Checklist for Confirmation of Personal Information Deletion and Return After EAP Operation Termination
After the termination of EAP operations
Personal Information Deletion/Return Confirmation Checklist
Confirm the data termination procedure.
๐ Key points to check first
The core of an EAP Operation Termination Confirmation does not lie merely in declaring deletion. It lies in establishing a list of the information processed by the provider during the contract period, distinguishing between materials the company must reclaim and those the provider must delete, and documenting the deletion timelines and verification methods. Sensitive information, such as counseling content or individual usage records, must be verified separately from operational statistics.
| division | Data to verify | Processing upon termination |
|---|---|---|
| Contract and Operation Data | Contract, Scope of Operation, Contact Person, Consultation Channel | Company Archives and Latest Version Marking |
| Usage and settlement data | Invoice, Usage Count, Session/Remaining Amount | Keep only necessary evidence and delete unnecessary data |
| Personal Information Data | Application, Reservation, Contact, and Consultation Linkage Information | Check return/deletion scope and completion date |
| Exception data | Materials related to legal disputes, audits, and settlement objections | Record the basis, period, and access rights separately. |
๐ 1. Compare the scope of termination with the contract
First, check the clauses in the contract regarding the processing, sub-entrustment, return, and destruction of personal information. If the contract states only "immediate deletion upon termination of contract," you must request a list from the vendor specifying exactly which systems and files are referred to. It is crucial not to omit any paths used in conjunction during operations, such as consultation reservation systems, text messaging tools, call center recordings, administrator portals, and backup storage.
Record the contract end date and data processing end date separately.
Record the last service usage date, settlement deadline, access permission revocation date, and deletion or return completion date, respectively. If different dates are grouped into a single 'termination date,' it is difficult to verify the duration for which permissions remained or the reason for the delayed deletion.
๐๏ธ 2. Creating Return/Delete Decision Tables by Information Item
If you request the deletion of all data at once, even the minimum materials necessary for settlements or handling complaints may be lost. We distinguish between company retention and vendor deletion by dividing the information items, processing purpose, storage entity, processing method, and proof of completion into a table.
| Information bundle | Company verification | Company Action |
|---|---|---|
| Operations Contact | Review whether only business contacts are needed. | Delete or return after purpose is fulfilled |
| Reservation/Reception Records | Determination of the period required for settlement and civil complaint processing | Delete data for periods other than necessary |
| Counseling-related information | Blocking receipt of personal counseling content | Confirmation of destruction including consultation system and backup |
| Compilation Report | Stored only at the de-identification and aggregation level | Delete original data and identifiable files |
โ 3. Verify the integrity and access permissions of the returned file
The files returned to the company may contain user lists, settlement data, and operational manuals. Immediately upon receiving the files, determine the storage location and access permissions, and record the delivery method and recipient. If encrypted files are received, it is advisable to separate the password delivery path and verify whether the download link expires after a certain period.
Items to include in the return confirmation
We record the returned filename or data bundle, file creation date, delivery date, delivery method, recipient, save location, viewing permissions, and verification results. We separately confirm that the file can be opened and that the material is suitable for business purposes.
๐งน 4. Obtain deletion proof separately for each system
The scope may not be clear based solely on the vendor's response that "deletion is complete." You must verify the deletion completion date and the person in charge by distinguishing between the primary storage, administrator account, consultation scheduling tool, message sending tool, backup, and subcontractor. You must also agree on the types of proof the vendor can provide, such as deletion logs or work confirmations, before the contract ends.
โ ๏ธ 5. Requires separate approval for exceptional archived materials
If there are materials that require retention for a specific period, such as settlement objections, legal disputes, or requests from supervisory authorities, they are not mixed with general operational data. The basis for retention, the scheduled termination date, the responsible personnel with access, and the review date are recorded, and a schedule for additional deletion is set as soon as the purpose is fulfilled.
