Earlier quoted context omitted.
> The very first point in that letter requires identifying every communication you have ever had with or about the data subject that is still stored anywhere in your organisation, among other actions. The magic words here are "still stored", PII is a liability so you never want to store it longer than absolutely necessary. Why are you hoarding this data when you can't even retrieve it easily, what is the point ?
Why are you hoarding this data when you can't even retrieve it easily, what is the point ? Do you have a filing system for every email you ever wrote? Can you identify every backup copy, every forwarded message, every print-out, every excerpt copied and pasted into a Word document? Can you remember or look up every individual ever referenced in those messages? Now, let's talk about letters. The paper kind. And faxes.…
If the regulator finds out that one of your staff scribbled down a customer's phone number once on a piece of paper while serving that customer, they won't care. If they find that your customer service process requires your customer service staff to scribble down phone numbers on scraps of paper that are then put out with the garbage, where they can be dumpster-dived, they will care (and so should you).
This is not some huge regulatory over-reach that will force you to go through every piece of paper in your organisation. It's a check on your data handling that forces you to acknowledge the trust placed in you by your customers.