DPO PARTAGE
No Result
View All Result
  • Login
  • Accueil
  • Cybersécurité
    Cyber threat Overview 2021

    Cyber threat Overview 2021 – CERT-FR

  • Trouver un DPO
  • Secteurs d’activité
  • Contact
Premium
S'INSCRIRE
  • Accueil
  • Cybersécurité
    Cyber threat Overview 2021

    Cyber threat Overview 2021 – CERT-FR

  • Trouver un DPO
  • Secteurs d’activité
  • Contact
No Result
View All Result
DPO PARTAGE
No Result
View All Result
Home Personal data

How to comply with GDPR principles when deleting user accounts on an e-commerce website

by Laurent de Cavel - DPO
7 March 2026
in Personal data
Reading Time: 4 mins read
0
Respecting GDPR for customer accounts

Respecting GDPR for customer accounts

A lire aussi sur DPO PARTAGE

TikTok Ban: US Government Action Insufficient to Halt Chinese Data Collection

The European Parliament Joins US and Canada in Banning TikTok for Security Reasons

GDPR for customer accounts : As an online sales site, the deletion of old accounts must be carried out in accordance with the provisions of the European Union’s General Data Protection Regulation (GDPR). Here are some important rules to follow when deleting old accounts in compliance with the GDPR:

Inform users: before deleting old accounts, you must inform the affected users of the deletion of their account. You can do this by email or by posting a notification on the website. The notice must specify the reason for the deletion and the date on which it will take place.

Comply with retention periods: the GDPR imposes retention periods for certain personal data. You must ensure that you comply with these periods before deleting accounts. If you retain data beyond the allowed periods, you risk violating the GDPR.

Allow access to personal data: users have the right to access and export their personal data. You must allow them to access their data before deleting their account.

Erase personal data: you must erase all personal data of the users after the deletion of their account. This includes purchase, payment, billing, and profile data.

Take security measures: you must take appropriate security measures to prevent the loss or unauthorized access to users’ personal data during the deletion process.

Provide recourse: if users have concerns or complaints regarding the deletion of their account, you must provide them with a recourse. This may include a claims process or the ability to contact a Data Protection Officer.

RGPD Compliance for WordPress Websites Paperback 

What are the deadlines?

Rules for deleting old accountsTimeframes in months
Inform users of the deletion of their accountN/A (may vary depending on contract terms)
Respect retention periods for personal data1-10 months
Allow access and export of personal data1 month
Erase all personal data after deletion1-3 months
Take appropriate security measuresN/A (ongoing)
Provide a remedy for users1 month

Internal procedure to comply with GDPR

Identify inactive user accounts: The Data Protection Officer (DPO) or the team responsible for managing accounts must identify inactive accounts that need to be deleted in accordance with the terms of the contract and the GDPR.

Inform users of the deletion of their account: The team responsible for managing accounts must inform affected users of the deletion of their account via a notification sent by email or displayed on the website. This notification must explain the reason for the account deletion and the date it will take place.

Comply with retention periods for personal data: The DPO or the team responsible for managing accounts must ensure that all users’ personal data is kept in compliance with the GDPR requirements and the company’s internal policy.

Allow access and export of personal data: Users must be able to access and export their personal data before their account is deleted. The team responsible for managing accounts must provide clear instructions to users on how to access and export their personal data.

Erase all personal data after deletion: The team responsible for managing accounts must delete all users’ personal data after their account has been deleted.

Take appropriate security measures: The team responsible for managing accounts must take all appropriate security measures to prevent the loss or unauthorized access to users’ personal data.

Provide recourse to users: If users have concerns or complaints regarding the deletion of their account, the team responsible for managing accounts must provide them with a recourse by providing information on how to file a complaint and by providing a point of contact for the company’s Data Protection Officer.

