What is an erasure concept under the GDPR?
An erasure concept under the GDPR is an internal company framework that systematically defines how personal data are erased once their processing is no longer necessary or permissible. It serves to implement the data protection erasure obligations under Article 17 GDPR and the principle of storage limitation under Article 5(1)(e) GDPR in practice.
Purpose and legal basis
Article 17 GDPR requires the erasure of personal data where the purpose of processing no longer applies or other grounds for erasure exist, such as withdrawal of consent.
Article 5(1)(e) GDPR, storage limitation, requires that personal data be stored only for as long as is necessary for the purposes for which they are processed.
Article 5(2) GDPR, accountability, requires controllers to be able to demonstrate compliance with the GDPR. A documented erasure concept contributes to this.
How do you create an erasure concept?
A practical erasure concept under the GDPR consists of several structured components that build systematically on one another. DIN 66398 is, among other things, an established guideline for developing such concepts.
1. Data inventory and categorisation
First, all personal data within the company are fully recorded. They are divided into data types, such as customer data or employee data, and grouped into erasure classes that share common erasure rules and deadlines.
2. Defining erasure periods and start dates
Specific erasure periods are defined for each erasure class, based on statutory retention obligations, such as those under the German Commercial Code, HGB, or Fiscal Code, AO, or on internal policies. The start date of the period, such as the end of a contract or last contact, is clearly determined.
3. Defining erasure rules and implementation measures
Specific erasure rules are defined for each erasure class, including methods for secure data erasure, such as overwriting, shredding or anonymisation, and taking into account different types of data carriers, both digital and physical. Responsibilities for implementing and monitoring the erasure concept are clearly assigned.
4. Integration into data protection management
The erasure concept is integrated into the existing data protection management system, in particular into the record of processing activities under Article 30 GDPR. This ensures consistent application and facilitates proof of compliance vis-à-vis supervisory authorities.
5. Documentation and evidence
All erasure processes are documented, including the time, type of erasure and responsible person. These logs serve accountability purposes under Article 5(2) GDPR and enable transparent traceability.
6. Regular review and updating
The erasure concept is reviewed regularly and updated where necessary to reflect changes in legal requirements or internal processes. This ensures that the concept remains current and effective.
Free expertise in your e-mail inbox
All the important news on data protection, information security, AI and data strategy conveniently delivered to your e-mail inbox once a month - free of charge, of course. (Currently only available in German)
What is DIN 66398?
DIN 66398 is a German standard entitled “Guideline for the development of an erasure concept with derivation of erasure periods for personal data”. Published in 2016, it provides organisations with a structured approach to creating an erasure concept that meets the requirements of the General Data Protection Regulation, GDPR.
The core components of DIN 66398 are:
- Data types: definition of groups of data objects processed for a uniform purpose.
- Erasure classes: grouping of data types with identical erasure periods and start dates.
- Erasure rules: definition of the erasure period and start date for each erasure class.
- Implementation specifications: specific instructions for the technical and organisational implementation of the erasure rules.
- Responsibilities: allocation of responsibilities for creating, maintaining and implementing the erasure concept.
- Documentation: recommendation for structuring documentation of the erasure concept and erasure processes.
Example of an entry according to DIN 66398
Data type: application documents of rejected candidates, where there is no documented consent for inclusion in the applicant pool.
Erasure class: LK-06M-EV, maximum erasure period: six months from rejection of the applicant or the end of the selection process.
Erasure rule: erasure takes place no later than six months after rejection of the applicant.
Implementation specification: automated erasure of digital application documents in the HR system. Physical documents are destroyed by the HR department.
Responsibility: Human Resources department, HR.
Documentation: erasure processes are recorded in the HR system’s erasure log and reviewed annually.
When must personal data be erased?
The personal data of data subjects must be erased if:
- the personal data are no longer necessary for the purposes for which they were collected or otherwise processed, Article 17(1)(a) GDPR;
- consent to data processing has been withdrawn and there is no other legal basis for processing, Article 17(1)(b) GDPR;
- the data subject has objected to processing, Article 17(1)(c) GDPR;
- the processing was unlawful, Article 17(1)(d) GDPR;
- erasure of the personal data is required to comply with a legal obligation under Union or Member State law, Article 17(1)(e) GDPR; or
- the personal data were collected in relation to the offer of information society services referred to in Article 8(1) GDPR, Article 17(1)(f) GDPR.
Example
A customer gives a company permission to use their email address to send newsletters. However, they have the right to withdraw this consent at any time with effect for the future.
If they do so, the legal basis for processing and storing their personal data no longer applies, Article 17(1)(b) GDPR. The company is then obliged to erase the email address. The same applies if no consent to receive newsletters was given in the first place, Article 17(1)(d) GDPR.
