4 ms·
If you follow GDPR strictly you would need to be able to purge the data from your backups. Now most backups are considered immutable, so you aren't g
by cbr 9y ago
If you follow GDPR strictly you would need to be
able to purge the data from your backups.
Now most backups are considered immutable, so
you aren't going to do that
Encrypt with a user-specific key, and destroy that key to drop all backups concerning that user.
- justinjlynn 9y agoDon't assume the law makes a distinction between data which is destroyed and data which is irretrievable. I can easily see someone arguing that the data is not destroyed -- there's simply a very, very low chance that anyone will be able to retrieve it. You and I both know that argument makes no sense, but hey, it's the law -- it doesn't have to make sense, it just has to convince a few people with power that you're wrong.
- solomatov 9y agoA similar scheme is used to erase data on SSD. Otherwise, you can't reliably delete any data from them.
- Spivak 9y agoThis only applies to home grown backup systems. If all you're doing are VM backups of your SQL database there's 0% chance you have the granularity to delete a single user. "Then don't do that" Sure, but now you actually have an imposition because the ability to do this kind of thing can't be done on any commercially available backup system.
- makomk 9y agoIf the key required to decrypt your backups isn't backed up, you don't have backups. If it is, you're back to the original problem.