Agent skill

Search Engine Erasure

by mukul975 in mukul975/Privacy-Data-Protection-Skills

Implements the right to be forgotten in search engines under GDPR Article 17 and the CJEU Google Spain ruling (C-131/12).

Apache-2.0Auto-check passedLegal & Compliance

Install Search Engine Erasure

skills CLI
$ npx skills add mukul975/Privacy-Data-Protection-Skills --skill search-engine-erasure -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install mukul975/Privacy-Data-Protection-Skills search-engine-erasure --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/mukul975/Privacy-Data-Protection-Skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/privacy/search-engine-erasure .claude/skills/search-engine-erasure && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
search-engine-erasure
GitHub stars
297
Token cost
~3.3k tokens
SKILL.md length
1,371 words
Files
5 (incl. scripts, references, assets)
Skills in repo
280
Repo updated
First seen
Licence
Apache-2.0

At a glance

Implements the right to be forgotten in search engines under GDPR Article 17 and the CJEU Google Spain ruling (C-131/12).

  • Works in 4 steps: Submitting Delisting Requests to Search… → Delisting Request Template for Orion… → Handling Search Engine Responses → …
  • Tasks that involve Privacy and GDPR
  • SKILL.md covers Overview, Legal Foundation, Delisting Assessment Criteria and Delisting Request Procedures, plus 3 more sections
  • Runs Python scripts from its folder

What it does

Search Engine Erasure is an agent skill from mukul975/Privacy-Data-Protection-Skills. Implements the right to be forgotten in search engines under GDPR Article 17 and the CJEU Google Spain ruling (C-131/12). Covers delisting request procedures, criteria assessment balancing privacy against public interest, and geographic scope determination. Activate for right to be forgotten, search delisting, Google Spain, de-indexing queries.

Its SKILL.md is about 3.3k tokens, which your agent loads only when the skill is triggered. The skill folder holds 7 other files, including scripts, reference files and assets (for example `assets/template.md`, `references/standards.md` and `references/workflows.md`).

It sits in Legal & Compliance, covering Privacy and GDPR. The repository describes itself as: 282+ structured privacy & data protection skills for AI agents. GDPR, CCPA, EU AI Act, HIPAA, LGPD, PIPL, DPDP Act. The licence is Apache-2.0.

When your agent uses it

  • Tasks that involve Privacy and GDPR

Example prompts

  • “Use the search-engine-erasure skill to implement the right to be forgotten in search engines under GDPR Article 17 and the CJEU Google Spain ruling…”
  • “/search-engine-erasure”

Requirements

  • Python 3

Workflow steps

4 steps, taken from the step headings in SKILL.md.

  1. Submitting Delisting Requests to Search Engines
  2. Delisting Request Template for Orion Data Vault Corp Employees/Customers
  3. Handling Search Engine Responses
  4. DPA Complaint Escalation

What it can do on your machine

Read from SKILL.md and the folder at commit 9b2ef9e. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships 1 file in scripts/ (Python), which the agent can run.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Search Engine Erasure loads about 3.3k tokens when it runs, and up to ~4.9k if it reads all its reference files. Until then it costs about 92 tokens; SKILL.md has 1,371 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~92
When it runs · the whole SKILL.md, loaded when a task matches
~3.3k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~4.9k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.

SKILL.md

The full file from mukul975/Privacy-Data-Protection-Skills at commit 9b2ef9e, republished under its Apache-2.0 licence (© mukul975). 1,371 words, ~3,348 tokens.

Download SKILL.mdSave it as .claude/skills/search-engine-erasure/SKILL.md (or your agent's skills folder). This skill also uses 4 other files; get the full folder from GitHub.
name
search-engine-erasure
description
Implements the right to be forgotten in search engines under GDPR Article 17 and the CJEU Google Spain ruling (C-131/12). Covers delisting request procedures, criteria assessment balancing privacy against public interest, and geographic scope determination. Activate for right to be forgotten, search delisting, Google Spain, de-indexing queries.
license
Apache-2.0
metadata.author
mukul975
metadata.version
1.0
metadata.domain
privacy
metadata.subdomain
data-retention-deletion
metadata.tags
right-to-be-forgotten, search-engine-delisting, google-spain, de-indexing, gdpr-article-17

Search Engine Erasure (Right to Be Forgotten)

Overview

The right to be forgotten in the search engine context refers to the right of individuals to request that search engine operators delist (remove from search results) links to web pages containing personal data about them. This right was established by the CJEU in Google Spain SL v AEPD (Case C-131/12) and subsequently codified in GDPR Article 17. It requires a balancing exercise between the data subject's privacy rights and the public's right to access information. This skill provides the assessment criteria, request procedures, and operational workflows for both data controllers (whose content may be subject to delisting) and organizations assisting data subjects with delisting requests.

