9. of Retention/Removal
Yes, we have defined a retention time for personal data; it’s defined by the IT department based on disk space usage.
Threat |
|
You are only removing data as a means to save disk space, which does not allow you to define the retention period, and neither does it meet the requirements of the different regulations. GDPR and other regulations state that “data should be kept in a form which permits identification of data subject no longer than is necessary for the purposes for which the personal data are processed” – unless it’s being archived because the data is in the public interest or for scientific research. |
|
GDPR |
Chapter 2, Art. 5 – 1. (e) Chapter 3, Art 13. – 2. (a) |
CCPA & CPRA |
CCPA 1798.100... |