Hello Jakob, the 72 hours was arbitrary, at the time that is what we were advised to use as a window to address data that is not GDPR compliant. In legal speak GDPR knew that there will be situations where personal identifiable information may be logged and that we must take steps to remove this information promptly, but no time frame was specifically given. At the time we picked 72 hours because in other areas of the GDPR documentation the time frame they do specify (for notifying users of breaches)...
Hello Jakub, the 72 hours was arbitrary, at the time that is what we were advised to use as a window to address data that is not GDPR compliant. In legal speak GDPR knew that there will be situations where personal identifiable information may be logged and that we must take steps to remove this information promptly, but no time frame was specifically given. At the time we picked 72 hours because in other areas of the GDPR documentation the time frame they do specify (for notifying users of breaches)...