Jack of Retention/Removal
We have defined a retention time for personal data, but that’s only a policy. There is no technical system that enforces it.
Threat |
|
You’re telling data subjects that their data will be removed after a period of 2 years, but it is not removed. If you suffered a data breach, data that should have been removed 6 years ago would also be leaked. |
|
GDPR |
Chapter 3, Art 13. – 2. (a) Chapter 4, Art. 25 – 2. |
CCPA & CPRA |
CCPA 1798.100. General Duties of Businesses that Collect Personal Information (a) (3) CCPA 1798.100. General Duties of Businesses that Collect Personal Information (c) |
OECD |
N/A |
... |