๐ 6. Checklist Before Signing the Final Confirmation
๐ฅ 7. Dividing roles by person in charge
If a single HR representative reviews the entire termination process, it is difficult to detect system omissions. HR determines the purpose of processing and the necessity of retention, while the Privacy Officer reviews the legal basis and the scope of destruction. The IT or Security Officer verifies whether to delete accounts, access rights, and backups, and the Purchasing and Finance Officers confirm the necessity of retaining contract and settlement data. The vendor representative provides feedback on the processing results for the company's systems and subcontracted areas.
| in charge | Key Confirmation | Records to leave behind |
|---|---|---|
| HR | Processing purpose, data items, necessity of retention | Scope determination table ยท Internal approval |
| Privacy Protection | Legal Basis and Exceptions Regarding Retention | Review Opinion ยท Re-review Date |
| ITยทSecurity | Account, Storage, Backup, Log | Confirmation of permission revocation/deletion |
| company | Main system, re-outsourcing, and backup processing | Deletion/Return Confirmation |
๐ 8. Example of Confirmation Record
Do not use only general expressions such as "all deleted" in the confirmation document. For example, specify the subjects and timelines concretely, such as: "Reservation and receipt data and dispatch history from the administrator portal were deleted by 18:00 on September 30, 2026, and backup copies will be automatically deleted after the backup cycle ends on October 7, 2026. Monthly summary tables related to settlement objections will be retained until March 31, 2027, accessible only to the finance manager."
๐ซ 9. Common mistakes during the termination phase
First, there are cases where downloaded files are omitted from the operations manager's personal PC or mailbox. You must not limit your checks to the company storage but also include work email attachments and shared drives. Second, there are instances where only the vendor's main system is checked, and text messaging or scheduling tools are not separated into sub-outsourcing areas. Third, there are cases where the delay period cannot be explained because the deletion request date and the actual completion date are not distinguished. Fourth, there are instances where non-identifiable statistics and identifiable raw data are stored in the same folder, thereby expanding access permissions.
๐ 10. Verify continuity when changing vendors
When switching to a new vendor, first determine the processing purpose and items of the new contract rather than unconditionally transferring data. For data requiring transfer, record the file list, transfer date, and recipient, and obtain a confirmation of original deletion from the previous vendor after the transfer is complete. If there are ongoing consultations or crisis response requests, you must separately verify the procedures and contact information for the new vendor to take over while minimizing personal information. Inform employees of the vendor change and whether usage methods and the scope of confidentiality have changed.
๐ 11. Post-completion inspection schedule
Signing the confirmation does not complete the process. Register dates requiring follow-up verification on the calendar, such as the automatic backup deletion date, the exception retention end date, and the first settlement date after switching to a new vendor. The first follow-up check verifies that the previous vendor's account has been actually deactivated, that shared links are no longer accessible, and that the new vendor has not received any unnecessary data. The second check reconfirms that exception-retained data was deleted as scheduled and that permissions have not been expanded due to a change in internal personnel. Linking the inspection results and the completion dates of actions to the original confirmation eliminates the need to search for the same data across multiple documents.
When employee inquiries arise after a change in vendors, it is advisable to specify in the confirmation document which partyโthe previous or the new oneโis responsible for responding. A seamless inquiry channel ensures that employees do not have to explain the same information multiple times and that any remaining requests arising from the operation termination process are not missed. Even if the internal person in charge changes, the person responsible for follow-up actions and the deadline should be identifiable simply by looking at the confirmation document.
This check is not a procedure to retain personal information for a longer period, but rather a procedure to verify the termination point to ensure that information whose purpose has ended does not remain.
๐ฌ Frequently Asked Questions
Q1. Does the company have to receive all materials once the contract ends?
Q2. What should I do if the vendor says they cannot immediately delete even the backup data?
Q3. Should non-identifiable statistics also be deleted?
Q4. If I receive a confirmation letter from the company, are internal records no longer needed?
๐ Next step
๐ Related Posts
๐ Source and Information
Personal Information Protection Commission Personal Information Portal
National Law Information Center, Standards for Measures to Ensure the Safety of Personal Information