GDPR has been a hot topic in recent years as new laws were brought in in 2018 to protect people’s data and how it is used. However, it seems that many people are still unaware of all of their responsibilities, as well as what data of yours businesses are allowed to hold on to.
Here, we take a look at what data can be kept by different organisations and how long it can be stored for. We also look at whether you have the right to be forgotten entirely by a company, how they should respond to a request and what exemptions there are to this.
What is GDPR?
The General Data Protection Regulation (GDPR) is the law which dictates how personal data is collected, processed and erased. GDPR is an EU data privacy and security law which has been implemented across Europe over the last few years. With more and more organisations and services collecting data about us, these laws have been put into place in order to make sure that it is used and stored correctly, with hefty penalties for those who suffer data breaches in order to put pressure on businesses to take the toughest security measures.
It can sometimes be difficult to know what is classed as personal data, and this has led to some confusion. Personal data is considered to be any information about an individual who can be directly or indirectly identified. This will obviously include names and contact details, but also factors such as ethnicity, gender, biometric data, religious beliefs, web cookies and political opinions. Any action performed on this is considered to be data processing and can include collecting, reading, organising, storing and structuring.
How long can data be held?
The overriding principle of GDPR laws is that data should not be held any longer than it is needed, and this time frame will need to be justified. Each organisation should have a policy setting out their standard retention periods, but the length of time you store data will depend on what it is and why you have it.
Currently, the UK does not state how long organisations should keep personal data, however, they will need to be clear on whether they need to retain your data after your relationship with them has ended. For example, a business might want to keep data about a previous customer in case complaints arise later, or if they might be required to provide a reference about an employee for a new employer. Even if you request that a company stops sending you direct marketing, they may need to retain some data to stop you from being included in future activities.
There may also be regulatory requirements surrounding how long data needs to be kept. There may need to be certain records retained for tax purposes, or in case someone makes an insurance claim. It may also relate to health and safety issues or other aspects of finance, and therefore there are laws and regulations which will dictate this.
The Right to be Forgotten
Whilst businesses have the right to hold on to some of your data, you also have the right to ask them to delete it. The right to be forgotten is specifically referenced in article 17 of the regulations, stating that a person has the right to obtain the erasure of personal data about them without undue delay. If you want to make a request like this, you need to be able to prove that you are the person about whom the data applies in order to avoid a security breach.
You might want to ask for this to be done if you believe there are errors within the data or that it is being stored unnecessarily. You might also want to request that your data be deleted if you no longer consent to the processing of it by a particular organisation.
The right be forgotten applies if the business has changed what they are doing and the data is no longer necessary for the original purpose, there is no longer a legitimate interest in processing the data, or it is being used for unwanted direct marketing, or it has been processed unlawfully. An organisation is also required to erase your data if there is a legal ruling or obligation to do so.
There are occasions in which an organisation may not be required to delete your information. This is possible if the data is being used to exercise the right of freedom of expression and information or if it complies with a legal ruling or obligation. If the data is being used to perform a task that is carried out in the public interest, or it is necessary for public health purposes then it does not have to be removed.
This is also the case if the data is processed by a health professional, and it is needed to perform preventative or occupation medicine. The data may represent important information that serves the public interest, scientific research, historical research or statistical purposes, and erasure of such would impair the achievement of collecting it in the first place. It also cannot be deleted if it is being used in the establishment of a legal defense or as part of other legal claims.
If a request to be forgotten is made, it should be addressed without undue delay, which is normally considered to be within a month. The organisation is able to request what is deemed a reasonable fee if it can be justified that the request was unfounded or excessive.
GDPR is a serious subject, and it is important that businesses, organisations and individuals all understand exactly what their rights are. This means that only the correct data will ever be stored, and never for longer than is needed. It also gives individuals the right to have that data removed if they feel the need and the situation allows it. This protects identifiable data and keeps individuals safe from hackers, scammers and abuse.
Author Bio
Gavin Prior is the Operations Manager at Rads Document Storage, a secure facility based in Nottingham which provides professional document management services.
Gavin Prior is the Operations Manager at Rads Document Storage, a secure facility based in Nottingham which provides professional document management services.