CJEU Case C-131/12 — Google Spain SL v AEPD (13 May 2014)

The Court of Justice of the European Union held that:

  1. A search engine operator is a data controller in respect of the processing of personal data that appears on web pages published by third parties.
  2. The operator of a search engine is obliged to remove from the list of results displayed following a search made on the basis of a person's name, links to web pages published by third parties and containing information relating to that person, if certain conditions are met.
  3. The data subject's rights override, as a rule, the interest of internet users in having access to that information, unless particular reasons (such as the role played by the data subject in public life) justify the interference with the data subject's fundamental rights.
CJEU Case C-507/17 — Google LLC v CNIL (24 September 2019)

The Court clarified the territorial scope of de-indexing:

  1. EU law does not require that de-indexing be carried out on all versions of the search engine globally.
  2. The search engine operator must carry out de-indexing on the versions of its search engine corresponding to all EU Member States.
  3. The search engine operator must take sufficiently effective measures to prevent or seriously discourage users in the EU from accessing the de-indexed links via non-EU versions of the search engine (geo-blocking).
GDPR Article 17 — Right to Erasure

Article 17(1) establishes six grounds for erasure. In the search engine context, the most commonly invoked grounds are:

  • Art. 17(1)(a): Data no longer necessary for the original purpose
  • Art. 17(1)(c): Data subject objects and no overriding legitimate grounds exist
  • Art. 17(1)(d): Unlawful processing

Article 17(3) establishes exceptions, particularly:

  • Art. 17(3)(a): Freedom of expression and information
EDPB Guidelines 5/2019 on the Right to Be Forgotten in Search Engine Cases

Adopted 7 July 2020, these guidelines provide 13 criteria for assessing delisting requests.

Delisting Assessment Criteria

EDPB 13-Point Assessment Framework

The following criteria must be evaluated when assessing a delisting request. The assessment is a balancing exercise — no single criterion is determinative:

#CriterionAssessment QuestionWeight Factors
1Role in public lifeDoes the data subject play a role in public life?Public figures (politicians, senior executives, public officials) have reduced expectation of delisting for information related to their public role
2Nature of informationWhat type of personal data is involved?Special category data (Art. 9) weighs heavily toward delisting; criminal conviction data requires careful balancing
3Accuracy of informationIs the information accurate and up-to-date?Inaccurate information strongly favours delisting
4RelevanceIs the information still relevant to the public interest?Information that was once relevant may become irrelevant over time
5Age of informationHow old is the information?Older information generally weighs toward delisting, unless there is a continuing public interest
6Source of informationWho published the original content?Journalistic sources and official government publications weigh against delisting
7Context of publicationWas the information published voluntarily by the data subject?Self-published information may weigh against delisting
8SensitivityHow sensitive is the information?Health data, sexual orientation, political opinions — higher sensitivity favours delisting
9Impact on data subjectWhat impact does continued indexing have?Significant harm (employment, reputation, safety) favours delisting
10Access contextWhat is the context in which users access the information via search?Name-based searches are more intrusive than topic-based searches
11MinorIs the data subject a minor (or was the data published when they were a minor)?GDPR Recital 65: data subjects who were children at the time have a strengthened right to erasure
12Criminal dataDoes the information relate to criminal proceedings?Spent convictions favour delisting; ongoing proceedings may not; national rehabilitation legislation applies
13Legal obligationIs there a legal obligation to index the information?Court orders, regulatory requirements to maintain public registers
Assessment Decision Matrix
[Delisting Request Received]
         │
         ▼
[Preliminary Assessment]
   │
   ├── Is the data subject identifiable from the search results? ──► No ──► Reject (no personal data at issue)
   │
   ├── Is the request against a search engine operator? ──► No ──► Redirect to content publisher (separate Art. 17 request)
   │
   └── Yes to both ──► [Full EDPB 13-Point Assessment]
         │
         ▼
[Apply Balancing Test]
   │
   ├── STRONG DELISTING CASE:
   │     - Data subject is a private individual
   │     - Information is inaccurate or outdated
   │     - Information is sensitive (Art. 9 categories)
   │     - Data subject was a minor when information published
   │     - Significant demonstrable harm from continued indexing
   │     - Information was not self-published
   │     ──► APPROVE delisting
   │
   ├── STRONG REFUSAL CASE:
   │     - Data subject is a prominent public figure
   │     - Information relates to their public role
   │     - Information is accurate and current
   │     - Strong public interest in access to the information
   │     - Information published by journalistic source
   │     - Legal obligation to maintain the information
   │     ──► REFUSE delisting (cite specific public interest justification)
   │
   └── BORDERLINE CASE:
         - Mixed factors present
         ──► [Detailed written balancing assessment required]
         ──► [Consider partial delisting or time-limited delisting]
         ──► [Consult DPO and Legal counsel]