Exceptions under Article 17(3) GDPR
Article 17(3) GDPR provides for exceptions to the right to erasure of personal data. These exceptions apply where processing remains necessary for specific reasons. The GDPR lists the following exceptions:
- exercising the right of freedom of expression and information;
- compliance with a legal obligation or performance of a task carried out in the public interest;
- reasons of public interest in the area of public health;
- archiving purposes, scientific or historical research purposes or statistical purposes;
- establishment, exercise or defence of legal claims.
Retention obligations
Statutory retention periods outside the GDPR may also prevent erasure. The following is a brief overview of selected retention periods:
| Document type / data type | Retention period | Legal basis |
|---|---|---|
| Commercial and business letters | 6 years | Section 147(3) AO, Section 257(4) HGB |
| Application documents, in case of rejection | max. 6 months | Section 15(4) AGG |
| Employment contracts, payslips | 10 years | Section 147(3) AO |
| Certificates of incapacity for work | 5 years | Section 6(1) AAG |
| Time sheets, more than 8 hours on working days | 2 years | Section 16(2) ArbZG |
| Documents relating to accidents at work | 5 years | Section 24(6) DGUV Regulation 1 |
| Documents relating to liability cases, bodily injury | 30 years | Section 199(2) BGB |
| Documents relating to liability cases, property damage | 10 years | Section 199(1) BGB |
What constitutes erasure?
The term “erasure” is not legally defined in the GDPR. It is only mentioned in Article 4(2) GDPR, where it is listed as a form of processing. It can be inferred that erasure means the complete and irreversible removal of personal data, making restoration impossible with reasonable effort. This includes both digital and physical data.
Technical implementation
Digital data: erasure is carried out using secure methods, such as overwriting the data with random values or physically destroying the storage media.
Physical data: paper files must be disposed of using a document shredder; the protection class and security level are based on the DIN 66399 standard for data carrier destruction.
Anonymisation as an alternative
Instead of erasure, the data may be anonymised by permanently removing any personal reference. However, this is only permissible if the anonymisation is complete and irreversible. In practice, this is often difficult to implement.
Blocking as an interim solution
In cases where immediate erasure is not possible, for example due to statutory retention obligations, the data must be blocked. This means that the data are blocked for further processing and remain accessible only for the intended purpose.
What sanctions may apply for non-compliance with the right to erasure?
The absence of an erasure concept and the resulting failure or delay in erasing personal data constitute infringements of the General Data Protection Regulation, GDPR. This can lead to significant sanctions. Article 83(5)(a) GDPR provides for fines of up to EUR 20 million or up to 4% of worldwide annual turnover, whichever is higher, for infringements of the principles relating to the processing of personal data.
Practical examples of sanctions
Hamburg, 2024: a company in receivables management stored personal data for up to five years despite expired erasure periods. The Hamburg Commissioner for Data Protection and Freedom of Information imposed a fine of EUR 900,000.
Berlin, 2019: Deutsche Wohnen SE was fined EUR 14.5 million because the archive system it used was technically unable to erase data that were no longer required. The data were stored without any review of whether storage remained permissible.
What must be considered for processing by processors in the erasure concept?
Under Article 4(7) GDPR, the controller is obliged to ensure that personal data are erased in due time. This obligation also extends to data processed by processors. This means that the controller must ensure that service providers also erase data within the applicable deadlines.
Under Article 28(3), second sentence, point (g) GDPR, the processor is obliged, after completion of the processing services, either to erase or return all personal data, unless a statutory storage obligation applies. This obligation should be clearly regulated in the data processing agreement.
If the processor breaches erasure obligations, the controller may generally be held liable under Article 82(1) GDPR. It is therefore in the controller’s interest to ensure that the processor properly fulfils the erasure obligations.
How we support you with your erasure concept
A well-designed erasure concept is essential for GDPR-compliant data processing. As specialised data protection consultants, we support you in a practical and legally secure way with the design, implementation and monitoring of your erasure concept.
Our services at a glance
- Analysis and categorisation of all relevant personal data
- Development of individual erasure rules in accordance with DIN 66398
- Derivation and documentation of statutory retention and erasure periods
- Creation of a company-specific erasure concept including erasure classes
- Support with integration into the data protection management system, for example ROPA and TOMs
- Review and optimisation of existing data erasure processes
- Development of technical and organisational erasure measures
- Advice on erasure in backup and archive systems
- Contract review and control of processors, Article 28 GDPR
- Training and awareness-raising for employees
- Regular reviews and updating of the erasure concept
- Support during authority audits and requests for information