Two legal deadlines, one system.

How an energy supplier combines retention obligations and GDPR-compliant data minimisation through Clarifall within an end-to-end case management system.

Industry

Utilities

Theme

Data Protection / Legal & Compliance

Focus

Retention & Deletion

Solution

Clarifall-Complaint

When both retention and deletion are required. But how do we achive that?

Scattered case data and varying retention requirements meant that no clear overall picture emerged. It was unclear which data was still required for record-keeping purposes and which should already have been deleted. As a result, requests for information and retention checks were handled on the basis of manual searches rather than a reliable, systematic process.

Keep and delete – at the same time.

Energy suppliers are required to retain certain transaction data as evidence. At the same time, under the GDPR, personal data must not be stored for longer than is necessary.

Furthermore, case data was scattered across the ticketing system, email threads and shared drives. As a result, it was difficult to systematically track deadlines and stored personal data.

  • Scattered Data

  • Manual search

  • Uncertain deadlines

A request from a data subject highlights the gap.

In response to a request for information, data from various systems had to be manually collated, reconciled and checked. At the same time, it was unclear which case data had already exceeded their permitted retention period.

Clarifall combines both requirements.

As soon as a case is opened, a suitable retention policy is assigned to it. Regulatory record retention requirements and the GDPR’s storage limits are managed in parallel – without the need for manual checks – and, even after deletion, a clear and traceable audit trail is maintained through metadata.

Two obligations. One policy engine.

A manual search becomes a structured query.

Case data from various systems, mailboxes and drives must be searched for individually and consolidated.

Furthermore, this may result in breaches of the GDPR, as personal data may be unlawfully deleted, or the entire log – including the audit trail – may be discarded.

All personal data relating to complaints is held in a central case file and can be retrieved and processed in a structured manner.

Even if personal data is deleted, the audit trail remains stable and traceable thanks to metadata.

Complex requirements are transformed into a manageable process.

Automated deadlines:

Retention policies are applied consistently.

Centralised data management:

Relevant case data is stored in a system.

Traceability:

An immutable audit trail records what happened, when it happened and in accordance with which policy.

Less manual effort:

The Legal and Data Protection teams can focus more on technical assessments.

ClariFall brings together case management, retention periods, data minimisation and record-keeping in a single centralised system.