

Did you know that under GDPR your organization will be subject to the ‘Right to Be Forgotten’?
And nope, this doesn’t mean that the regulator can forget about you.
On the contrary, when enforcement of the General Data Protection Regulation (GDPR) begins on May 25, 2018, any person located in the European Union – anyone residing in the EU, not just EU citizens – can request their personal information be removed from corporate databases in a timely fashion, or know the reason why it can't.
So, if your company handles any European personal data, whether you're inside or outside of the European Union, you are subject to the General Data Protection Regulation and to the ‘Right to Erasure’, also known as ‘Right to Be Forgotten’.
The new regulation means that companies are required to delete or ‘forget’ personal data related to an individual upon request. However, the right to erasure does not provide an absolute ‘Right to Be Forgotten’.
According to Article 17 of the GDPR, individuals have a right to have personal data erased and to prevent processing in specific circumstances:
Organizations don’t always have to comply with an individual’s request for erasure. Remember that the 'Right to Be Forgotten' isn’t an absolute right. A company can refuse to comply with a request for erasure when the personal data is processed for the following reasons:
To avoid forgetting about the ‘Right to Be Forgotten’, here are 3 steps that any organization can take:
Do you recall the movie ‘Eternal Sunshine of the Spotless Mind’? You can erase someone from your mind, but getting them out of your heart is another story. While your mind might forget, your heart will always remember.
Residual data known as Data Remanence, works in a similar way. When ‘deleting’ a file, it appears to be gone from memory. However, the contents of the ‘deleted’ file continues to exist deeper inside the system.
To comply with the ‘Right to Be Forgotten’, data must be deleted completely.
Here are the capabilities to look for when selecting a data erasure tool:
Jetico provides pure and simple wiping software for National Security, Compliance and Personal Privacy. Trusted for over 10 years by the U.S. Department of Defense, Jetico's BCWipe can wipe selected files beyond forensic recovery, delivering full GDPR compliance with confidence.
Enterprise Edition of BCWipe includes Jetico Central Manager for client software control. For auditing purposes, admins can also run and retrieve wiping reports.
Get started now!
Request a free trial
Contact us for a free consultation
Related Articles
Does GDPR Require Encryption?
Navigating NIS2: Ensuring Compliance through Encryption
NIS2 Requirements for Basic Cyber Hygiene Practices & Data Sanitization
Michael Waksman has been serving as CEO of Jetico since 2011, more than doubling the size of the company during his tenure. He brings more than 20 years of communications, technology and leadership experience.
At Jetico, Waksman has lead creation of the corporate identity, raising global brand awareness, building a more commercially-driven team and initiating enterprise customer relations. Jetico has maintained a wide user base throughout the U.S. Defense community, in the global compliance market and for personal privacy.
Waksman served as vice-chairman of the Cyber Group for the Association of Finnish Defense and Aerospace Industries. Recognized as a security and privacy advocate, he is a frequent speaker at international events, occasionally on behalf of the Finnish cyber security industry. In 2012, Waksman was honored with The Security Network's Chairman's Award for fostering collaboration between the United States and Finland. As dual citizen, he is a native New Yorker and has been living in the Helsinki region for over 15 years.