15.13 Practical illustrations of the Rule as a whole
15.14 Illustration 1: Former e-commerce customer
A former customer no longer has access to her old mobile number. She asks what information the marketplace still processes and requests erasure.
The marketplace should provide an alternative means of authentication using proportionate information. It should search relevant systems, identify Processor-held data and separate:
-
records that can be erased;
-
records required for legal retention;
-
account-access information;
-
transaction evidence;
-
and security logs.
If she disputes the result, she should be able to use the published grievance process, and the organisation must respond within its published period, which cannot exceed ninety days.
15.15 Illustration 2: Employee correction request
An employee discovers that the HR system contains an incorrect date of joining, affecting benefits calculations.
The employer should correct the source record, consider downstream payroll and benefits systems, and instruct any Processor to update relevant copies. If the employer delays or refuses, the employee may use the grievance mechanism.
The response should not merely modify the visible employee portal while leaving the inaccurate date active in payroll.
15.16 Illustration 3: Consent Manager dispute
A customer withdraws consent through a Consent Manager, but the relevant Data Fiduciary continues processing.
The Consent Manager should be able to show whether and when the withdrawal instruction was transmitted. The Data Fiduciary should investigate whether it received and implemented the instruction.
Each must provide a grievance mechanism for its own act or omission. The customer should not be indefinitely redirected between them.
15.17 Illustration 4: Nomination after death
A Data Principal has nominated her sibling to exercise DPDPA rights after death. The sibling requests erasure of an inactive digital account.
The Data Fiduciary should verify the nominee, nomination and death. It should then assess the erasure request while accounting for:
-
statutory retention;
-
jointly held information;
-
personal data of living users;
-
contractual digital-asset rules;
-
and the limited nature of the nominee’s DPDPA authority.
15.18 Illustration 5: Impersonated access request
An attacker knows a customer’s email address and submits an access request seeking account data.
The email address identifies the customer but does not authenticate the attacker. The Data Fiduciary should use proportionate verification before disclosure. The rights framework must protect the Data Principal as well as enable her rights.