Delisting Request Procedures

Step 1: Submitting Delisting Requests to Search Engines

Each major search engine maintains a dedicated form for delisting requests:

Google
  • Form: Google Search removal request under European privacy law
  • URL path: Available via Google's support documentation under "Remove personal information"
  • Required information: Full name, email address, country of residence, specific URLs to delist, explanation of why each URL should be delisted, identity verification
  • Response timeline: Google typically responds within 3-6 months; complex cases may take longer
Show full SKILL.md (532 more words)Show less
Microsoft Bing
  • Form: Request to Block Bing Search Results in Europe
  • Required information: Full name, email address, country of residence, specific URLs, explanation, identity verification
  • Response timeline: Typically 3-6 months
Other Search Engines
  • DuckDuckGo: Does not maintain its own index of web pages; relies primarily on Bing results. A successful Bing delisting will typically cascade.
  • Yahoo: Uses Bing's index in most European markets. A successful Bing delisting will typically cascade.
Step 2: Delisting Request Template for Orion Data Vault Corp Employees/Customers
DELISTING REQUEST — SEARCH ENGINE
Organization Support Reference: DELIST-YYYY-NNNN

Data Subject: [Name]
Search Engine: [Google / Bing / Other]
Date of Request: [YYYY-MM-DD]

URLs REQUESTED FOR DELISTING:
1. [Full URL] — Reason: [Specific reason per EDPB criteria]
2. [Full URL] — Reason: [Specific reason per EDPB criteria]

GROUNDS FOR DELISTING (cite applicable Art. 17(1) ground):
□ Art. 17(1)(a) — Data no longer necessary for original purpose
□ Art. 17(1)(c) — Data subject objects; no overriding legitimate grounds
□ Art. 17(1)(d) — Unlawful processing
□ Other: [specify]

SUPPORTING INFORMATION:
- Relationship to Orion Data Vault Corp: [employee/customer/former employee/other]
- Nature of information: [describe what the search results reveal]
- Impact of continued indexing: [describe harm]
- Age of information: [when was the content published?]
- Public role: [any public-facing role that may be relevant?]
- Previous attempts to resolve: [contact with content publisher?]

IDENTITY VERIFICATION:
- [Attach government-issued ID — to be submitted to search engine only]
- [Orion Data Vault Corp can verify employment/customer relationship if needed]
Step 3: Handling Search Engine Responses
ResponseAction
Delisting approvedVerify URLs no longer appear in name-based searches from EU locations; log outcome; notify data subject
Delisting refusedReview reasoning; assess whether to escalate; advise data subject of right to complain to DPA
Partial delistingReview which URLs were accepted/refused; assess remaining URLs; advise data subject
Request for more informationProvide requested information within 14 days
No response (6+ months)Escalate: lodge complaint with relevant DPA
Step 4: DPA Complaint Escalation

If a search engine refuses a delisting request, the data subject may complain to the supervisory authority:

  1. Identify the lead DPA: For Google, the lead authority is the Irish Data Protection Commission (DPC). For Bing, it is the Irish DPC (Microsoft Ireland Operations Ltd).
  2. Prepare complaint: Include the original request, the search engine's refusal with reasoning, the data subject's counter-arguments per the EDPB 13-point criteria.
  3. Submit complaint: Via the DPA's online complaint form.
  4. Timeline: DPA investigations typically take 6-18 months.

