When an establishment ceases or relevant processing ends, the Controller must securely delete, anonymise or transfer personal data as required, while preserving evidence of compliance and lawful retention.
Interpretation and application must be checked against the official text and current version.
