// analysis
Personal data: the life of copies after the contract ends

Deezer and Mobius, cloud backups, LiveRamp audiences: an investigation into personal-data copies and the work of deleting them after a contract ends.
The trade in our traces · Part five of a six-part investigation.
A contract ends, but the data may already have several lives: a test file, a backup, an advertising audience, a derived product. Removing it means finding those copies and coordinating the organisations holding them. Through Deezer and Mobius, LiveRamp and US orders targeting data brokers, this instalment explores the work that begins after the final invoice.
The contract between Deezer and Mobius Solutions ended on 1 December 2020. The copy described in the French data protection authority’s decision remained with the provider until 1 October 2023, the deletion date it reported. Thirty-four months separate those dates. In the meantime, Deezer had notified the CNIL of a data breach on 10 November 2022. S01
Article 6.1.5 of the contract required deletion on termination. Mobius said it had erased the data its management knew about. The remaining copy was in a non-production environment, separate from the systems running the live service. S01
After buyers and their contracts, the investigation follows the exit from the relationship. The cases cover processing services, hosting, audience distribution and sales to third parties. Each has its own obligations and technical arrangements. They share a practical question: who takes care of the copies when the commercial relationship ends?
The test copy outlived the service
On 11 December 2025, the CNIL fined Mobius Solutions, which markets the Optimove platform, €1 million. Its announcement on 19 December referred to data relating to more than 46 million Deezer users, retained after the contract ended. The regulator also found reuse outside the client’s instructions and a failure to keep the required records of processing activities as a processor. S02
According to the defence recorded in the decision, three employees made the copy without informing management. The CNIL found that it had been created in 2019, stored in an environment belonging to Mobius and used in the course of its business. It served improvements both to the service supplied to Deezer and to Mobius’s own platform. The company remained responsible for that processing. S01
The benefit sought here was service development. The decision addresses that reuse and makes no finding of a sale to a data broker. This use belongs in an investigation of the economics of personal data: material entrusted for an assignment can also become a resource for the provider’s development work. CNIL guidance requires prior written authorisation and an assessment of compatibility with the original processing when a processor wants to reuse data for its own purposes. The provider then becomes the controller of that new processing. S18
The Mobius case also exposes a gap in the inventory. A departure procedure focused on live databases can leave test environments out of scope. Before measuring how long deletion takes, the client needs to know which systems the process actually reaches.
The agreement ends; obligations remain
The GDPR distinguishes the controller, which decides the purposes and essential means of processing, from the processor, which acts on its behalf. At the end of the service, Article 28 provides for deletion or return of the data, at the controller’s choice, and deletion of existing copies unless Union or Member State law requires retention. It also covers obligations passed down to subprocessors and rights to information and audits. S03
Some records may remain necessary for a legal obligation or a dispute. The CNIL distinguishes intermediate archiving, with restricted access and a justified purpose, from active business use. A file retained for litigation should be separated from the data available to commercial teams. S19
The European Commission’s standard contractual clauses, adopted in June 2021, put this exit process into a contractual template. Clause 10(d) provides for certification of deletion, or return accompanied by deletion of copies. The clauses continue to apply until the data is deleted or returned. For parties using this model, closing the account leaves further work to complete. S04
An independent buyer is in a different legal relationship. A licence may address the survival of certain uses or products after its term, while personal-data processing still needs its own lawful basis. Individual erasure requests and notification to recipients are addressed in particular by GDPR Articles 17 and 19, subject to their conditions and exceptions. Closing an app account therefore calls for tracing recipients, their roles and the information they retain. S03
Backups follow their own timetable
Amazon S3 documentation describes a concrete distinction. With versioning enabled, a simple delete request without a version identifier adds a delete marker. An ordinary read can then return “not found” while earlier versions remain in storage. Removing them requires operations or lifecycle rules that also cover those versions. This functionality supports data recovery. S06
Checking deletion in that configuration therefore means examining the version history as well as the current object. This technical example concerns S3; the material reviewed does not detail Mobius’s storage architecture.
