The State Commissioner for Data Protection of Saxony-Anhalt published a guide in September 2026 setting out how small businesses are expected to build a data deletion policy under the GDPR. The 18-page document covers records of processing, inventories of storage locations, a model deletion catalog with concrete retention periods, shredder security levels, backup handling and a step-by-step procedure for erasure requests. It also states plainly that moving files to an operating system's recycle bin "does not meet the requirements for deletion."
In Short
A German state privacy regulator wrote a how-to guide for small companies explaining when and how they have to delete the personal information they hold about customers, staff and website visitors. It matters because many small firms keep data in emails, spreadsheets, chat apps and backups without knowing it, and regulators across Europe have started fining companies that ignore deletion requests. The guide turns a vague legal duty into a checklist: know what you hold, decide how long to keep each kind, delete it properly when the time is up, and keep a record that you did.
What the document is
The guide, titled "Data Erasure Policy for Personal Data Under the GDPR - Guide for Small Businesses," is dated September 2026 and carries the legal notice of the State Commissioner for Data Protection of Saxony-Anhalt, based at Otto-von-Guericke-Str. 34a in Magdeburg. It runs to 18 pages across 13 numbered sections, from an opening section on why a deletion policy is needed to a closing list of templates and support resources.
The version reviewed for this article is an English machine translation of the German original, produced with DeepL, whose watermark appears on the first page. Quotations below are taken from that English text. One element was left untranslated: the model deletion catalog on page 9, which appears as an image and remains in German, using the German abbreviation DS-GVO for the GDPR.
The document closes with a disclaimer that it "does not claim to be exhaustive but is intended as a starting point for implementing the GDPR requirements." It carries no new legal obligations. What it does is translate obligations already in the regulation - mainly the storage limitation principle in Article 5(1)(e) and the right to erasure in Article 17 - into the kind of operational routine a company with a handful of staff could follow.
That framing matters. Saxony-Anhalt's authority supervises data protection in one of Germany's 16 federal states, and the guide is written for the smallest organizations it oversees: its worked examples involve a newsletter, a renovation job and a security camera.
Who counts as a controller
The guide begins with a test that many small firms would not think to apply to themselves. Anyone who processes personal data "belonging to customers, employees, suppliers, or website visitors" - including through video surveillance on company premises - is a controller under Article 4(7) of the GDPR and must comply with the regulation.
Its definition of personal data is broad and concrete. Beyond names, addresses and dates of birth, the guide lists data that identifies a person indirectly, "e.g., via a customer number or a combination of several pieces of information," and adds that the category "also includes email addresses with real names, license plate numbers of natural persons, opinions, and credit reports."
From there it moves to lawfulness. For each category of data, a business must specify the purpose and the legal basis, such as consent, contract performance or legitimate interest under Article 6(1). The guide then gives three scenarios in which the purpose falls away:
- Consent: a customer's email address is stored to send a newsletter, and the customer unsubscribes.
- Performance of a contract: a customer's address is stored to carry out work at their home and send an invoice; the work is done and the invoice paid.
- Overriding legitimate interest: a camera monitors company premises outside business hours because materials have been stolen before, and "No incident occurred last night."
In each case, according to the guide, the business "must decide whether to delete the data or continue storing it." The point is that the end of a purpose triggers a decision, not automatic deletion. Statutory retention duties often intervene. As the guide puts it: "Immediate erasure is usually precluded by statutory or contractual retention obligations or warranty periods."
Building the inventory
Section 5 lays out a sequence of four tasks: identify which personal data is processed and why; document where it is stored; specify who deletes what, how and when; and set out in an internal work instruction who handles deletion requests and how deletion is documented.
The record of processing activities
The first task relies on the record of processing activities required under Article 30 GDPR, abbreviated in the translation as RPA in one place and VVT (from the German Verzeichnis von Verarbeitungstätigkeiten) in another. For each processing activity, the guide lists what has to be recorded: the name and contact details of the controller and any data protection officer, including any joint controllers; the purposes of processing; categories of data subjects and data; categories of recipients; retention periods; transfers to third countries; and technical and organizational measures.
