A systems administrator at a multinational e-commerce firm receives a formal request from an EU resident demanding the immediate erasure of their account history under the General Data Protection Regulation (GDPR) Right to be Forgotten. However, the company's accounting department notes that statutory financial laws mandate keeping transaction records for a minimum of seven years for audit purposes. Which of the following actions should the administrator take to maintain compliance across all legal frameworks?
- Retain the specific transaction data required by statutory financial retention laws while anonymizing or erasing all non-essential personal data and user profile records.Cevap
- BPerform a full database purge of all customer logs and order histories to ensure GDPR compliance takes complete precedence over domestic tax laws.
- CReject the deletion request in its entirety and maintain all active user profile details because tax laws override GDPR mandates.
- DEncrypt the customer profile using PCI-DSS compliant AES-256 standards and archive the database without processing any deletion.
Cevap
Retain the specific transaction data required by statutory financial retention laws while anonymizing or erasing all non-essential personal data and user profile records.
Under GDPR regulations, the Right to be Forgotten is not absolute. When a statutory legal obligation (such as tax or financial audit laws) mandates record retention, organizations are legally permitted to retain the necessary transactional records. However, to remain compliant with privacy principles, any personal identifiers not strictly necessary for that legal purpose (such as marketing profiles or user credentials) must be erased or anonymized.
Adım Adım Çözüm
Anahtar Kavram
Balancing GDPR Right to Erasure with Statutory Legal Retention Mandates
Tahmini Süre:2m 0s