UK routes differ in processing and in how appeals work.
Decisions are made case by case, and outcomes cluster into four buckets.
| Outcome | What it means | Your next move |
|---|---|---|
| Delisted in EU/UK only | Index removed for those regions | Ask for global delisting. This is the most common result. |
| Partially granted | Some URLs removed, some kept | Re-request each refused URL with sharper harm detail |
| Refused on public interest | Kept for journalism or because you are a public figure | Go back to layer 1 if you control the page |
| Not processed | Usually an identity or jurisdiction gap | Resubmit with complete documents |
Budget two to eight weeks. Refusals are worth appealing, because the same URL gets re-reviewed by a different assessor and added context often flips the call.
Layer 3: the copies nobody mentions
Two sources of copies matter most. The Internet Archive is a nonprofit with its own exclusion process, and it generally honours requests. People-search aggregators are commercial, and most run opt-out forms because the opt-out is part of their compliance story. Do both once layers 1 and 2 are moving.
Scrapers that resell raw tweet dumps are harder. Most have no form at all. E-mail a data-subject request to whatever contact address exists, and file a complaint with your local data protection authority if nothing comes back. The authority route is slow, but unlike an e-mail it creates an official record.
Which layer fixes which symptom
| Symptom | Right layer | Why |
|---|---|---|
| Your name still returns the tweet in search | Layer 2 | Deleting on X does not clear the cached result |
| A recruiter found the tweet on X itself | Layer 1 | No index is involved |
| A "who is this person" site lists your data | Layer 3 | It assembles records independently of X |
| An old snapshot is still shareable | Layer 3 | That is an archive request, not a search request |
Where this fails
If you live outside the EU and UK, Google is not obliged to delist results based on your location. One exception is worth knowing: you can request removal under Google's own policies for content that exposes personal data, such as ID numbers, bank details, or doxxing material. That is a policy removal rather than a legal one, and its scope is narrower than a delisting, but it beats having no route at all.
The other failure mode is chasing the index before the source. Plenty of people spend a month on forms while the original post stays live. Fix the ordering before you spend the effort.
Writing the harm statement
The harm paragraph is the only part of the form you write yourself, so it carries the decision. Three things make it land.
- Tie the page to a concrete identifier. Not "this is my old account" but "this page shows my full name, my employer, and the city I live in".
- Say what changed. If you posted it at nineteen, say so, and say what the page means now that people search your name before an interview.
- Keep it under 200 words. Long submissions get skimmed. Specific ones get read.
A usable version reads like this: "This URL is an archived profile from 2013 listing my full name, my employer at the time, and the neighbourhood I lived in. I no longer live there. The page is the first result when a recruiter searches my name, and it exposes my former address to anyone who looks." Four sentences, and every one gives the assessor something to act on.
Write it in the language of the jurisdiction: English for the UK form, and either the local language or English for EU submissions. Do not run your legal reasoning through a machine translator. If you are not confident in the wording, get the harm statement checked before you send it.
About digital-footprint-health.shop
digital-footprint-health.shop runs a 100% on-device footprint check: you load your X archive, it parses locally, and it returns a 0-100 health score plus a list of the phone numbers, emails and addresses sitting in your old tweets. It is the fastest way to work out which URLs are even worth a delisting request. Start with the free check, read how to download your X archive, or see the phone number check.
Frequently Asked Questions
Does the right to be forgotten only apply to EU residents?
The legal delisting right applies mainly to EU and UK residents. Everyone else can still use Google policy removals for things like ID numbers, bank details and doxxing material, but that is a policy route rather than an obligation, and it covers less.
Does delisting remove the tweet from X?
No. Delisting only affects search results. The original post has to be deleted on X separately. One does not substitute for the other.
How long does a request take, and can I reapply if refused?
Budget two to eight weeks. Refusals can be appealed or resubmitted, and since each URL is re-reviewed by a different assessor, adding specific harm detail often changes the outcome.
Why can deleted tweets still be found elsewhere?
Because the copies predate your deletion. Web archives, scraper datasets and people-search sites captured a version before you removed it. Those need separate requests, which is layer three.
Check your own X/Twitter footprint
Free on-device scan. Your archive never leaves your computer.
Start Free CheckRelated Reads
GDPR Data Portability: How to Export Your Twitter Data
The GDPR gives you the legal right to receive a copy of your personal data and transfer it. For Twitter users, this means downloading your complete tweet history, media, and account data.
CCPA & Global Privacy Laws: What Are Your Rights
The California Consumer Privacy Act (CCPA) is one of the most comprehensive US privacy laws, giving California residents specific rights over their personal data.