Implement a user-facing data deletion mechanism

SkillDev tools

Right-to-erasure is a skill for auditing whether an application gives users a complete data deletion path. It checks account settings pages, privacy dashboards, and API routes against GDPR Article 17, covering client-side storage, server

Available today. Use it from your connected AI after setup.

Have an AI agent that can load skills, and the right-to-erasure skill files available to it.

Then ask your AI: use the Implement a user-facing data deletion mechanism skill

What your AI can do with it

  • Audit account settings pages, privacy dashboards, and API routes for a deletion mechanism
  • Check that localStorage, sessionStorage, IndexedDB, and cookies are cleared on deletion
  • Verify a server-side deletion request is sent and receipt is confirmed to the user
  • Explain GDPR Article 17 and what a compliant deletion flow must cover
  • Review code for missing storage clearance, absent confirmation UI, or missing deletion end
  • Provide implementation details and framework-specific guidance via references/rule.md

Getting started

  1. Have an AI agent that can load skills, and the right-to-erasure skill files available to it.
  2. Add the skill to the agent's skill collection so it can be invoked during privacy audits.
  3. Point the agent at the account settings pages, privacy dashboard, or API routes to audit.
  4. Ask the agent to check for a user-facing deletion flow, client-side storage clearance, and server-side deletion calls.
  5. Consult references/rule.md for full implementation details and framework-specific guidance.

What this skill tells your AI

The instructions your AI receives, as published by thedaviddias/front-end-checklist in skills/right-to-erasure/SKILL.md and read by ahel’s review.

GDPR Article 17 gives EU residents the right to have their personal data erased when it is no longer necessary for the purpose it was collected, or when they withdraw consent. Failing to honour this right can result in regulatory fines of up to €20 million or 4% of global annual turnover. Providing a clear deletion flow also builds trust with users who value control over their data.

Quick Reference

  • Provide a visible "Delete my account / data" option in account settings
  • Clear all client-side storage: localStorage, sessionStorage, IndexedDB, and cookies
  • Send a deletion request to the server and confirm receipt to the user
  • Complete deletion within 30 days as required by GDPR Article 17

Check

Check whether this application provides a user-facing data deletion mechanism that clears all client-side storage and triggers a server-side deletion request.

Fix

Implement a data deletion flow that clears localStorage, sessionStorage, IndexedDB, and cookies, then sends a deletion request to the server and shows confirmation to the user.

Explain

Explain GDPR Article 17 (right to erasure) and what a compliant data deletion flow must cover, including both client-side and server-side data.

Code Review

Review account settings, privacy pages, and API routes for a data deletion endpoint. Flag missing client-side storage clearance, absent confirmation UI, or missing server-side deletion calls.


For full implementation details, code examples, and framework-specific guidance, see references/rule.md.

Rule page: https://frontendchecklist.io/en/rules/privacy/right-to-erasure

Signals

GitHub stars
74k
Forks
7k
Last commit
Aug 2026

Questions

What does the skill check for?
It checks whether an application provides a user-facing data deletion mechanism that clears all client-side storage (localStorage, sessionStorage, IndexedDB, cookies) and triggers a server-side deletion request.
What does GDPR Article 17 require?
EU residents can have their personal data erased when it is no longer necessary for its collected purpose or when they withdraw consent. Deletion must be completed within 30 days; non-compliance can bring fines up to €20 million or 4% of global annual turnover.
Advanced
Item type
skill
Key
right-to-erasure
Source
github.com/thedaviddias/front-end-checklist