The examples are mundane by design. Human resources activities include "Personnel file management/master data," "Payroll processing" and "Time tracking." Recipients of payroll data include banks, social security agencies, tax offices and corporate pension providers. Processes with similar data categories and the same legal basis, such as all supply contracts, can be grouped together, according to the guide.
This sits against an active policy debate. The European Commission proposed in May 2025 to raise the Article 30 record-keeping exemption threshold from 250 to 750 employees, with records required below that level only for processing likely to result in a high risk. That proposal had not been adopted at the time of the guide's publication, and the guide does not mention it. Its approach assumes that even very small firms will keep a record, if only because deletion cannot be organized without one.
Every place data can hide
The second task is where the guide becomes most specific. It asks businesses to document "as precisely as possible all systems and storage locations that contain personal data," and lists eight categories: central databases, backup systems, email inboxes, Excel or Access files, document repositories on file servers and cloud storage, ticket systems, databases held by processors or partners, and test databases.
A second list, introduced with "Don't forget," adds unstructured files on employees' local computers, messaging services such as WhatsApp and Signal, mobile devices, and cloud storage providers, naming Nextcloud, OneDrive and Dropbox. Paper records - "non-automated" processing - are also in scope.
The guide singles out shadow IT as a key term. Determining whether and where employees process personal data outside central systems, "or perhaps even on personal devices," is described as "a laborious task." The authority's response is organizational rather than technical: provide alternatives and set out, through work instructions, how and where personal data may be stored.
The deletion catalog
Section 8 asks businesses to keep a catalog of deletion rules, in a spreadsheet or data management tool, with eight fields for each data category: the category itself, the purpose and legal basis, the retention period, the deletion period after retention ends, the storage location, the person or department responsible, the form of evidence, and remarks.
The distinction between the two time periods is central. The retention period is how long data "must be retained, at a minimum," such as 10 years for invoices. The deletion period is how soon after that the data is actually removed, which the guide describes as a "short, reasonable processing time."
The model catalog
The page 9 example, left in German in the translation, fills in six rows. Rendered in English by PPC Land, it reads as follows:
| Data category | Purpose and legal basis | Retention period | Deletion period after retention ends | Location | Responsibility | Evidence | Remarks |
|---|---|---|---|---|---|---|---|
| Applicant data | Application process, Art. 6(1) sentence 1 lit. b GDPR | 6 months after end of procedure | 7 days | File server | HR department | Manual logs | Consent for longer storage possible |
| Employee data | Employment contract | 10 years after departure | 1 month | Electronic personnel file | HR department | Log files | Observe tax retention obligations |
| Payroll records | Wage and salary statements, payroll accounts, accounting vouchers; Section 147 AO, Section 257 HGB, Section 41 EStG, Section 28f SGB IV | 10/8/6 years | - | Payroll system | HR department, payroll service provider | - | - |
| Customer data | Contract processing, Art. 6(1) sentence 1 lit. b GDPR | 10 years after end of contract | 1 month | - | Sales | - | Commercial and tax obligations |
| Newsletter subscribers | Sending newsletters, Art. 6(1) sentence 1 lit. a GDPR | Until consent is withdrawn | 7 days | - | Marketing | Log files | Immediate deletion upon withdrawal |
| Video surveillance | Building security, Art. 6(1) sentence 1 lit. a GDPR | 72 hours | Immediately | - | IT/Facility | - | Longer storage only in case of incident |
Several of these entries are relevant beyond the HR department. Newsletter data sits with marketing and is logged. Customer data is held for a decade after a contract ends because of commercial and tax obligations. Camera footage is kept for 72 hours and deleted immediately afterwards unless something happens.
How long is long enough
Retention periods, according to the guide, "are generally based on statutory requirements," naming the German Commercial Code (HGB) and the German Fiscal Code (AO). The authority acknowledges that standard periods have emerged in practice but warns that they "should be reviewed and adapted to the specific case."
