[Domaines API]

Erasure Domain

The Erasure domain implements the GDPR Article 17 right-to-be-forgotten workflow.

Metadonnees du module

The Erasure domain implements the GDPR Article 17 right-to-be-forgotten workflow.

Retour à la Liste

Reference source

content/modules/domain-erasure.md

Dernière Mise à Jour

24 févr. 2026

Catégorie

Domaines API

Checksum du contenu

4a1985a5adb0fa21

Étiquettes

api-domains

Documentation rendue

Cette page rend le Markdown et Mermaid du module directement depuis la source publique de documentation.

Overview#

The Erasure domain implements the GDPR Article 17 right-to-be-forgotten workflow. It manages the full erasure lifecycle: request submission with identity verification, legal hold checking, PII anonymisation across user records and audit events, and tamper-evident receipt generation. The system preserves audit trail integrity per GDPR Article 17(3)(e) by anonymising actor fields rather than deleting audit rows.

Key Features#

  • GDPR Article 17 erasure request submission with identity verification
  • Legal hold checking before erasure execution
  • PII anonymisation across user records and audit events
  • Tamper-evident erasure receipt generation
  • Deterministic anonymisation placeholders for data consistency
  • Blind index-based email lookup for subject identification
  • Audit trail preservation through field anonymisation rather than row deletion
  • Erasure lifecycle management (request, verification, execution, receipt)

Use Cases#

  1. Processing GDPR right-to-be-forgotten requests with legal hold verification
  2. Anonymising PII across user records while preserving audit trail integrity
  3. Generating tamper-evident receipts for completed erasure operations
  4. Managing the complete erasure lifecycle from request through verification

Integration#

Integrates with user management, audit trail, and legal hold systems for GDPR-compliant data erasure workflows.

Last Reviewed: 2026-02-24