DPO PARTAGE
No Result
View All Result
  • Login
  • Accueil
  • Cybersécurité
    Cyber threat Overview 2021

    Cyber threat Overview 2021 – CERT-FR

  • Votre conformité RGPD (Tarifs)
  • Secteurs d’activité
  • Contact
Premium
S'INSCRIRE
  • Accueil
  • Cybersécurité
    Cyber threat Overview 2021

    Cyber threat Overview 2021 – CERT-FR

  • Votre conformité RGPD (Tarifs)
  • Secteurs d’activité
  • Contact
No Result
View All Result
DPO PARTAGE
No Result
View All Result
Home Personal data

How to comply with GDPR principles when deleting user accounts on an e-commerce website

DPO Partagé by DPO Partagé
27 August 2023
in Personal data
Reading Time: 4 mins read
0
Respecting GDPR for customer accounts

Respecting GDPR for customer accounts

Sommaire

Toggle
    • TikTok Ban: US Government Action Insufficient to Halt Chinese Data Collection
    • The European Parliament Joins US and Canada in Banning TikTok for Security Reasons
  • What are the deadlines?
  • Internal procedure to comply with GDPR
  • Comply with GDPR for customer accounts: GDPR source

GDPR for customer accounts : As an online sales site, the deletion of old accounts must be carried out in accordance with the provisions of the European Union’s General Data Protection Regulation (GDPR). Here are some important rules to follow when deleting old accounts in compliance with the GDPR:

A lire aussi sur DPO PARTAGE

TikTok Ban: US Government Action Insufficient to Halt Chinese Data Collection

The European Parliament Joins US and Canada in Banning TikTok for Security Reasons

Inform users: before deleting old accounts, you must inform the affected users of the deletion of their account. You can do this by email or by posting a notification on the website. The notice must specify the reason for the deletion and the date on which it will take place.

Comply with retention periods: the GDPR imposes retention periods for certain personal data. You must ensure that you comply with these periods before deleting accounts. If you retain data beyond the allowed periods, you risk violating the GDPR.

Allow access to personal data: users have the right to access and export their personal data. You must allow them to access their data before deleting their account.

Erase personal data: you must erase all personal data of the users after the deletion of their account. This includes purchase, payment, billing, and profile data.

Take security measures: you must take appropriate security measures to prevent the loss or unauthorized access to users’ personal data during the deletion process.

Provide recourse: if users have concerns or complaints regarding the deletion of their account, you must provide them with a recourse. This may include a claims process or the ability to contact a Data Protection Officer.

Audit RGPD / Conformité RGPD Audit RGPD / Conformité RGPD Audit RGPD / Conformité RGPD
ADVERTISEMENT
RGPD Compliance for WordPress Websites Paperback 

What are the deadlines?

Rules for deleting old accountsTimeframes in months
Inform users of the deletion of their accountN/A (may vary depending on contract terms)
Respect retention periods for personal data1-10 months
Allow access and export of personal data1 month
Erase all personal data after deletion1-3 months
Take appropriate security measuresN/A (ongoing)
Provide a remedy for users1 month

Internal procedure to comply with GDPR

Identify inactive user accounts: The Data Protection Officer (DPO) or the team responsible for managing accounts must identify inactive accounts that need to be deleted in accordance with the terms of the contract and the GDPR.

Inform users of the deletion of their account: The team responsible for managing accounts must inform affected users of the deletion of their account via a notification sent by email or displayed on the website. This notification must explain the reason for the account deletion and the date it will take place.

Comply with retention periods for personal data: The DPO or the team responsible for managing accounts must ensure that all users’ personal data is kept in compliance with the GDPR requirements and the company’s internal policy.

Allow access and export of personal data: Users must be able to access and export their personal data before their account is deleted. The team responsible for managing accounts must provide clear instructions to users on how to access and export their personal data.

Erase all personal data after deletion: The team responsible for managing accounts must delete all users’ personal data after their account has been deleted.

Take appropriate security measures: The team responsible for managing accounts must take all appropriate security measures to prevent the loss or unauthorized access to users’ personal data.

Provide recourse to users: If users have concerns or complaints regarding the deletion of their account, the team responsible for managing accounts must provide them with a recourse by providing information on how to file a complaint and by providing a point of contact for the company’s Data Protection Officer.

Comply with GDPR for customer accounts: GDPR source

Rules for deleting old accountsGDPR Articles
Inform users of the deletion of their accountArticle 13(1)(c) of the GDPR
Comply with retention periods for personal dataArticle 5(1)(e) of the GDPR
Allow access and export of personal dataArticles 15 and 20 of the GDPR
Erase all personal data after deletionArticle 17(1)(a) of the GDPR
Take appropriate security measuresArticle 32 of the GDPR
Provide recourse to usersArticle 77 of the GDPR
Tweet231Share65
Previous Post

European NIS 2 directive: a new challenge for DPOs and cybersecurity.

Next Post

Pepsi Bottling Ventures LLC suffered a data breach.