Its list of typical periods is short:
- Invoices: 10 years, under Section 257 HGB and Section 147 AO.
- Business correspondence and accounting documents: 6 or 10 years.
- Employee records such as employment contracts: usually 3 to 10 years.
The starting point varies. The clock may begin at the end of a contract, the conclusion of a hiring process, the end of a purpose such as a project, or the moment data is collected. Where several rules apply at once, "the longest period always applies." The guide also allows longer retention for legal defense, provided the decision is documented and justified in the policy.
Once the retention period expires, data must be deleted immediately under Article 17(1), according to the guide, though "A short organizational grace period with a technically or organizationally appropriate justification (e.g., deletion runs, audits, ensuring complete deletion) is permissible."
Deletion, destruction and the recycle bin
Section 9 draws a line that is easy to blur in practice. Deletion, in the guide's words, "removes personal data from IT systems in such a way that it cannot be recovered with reasonable effort," leaving the hardware usable. Destruction physically destroys the storage medium so that no data can be retrieved from what remains. Destruction becomes mandatory when software-based deletion is no longer feasible, for example because a drive is defective.
The evidence trail must record which data categories were deleted, when, by whom, and whether the process was automatic or manual. One instruction is notable: "The personal data itself should not be included in the documentation." A deletion log can be a spreadsheet, a Word document or the log files of an IT system, so long as it can be presented during an audit by the supervisory authority.
Paper and DIN 66399
For paper, the guide refers to the German standard DIN 66399, which distinguishes three protection classes and seven security levels. Businesses are directed to use a shredder meeting at least security level P-3, with P-4 or higher recommended for data requiring special protection, such as health data and personnel files. Where a service provider destroys documents, a data processing agreement under Article 28 GDPR is required, specifying protection class and security level.
Electronic data, automation and the recycle bin
Electronic data is to be deleted using the tools built into the relevant system, ideally on a schedule and with logging enabled. Hard drives and USB sticks must be securely overwritten or processed with dedicated erasure tools before disposal or reuse, and that process is logged too, including the name of the storage medium.
Automated deletion is presented as the default for modern software. "Many modern programs (e.g., DMS, CRM, ERP) offer automatic deletion functions," the guide states, adding that these must be enabled and configured so that data is deleted or archived when retention periods expire. Internally, automated processes must be set up under the dual-control principle and documented in detail. Data held with a cloud provider is deleted either through the provider's own function or by instructing the provider, which must be bound as a processor under Article 28.
Then comes the line that gives this article its title: "Moving documents and files to the Recycle Bin of the operating system or email program does not meet the requirements for deletion. Individual files can often be recovered with little effort, even if the Recycle Bin has been emptied."
Backups and the block list
The guide treats backups as a special case. "It is often technically impossible to selectively delete individual data records from a backup," it notes, so backup strategies need to ensure that backups are regularly overwritten and that deleted data cannot be restored.
Two organizational controls follow. Backups are to be used only to restore data lost accidentally or maliciously, "and not for restoring data that has already been properly deleted," with administrative access limited to as few people as possible. And when a system is restored from a backup, any personal data deleted in the meantime must not be reimported. The guide calls this a "block list" and says the relevant data "must be recorded in advance in an appropriate format."
That last requirement carries a tension the document does not resolve: maintaining a list of what must stay deleted means retaining some identifying information about the people whose data was erased.
Who is responsible, and how often to check
Section 10 assigns ownership. A named person or function - the guide suggests a manager, accounting or IT - is responsible for deletion and oversight. Staff are to be trained "so they do not continue to store data unchecked," and rules are needed for local files, emails and mobile devices. Contracts with cloud providers and processors are to include deletion provisions once the purpose ends, "so that data is deleted even outside your organization."
The policy is to be reviewed at least once a year. Triggers for an update include new IT systems, changed business processes and new or amended legal requirements, with "shorter retention periods" given as an example. The annual review asks four questions: whether deadlines are met, whether technical deletion mechanisms work, whether new types of data need adding, and whether the policy still reflects the state of the art and the law.
