Question
GDPR and the right to be forgotten
Has anyone received any requests to comply with the right to be forgotten?
We are currently working through best methods of executing this and I'm wondering if anyone has come up with best practices or a guide to ensure personal data can be expunged. Our strategy includes overwriting all contact information in SFDC upon request so the only remaining identifier is the ID. It would be great to have a method for executing this in MDA as well without needing to know every place a name or email address has been stored.
I'm also curious how best to address this with limited access email opt-out records.
We are currently working through best methods of executing this and I'm wondering if anyone has come up with best practices or a guide to ensure personal data can be expunged. Our strategy includes overwriting all contact information in SFDC upon request so the only remaining identifier is the ID. It would be great to have a method for executing this in MDA as well without needing to know every place a name or email address has been stored.
I'm also curious how best to address this with limited access email opt-out records.