
When Mohamed Maslouh, a London-based contractor, was assigned to enter data into Google's internal gHire recruitment system last September, he noticed something surprising. The database contained the profiles of thousands of people in the EU and U.K. whose names, phone numbers, personal email addresses and resumés dated back as far as 2011.
Maslouh knew something was amiss, as he had received data-protection training from Randstad, the European human-resources giant that employed him, and was aware of the EU's five-year-old General Data Protection Regulation (GDPR), which remained part of British law after Brexit.
Under the law, companies in the European Union and U.K. may not hang onto anyone’s personal data—that is, information relating to any identifiable living person—for longer than is strictly necessary, which generally means a maximum retention time measured in weeks or months.