A recent decision from the Higher Regional Court of Dresden, Germany, highlights the need for controllers to ensure their processors are deleting data when they’re supposed to and to obtain a specific written confirmation that all personal data has in fact been deleted. At issue in the instant matter was a controller that used a processor up until 2019 and where the processor claimed to delete the controller’s data afterward. The processor later suffered a data breach in 2022. The data that was supposedly deleted was contained in the data breach.
The agreement between the controller and processor specified that the controller could choose for the processor to return or delete the controller’s personal data upon the conclusion of their relationship, as many such agreements do. However, the controller never made this election. The agreement also required the processor to confirm to the controller in writing within 21 days after the end of the agreement that the processor deleted the data. This wasn’t done either.
What did happen was the day before the conclusion of the agreement, the processor informed the controller it would delete the controller’s data the following day. That never happened (sub-lesson: only promise to delete data within a time period you can actually meet – don’t get overzealous with your data deletion claims). A year later, in 2020, the processor claimed it would imminently be deleting the data (second sub-lesson: don’t promise you’ll do something you already promised you’d do). What happened then? Did the processor delete the data?
Surprise: No. Did the controller ask for confirmation of deletion? More “no.” And then the processor had a data breach in 2022 which included the data they were supposed to delete (twice) and for which the processor was supposed to provide a confirmation of deletion which they never sent and which the controller never requested.
You’d think this would be enough of a lesson to make sure your processors are deleting your data – but we’re not done yet.
The controller still didn’t request confirmation of deletion directly following the 2022 breach. It wasn’t until 2023 when the processor finally provided some kind of confirmation that it conducted a deletion – a confirmation the court did not find sufficient.
The final lessons of this case are:
- if you’re a controller, make sure your processors delete data as specified in your agreement, and in particular, get written confirmation the data was deleted. Create processes to ensure this takes place.
- if you’re a processor, delete data as specified in your agreements. Create processes to ensure these deletions indeed take place.