Comply with GDPR for customer accounts: GDPR source

Rules for deleting old accountsGDPR Articles
Inform users of the deletion of their accountArticle 13(1)(c) of the GDPR
Comply with retention periods for personal dataArticle 5(1)(e) of the GDPR
Allow access and export of personal dataArticles 15 and 20 of the GDPR
Erase all personal data after deletionArticle 17(1)(a) of the GDPR
Take appropriate security measuresArticle 32 of the GDPR
Provide recourse to usersArticle 77 of the GDPR
A lire aussi sur le meme sujet :

  • Web Analytics and GDPR Compliance: How Website Hosts Can Adhere in France
  • What about the GDPR with the European Commission’s proposal for a digital driving license?
  • Thales is attempting to improve its image by presenting a transparency operation following a cyber attack that compromised three user accounts and downloaded 9 GB of data.
Tweet405Share113
Previous Post

European NIS 2 directive: a new challenge for DPOs and cybersecurity.

Next Post

Pepsi Bottling Ventures LLC suffered a data breach.

Laurent de Cavel - DPO

Looking for a DPO? Entrust your mission to DPO PARTAGE - Contact us at +1 813 768 3616or by email at contact@dpo-partage.fr. DPO PARTAGE is the leader in DPO services for health and sensitive data.

Related Posts

TikTok Ban
Personal data

TikTok Ban: US Government Action Insufficient to Halt Chinese Data Collection

7 March 2026
Banning TikTok
Personal data

The European Parliament Joins US and Canada in Banning TikTok for Security Reasons

8 March 2026
Next Post
Pepsi data breach.

Pepsi Bottling Ventures LLC suffered a data breach.

TikTok Ban

TikTok Ban: US Government Action Insufficient to Halt Chinese Data Collection

APPLICATION RGPD

Démo gratuite

Découvrez DPO SUITE

Gérez votre conformité RGPD de A à Z avec une solution qui anticipe les évolutions réglementaires, sans effort supplémentaire.

Rappel par un expert dans les prochaines minutes

Vos données sont traitées pour répondre à votre demande. En savoir plus.

Demande envoyée !

Un expert DPO PARTAGE vous rappelle
dans les prochaines minutes.

Articles recommandés

Digital driving license GDPR

What about the GDPR with the European Commission’s proposal for a digital driving license?

7 March 2026
European NIS 2 directive

European NIS 2 directive: a new challenge for DPOs and cybersecurity.

7 March 2026
Exit GDPR

Exit GDPR: The United Kingdom relaxes its data protection rules to facilitate business operations and save £4 billion over 10 years.

7 March 2026

Articles populaires

    DPO PARTAGE DPO externalisé

    DPO Partage se positionne comme un acteur clé dans le domaine de la protection des données personnelles, en offrant une gamme complète de services axés sur le Règlement Général sur la Protection des Données (RGPD). Notre structure fournit des informations régulières et pointues sur les dernières évolutions et exigences du RGPD, ce qui en fait une ressource précieuse pour les entreprises soucieuses de se conformer à la législation.

    Faites appel à DPO PARTAGE pour votre conformité RGPD.
    Contactez nous au 01 83 64 42 98
    En savoir plus »

    Recent Posts

    • Xerox Corp is reportedly the victim of a major cyberattack.
    • Navigating the Regulatory Landscape of Health Data Hosting: A Comparison of France and the United States with Advice for American Companies
    • Turning GDPR Compliance into Competitive Advantage: Unveiling the New Guide for American Enterprises
    • Web Analytics and GDPR Compliance: How Website Hosts Can Adhere in France
    • Data Breach at DecathlonThe Critical Importance of Cybersecurity Highlighted by the Recent Data Breach Involving Nearly 8,000 Employees and Customers of DecathlonData Breach at Decathlon
    • Mentions Légales
    • Politique de confidentialité
    • Politique cookies DPO Partagé
    • Nous contacter
    • Politique de cookies (UE)
    SITE AUDITÉRGPDAudit automatiséby DPO-FRANCE

    © 2026 DPO PARTAGE - Pilote de votre conformité RGPD

    Welcome Back!

    Login to your account below

    Forgotten Password?

    Retrieve your password

    Please enter your username or email address to reset your password.

    Log In
    Question ?

    Question ?

    Comment pouvons-nous vous aider ?

    Être rappelé

    Vos données sont traitées conformément au RGPD.

    Voir une démo

    Vos données sont traitées conformément au RGPD.

    Demander un devis

    Vos données sont traitées conformément au RGPD.

    Demande envoyée !

    Nous reviendrons vers vous très rapidement.

    Une erreur est survenue

    Veuillez réessayer ou nous contacter directement.