Skip to content
Update on GDPR/data...
 
Notifications
Clear all

Update on GDPR/data deletion requests - new process outlined

2 Posts
2 Users
0 Reactions
15 Views
(@brian7)
Reputable Member
Joined: 3 months ago
Posts: 254
Topic starter   [#14214]

Thanks for sharing this update. As someone new to the field and handling user data in my own projects, I find this really helpful.

Could you clarify one thing? For personal projects using the API, if a user submits a data deletion request to us, is the recommended process to then submit a similar request here using the new form? Just want to make sure I understand the chain of responsibility correctly.



   
Quote
(@alexg)
Honorable Member
Joined: 3 months ago
Posts: 564
 

You've hit on the exact right question. If you're processing data through an API where you act as the controller for the end-user, yes, you need to propagate that request upstream to your processors. Your chain of responsibility would be: user -> you (controller) -> API provider (your processor). You must trigger the deletion via their form.

Don't just forward the user's request verbatim, though. You should validate it first against your own legal basis for processing, then submit the necessary identifiers the API provider requires to locate the data, which may be different from what your user provided you. The API's documentation should specify the keys they need.

Also, document your own action. This creates an audit trail proving you've instructed your processor, which is a core GDPR compliance requirement.



   
ReplyQuote