Google Cloud describes staged deletion across active systems and backups. It can combine overwriting with removal of the keys needed to decrypt the data, known as cryptographic erasure. Backup snapshots follow their own retirement cycle. S08
The Google Cloud terms reviewed on 19 September 2026 set out a contractual timetable. At the end of the agreement, section 6.2 provides for a recovery period of up to 30 days, followed by deletion as soon as reasonably practicable and within a maximum of 180 days. Section 6.3 defers the trigger for data also covered by another agreement that is still running. These commitments include legal exceptions and product-specific variations; they are the supplier’s own terms. S07
Restoration adds a complication. An old backup may contain a profile removed after the snapshot was created. Bringing that backup into service requires applying the intervening deletions, or the profile can return to the live database.
Disconnecting a feed can stop audience removals
LiveRamp’s Record Sync sends membership removals to compatible destinations when an audience changes. But removing a segment from the distribution account stops its refreshes and deletion jobs at the destination. The documentation describes two ways to address data already sent: distribute the segment with an empty membership list to trigger removals, or work directly with the receiving platform to remove the segment completely. S09
Without Record Sync, most distributions described by LiveRamp work by adding users. An identifier missing from an update then remains until the destination’s expiry window is reached. This validity period, the time to live, or TTL, applies to the identifier within that mechanism. Some destinations or identifier types have no automatic expiry. For existing distributions, the full benefits of Record Sync can also depend on stale identifiers expiring. S09 S10
The order of operations matters when closing a connection: membership removals need to be delivered before the channel carrying them is disabled. This follows from LiveRamp’s published functionality; we have not audited its clients’ campaigns.
Individual rights requests follow a separate process. LiveRamp describes deletion within the relevant client’s databases, recording opt-outs and making requests available to active destinations. It also says that it cannot apply a buyer’s opt-outs to third-party segments already inside destination platforms, and recommends applying a suppression file before distribution. Scope therefore depends on the client, the type of request and the destination. S11
Remove the copy, prevent the reimport
Consider a fictional example: a profile appears in a live database, a test copy, an export and a backup. Deleting it only from the live database leaves the other three occurrences in place. If the backup is later restored unchanged, the profile returns to the service.
Closing this example requires several operations: removing the profile from working copies, dealing with the export, governing backup retention and filtering any restore. The diagram below maps these steps. It is a teaching example constructed to explain the mechanism.
A minimal record may remain useful to prevent reimport. In guidance published on 10 June 2026, the CNIL explains this principle for suppression lists used to respect objections to direct marketing. They should keep only the information needed for that purpose. An exclusion key and a full commercial history serve very different functions. S12
Derived products need an exit plan too
A profile built from personal traces may become an audience, an identity mapping, a statistic or a model. Each object needs an exit rule. A profile still linkable to a person remains personal data. Genuinely anonymous statistics have a different status. CNIL guidance distinguishes anonymisation from pseudonymisation, which allows attribution using additional information. S17
There is an economic consequence. Where a provider can lawfully keep an anonymous result after removing the inputs, some of the value created survives. A corrective measure covering derived products can instead require the rebuilding of service capabilities.
The Avast order made final in June 2024 requires deletion of Jumpshot data and models, algorithms and software developed by Jumpshot from that data. It includes retention exceptions, notably for legal obligations, which must be detailed to the Federal Trade Commission, the US consumer-protection agency. This remedy’s scope is specific to the case. S13 S15
Avast says it closed Jumpshot in January 2020 and disputes the FTC’s characterisation of the facts. The agreement contains no general admission of the allegations. In its FAQ, the company also says it instructed Jumpshot customers to delete the data they acquired. S14 S13
The detail of an exit clause therefore matters: does it cover only files received, or also the audiences and outputs made from them? Contractual ownership of a deliverable and permission to process the personal data it contains remain separate questions.
Avast must delete its holdings and contact recipients
Section III of the Avast order sets twenty days from its effective date to delete the covered data and derived products held by the respondents. It requires a statement to the FTC under penalty of perjury. Within the same period, the companies must send destruction instructions to third parties that received browsing information. Those instructions cover the information, specified derivatives and analysis software. The companies must certify that they sent the instructions and submit correspondence to the regulator. S13
The distinction is operational: the seller acts directly on its own systems, then calls on recipients to act on theirs. Following up on replies becomes a task in its own right.
