The risk comes from fragmentation. Personal data can exist in CRM systems, spreadsheets, documents, databases, archived files, and employee devices, so a request may require searching many systems under time pressure. If teams cannot locate every copy quickly, they may miss instances, breach the deadline, or fail to demonstrate compliance with GDPR expectations.
Why fragmentation turns erasure into an operational problem
The operational burden comes from the fact that erasure is a discovery and coordination task, not just a deletion task. If personal data is spread across live systems, exports, archives, shared documents and endpoints, the organisation has to find every copy, confirm it is in scope, and then remove or suppress it consistently.
That creates time pressure and dependency risk. The more places data can land, the more likely teams are to miss an instance, overwrite the wrong record, or depend on manual tracking that cannot keep up with real request volumes.
Fragmentation also weakens certainty. A team may delete the primary record in one system but leave replicas in a cache, backup set, document store, or offline export. The operational challenge is therefore not only execution, but proving that the response was complete enough to satisfy the request.
Why location, ownership, and retention rules make the process brittle
Erasure requests often cross team boundaries, and that makes ownership a practical bottleneck. If no single team knows where data lives, the request becomes a chain of handoffs between business units, IT, legal, and records owners, each with different visibility and retention rules.
Retention exceptions can also create conflict. Some copies may need to be removed, while others must be preserved for tax, legal hold, audit, or security purposes. Organisations have to distinguish between deleting personal data and lawfully retaining records with restricted access, which is easy to get wrong when storage is scattered.
Systems that were not designed with inventory and traceability in mind make this worse. If a request cannot be mapped back to a complete data footprint, the organisation cannot confidently show that it searched all relevant locations or applied the right exceptions.
What good operational handling looks like
Good practice is to treat erasure as a controlled workflow with discovery, verification, and evidence capture. That means maintaining a current data map, knowing which systems can create copies, and making sure deletion actions are logged in a way that can be reviewed later.
Where data is replicated into analytics, exports, or documents, teams should be able to say which copies are authoritative, which are transient, and which are subject to separate retention rules. That clarity reduces rework and helps prevent the same request from being handled differently in each system.
Automation helps only when the underlying inventory is reliable. If the organisation does not know where data spreads, automating deletion can create false confidence rather than compliance. A fast process that misses hidden copies is operationally efficient but still unsuccessful.
Risk and Threat Considerations
Fragmented storage increases the chance of non-completion, late completion, or inconsistent completion of an erasure request. The risk is not just a missed task, but an inability to demonstrate that the organisation located and handled all relevant personal data within the required timeframe.
Failure mechanism: Data sprawl, weak asset inventory, and unmanaged copies in exports, backups, documents, or endpoints prevent teams from finding every instance before the deadline, or from applying retention exceptions consistently.
Impact: The organisation can breach GDPR expectations, create audit findings, and retain personal data longer than intended, which increases both compliance exposure and the operational cost of remediation.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
GDPR provides the primary governance reference for this topic.
| Framework | Control / Reference | Relevance |
|---|---|---|
| GDPR | Article 5 — Principles relating to processing of personal data | Erasure risk arises from proving complete, accurate handling of personal data across storage locations. |
| Article 25 — Data protection by design and by default | Fragmentation is reduced when systems are designed to locate, govern, and suppress personal data consistently. | |
| Article 32 — Security of processing | Operational erasure depends on controls that protect, track, and reliably execute data-handling actions. | |
| Recommendation — Map deletion workflows to data-minimisation and storage-limitation obligations, then verify coverage across all repositories. Design systems so personal data inventories, deletion paths, and default retention controls are built in from the start. Implement access, logging, and process controls that make deletion actions traceable and repeatable. | ||
Practitioner Guidance
What to prioritise: Build a deletion workflow around discovery quality first, not around the deletion action itself. If you cannot answer where personal data can be copied, exported, or cached, you cannot trust the erasure process.
What to verify: Confirm that each request can produce evidence of search scope, system coverage, exception handling, and completion status. The key question is whether a reviewer could reconstruct why specific copies were removed or retained.
Practitioner takeaway: The real control objective is not “delete data somewhere”, it is “prove all relevant copies were found and handled consistently before the deadline.”
Related resources from NHI Mgmt Group
- Why does personal data create legal and operational risk when organisations do not know where it is?
- Why does GDPR create higher operational risk for organisations that process EU personal data?
- Why do data privacy laws create operational risk when organisations collect or share personal data without clear consent and purpose limits?
- Why do documents with embedded personal data create so much operational risk in cloud and GenAI environments?
Deepen Your Knowledge
Reviewed and updated by the NHIMG editorial team on September 26, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org