Geographic Scope of Delisting

EU/EEA Scope (Minimum)

Following C-507/17 (Google v CNIL), delisting must be implemented on:

  • All EU/EEA country-specific versions of the search engine (e.g., google.de, google.fr, google.nl, etc.)
  • The global version (e.g., google.com) when accessed from within the EU/EEA (geo-blocking)
Geo-Blocking Requirements

The search engine must implement measures to prevent EU/EEA users from circumventing delisting:

  • IP-based geo-blocking on non-EU versions
  • GPS-based location verification on mobile devices
  • The measures must be "sufficiently effective" but absolute prevention is not required
Global Delisting (Exceptional Cases)

In exceptional circumstances, a DPA or national court may order global delisting. This remains controversial and is assessed case-by-case. Factors favouring global scope include:

  • Safety of the data subject (e.g., stalking, domestic violence)
  • Information about a minor
  • Manifestly inaccurate or defamatory content

Interaction with Content Source

Delisting from search results does NOT remove the original content from the source website. For complete erasure:

  1. Contact the content publisher directly: Submit an Art. 17 erasure request to the website hosting the content.
  2. National defamation/privacy law: If the content is defamatory or violates privacy law, pursue removal under applicable national law.
  3. Court order: In severe cases, obtain a court order requiring the publisher to remove the content.
  4. Cache clearing: After source content is removed, request that search engines clear their cached copies.

Record Keeping for Delisting Cases

RecordRetention PeriodPurpose
Delisting request and assessment3 years from final outcomeDemonstrate compliance with Art. 17
Search engine correspondence3 years from final outcomeEvidence of due diligence
DPA complaint (if any)6 years from final outcomeLegal records
Balancing assessment documentation3 years from final outcomeDemonstrate EDPB criteria application
Outcome verification (screenshots)1 year from delisting confirmationVerify ongoing effectiveness

© mukul975, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 4 other files (scripts, references, assets) in skills/privacy/search-engine-erasure of mukul975/Privacy-Data-Protection-Skills.

  • SKILL.md
  • assets/template.md
  • references/standards.md
  • references/workflows.md
  • scripts/process.py

Open the folder on GitHubat commit 9b2ef9e

Compare with similar skills

Search Engine Erasure next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Search Engine Erasure compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Search Engine Erasure this skillmukul975/Privacy-Data-Protection-Skills297—~3.3kAutomated safety check: PassApache-2.0
C15tc15t/c15t1.9k1 repos~1.6kAutomated safety check: PassApache-2.0
HIPAA Safe Harbor Coverage Auditmaziyarpanahi/openmed5.5k—~1.7kAutomated safety check: PassApache-2.0
Korean Privacy Termskimlawtech/korean-privacy-terms586—~2.9kAutomated safety check: PassApache-2.0
Gdpr ComplianceSushegaad/Claude-Skills-Governance-Risk-and-Compliance9431 repos~3.9kAutomated safety check: PassMIT
Hipaa ComplianceSushegaad/Claude-Skills-Governance-Risk-and-Compliance9431 repos~2.3kAutomated safety check: PassMIT

Similar skills

  • C15t

    c15t/c15t

    Work with c15t consent management docs, APIs, and integrations for Next.js, React, and JavaScript.

    1.9k GitHub starsUsed in 1 repo~1.6k tokens
    Legal & ComplianceAuto-check passed
  • Checks OpenMed de-identified clinical text against the 18 HIPAA Safe Harbor identifier categories and reports gaps and residual re-identification risk.

    5.5k GitHub stars~1.7k tokensUpdated today
    Legal & ComplianceAuto-check passed
  • Korean Privacy Terms

    kimlawtech/korean-privacy-terms

    처리방침·이용약관 자동 생성 스킬 패키지 (v4.0). An agent skill from kimlawtech/korean-privacy-terms.

    586 GitHub stars~2.9k tokensUpdated 1 mo ago
    Legal & ComplianceAuto-check passed
  • Gdpr Compliance

    Sushegaad/Claude-Skills-Governance-Risk-and-Compliance

    Expert GDPR compliance assistant covering all four core workflows: (1) auditing code and systems for GDPR violations, (2) drafting GDPR-compliant documents such as privacy policies, Data Processing…

    943 GitHub starsUsed in 1 repo~3.9k tokens
    Legal & ComplianceAuto-check passed
  • Hipaa Compliance

    Sushegaad/Claude-Skills-Governance-Risk-and-Compliance

    Expert HIPAA compliance assistant for healthcare and software contexts.

    943 GitHub starsUsed in 1 repo~2.3k tokens
    Legal & ComplianceAuto-check passed
  • Pii Contract Analyze

    gregmos/PII-Shield

    Universal legal document processor with PII anonymization. An agent skill from gregmos/PII-Shield.

    149 GitHub stars~8.9k tokensUpdated 3 mo ago
    Legal & ComplianceAuto-check: notes

More from mukul975/Privacy-Data-Protection-Skills

All 280 skills in this repo
  • Age Gating Services

    mukul975/Privacy-Data-Protection-Skills

    Implements age-gating mechanisms for online services to restrict access based on user age.

