Question

Difficulty: Very hardData Privacy and Compliance Regulations

A systems administrator at a multinational e-commerce firm receives a formal request from an EU resident demanding the immediate erasure of their account history under the General Data Protection Regulation (GDPR) Right to be Forgotten. However, the company's accounting department notes that statutory financial laws mandate keeping transaction records for a minimum of seven years for audit purposes. Which of the following actions should the administrator take to maintain compliance across all legal frameworks?

  1. Retain the specific transaction data required by statutory financial retention laws while anonymizing or erasing all non-essential personal data and user profile records.Answer
  2. B
    Perform a full database purge of all customer logs and order histories to ensure GDPR compliance takes complete precedence over domestic tax laws.
  3. C
    Reject the deletion request in its entirety and maintain all active user profile details because tax laws override GDPR mandates.
  4. D
    Encrypt the customer profile using PCI-DSS compliant AES-256 standards and archive the database without processing any deletion.

Answer

Retain the specific transaction data required by statutory financial retention laws while anonymizing or erasing all non-essential personal data and user profile records.
Under GDPR regulations, the Right to be Forgotten is not absolute. When a statutory legal obligation (such as tax or financial audit laws) mandates record retention, organizations are legally permitted to retain the necessary transactional records. However, to remain compliant with privacy principles, any personal identifiers not strictly necessary for that legal purpose (such as marketing profiles or user credentials) must be erased or anonymized.

Step-by-Step Solution

1
Analyze the privacy request scope under GDPR.
Identified that the customer is invoking GDPR Article 17 (Right to Erasure / Right to be Forgotten).
EU citizens have the right to request deletion of personal data held by data controllers.
2
Evaluate statutory exemptions and conflicting compliance obligations.
Recognized that tax and financial regulations mandate retaining transactional records for seven years, which acts as a legal exemption under GDPR Article 17(3)(b).
Data controllers are not required to erase personal data if retention is necessary to comply with a legal obligation under applicable law.
3
Formulate a compliant data minimization and retention strategy.
Isolate the strictly mandated financial audit data while anonymizing or deleting all unnecessary Personally Identifiable Information (PII) and marketing profiles.
This satisfies both statutory financial record retention requirements and GDPR data minimization mandates.

Key Concept

Balancing GDPR Right to Erasure with Statutory Legal Retention Mandates
Estimated Time:2m 0s
Rate this question