Unify and manage your data

GDPR compliance in the Reltio Platform

Learn about how the Reltio Platform supports compliance with EU General Data Protection Regulation (GDPR) requirements.

About GDPR

The European Union (EU) General Data Protection Regulations (GDPR) is a law designed to enhance data protection for EU residents and provide a consolidated framework to guide business usage of personal data across the EU. According to the written regulation published by gdpr.eu , it:
  • protects the personal data of individuals residing in the EU, as well as non-EU residents visiting the EU.
  • applies to monitoring individual behavior, processing personal data through automation, and processing data by any method with the intention of filing that data.
  • applies to any entity that processes or controls data in the EU, offers goods or services to people who are in the EU, or monitors behaviors of people physically in or related to the EU.
  • extends due diligence obligations and potential liability to data controllers and data processor.
The broad scope and definitions of the GDPR means it applies to almost every website or app that tracks data, and any business - whether located in the EU or not - that does work in or for the EU.
Note: The breadth and scope of the GDPR typically outweighs the regulations of local laws, such as the California Consumer Privacy Act (CCPA) in the US. Local laws may or may not have different regulations that apply to you.

GDPR compliance requirements

According to the GDPR Compliance requirements, the following data is affected:
  • All profile entity or entities
  • All historical data
  • All losing entity or entities (for more information, see Merging Two Entities)
  • All records from the Activity Log except records about creating and deleting
Your consumer data in Reltio must be compliant within 30 days of the request, unless:
  • The customer has a pending transaction.
  • The customer has completed a transaction with the past 30 days.
Important: We recommend that you keep a record of the person or organization requesting each GDPR delete, preferably in a rights management system, as the Reltio platform doesn't store the identity of the requester.

How the Reltio Platform supports GDPR compliance

The Reltio Platform supports compliance with the EU GDPR by providing mechanisms to remove personal data when a data subject exercises their Right to be forgotten.

When consumer data is deleted for GDPR purposes, the platform removes personal attribute values and related historical information associated with the entity. This ensures that personal data is no longer accessible or processed within the platform.

The platform also sanitizes audit and activity information to ensure that sensitive data is no longer visible, while retaining minimal system events related to entity creation and deletion for compliance and traceability.

GDPR deletion requests are typically initiated outside of the Reltio Platform through a rights management or compliance system. The Reltio Platform does not store the identity of the individual or organization requesting the deletion.

For more information about how GDPR deletion is implemented in Reltio, see Delete Entities by GDPR.