ON
← Back to feed
Right: GDPR deletion requirements in clinch with backups and log files
Germany🏛️ PoliticsCenter2 days ago

Right: GDPR deletion requirements in clinch with backups and log files

The article discusses the conflict between the EU General Data Protection Regulation (GDPR)'s data deletion requirements and the need for IT security measures such as backups and log files. Under GDPR Article 17, individuals have the right to request the deletion of their personal data. However, companies often maintain backups and logs for security and operational purposes, which may contain the same data. This creates a dilemma because deleting specific data from backups and logs could compromise their integrity and reliability. The article highlights the challenge of complying with both legal obligations while maintaining secure and unalterable records.

A German customer has demanded the deletion of all personal data held by a company, triggering a legal conflict between data protection laws and information security requirements. The situation highlights the tension between the General Data Protection Regulation (GDPR) and the need for secure data management practices. According to the case described, the customer sent an email on a Tuesday morning requesting the removal of his data. While the company quickly deleted the relevant entry from its Customer Relationship Management (CRM) system, the data had already been backed up overnight onto multiple tapes. Incremental backups also contained the information, and the customer’s IP address with timestamps appeared repeatedly in server logs. Now the question arises: must all this data be erased, and if so, how? The core issue lies in the contradiction between two legal obligations. On one side stands the right to erasure under Article 17 of the GDPR, which allows individuals to request the deletion of their personal data. This is supported by the principle of limited storage under Article 5, which states that personal data should only be kept for as long as necessary for the purpose of processing. If that purpose ends, such as through unsubscribing from a newsletter, the data collected for that purpose must be deleted. On the other side is the requirement for information security. Companies operating under an Information Security Management System (ISMS), such as those certified by the Bundesamt für Sicherheit in der Informationstechnik (BSI) or ISO/IEC 27001, are required to maintain backups and collect log files. The GDPR itself indirectly supports these practices through Article 32, which mandates that data must be recoverable after an incident. However, security standards demand immutability and tamper-proofness. A backup from which individual records can be removed later is not reliable, and a log file loses its evidentiary value if personal data within it can be deleted. This dilemma presents a challenge for organizations using standard technology. It is nearly impossible to delete specific personal data while ensuring that backups and logs remain intact. The situation underscores the complexity of complying with both data protection and information security regulations simultaneously. The case illustrates a broader problem faced by many companies. When a user exercises their right to erasure, they expect all traces of their data to be removed. Yet, maintaining operational integrity requires retaining copies of data for recovery purposes. This creates a conflict that is difficult to resolve with current tools and processes. Legal experts have noted that there is no clear guidance on how to handle such scenarios. The European Data Protection Board (EDPB) has issued guidelines, but they focus more on general principles than on specific technical solutions. As a result, businesses often find themselves navigating a gray area, balancing compliance with practical constraints. In response to such cases, some companies have begun exploring alternative approaches. For example, they might implement systems that allow for selective deletion without compromising the integrity of backups. Others are working with legal advisors to develop policies that clarify how to manage these conflicts. However, these measures are still evolving, and there is no universally accepted solution yet. As the debate continues, the key stakeholders, including regulators, legal professionals, and IT managers, are likely to see increased scrutiny. The outcome of this particular case could influence future interpretations of the GDPR and shape best practices for data management. Until then, the challenge remains: how to honor the rights of individuals while safeguarding the reliability of critical systems.

1 reports

heise online logoheise onlineIndependentCenterFactual 94Objective 962 days ago
Right: GDPR deletion requirements in clinch with backups and log files

The article discusses the conflict between the EU General Data Protection Regulation (GDPR)'s data deletion requirements and the need for IT security measures such as backups and log files. Under GDPR Article 17, individuals have the right to request the deletion of their personal data. However, companies often maintain backups and logs for security and operational purposes, which may contain the same data. This creates a dilemma because deleting specific data from backups and logs could compromise their integrity and reliability. The article highlights the challenge of complying with both legal obligations while maintaining secure and unalterable records.

Bias read (Center): The article presents a technical and legal discussion about GDPR compliance and IT security practices without taking a clear ideological stance. It explains the conflict between regulations and practical implementation but does not favor one side over the other.

Why factuality (94): The article accurately describes the conflict between GDPR Article 17's right to deletion and data retention requirements from IT security standards like ISO/IEC 27001 and BSI's IT Grundschutz. It provides specific references to relevant GDPR articles (17, 5, 32) and explains the practical challenge

Why objectivity (96): The article presents the issue in a neutral and balanced manner, avoiding any overt bias toward either the GDPR or IT security requirements. It uses professional and objective language throughout, explaining both sides of the issue without editorializing or using emotionally charged terms.

How each side covered it

The same event, grouped by the political lean of the outlets covering it.

How each side covered it

Support independent, bias-aware news and unlock the social pulse, community voting, and every other Supporter feature.

Become a Supporter

Covered around the world

The same event as reported in other countries.

Covered around the world

Support independent, bias-aware news and unlock the social pulse, community voting, and every other Supporter feature.

Become a Supporter

Claims check

Key factual claims, and how many sources assert vs dispute each.

Claims check

Support independent, bias-aware news and unlock the social pulse, community voting, and every other Supporter feature.

Become a Supporter

Keep the news honest.

ObjectiveNews is reader-funded and ad-free — we show you the bias instead of hiding it. Support independent journalism for €4/month.

Become a Supporter

Related stories