CJEU Rules Annotation Is Not Erasure: GDPR Applies to Baptismal Registers
This case highlights that GDPR's right to erasure (Article 17) applies broadly to any structured filing system, including physical records like baptismal registers maintained by religious organizations. Simply crossing out, annotating, or striking through personal data does not meet the legal standard of erasure, as the underlying data remains readable and recoverable. Organizations — including religious bodies — must implement technically and procedurally adequate erasure methods that render data genuinely inaccessible. This ruling matters because it signals that non-digital record holders cannot rely on superficial redaction as GDPR compliance, exposing them to regulatory risk. All data controllers must audit both digital and physical records management practices against GDPR obligations.
Tactical Insight
Immediate actions
- Audit all physical and digital filing systems to identify records containing personal data subject to GDPR erasure requests.
- Replace superficial redaction methods (strikethroughs, annotations) with approved erasure techniques such as opaque, tamper-evident covers or certified destruction for physical records.
Policy & Process improvements
- Establish a formal Data Subject Rights procedure that defines technically sufficient erasure standards for both digital and physical record formats.
- Train staff responsible for records management on the legal definition of erasure and the specific approved methods for each record type.
- Document all erasure actions with timestamps and method descriptions to demonstrate compliance in the event of a regulatory audit.
Long-term governance
- Conduct periodic Data Protection Impact Assessments (DPIAs) to identify non-obvious filing systems (physical archives, legacy ledgers) that may fall under GDPR scope.
- Engage a Data Protection Officer (DPO) to review third-party and institutional record-keeping practices and align them with evolving CJEU interpretations of GDPR obligations.