There is one consequence of a personal data breach that almost nobody anticipates and that arrives punctually a few weeks later: the wave of erasure requests. They come in numbers, they look alike and they often arrive coordinated. Each one handled badly is a new claim, separate and independent from the breach that caused it.
In other words: the incident exposes you once, and the way you answer the email that follows exposes you again. The second exposure is entirely avoidable.
What Article 17 requires of you
The right to erasure is not a courtesy you attend to when you have time. It has a form, a deadline and consequences. Let us start with the form.
The controller is obliged to provide the data subject with a simple and free procedure for dealing with the exercise of these rights [translation]
Simple and free. A form that forces people to register, an inbox nobody reads or an invented requirement is not a procedure: it is a further failure that will be added to the main one.
The controller must resolve the request expressly, even where it holds no personal data of the data subjects exercising their rights, and it must do so regardless of the procedure the data subject uses to exercise that right [translation]
This paragraph is the one that causes most trouble. If you hold no data on that person, the correct answer is not silence: it is to reply expressly that you hold none. Silence reads as neglect, and neglect can be claimed against you even where you were right on the substance.
The clock: one month, and the extension has its own rule
In the case of the right to erasure of data, it must be dealt with without undue delay and, in any event, within one month. However, the controller may resort to a further two-month extension where this is essential because of the complexity of the request [...] the controller must notify the data subject of that extension within the initial one-month period [translation]
Note the trap, because many people fall into it. The extension is not earned by the request being complex: it is earned by notifying it within the first month. If you let the month pass and then plead complexity, you no longer have an extension. You have a failure and a date against you.
The defensive side: who has to prove what
Now the part almost nobody mentions and which, in serial claims, decides many cases. The burden of proving that the request was sent and received is not yours.
[...] the burden of proving that the request was sent and received falls on the claimant [...] circumstances that are essential for the right to be regarded as having been exercised [translation]
Many serial claims rest on an email with no record of receipt, or on the bare assertion of having written. If the claimant cannot prove sending and receipt, the right is not treated as exercised. And with no exercise there is no neglect to hold against you.
This has a very concrete operational implication. Your log of incoming requests does not only serve to comply: it serves to deny, with authority, what never came in. A log that records only what gets answered is half a log, and the missing half is precisely the one that defends you.
What is lawful today may cease to be tomorrow
There is a second front, quieter. An erasure request is not answered by checking how the data was obtained at the time.
[...] even processing of accurate data that was initially lawful may, over time, become incompatible with that Directive [now the GDPR] where the data is no longer necessary in relation to the purposes for which it was collected or processed [translation]
The right question is whether today, as of today, that data is still necessary for the purpose that justified it. A ‘yes’ from six years ago does not answer that question.
After a breach this gets worse. Working lists are created to locate those affected, to cross-check records, to prepare communications. When the incident is closed, those files lose their reason to exist. Keeping them ‘just in case’ is manufacturing your next problem with your own hands.
The minimum procedure, in six steps
- A single, visible channel, free of charge, that does not force people to register or to fill in forms of your own.
- An incoming log with the date, the channel and the content of every request received.
- Proportionate identification of the applicant, asking for no more than necessary and recording what was checked.
- A reasoned decision: what is erased, what is restricted, what is refused and why.
- An express reply within the month; if there is to be an extension, notify it before that month expires.
- Closure: a record of the actual erasure across every system and of what was communicated to third parties.
Six steps and not one of them technical. They are organisational decisions, management takes them and all of them leave paper. That paper is, at the same time, your compliance and your defence.
What you gain from this, in business terms
You gain predictability. A wave of fifty requests with a procedure in place is a two-week administrative task. The same wave without a procedure is a crisis: nobody knows how many there are, two get answered, three get lost, and the ones that get lost come back as a claim.
And you gain the ability to reject what does not apply. With a log, you separate the real requests from the ones that are merely asserted, and you answer each group accordingly. Without a log, everything is one assertion against another and you are the one starting at a disadvantage. In what a court looks at when the claim arrives you will see why this point always appears among the five decisive ones.
Must I erase whenever I am asked to?
No. The right arises when one of the specific circumstances listed in Article 17 applies, and there is processing you must keep by legal obligation. What you must always do is resolve the request expressly and give reasons for any refusal within the deadline.
Does an automatic acknowledgement count as a reply?
No. The acknowledgement evidences that the request came in, which is useful for your log, but it is not the express decision the rules require.
And if the request arrives through a channel that is not the official one?
It must be dealt with all the same. The duty to resolve is independent of the procedure the data subject has chosen to exercise the right.
If you do not know how many requests you received last year or what was answered to each one, the Breach Management Test will tell you exactly where that gap sits.
Could you evidence every reply you gave?
Twelve questions about what your company can prove. At the end, your Defensibility Index and the points worth closing first.
Take the Breach Management Test