Deletion is a normal part of everyday life. We send files to the Recycle Bin, empty folders and get rid of user accounts we no longer use. But do you know what actually happens when you press “delete”?
The process of deletion is often poorly explained by technology providers. A lack of transparency about how requests are processed, and the absence of clear confirmation that data has actually been removed, are recurring themes in research.
Read: Paramount postpones giant merger with Warner Bros pending “Antitrust” lawsuit
This doesn’t just apply to operating systems. Also on social media and subscription services, the deletion mechanisms are often just as unclear. Such misunderstandings can have serious consequences for users’ privacy and security.
In addition, there is the fear of losing data – a condition called “diagraphephobia” – where users are afraid of accidentally deleting. Although this is not a recognized disease, studies show that some people experience great anxiety at the thought of losing personal photos, files, and music.
Such concerns lead to large amounts of personal data lying untouched – but not deleted – ready to be misused.
Erasing vs. erasing
A common misconception is to think that deletion means erasing – i.e. that the data is completely gone and impossible to retrieve again. This is mostly wrong.
When you delete files — and empty the Recycle Bin — the data isn’t actually erased. However, the system marks the storage space as available for reuse and updates metadata so that the file is no longer connected. But the content is often still there, and can be recovered with the right tool – especially when data is duplicated across systems or devices.
More robust forms of deletion include physically destroying the storage media, overwriting the memory blocks with new data, or encrypting the data and then erasing the key.
However, such methods can be costly – and can render the storage device unusable. Cloud solutions also present their own challenges when it comes to secure deletion.
Content on social media also does not necessarily disappear after deletion, due to replies, comments and internet archives that can store posts in different ways.
Zombie accounts
Another misconception is that deleting an app from the device automatically deletes the associated account. Users often leave accounts behind because they are unaware that they exist after the app is removed.
These are called zombie accounts – abandoned profiles for everything from shopping and storage to dating, finance, and streaming. Millions of users have such accounts, with personal data vulnerable to cyberattacks and data leaks.
AI and the right to be forgotten
The exponential growth of AI raises a new question: Can data really be erased once it’s been used to train AI models? Machine learning models easily memorize the data they are trained on – but “unlearning” is difficult.
In theory, people in Europe and many other countries have a legal “right to be forgotten”. This means that you can demand full deletion of all personal data a platform or company may have. AI developers are considered data controllers under the General Data Protection Regulation (GDPR) and are subject to this duty.
But there are no clear guidelines for how deletion should be enforced in AI systems. Regulatory authorities can demand deletion, but AI companies can argue that it is technically impossible to comply.
Explainable deletion
To address the risks posed by incomplete deletion, I believe there is an urgent need to provide concise, accessible and clear information about how erasure actually works.
One possible approach is “explainable erasure” – a protocol developed by Marvin Ramokapane at the UK’s National Research Centre Rephrain, based at the University of Bristol.
The goal is to make deletion processes more transparent and understandable – without overwhelming users with too much information at once.
Explainable deletion divides information into six categories: what, how, when, who, where, and why. Each tab provides the user with easy-to-understand information about one part of the process.
| Category | Explanation |
|---|---|
| What | What is deleted? |
| How | How is the deletion carried out? |
| When | When will the deletion take place? |
| Who | Who has access to the data? |
| Where | Where is the data stored? |
| Why | Why is the data deleted? |
Explainable deletion is designed to give users control over their own actions, the autonomy to choose the right deletion type – and assurance that the actions have been completed. It can also curb the anxiety of losing data by offering recovery options.
Although explainable deletion has not yet been adopted, service providers can increase user trust by adopting such protocols. Such a framework can also serve as documentation of compliance with the GDPR and the right to be forgotten.
Most of us use systems that collect and store our data on a daily basis. If these systems clearly explained what they store – and what deletion really means – it could help us detect accounts and data that pose a real risk – and take back control of our digital footprint.





