GDPR: The Right to be Forgotten

Alicja Kwiatkowski
October 3, 2018

The right of erasure vs. the legal requirement to store data

The protection and privacy of personal data has become a hot topic. Regulators across the globe implement laws which aim to provide greater protection of the privacy of personal data. One of the most significant pieces of legislation is GDPR which came into effect in Europe earlier this year. Modern personal data protection laws, including GDPR itself, are providing stronger enforcement rights, including punitive fines. But how far do an individual’s rights go? Whilst much has been written on GDPR, this article looks at an area that has received little attention – an individual’s right of erasure of his/her personal data versus an organisation’s legal requirement to retain that data.

The key point here is that the right of erasure under Article 17 of GDPR is in many cases not an absolute right for the individual. In fact, quite the opposite. Depending on the legal basis under which the data is processed, the handler of the data may reject such requests as it may be legally required to retain that data for regulatory purposes. There is only a handful of cases in which a data handler needs to abide by a request for deletion of data, such as for marketing when the consent of the individual is the legal basis for processing data.

For businesses, the legal basis for processing data is often either in the legitimate interest of the company handling the data or a legal obligation to process the data, stemming from tax laws or employment and insurance laws. In the second case, legal obligations laid down in the EU or its member states’ laws give the company an absolute right to reject a request for deletion of data. Imagine a situation where the French accounting law requires the taxable person to store invoices for 10 years. In this scenario, when the invoice contains an individual’s personal data, they have no legal right to ask for their personal data to be deleted. Consequently, any personal data deletion requests received by the company storing the invoice can legally be rejected.

The situation is not as straightforward in cases where it is a non-EU law that includes an obligation to store the data. For a US invoice, the obligation to store it will fall under the legal basis of legitimate interest, which is tougher to prove objectively. In such a scenario, the company holding the invoice data under US law needs to perform an assessment balancing the individual’s interest in having his/her data deleted against the company’s compelling legitimate grounds for processing the data. This is one of many reasons why companies appoint a Data Protection Officer who can help them make balanced decisions.

Whilst an individual’s rights are strong when it comes to the privacy and protection of their personal data, they are far from absolute. Personal data should be treated with respect in line with principles set out by law, but it is equally important to bear in mind that an individual’s request for their personal data may be rejected if the company processing that data has a legitimate reason for doing so.

Take Action

Sovos Trustweaver provides eArchiving solutions for clients in over 50 countries. To find out more visit https://www.trustweaver.com/solutions/e-archive/

Sign up for Email Updates

Stay up to date with the latest tax and compliance updates that may impact your business.

Author

Alicja Kwiatkowski

Alicja Kwiatkowski is a Legal Counsel at Sovos TrustWeaver. Based in Stockholm, Alicja’s background is in law and IT with a professional focus on international e-invoicing compliance, personal data protection and cyber security. Alicja earned her degree in Law from University of Warsaw, Poland and LL.M in European IP Law from Stockholm University, Sweden.
Share this post

North America
June 6, 2024
Observations and Predictions: The Future of Tax and Compliance

When I became the CEO of Sovos one year ago, I knew that I was stepping into an innovative company in an industry primed for a seismic transformation. However, even with this knowledge in place, I must admit that the speed and scope of change over the past year has been extraordinary to witness. Here […]

EMEA IPT
July 8, 2024
Hungary Insurance Premium Tax (IPT): An Overview

Regarding calculating Insurance Premium Tax (IPT), Hungary is the only country in the EU where the regime uses the so-called sliding scale rate model.

North America ShipCompliant
July 3, 2024
The Prospects and Perils of AI in Beverage Alcohol

I recently had the privilege of speaking on a panel at the National Conference of State Liquor Administrators (NCSLA) Annual Conference, a regular meeting of regulators, attorneys and other members of the beverage alcohol industry to discuss important issues affecting our trade. Alongside Claire Mitchell, of Stoel Rives, and Erlinda Doherty, of Vinicola Consulting, and […]

North America ShipCompliant
June 27, 2024
Shifting Focus: How to Make Wine Country Interesting to Millennials

Guest blog written by Susan DeMatei, President, WineGlass Marketing WineGlass Marketing recently conducted a study to explore how Millennials and Gen X feel about wine, wine culture and wine country. The goal was to gain insight into how we can make wine, wine club and wine country appealing to these new audiences. We’ll showcase in-depth […]

North America Sales & Use Tax
June 24, 2024
Illinois to Adjust Sales Tax Nexus Rules in Light of PetMeds Threat

Illinois is poised to change their sourcing rules again, trying to find their way in a world where states apply their sales tax compliance requirements equally to both in-state and remote sellers. With this tweak, they will effectively equalize the responsibilities of remote sellers with no in-state presence, to those that have an Illinois location. […]

EMEA VAT & Fiscal Reporting
June 21, 2024
ViDA Rejected Again – Europe Misses Another Chance to Harmonize e-Invoicing

During the latest ECOFIN meeting on 21 June, Member States met to discuss if they could come to an agreement to implement the VAT in the Digital Age (ViDA) proposals. At the ECOFIN meeting in May, Estonia objected to the platform rules being proposed, instead requesting to make the new deemed supplier rules optional (an […]