SAPanoptikum February 2017


Right to be forgotten
If there is no legitimate reason for storage and a person insists that their data be deleted, the company must comply with the request within a specified period of time in accordance with the GDPR.
Furthermore, a lack of insight into dark data and information stored outside of company systems makes compliance more difficult. This exposes companies to considerable financial and legal risks.
A fine of a maximum of 20 million euros or up to four percent of global turnover - whichever is greater - may be imposed.