DPO Partagé

DPO Partagé

Looking for a DPO? Entrust your mission to DPO PARTAGE - Contact us at +33 (0)7 56 94 70 90 or by email at contact@dpo-partage.fr. DPO PARTAGE is the leader in DPO services for health and sensitive data.

Related Posts

TikTok Ban
Personal data

TikTok Ban: US Government Action Insufficient to Halt Chinese Data Collection

2 March 2023
Banning TikTok
Personal data

The European Parliament Joins US and Canada in Banning TikTok for Security Reasons

1 March 2023
Next Post
Pepsi data breach.

Pepsi Bottling Ventures LLC suffered a data breach.

TikTok Ban

TikTok Ban: US Government Action Insufficient to Halt Chinese Data Collection

DPO PARTAGE

Votre partenaire pilote de votre
conformité RGPD
  • - DPO Externalisé
  • - Audit Conformité RGPD
  • - Application Conformité RGPD
  • - Devis missions RGPD

Pour toute question
01 83 64 42 98.

Articles recommandés

Compliance maintenance action plan

Plan of action over 12 months for maintaining your GDPR compliance.

18 February 2023
Pepsi data breach.

Pepsi Bottling Ventures LLC suffered a data breach.

2 March 2023
Theft of my iPhone

My iPhone has been stolen, what should I do?

5 March 2023

Articles populaires

    DPO PARTAGE DPO externalisé

    DPO Partage se positionne comme un acteur clé dans le domaine de la protection des données personnelles, en offrant une gamme complète de services axés sur le Règlement Général sur la Protection des Données (RGPD). Notre structure fournit des informations régulières et pointues sur les dernières évolutions et exigences du RGPD, ce qui en fait une ressource précieuse pour les entreprises soucieuses de se conformer à la législation.

    Faites appel à DPO PARTAGE pour votre conformité RGPD.
    Contactez nous au 01 83 64 42 98
    En savoir plus »

    Recent Posts

    • Xerox Corp is reportedly the victim of a major cyberattack.
    • Navigating the Regulatory Landscape of Health Data Hosting: A Comparison of France and the United States with Advice for American Companies
    • Turning GDPR Compliance into Competitive Advantage: Unveiling the New Guide for American Enterprises
    • Web Analytics and GDPR Compliance: How Website Hosts Can Adhere in France
    • Data Breach at DecathlonThe Critical Importance of Cybersecurity Highlighted by the Recent Data Breach Involving Nearly 8,000 Employees and Customers of DecathlonData Breach at Decathlon
    • Mentions Légales
    • Politique de confidentialité
    • Politique cookies DPO Partagé
    • Nous contacter
    • Politique de cookies (UE)

    © 2024 DPO PARTAGE - Pilote de votre conformité RGPD

    Welcome Back!

    Login to your account below

    Forgotten Password?

    Retrieve your password

    Please enter your username or email address to reset your password.

    Log In
    Gérer le consentement aux cookies
    Pour offrir les meilleures expériences, nous utilisons des technologies telles que les cookies pour stocker et/ou accéder aux informations des appareils. Le fait de consentir à ces technologies nous permettra de traiter des données telles que le comportement de navigation ou les ID uniques sur ce site. Le fait de ne pas consentir ou de retirer son consentement peut avoir un effet négatif sur certaines caractéristiques et fonctions.
    Fonctionnel Always active
    Le stockage ou l’accès technique est strictement nécessaire dans la finalité d’intérêt légitime de permettre l’utilisation d’un service spécifique explicitement demandé par l’abonné ou l’utilisateur, ou dans le seul but d’effectuer la transmission d’une communication sur un réseau de communications électroniques.
    Préférences
    Le stockage ou l’accès technique est nécessaire dans la finalité d’intérêt légitime de stocker des préférences qui ne sont pas demandées par l’abonné ou l’utilisateur.
    Statistiques
    Le stockage ou l’accès technique qui est utilisé exclusivement à des fins statistiques. Le stockage ou l’accès technique qui est utilisé exclusivement dans des finalités statistiques anonymes. En l’absence d’une assignation à comparaître, d’une conformité volontaire de la part de votre fournisseur d’accès à internet ou d’enregistrements supplémentaires provenant d’une tierce partie, les informations stockées ou extraites à cette seule fin ne peuvent généralement pas être utilisées pour vous identifier.
    Marketing
    Le stockage ou l’accès technique est nécessaire pour créer des profils d’utilisateurs afin d’envoyer des publicités, ou pour suivre l’utilisateur sur un site web ou sur plusieurs sites web ayant des finalités marketing similaires.
    • Manage options
    • Manage services
    • Manage {vendor_count} vendors
    • Read more about these purposes
    Voir les préférences
    • {title}
    • {title}
    • {title}
    No Result
    View All Result
    • Accueil
    • Cybersécurité
    • Votre conformité RGPD (Tarifs)
    • Secteurs d’activité
    • Contact

    © 2024 DPO PARTAGE - Pilote de votre conformité RGPD

    Are you sure want to unlock this post?
    Unlock left : 0
    Are you sure want to cancel subscription?