Auditen
sector watch

The Security Budget was Spent. The Deletion Button Broke.

Most small businesses dump their tiny compliance budgets into the front door, and they buy the firewall and pay for encrypted email, then hope a locked server room keeps people out. It makes sense. A breach is a disaster, but a paperwork mistake just looks like a typo.

But this week’s fines show that regulators aren't just looking at who let the hackers in. They're looking at who refuses to let the customers out.

Pressure is mounting on how we handle health and personal data; france's CNIL just slapped Hôpital Privé de la Loire with a 500,000 euro fine after a breach leaked more than 720,000 patient records. That's the classic front door failure (the kind that keeps us up at night). Then you have the smaller slips, and extia paid 300,000 euros because they didn't manage erasure requests right. In Italy, BBVA's arm took a bigger hit of 5.5 million euros for ignoring marketing opt-outs, and why is this so hard to get right?

The pattern is clear. The regulator doesn't care if your encryption is military-grade if you can't actually find and delete a single person's email address when they ask.

We've been trained to believe compliance is just buying some software and spitting out a PDF report once a year. I don't trust any consultant who tells you to simply implement an automated privacy platform, and most of these tools are just expensive wrappers around basic databases (which usually can't talk to your legacy files or backup tapes).

The cheapest control that actually works is a manual, ugly spreadsheet and a calendar invite.

Skip the platform if you don't have a compliance team. You can't afford one anyway, and just give someone on your staff an hour every Friday to look for erasure requests. They can manually check that those records are gone from the three places they actually live: the shared drive, the email list and the main CRM.

People usually argue that total deletion is technically impossible. They talk about backups. They claim you can't scrub a single record from a compressed tape backup without risking the entire archive.

That isn't an excuse; it's a liability.

You can't just leave data sitting in your backups if you can't delete it, and you need a written process for managing those scraps and a policy that says exactly when old backups are destroyed. Regulators aren't stupid about how backup systems work. But they won't stand for a company calling itself GDPR compliant while maintaining a permanent archive that turns the Right to Erasure into a joke.

This leads us to the second-order effect: the Vendor Liability Gap.

Most small businesses dump their data storage on SaaS providers, and you pay your monthly bill and they check a box claiming they follow every regulation out there. That is the trap. When a customer tells you to delete their info but your vendor's interface makes it too complex or impossible, the regulator won't go after the software giant. They come for you. You're the data controller here. The vendor is just the processor.

Why are you paying for services that make you legally radioactive? It's because these companies value data persistence over deletion. If your vendor's delete button just marks a record as inactive instead of purging it, you're the one stuck with the €300,000 fine. Not them.

It’s an uncomfortable reality. We spend thousands on insurance to protect against the "big hack," but we ignore the slow leak of administrative negligence.

I bet the next round of fines won't care how big your breach was, and they'll care how fast you reacted. Regulators stopped asking if you tried to fix things and started asking if it actually got done. If a customer asks to be deleted then pops up in a marketing email two weeks later, fancy software isn't going to stop the fine.

The biggest threat isn't some foreign hacker. It's the former client who's pissed off, knows their rights, and has plenty of time to file a report with the ICO or CNIL.

Go check your delete requests and unsubscribe workflows this week. Try it yourself. Create a test account, trigger a request, and see if that data is really gone from every system or if it's just sitting in a folder called 'Inactive'.

Sources

The reporting this piece was written from. Check the originals before relying on anything here.

  1. Health data breach: the CNIL fined Hôpital Privé de la Loire 500 000 EUR European Data Protection Board
  2. LG Smart TVs Record Audio While Off and Scan Home Networks, Report Finds - Morocco World News Data Privacy (Google News)
  3. Facebook trial over Cambridge Analytica privacy scandal begins in New Mexico - News4JAX Data Privacy (Google News)
  4. BBVA’s Italian arm faces €5.5m GDPR fine over failed marketing opt-out - MLex Data Privacy (Google News)
  5. Federal court ruling conflicts with part of Wisconsin law banning AI child pornography - WPR Data Privacy (Google News)
  6. FTC Withdraws Obsolete Policy Statement FTC Press Releases
  7. Building privacy-safe MCP servers: What GDPR actually requires - IAPP Compliance Week (Google News)
  8. Extia faces €300,000 French GDPR fine over erasure-request failures - MLex Data Privacy (Google News)

How stories are selected and assessed