Earlier quoted context omitted.
Yes it surely creates some work for companies, but on the other hand what good would it be if you could just keep personal data around just because it happens to be on a backup tape? Companies simply have to implement suitable backup schedules, which will ensure that the data gets deleted within an acceptable time period (e.g. two weeks), which is doable without actively erasing any specific data (instead of simply e…
You and I have very different definitions of the word "simply". Arranging proper backups at all is not something to take for granted when you're dealing with small businesses that have many other things to do, but obviously they're important for safeguarding the provision of products and services to all customers and it's important that any backups that are made are handled with proper regard to both security and int…
In General, I think requiring that companies do not hold on to your personal data indefinitely is a pretty reasonable regulation. If there were exceptions e.g. for backup data it would provide a convenient loophole for companies to keep the data.
Also, if companies keep copies of their personal data lying around it increases the risk of the data being stolen or leaked into the public. We have seen that even for the largest companies it's impossible to avoid "losing" data once in a while, so making sure that this data contains the least amount of sensitive information possible is very reasonable. The regulation does not even assume that companies are malicious, it just assumes that sh*t happens and tries to mitigate potential damage to individuals.