German Regulator Clarifies GDPR Data Deletion Requirements for Businesses
· 2h ago · Originally reported by PPC Land
A data protection authority in Saxony-Anhalt has clarified that simply moving personal data to a recycle bin does not fulfill GDPR deletion requirements. The regulator provided guidance on how long different types of data, such as invoices and job applications, should be retained and properly deleted.
Why it matters
This matters because it helps businesses understand how to comply with strict European privacy laws, reducing the risk of fines for improper data handling.
Explain it like I’m new here
Just putting files in the computer's trash bin isn't enough—companies have to really erase them to follow the rules.
Terms in this story
GDPR
The GDPR (General Data Protection Regulation) is the European Union's data protection law, applying since May 2018, which governs how organisations collect and use personal data about people in the EU.
PII (personally identifiable information)
PII (personally identifiable information) is information that identifies, or can be used to identify, a specific person, such as a name, email, phone number or government ID number.
Guidance (forecast)
Guidance is a public company's own forecast of its future results, such as next quarter's revenue or full-year adjusted EBITDA, usually given as a range alongside an earnings report.
Go deeper
Related stories
Meta's Advanced Matching Uses Hashed Customer Data for Improved Pixel Tracking
Meta's advanced matching feature allows its pixel to collect hashed customer information, like emails and phone numbers, during web events. This data is then used to better match website visitors to Meta user accounts, enhancing ad…
Pen Registers Now Used to Monitor Web Trackers’ Data Collection
Pen registers, traditionally used to log phone call metadata, are now being applied to track the data collected by web trackers. This approach focuses on recording addressing and routing information, not the actual content of…
All-Party Consent Laws Impact Pixel and Chatbot Data Collection
All-party consent laws in several US states require everyone involved in a conversation to agree before it can be recorded. These regulations are increasingly cited in lawsuits related to the use of tracking pixels and chatbots on websites.
Meta Pixel: How It Tracks Website Activity for Ad Measurement and Targeting
Meta Pixel is a JavaScript tag that collects data on website visits and purchases, sending this information to Meta for use in advertising measurement and audience targeting. Its operation has raised legal questions, with courts…
Court Dismisses Meta Pixel Wiretap Lawsuit Against Seattle Children's Hospital
A lawsuit accusing Seattle Children's Hospital of wiretapping via Meta Pixel was dismissed after the court ruled that automated server responses do not meet the legal definition of communication between two or more individuals. This…
Apple Introduces Block List Targeting Cross-Site Tracking by Ad Tech Vendors
Apple has implemented a new block list aimed at data brokers and ad tech companies that engage in cross-site user tracking. This move could potentially extend to a wider range of ad tech and martech vendors throughout the digital…