

What would be your preferred approach ? I’m on the implementation side of this in a reasonably large company and so far I found the act to be reasonable. It must rely on some interpretation as every piece of such regulation. Same as GDPR for example and yet it’s a very important progress for EU citizens guarantee wise.
Companies are still allowed to store data and not delete it depending on the purpose… Being able to demonstrate that they complied with your request by keeping the associated email would be a fair exemple.