This clause requires one party to formally prove that they've deleted personal data by providing written certification (usually a signed letter or report). For example, after a contract ends, a service provider must send you a signed statement confirming they've permanently destroyed all customer records. This is high-risk because deletion is often difficult to verify—the other party might claim deletion but secretly keep copies, exposing you to data breach liability. Under GDPR and similar laws, if personal data is breached, the party responsible for holding it can face substantial fines (up to 4% of global revenue under GDPR). Certification creates a paper trail proving you took reasonable steps to protect data, which is your legal defense if something goes wrong.
Always require deletion certification in writing, signed by an authorized person—never accept verbal assurances. Specify exactly what "deletion" means (permanent destruction, not just hiding files) and ask for details like the date, method, and systems affected. If the data is highly sensitive, consider requiring third-party verification or allowing yourself to audit their deletion process before signing off.
Frequently Asked Questions
What does this clause mean in simple terms?
This clause requires one party to formally prove that they've deleted personal data by providing written certification (usually a signed letter or report).
Why should I care about this clause?
For example, after a contract ends, a service provider must send you a signed statement confirming they've permanently destroyed all customer records.
What are my options?
This is high-risk because deletion is often difficult to verify—the other party might claim deletion but secretly keep copies, exposing you to data breach liability.
How does this affect small businesses?
Under GDPR and similar laws, if personal data is breached, the party responsible for holding it can face substantial fines (up to 4% of global revenue under GDPR).