    297 GitHub stars~3.7k tokensUpdated 6 mo ago
    Auto-check passed
  • AI Data Retention

    mukul975/Privacy-Data-Protection-Skills

    Manages AI model retention and machine unlearning requirements.

    297 GitHub stars~1.9k tokensUpdated 6 mo ago
    Auto-check passed
  • AI Dpia

    mukul975/Privacy-Data-Protection-Skills

    Conducts Data Protection Impact Assessments for AI and ML systems per EDPB Guidelines 04/2025 on AI processing.

    297 GitHub stars~3.4k tokensUpdated 6 mo ago
    Auto-check passed
  • Dpia Mitigation Plan

    mukul975/Privacy-Data-Protection-Skills

    Structures risk mitigation planning and residual risk tracking for Data Protection Impact Assessments under GDPR Article 35(7)(d).

    297 GitHub stars~846 tokensUpdated 6 mo ago
    Auto-check passed
  • Gdpr Accountability

    mukul975/Privacy-Data-Protection-Skills

    Guides implementation of the GDPR accountability principle under Articles 5(2) and 24, including documentation requirements for policies, DPIAs, RoPA, training records, and breach logs.

    297 GitHub stars~1.9k tokensUpdated 6 mo ago
    Auto-check passed
  • Pia Threshold Screening

    mukul975/Privacy-Data-Protection-Skills

    Conducts pre-DPIA threshold screening to determine whether a full Data Protection Impact Assessment is required under GDPR Article 35.

    297 GitHub stars~880 tokensUpdated 6 mo ago
    Auto-check passed

Questions about Search Engine Erasure

What does Search Engine Erasure do?

Implements the right to be forgotten in search engines under GDPR Article 17 and the CJEU Google Spain ruling (C-131/12). Search Engine Erasure is an agent skill from mukul975/Privacy-Data-Protection-Skills. Implements the right to be forgotten in search engines under GDPR Article 17 and the CJEU Google Spain ruling (C-131/12).

When should I use Search Engine Erasure?

Search Engine Erasure fits situations like: tasks that involve Privacy and GDPR.

How do I install Search Engine Erasure in Claude Code?

Run `npx skills add mukul975/Privacy-Data-Protection-Skills --skill search-engine-erasure -a claude-code`. Or copy the skill folder (skills/privacy/search-engine-erasure in mukul975/Privacy-Data-Protection-Skills) into .claude/skills/search-engine-erasure in your project. Claude Code loads it when a task matches its description.

How do I install Search Engine Erasure in Codex?

Run `npx skills add mukul975/Privacy-Data-Protection-Skills --skill search-engine-erasure -a codex`. Or copy the skill folder (skills/privacy/search-engine-erasure in mukul975/Privacy-Data-Protection-Skills) into .agents/skills/search-engine-erasure in your project. Codex loads it when a task matches its description.

Can I use Search Engine Erasure in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add mukul975/Privacy-Data-Protection-Skills --skill search-engine-erasure -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/search-engine-erasure, .gemini/skills/search-engine-erasure, .github/skills/search-engine-erasure and .opencode/skills/search-engine-erasure in your project.

What does Search Engine Erasure need to run?

Going by SKILL.md and its folder, Search Engine Erasure needs Python for the scripts in its folder. Our summary lists: Python 3.

Does Search Engine Erasure access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Search Engine Erasure safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.

What licence does Search Engine Erasure use?

Search Engine Erasure is published under the Apache-2.0 licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Search Engine Erasure use?

About 3.3k tokens (SKILL.md is roughly 13k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 1.5k tokens, read only when the agent opens those files.

What are the alternatives to Search Engine Erasure?

Skills that share tags, products or a category with Search Engine Erasure: C15t (c15t/c15t, 1.9k stars), HIPAA Safe Harbor Coverage Audit (maziyarpanahi/openmed, 5.5k stars), Korean Privacy Terms (kimlawtech/korean-privacy-terms, 586 stars) and Gdpr Compliance (Sushegaad/Claude-Skills-Governance-Risk-and-Compliance, 943 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Search Engine Erasure?

mukul975 (a GitHub user) maintains it in mukul975/Privacy-Data-Protection-Skills, which has 297 GitHub stars. The repository holds 280 skills in this directory. The repository was last updated on March 16, 2026.

Source: mukul975/Privacy-Data-Protection-Skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.