Handling erasure requests
Sections 11 and 12 address requests from data subjects. Anyone whose data a business holds can ask for deletion - customers, business partners, employees, website visitors and "people who appear on your video surveillance footage."
The time limits are those in the GDPR. A response is due without delay and no later than one month after receipt. In exceptional cases, such as complex requests or a high volume of simultaneous requests, the period can be extended by up to two further months, but the individual must be told about the delay and the reasons within the first month, citing Articles 17 and 12(3). Responses must be clear, and on request may be given orally, including by phone, under Article 12(1).
The guide then sets out eight steps:
- Recording: requests can arrive in writing, by email, by phone or in person, and each is documented to meet the burden of proof in a dispute.
- Responsibility: a person is designated to handle requests, such as the owner, the data protection officer or accounting.
- Identity verification: the requester's identity is checked, with additional information such as address verification requested where there are reasonable doubts.
- Substantive review: a right to erasure exists, for example, where data is no longer needed, consent has been withdrawn, an objection has been raised without overriding legitimate grounds, or processing was unlawful.
- Rejection: a request may be refused if identity cannot be verified, if data must be kept for legal reasons such as commercial or tax retention, or if it is needed to defend legal claims. In those cases data must be blocked - no longer used for other purposes - and deleted once the impediment ends, with the person informed of the decision and the reasons under Article 12.
- Execution and confirmation: justified requests are carried out without delay, and the person is told the data has been erased.
- Documentation: each erasure process is recorded, including the request, the review, the measures taken and the completion date.
- Notifying recipients: where data has been disclosed to third parties or contractors, such as tax advisors or cloud providers, they must be informed under Article 19.
A closing practical tip addresses what the guide calls data that is "sort of deleted." Such data "resurfaces at inopportune times and can trigger claims for damages by the data subject and/or result in action by the data protection supervisory authority."
Inconsistencies in the document
The guide is a practical text, and some of its internal references do not line up. Three points are worth recording.
First, the model catalog cites Article 6(1) sentence 1 lit. a GDPR - consent - as the legal basis for video surveillance for building security. The guide's own worked example in Section 3 places the same camera scenario under "overriding legitimate interest," which corresponds to lit. f. It is not clear from the document whether the catalog entry reflects a deliberate choice or a copying error from the newsletter row above it.
Second, the newsletter row lists a deletion period of 7 days after consent is withdrawn, while the remarks column in the same row reads "immediate deletion upon withdrawal." The text elsewhere permits a short organizational grace period, which may explain the gap, but the row does not say so.
Third, Section 9 instructs that personal data "should not be included" in deletion documentation, while Section 12 calls for every erasure process to be documented "including the request." A request ordinarily identifies the person who made it. The guide does not explain how the two instructions fit together. A German local court touched on a related question in March 2025, when the Local Court of Lörrach rejected a data subject's demand for proof of deletion, reasoning in part that keeping proof of erasure would mean the data was not deleted without residue.
There are smaller issues as well. Section 5 refers to items 9 and 10 for the work instruction on requests and the documentation of deletion practices, though those topics sit in Sections 9, 11 and 12 of the final document. A link to the retention overview on page 9 is printed with a stray hyphen as "ds-kleinunterneh-men.de," while the same address appears correctly elsewhere as ds-kleinunternehmen.de/arbeitshilfen. The payroll row gives "10/8/6 years" without saying which documents fall under which period, and the eight-year figure does not appear in the guide's text list of typical retention periods.
Why this matters for marketing teams
Most of the guide addresses HR and accounting, but marketing systems run through it. The newsletter list is the first example of a consent-based purpose ending. CRM platforms are named as tools with automatic deletion functions. Email inboxes, spreadsheets, ticket systems and cloud services - the everyday infrastructure of small agencies and e-commerce businesses - all appear in the storage inventory. And Article 19, cited in the final step, extends the deletion chain to any third party that received the data.