The Gravy Analytics–Venntel order, finalised on 14 January 2025, sets out that follow-up in section VIII. It offers an alternative to identifying recipients: let consumers request deletion from recipients’ commercial databases, pass on those requests, demand written confirmation and give consumers the instructions sent along with deletion confirmations received, where available, no later than 90 days after their request. S16 S20
Section XIII also covers historical location data and derived products. It permits retention under specified conditions, including obtaining the required consent records or transforming the data under the order’s criteria to deidentify it or render it non-sensitive. The deadlines, covered objects and conditions need to be read together. S16
The public documents reviewed describe these obligations and company statements. Complete follow-up on deletion by former Jumpshot buyers and Gravy recipients remains outside the accessible record; some compliance exchanges may be submitted to the regulator without publication.
Know the recipients before closing the account
Several layers of subprocessors can operate behind a supplier. In Opinion 22/2024, adopted on 7 October 2024, the European Data Protection Board says that the identity of all those organisations should be readily available to the controller and kept up to date. This inventory requirement applies regardless of the level of risk. S05
The extent of verification adapts to the circumstances. The same opinion leaves the controller to assess, case by case, whether it needs to obtain and review subprocessing contracts. The European standard clauses also provide for information and audits. S05 S04
A useful exit report can connect the destination inventory, completed operations and open exceptions: active databases purged, export removed, backup protected until a specified date, a recipient’s reply still outstanding. Logs and a restore test can help examine that scope. This proposed approach needs to fit the service and its risks, with clandestine copies and previously exfiltrated files beyond its reach.
The service price should include the exit
Service revenue may end on a readily identifiable date. Closure work can continue: mapping copies, identifying derivatives, forwarding removals, tracking replies and retiring backups. These operations require staff and technical capacity after the last invoice.
That creates an asymmetry: retention may preserve future usefulness for the holder, while deletion requires immediate effort and removes that option. This is an economic reading of the mechanism; the documents reviewed do not provide comparable estimates of its full costs.
A contract should therefore specify at the outset who funds and carries out the exit, which environments it covers and how exceptions expire. The client is also buying the ability to unwind the relationship. A service with a clear entry price benefits from an equally clear exit scope.
Sources and method
Research cut-off: 19 September 2026. Regulatory decisions, company statements and product documentation are identified separately. The private Deezer–Mobius agreement is described through the CNIL decision. Searches conducted did not identify a public decision changing that sanction; the status of any appeal remains unconfirmed. No requests for comment were sent.
The second diagram is a fictional example of how a profile is copied and removed. The other figures present the Mobius chronology and requirements in the US orders. Mobius’s reported deletion concerns its own copy; the fate of any exfiltrated copies falls outside that scope.
- S01 · CNIL decision SAN-2025-014 concerning Mobius Solutions
- S02 · CNIL announces €1 million Mobius Solutions fine
- S03 · Regulation (EU) 2016/679: GDPR
- S04 · Decision (EU) 2021/915: controller–processor standard clauses
- S05 · EDPB Opinion 22/2024 on reliance on processors and subprocessors
- S06 · Deleting object versions from a versioning-enabled bucket
- S07 · Cloud Data Processing Addendum
- S08 · Data deletion on Google Cloud
- S09 · Keep Destination Data Fresh with Record Sync
- S10 · How LiveRamp Refreshes Distributed Data
- S11 · Sending Data Subject Rights Requests
- S12 · CNIL guidance on suppression lists for direct-marketing objections
- S13 · Avast complaint and final decision and order
- S14 · Jumpshot settlement FAQs
- S15 · FTC Avast case docket
- S16 · Gravy Analytics–Venntel final consent package
- S17 · CNIL guidance on anonymisation
- S18 · CNIL guidance on processors reusing entrusted data
- S19 · CNIL guidance on retention periods
- S20 · FTC Gravy Analytics case docket
This analysis is not investment advice.
// cite this analysis
l0g, “Personal data: the life of copies after the contract ends”, l0g.fr, published September 19, 2026, updated September 19, 2026, https://l0g.fr/en/analysis/personal-data-after-the-contract-ends/
$ cd ../analysis