GDPR Right of Access Violated When Processor Deleted Data During Active Request
The Austrian Data Protection Authority found that the Public Employment Service Austria failed to uphold a data subject's right of access under Article 15 GDPR when personal data was deleted by a processor while an information request was still pending. The core failure was the absence of a legal hold or data preservation mechanism to freeze relevant records during active data subject rights proceedings. This case underscores that controllers cannot delegate away their GDPR accountability — even if a processor performs the deletion, the controller bears full responsibility for the outcome. Organisations must ensure that contractual and operational controls with processors explicitly address data subject rights workflows, including suspension of routine deletion schedules when a request is in flight.
Tactical Insight
Immediate actions
- Implement a formal legal hold procedure that automatically suspends data deletion schedules when a Data Subject Access Request (DSAR) is received.
- Notify all relevant processors in writing whenever a DSAR is active, explicitly instructing them to preserve related personal data until the request is resolved.
Process & contractual improvements
- Update Data Processing Agreements (DPAs) to require processors to check for active DSARs before executing any deletion or purging routines.
- Establish a centralised DSAR tracking register that flags records under active requests to prevent accidental or scheduled deletion.
- Assign a designated Data Protection Officer or privacy lead with authority to issue and lift legal holds across processor environments.
Long-term governance improvements
- Conduct periodic joint reviews with processors to audit DSAR compliance workflows and verify that hold mechanisms function as intended.
- Train both internal staff and processor contacts on GDPR data subject rights obligations, with specific scenarios covering deletion-during-request conflicts.
- Integrate DSAR status checks into data lifecycle management tooling so preservation rules are enforced automatically rather than manually.