4 ms·
To be more precise, the focus of the spirit of GDPR is processing of personal data. When you receive a deletion request, you must delete the data and stop usin
by Fradow 6y ago
To be more precise, the focus of the spirit of GDPR is processing of personal data.
When you receive a deletion request, you must delete the data and stop using it from anywhere you don't have a legitimate reason to continue processing it under one of the reasons for processing personal data without user consent.
Which is easier said than done, because it's against general development practice of having a single copy of any data that you use everywhere without much checking. Instead, you have to either check a flag before using data (do I have consent? Has it been revoked?), or keep several copies of the same data for distinct use (for example, one copy for your app, one copy for legal reasons). The first approach helps you to be able to prove consent. The second approach helps you when you need to archive data past its retention date.