Published
Keep only as long as needed — and delete on request
The office's retention periods now run on their own, only figures are kept before anything is deleted, and the owner can erase a person's data on request.
The privacy law, after amendment 13, asks for two things that are easy to state and hard to do by hand: do not keep data longer than needed, and delete it when a person asks. Until now the retention periods were a setting rather than an action. Now the system carries them out itself and leaves a record behind.
How long to keep is an office setting. By default it is 24 months from the last contact with the inquiry, so a call or a status change starts the count again. An inquiry marked as not relevant is kept for 12 months. The raw content that arrives from an advertising form — the request as it was sent, before it became a record — is removed after 60 days. The access log, the internal note of who looked at what, rotates every 12 months.
Thirty days before a scheduled deletion the office owner gets a warning, so there is time to step in and bring back an inquiry the work on which has resumed. The warning itself carries no personal data: type, number and date. Automatic deletion can also be switched off entirely — the system then keeps warning you and deletes nothing.
A person asking for their data to be erased is a separate case, and it now has an action of its own. On the inquiry record, for whoever holds the deletion right, there is "Erase at the subject's request" — with a confirmation step and a reason chosen from a list.
On every deletion, whether it comes from the retention period or from a person's request, the system does the same things:
- before the inquiry goes, only a numeric summary of it is kept, and a breakdown holding fewer than five inquiries is not stored on its own — the funnel figures do not shrink after the fact, while the person's data is no longer there;
- in the quality-loop log and in the access log the reference to the person is replaced by an anonymous marker: the entries stay, and there is no personal data in them;
- the deletion itself is recorded — what was deleted, when, and on what grounds;
- the steps run in a fixed order, and every step is counted.
Two neighbouring points. The office can receive an export of one person's data in a single file — by a request to support. And importing history from a file now leaves an entry in the log with row counts and no personal data; the source file and the leftover rows sit outside the public folder and are removed once the import is done.
Want to see this on your own office's inquiries?