How Quickly Must Personal Data Be Deleted Under GDPR?
Learn how long you have to delete personal data under GDPR and what triggers the obligation to erase data promptly.
110 views
Under the GDPR, you must delete personal data without undue delay when it is no longer necessary for the purposes for which it was collected or processed, if the data subject withdraws consent (and there is no other legal ground for processing), or if the data subject objects to the processing and there are no overriding legitimate grounds for the processing. While there's no specific timeframe mentioned, it's important to act promptly and ensure compliance with requests for deletion to avoid potential penalties.
FAQs & Answers
- Is there a specific deadline to delete data under GDPR? GDPR does not specify an exact deadline for data deletion, but organizations must delete personal data without undue delay once it is no longer necessary or upon the data subject's valid request.
- What triggers the obligation to delete personal data under GDPR? The obligation to delete arises when data is no longer needed for its original purpose, when consent is withdrawn without another legal justification, or when the data subject objects to processing without overriding legitimate interests.
- What are the risks of not complying with GDPR data deletion requirements? Failing to delete personal data as required can result in penalties from supervisory authorities, reputational damage, and loss of trust from customers and clients.
- Can organizations keep data after a deletion request if they have a legitimate reason? Yes, if the organization has a legitimate legal basis or overriding legitimate interests for processing the data, it may retain data even after a deletion request, but must document and justify this appropriately.