18 February 2026
Honouring deletion without breaking fraud controls
Finance apps must delete personal data on request while retaining what AML and dispute rules require. Audits should test both.
Deletion tickets often stall at the edge of fraud, credit, and settlement systems. Teams either over-retain “just in case” or wipe identifiers that later make chargebacks impossible to defend.
A rights audit walks the exception list: what must remain, under which legal basis, for how long, and who can still see it. We then sample completed deletions to confirm shadow copies in support tools and data warehouses are gone.
Documented retention schedules that name the fraud and AML owners close more findings than generic “we delete within 30 days” statements.