Erasure has been a priority for European regulators. The European Data Protection Board's 2025 coordinated enforcement action focused on the right to erasure, with 32 data protection authorities and 764 responding controllers ranging from SMEs to large corporations, and a report published in February 2026. The same EDPB annual report recorded 1,145,760,374 euros in GDPR fines issued by national authorities in 2025.
Individual cases show what mishandled requests cost. France's CNIL fined consultancy EXTIA 300,000 euros in a decision dated July 21, 2026, after 204 of 265 erasure requests received in 2024 were never processed, never answered or answered late. Among them, 166 people were never told what happened to their request, including 125 unshortlisted candidates whose data had been deleted automatically after 60 days. The deletion happened; the answer to the requester did not, and the CNIL counted it as a failure all the same.
Deletion orders also reach marketing data directly. Italy's Garante fined sales intelligence broker Lusha 2 million euros in July 2026, ordering it to erase the personal data of individuals located in Italy and rejecting its legitimate interest claim, with findings that included breaches of data minimisation. In Germany, the Hesse authority fined an IT company 10,000 euros over a single email campaign to more than 2,700 recipients, in part because the controller relied on a processor's assurance of compliance rather than its own assessment.
The question of what counts as erasure is also before the EU's highest court. On October 1, 2026, Advocate General Laila Medina told the Court of Justice in a case involving the Diocese of Ghent that striking through an entry while leaving it legible "does not constitute erasure under the GDPR". The Saxony-Anhalt guide makes the digital equivalent of the same point with the recycle bin.
German regulators are under pressure on volume. Bavaria's private-sector authority, BayLDA, recorded 9,746 complaints and supervisory prompts in 2025, up 61 percent, with video surveillance accounting for 20 percent and advertising and marketing for 12 percent. Practical guidance aimed at small businesses is one way an authority can try to reduce routine complaints before they arrive.
The guide also lands while the rules themselves are being renegotiated. The German government in October 2025 asked the Commission to examine excluding SMEs and low-risk processing from GDPR scope, citing tradespeople's customer lists as an example. In September 2026, an Irish Presidency compromise text on the Digital Omnibus would move breach notification to 96 hours and rework several GDPR provisions, though it remained a Council-level draft. None of those proposals changes Articles 5(1)(e) or 17, the two provisions on which the Saxony-Anhalt guide rests.
For ad tech, the guide's emphasis on processors and recipients connects to standardization efforts. IAB Tech Lab's Data Deletion Request Framework, first released in June 2024, defines a protocol for passing deletion requests between companies using signed JSON Web Tokens and a dsrdelete.json file at each participant's domain root, and was endorsed by the UK Information Commissioner's Office in July 2025. The Saxony-Anhalt guide describes the same obligation - informing recipients under Article 19 - in terms of a phone call to the tax advisor.
What the guide leaves open
The document is deliberately limited. It sets no fines, cites no enforcement cases, and does not address AI systems, tracking pixels, advertising platforms or customer list uploads, all of which raise their own deletion questions. Its retention periods are German statutory periods and apply to businesses subject to German commercial and tax law. Its three linked resources - ds-kleinunternehmen.de/arbeitshilfen and two lsaurl.de short links for a records template and short papers - point to further material not reviewed here.
What it does offer is a clear statement of the authority's expectations. A small business in Saxony-Anhalt facing an audit will be asked, in effect, the questions the guide lists: what data is held, where, for how long, who deletes it, and how that is proven. According to the guide, the answer has to be documented, reviewed yearly, and extend to backups, phones, chat apps and service providers. Whether many small firms can meet that standard without outside help is a question the document itself does not answer, beyond closing with an invitation to contact the State Commissioner and her staff.
