P3.10.4Incomplete exitdesign

Data processing that continues after exit makes the exit incomplete

Aliases: right to erasure · retention disclosure · post-deletion processing

What it is

Exit is not the end of data processing: after account deletion, the profile may still live in the ad system, caches persist on edge nodes, backups wait for the next rotation to be overwritten, and statutory records remain on schedule. In the user's mental model, exit means "everything stops"; what the system executes is "the main pipeline stops." That gap makes the exit incomplete: the person has left, the data is still working.

Why it happens

Three sources of continuation. Distribution and asynchrony: profiles and features are not single records but replicas distributed across systems with independent lifecycles — deleting from the master store does not delete downstream, and backups wait for rotation. Statutory duties: transaction, tax, and compliance records carry retention periods that outrank user instructions. Commercial inertia: an exiting user's features still hold training value for models, and absent a technical barrier, retention is the default. The three differ in kind — the first two are structural delays, the third a choice — but to the user they are one thing: I said I was leaving, and you are still using me. The root of the incompleteness is agency failure: the exit instruction is understood as revocation of consent to all data processing, while it actually reaches only the main account pipeline.

Where it stops holding

"Stop everything instantly" is physically unattainable (the propagation chains of replicas, backups, caches); the reasonable standard of completeness is not instantaneous zero but disclosable, deadlined, auditable. De-identified statistical use is legal in most jurisdictions, but whether users count it as "still processing" is a perception matter — legality does not waive disclosure. Stopping third-party sharing has its own chain: the exit instruction reaches first-tier recipients directly, while onward transfers depend on contractual propagation, with longer delays and higher failure rates.

Applying it

Replace the blanket phrase "delete your data" with three-list disclosure delivered at exit: processing that stops now (targeted advertising, profiling, outbound sharing); processing that stops on a deadline (caches in days, backups in tens of days as rotation completes — each with its number); data retained by law (categories, periods, usage boundaries — kept for compliance, not reuse). Institute a post-exit silence audit: zero touchpoints for ninety days — no recall messages, no recommendation pools, no retargeting — with a touchpoint audit at expiry; only a clean audit counts as a complete exit. Verification: sample deleted accounts and trace processing touchpoints at the log level; the divergence between the three lists and observed behavior is the defect list.

Related

  • Same group: P3.10.1 The cost of leaving includes the loss of social ties · P3.10.2 The count and wording of retention steps decide whether they inform or obstruct · P3.10.3 Deactivation and permanent deletion are two different exits
  • Adjacent: P3.04.3 Platform self-restraint has a conflict of interest · P3.05.1 Close, unsubscribe, and delete must be equally reachable
  • Search terms: data deletion · right to erasure · retention disclosure

Cards in the same group

Quick Actions

Share

Share this page

ios_share

https://hci.top/en/handbook/P3.10.4