The GDPR requires that personal data be kept in a form that permits identification of the data subjects for no longer than what is necessary for the purposes for which it is being processed. This duration can be determined by law; otherwise, it should be determined for each phase of the datalife cycle. At the end of the defined retention time, the data should be deleted or their identifying characteristics should be removed by means of an anonymization process.
Anonymization consists in using a set of techniques to make it impossible to identify the person, in an irreversible way. It must no longer be possible to achieve:
This technique is used for statistical purposes or when it is impossible to delete data.
There are two main approaches to anonymization:
Thanks to its technical and legal skills in data protection and digital transformation, TNP Consultants supports its clients in the definition and implementation of a personal data deletion strategy.
Data flow mapping, consideration of IT architecture constraints
Analysis of data usefulness for the company
Definition of the data strategy: anonymization, pseudonymization, deletion
Definition of the data strategy: anonymization, pseudonymization, deletion
Implementation of the data strategy
Evaluation of individualization, correlation and inference risks
Evaluation of individualization, correlation and inference risks