Picture the most common case in the courts: the debt was certain, the contract informed the customer correctly and the entry in the credit default register was lawful. Months later, the debtor — or a firm that runs serial claims — sends a request for erasure of data. Nobody in your company answers it in time, or nobody answers it at all. That silence is, on its own, ammunition for a claim. And awards for defective handling of data in credit default registers run, indicatively, from 3,000 to 10,000 euros plus costs.
The practical conclusion is uncomfortable but clear: when it comes to erasure of data, the risk lies not only in how you register the debt, but in how you respond afterwards. This article explains what the courts require and also why many claims against companies fail because the claimant cannot prove their own case.
What Article 17 GDPR requires of you: a simple, free-of-charge procedure
The right to erasure is not dealt with "when we can" or "as best we can". The controller — your company, if it reports debtor data — must have a channel in place so that any data subject can exercise the right without obstacles and at no cost. It is not acceptable to require impossible forms, to send the applicant from one department to another, or to charge for handling the request.
The controller is obliged to provide the data subject with a simple, free-of-charge procedure for dealing with the exercise of these rights. [translation]
Translated into a business decision: if a customer sent an erasure request to your general contact inbox today, would your team know what to do with it, within what deadline and with what record? If the answer is "it depends who reads it", you have an open risk.
You must decide expressly. Even if you hold no data on the applicant
This is the point that most surprises directors. Even if your company holds no data at all on the person making the request — because the debt was assigned, because the file was closed or because the applicant wrote to the wrong recipient — the request cannot go unanswered. Silence is never a safe option.
The controller must decide the request expressly, even where it holds no personal data of the data subjects exercising their rights, and must do so irrespective of the procedure used by the data subject to exercise that right. [translation]
Note the final words: "irrespective of the procedure used by the data subject". The fact that the request arrives by burofax (certified fax with content certification), by email or in an unusual written form does not excuse you from replying. What your company may require are the formal requirements for identifying the applicant; what it may not do is simply file the request away.
The deadline: one month. The extension is not a get-out
Erasure must be dealt with without undue delay and, in any event, within one month. There is an extension of a further two months, but subject to two cumulative conditions worth writing into the internal procedure: it is available only because of the complexity of the request, and it must be notified to the data subject within the first month. An extension invoked late, or invoked for mere operational convenience, protects nothing.
In the case of the right to erasure of data, it must be dealt with without undue delay and, in any event, within one month. However, the controller may resort to a further two-month extension where this is essential by reason of the complexity of the request… the controller must notify that extension to the data subject within the initial one-month period. [translation]
Time counts too: what was lawful can cease to be
There is a second front that companies tend to overlook. Data entered correctly is not protected for ever: if it ceases to be necessary for the purpose that justified the processing, keeping it becomes a breach. The snapshot taken at the moment of registration does not save you if the film that follows is one of neglect.
…even processing that was initially lawful, of accurate data, may in the course of time become incompatible with that Directive [now the GDPR] where those data are no longer necessary in the light of the purposes for which they were collected or processed. [translation]
In practice: debts that have been paid but remain registered, closed files whose data nobody purges, balances already in dispute that remain published. Each of those situations is a potential claim, even if the origin of the processing was beyond reproach. This principle connects directly with the duty to keep data accurate and up to date, which we analyse in the five mistakes that lead a company to be found liable for registering a defaulter.
The defensive side: the burden of proving dispatch and receipt lies with the claimant
So far, the obligations. Now, the good news for the company being sued. In serial claims it is common for the claim to state that "erasure was requested and the company did not reply". Well: whoever alleges that they exercised the right must prove two things, not one. That they sent the request and that the controller received it.
…the burden of establishing the dispatch and receipt of the access request supposedly made falls on the claimant… circumstances that are essential in order to hold that the right was exercised. [translation]
Many serial claims fail on exactly this point: an email with no acknowledgement, a screenshot with no verifiable recipient, a burofax that was never delivered. If your company logs incoming correspondence rigorously, you will be able to show what you received and what you did not, and dismantle the premise of the claim. The defence starts in the incoming post log, not in the courtroom.
What to do this week
- Appoint an internal owner for GDPR rights, with a deputy. Requests cannot depend on who opens the inbox.
- Document the procedure: receipt, identity verification, express decision, one-month deadline, criteria for an extension.
- Review periodically the data reported to registers: what has been paid, what is in dispute and what is time-barred must come out without anyone asking.
- Keep evidence of every reply sent: in this area, what cannot be proved does not exist.
If you want to know where your company stands before a judge decides it, you can measure it right now with the Exposure Test: five minutes, no confidential data, using the same criteria the Provincial Courts of Appeal (Audiencias Provinciales) apply.
Would your erasure procedure withstand a claim?
Check in five minutes whether your company handles Article 17 GDPR requests according to the criteria the courts require, and where your real financial exposure lies.
Take the Exposure Test