Timeline
- June 2024: IAB Tech Lab releases the first version of its Data Deletion Request Framework
- 2024: EXTIA receives 28,322 job applications and 265 erasure requests, 204 of which are mishandled
- March 3, 2025: Local Court of Lörrach rules data subjects cannot demand proof of deletion
- May 21, 2025: European Commission proposes raising the Article 30 record-keeping threshold from 250 to 750 employees
- June 16, 2025: Hesse authority's 10,000-euro fine for an email campaign to over 2,700 recipients is reported
- July 8, 2025: EDPB and EDPS adopt Joint Opinion 01/2025 on the record-keeping proposal
- July 2025: UK ICO endorses the IAB Tech Lab deletion framework
- October 23, 2025: German government document asks the Commission to examine excluding SMEs from GDPR scope
- February 2026: EDPB publishes its report on the 2025 coordinated enforcement action on the right to erasure
- March 2026: BayLDA reports 9,746 complaints and supervisory prompts for 2025
- April 9, 2026: EDPB 2025 annual report records 1,145,760,374 euros in GDPR fines
- July 14, 2026: Garante adopts 2 million euro fine and erasure order against Lusha
- July 21, 2026: CNIL fines EXTIA 300,000 euros for breaches of Articles 12 and 17
- September 3, 2026: Irish Presidency Digital Omnibus compromise text dated
- September 2026: State Commissioner for Data Protection of Saxony-Anhalt publishes "Data Erasure Policy for Personal Data Under the GDPR - Guide for Small Businesses"
- October 1, 2026: Advocate General Medina says a legible strike-through is not erasure under the GDPR
Related PPC Land coverage
- CNIL fines EXTIA 300,000 euros over 204 mishandled erasure requests - France's regulator sanctioned a consultancy that left more than three quarters of erasure requests unprocessed, unanswered or late.
- EU court adviser says Diocese of Ghent may have to erase a man's baptism data - Advocate General Medina's opinion on Article 17, objection rights and why striking through an entry is not erasure.
- Data subjects cannot demand deletion proof, German court rules - The Local Court of Lörrach's 2025 ruling on deletion confirmation and Article 5(2).
- EDPB 2025 annual report: €1.15bn in GDPR fines, new AI and DMA rules - The board's annual figures, including the coordinated enforcement action on the right to erasure.
- GDPR relaxes record-keeping for companies under 750 employees - The Commission's proposal to change Article 30 thresholds and the EDPB-EDPS response.
- Germany pushes for sweeping data protection simplification beyond EU proposal - Berlin's two-stage plan, including a review of SME exemptions from the GDPR.
- Bavaria's data watchdog hit a record 9,746 complaints in 2025 - and AI is partly to blame - BayLDA's annual report, with video surveillance and marketing among the largest complaint categories.
- Italy fines Lusha 2 million euros, orders erasure of Italian contact data - The Garante's processing ban and erasure order against a sales intelligence data broker.
- Hesse data protection authority fines IT company €10,000 for email marketing - A German state authority's fine over an email campaign built on publicly sourced contact details.
- IAB Australia publishes data deletion framework explainer for adtech - How IAB Tech Lab's protocol passes deletion requests between ad tech companies.
- EU Council draft drops unconditional opt-out from GDPR AI clause - The September 2026 Digital Omnibus compromise text and its proposed GDPR changes.
Summary
Who: The State Commissioner for Data Protection of Saxony-Anhalt, the German state authority based in Magdeburg, writing for small businesses that process personal data of customers, employees, suppliers and website visitors.
What: An 18-page guide on building a GDPR data deletion policy, covering records of processing, inventories of storage locations including shadow IT, a model deletion catalog with retention periods, DIN 66399 shredding levels, automated deletion, backup handling with a block list, and an eight-step procedure for erasure requests. It states that moving files to a recycle bin does not meet the requirements for deletion. The document contains several internal inconsistencies, including a legal basis for video surveillance that differs between the text and the model catalog.
When: The guide is dated September 2026. The English version reviewed is a DeepL machine translation of the German original.
Where: Saxony-Anhalt, Germany, with relevance to any business subject to the GDPR and German commercial and tax retention rules.
Why: Storage limitation and the right to erasure under Articles 5(1)(e) and 17 GDPR apply to businesses of every size, and European regulators have made erasure an enforcement focus, from the EDPB's 2025 coordinated action involving 764 controllers to the CNIL's 300,000-euro fine against EXTIA. The guide translates those obligations into routines a small firm can document and defend during an audit.
Discussion