PrivacySignal
News

Notes from the IAPP Canada: When deleting data too soon becomes the privacy risk

IAPP · · International · Privacy Law

A session at the IAPP Canada conference examined a counterintuitive privacy problem: deleting personal data prematurely can itself create privacy risks, rather than reduce them.

Why this matters: Most privacy advice points one direction — collect less, delete faster. This flips that. There are real situations where deleting data too early can hurt the very people it was meant to protect. Think of someone needing records to dispute a decision, prove discrimination, or establish a legal claim. If the data is gone, so is their evidence. Retention is not just a compliance dial. Sometimes it is the only protection a person has.

Who should care: General readers · Privacy officers · Policy

This summary is AI-assisted and may contain errors. It is an original briefing to help you gauge significance quickly — not a reproduction of the source. Always read the linked original before relying on it. See our methodology.

Analysis

All analysis →

Weekly Editorial Analysis from Experts and Editors

The Attacker Did Not Need to Sleep

Spain received its first reported personal-data breach carried out by an AI agent. The techniques were familiar. The speed and autonomy were not.

· 4 min read Read →

Related stories

News
Inside Privacy (Covington) · · International

California Governor Signs SB 690, Eliminating Private Website-Based CIPA Pen Register Claims and Calling for Broader CIPA Reform

On September 30, Governor Gavin Newsom signed SB 690, a significant new law aimed at curbing the wave of lawsuits and demand letters asserting “pen register” claims under the California Invasion of Privacy Act (“CIPA”). The legislation eliminates the private right of action for pen register and trap-and-trace claims arising from conduct occurring on internet... Continue Reading…

Who should care: General readers · Privacy officers · Policy