A German customer has demanded the deletion of all personal data held by a company, triggering a legal conflict between data protection laws and information security requirements. The situation highlights the tension between the General Data Protection Regulation (GDPR) and the need for secure data management practices. According to the case described, the customer sent an email on a Tuesday morning requesting the removal of his data. While the company quickly deleted the relevant entry from its Customer Relationship Management (CRM) system, the data had already been backed up overnight onto multiple tapes. Incremental backups also contained the information, and the customer’s IP address with timestamps appeared repeatedly in server logs. Now the question arises: must all this data be erased, and if so, how? The core issue lies in the contradiction between two legal obligations. On one side stands the right to erasure under Article 17 of the GDPR, which allows individuals to request the deletion of their personal data. This is supported by the principle of limited storage under Article 5, which states that personal data should only be kept for as long as necessary for the purpose of processing. If that purpose ends, such as through unsubscribing from a newsletter, the data collected for that purpose must be deleted. On the other side is the requirement for information security. Companies operating under an Information Security Management System (ISMS), such as those certified by the Bundesamt für Sicherheit in der Informationstechnik (BSI) or ISO/IEC 27001, are required to maintain backups and collect log files. The GDPR itself indirectly supports these practices through Article 32, which mandates that data must be recoverable after an incident. However, security standards demand immutability and tamper-proofness. A backup from which individual records can be removed later is not reliable, and a log file loses its evidentiary value if personal data within it can be deleted. This dilemma presents a challenge for organizations using standard technology. It is nearly impossible to delete specific personal data while ensuring that backups and logs remain intact. The situation underscores the complexity of complying with both data protection and information security regulations simultaneously. The case illustrates a broader problem faced by many companies. When a user exercises their right to erasure, they expect all traces of their data to be removed. Yet, maintaining operational integrity requires retaining copies of data for recovery purposes. This creates a conflict that is difficult to resolve with current tools and processes. Legal experts have noted that there is no clear guidance on how to handle such scenarios. The European Data Protection Board (EDPB) has issued guidelines, but they focus more on general principles than on specific technical solutions. As a result, businesses often find themselves navigating a gray area, balancing compliance with practical constraints. In response to such cases, some companies have begun exploring alternative approaches. For example, they might implement systems that allow for selective deletion without compromising the integrity of backups. Others are working with legal advisors to develop policies that clarify how to manage these conflicts. However, these measures are still evolving, and there is no universally accepted solution yet. As the debate continues, the key stakeholders, including regulators, legal professionals, and IT managers, are likely to see increased scrutiny. The outcome of this particular case could influence future interpretations of the GDPR and shape best practices for data management. Until then, the challenge remains: how to honor the rights of individuals while safeguarding the reliability of critical systems.
★
Keep the news honest.
ObjectiveNews is reader-funded and ad-free — we show you the bias instead of hiding it. Support independent journalism for €4/month.
Become a Supporter