A deletion concept sets out in a binding manner which personal data is deleted when, how and by whom.
Why a deletion concept?
The GDPR requires data to be deleted as soon as it is no longer needed, and requires this to be demonstrated. Without a systematic concept, this obligation can hardly be met in IT landscapes that have grown over time.
Components
- overview of data types and systems
- retention periods and when they start, derived from purposes and retention obligations
- deletion rules and responsibilities
- technical implementation and logging
- handling of backups and archives
In Germany, the DIN 66398 standard is often used as guidance. The time limits for erasure also belong in the record of processing activities.
Legal provisions
- Art. 5(1)(e) GDPR
- Principle of storage limitation.
- Art. 17 GDPR
- Right to erasure.
- Art. 30(1)(f) GDPR
- Time limits for erasure as mandatory content of the record of processing activities.
- Art. 5(2) GDPR
- Accountability.