If you live in Europe and someone has posted intimate images of you, GDPR is one of the strongest tools you have, and most people never realize it applies to them. It is usually filed away as something for cookie banners and corporate compliance teams. Underneath all of that sits a personal right that fits leaked content almost perfectly.
This is a plain-English walkthrough of what GDPR is, why its “right to be forgotten” works even when other tools fall flat, and how to actually use it to get content deleted.
The short version
GDPR stands for the General Data Protection Regulation. It is the European Union’s main data-protection law, in force since 2018, and it governs how organizations are allowed to collect, store, and use information about people. Behind the acronym is a simple idea: information about you belongs, in an important sense, to you.
The part that matters most here is Article 17, the “right to erasure,” better known as the right to be forgotten. It gives you the power to demand that an organization delete personal data it holds about you. When no valid reason to keep processing that data exists, for example when you never consented to it in the first place, the organization has to erase it.
Intimate images of you are personal data. A leak site that hosts them, a forum that reposts them, a search engine that indexes them: each is an organization processing your personal data. The right to erasure reaches all of them.
It helps to know that erasure is not the only right GDPR gives you, just the most useful one for this situation. The same law lets you ask what data an organization holds, correct it if it is wrong, and object to certain uses of it. For leaked content, though, the question is rarely subtle. You want it gone, and Article 17 is the provision that says it has to go.
Why this works even when you do not own the copyright
Here is the difference that surprises people. The DMCA is built on copyright, so it only helps when you own the work. If a partner filmed the video or a photographer took the picture, that person usually owns the copyright, not you, and the DMCA gets awkward fast.
GDPR does not care who held the camera. It is not about authorship at all. It is about your personal data and whether anyone has a lawful basis to keep using it. A photo of you is data about you no matter who pressed the shutter, and a stranger publishing intimate images you never agreed to share has no lawful basis to do so.
That single shift opens the door for a large group of people the DMCA leaves stranded:
- Images and videos that someone else recorded of you.
- Content from an old relationship where you never consented to it being public.
- Anything where the core problem is the absence of your consent rather than a question of who owns the file.
Who can actually use it
GDPR protects people in the EU and the wider European Economic Area (the EU plus Iceland, Liechtenstein, and Norway). If you live there, the right to erasure is yours to use.
The United Kingdom kept a near-identical version after leaving the EU, called the UK GDPR. UK residents have the same right to be forgotten, with the same one-month response norm and the same ability to escalate to a regulator.
The reach goes further than where you live. GDPR applies to any organization that processes the personal data of people in the EU, even if that company sits in another country entirely. A site hosted in the United States that has European users and European traffic is still on the hook for European residents’ data. Enforcement against a distant company is harder in practice, but the legal obligation is real.
One feature worth knowing about: GDPR is the basis for the Google delisting requests many Europeans have heard of. Under the right to be forgotten, you can ask Google to remove specific pages from results that show up when someone searches your name. The page can stay online, but it stops surfacing in European search results for your name, which for a lot of people is most of the harm gone.
How to use it
The mechanics are more approachable than the legal language suggests. You are sending a written request, not filing a lawsuit.
Find the data controller. That is the organization deciding what to do with your data, usually the website operator. Look for a privacy policy, a contact page, or a dedicated privacy or DPO (data protection officer) email address. Many sites legally have to publish one.
Send a written erasure request. State clearly that you are exercising your right to erasure under Article 17 of the GDPR, identify the content (exact URLs help), and explain that you never consented to it being published. You do not need a lawyer and you do not need to pay a fee.
Give them a deadline. The law sets the response norm at one month from receipt. Complex cases can be extended by up to two further months, but the organization has to tell you it is taking the extension and why. Naming the one-month window in your request signals that you know the rule.
Keep a record. Save the request you sent, the date, and any reply (or the silence). If the controller ignores you, that paper trail becomes the evidence a regulator looks at. A short email thread is enough; you do not need anything formal.
Escalate if you are ignored. If the controller stalls or refuses without a valid reason, you can lodge a complaint with a national data protection authority, the official regulator (also called a supervisory authority) in your country. They can investigate and, in serious cases, fine the organization. The threat of that escalation is often what moves a reluctant site. Article 17 is not unconditional, and a site can sometimes point to a narrow exception such as freedom of expression, but those carve-outs were written for journalism and public records, not for non-consensual intimate images, and they almost never apply to a leak.
Writing the request from scratch is the tedious part, so our GDPR erasure request generator assembles the legal language around your details and produces text you can paste and send.
Where it stops being enough
GDPR is powerful, but it has a particular shape, and knowing the edges keeps you from waiting on a tool that will not deliver in time.
It runs through regulators, not instant takedowns. A DMCA notice can pull content within days because the host wants to keep its legal protection. A GDPR complaint can win, but enforcement moves at the pace of a government office, which is weeks or months, not hours.
Genuinely offshore sites can stretch it thin. A site with no European presence and no interest in European law may ignore both your request and a regulator’s letter. The obligation exists on paper. Forcing compliance from across the world is the hard part.
And if your situation is entirely inside the United States, GDPR may not be the right starting point at all. There the DMCA or the Take It Down Act usually moves faster, because both are built for quick removal rather than regulatory investigation.
None of this is a reason to skip GDPR. It is a reason to use it as one tool among several. For most people the strongest approach is to stack them: a DMCA notice where you own the content, a GDPR erasure request where you do not, and a delisting request to keep your name clean in search. Use whichever apply, and run them together where you can.
The first request feels unfamiliar. Once you have sent one, you have the template for every site after it.