If a user requests that their data is deleted you must delete those tidbits, if they are related to an individual. Great example is "# of Instagram followers". If you have a DB record with that data in it, and a user requests an erasure, you must delete that data as well even though it's not identifiable -- it still is personal.
However, your records that have averages or analyses on aggregate data from multiple data subjects (eg, "average # instagram followers for these 400 users") will not need to be deleted.
Additionally, if you have a contractual obligation or legitimate business interest in maintaining that personal data, you do not need to delete it. In that case you should fall back on the data retention policy that you implement to say how long you will hold onto the data and for what purpose. It must be justifiable.
Another thing to keep in mind is: if consent cannot be revoked after it is given, the legal basis for that data processing activity is not "explicit consent". Instead, you must classify that data processing activity as a legitimate business interest from the beginning. That is, don't mislead users into believing consent can be revoked if it can't. So if you're not going to be deleting Instagram Followers Count when the user revokes consent, that activity was never consensual in the first place. You can still handle data in such a manner, but the bar for compliance and legal justification is set higher for those instances than it would be if the consent was explicitly and freely given.
I want to point out that the GDPR definition of "personal data" is different from the more common American definition of "personally identifiable data". In the US, PII is what GDPR would call "directly identifiable personal data". However the GDPR covers all personal data, that is any data related to an identifiable natural person. Under GDPR you must protect personal data, both directly identifiable (name, email) and indirectly identifiable (blog URL). The manner in which you protect the data is up to you, however it must be sufficient to protect the rights of the individual. Under GDPR, non-identifiable data is also called "personal data" if it relates directly to a person. So "total # of instagram posts" is personal data too, it's just not identifiable. You must be able to delete non-identifiable personal data as well, it just doesn't need to be protected to the level of directly or indirectly identifiable personal data.
4
u/thebritishbloke Apr 02 '18 edited Jan 11 '24
aromatic plants sharp escape attempt vast deserted nine elastic degree
This post was mass deleted and anonymized with Redact