5 ms·
Is it truly a WORM store that cannot delete any data ever never? If so, you'll need to encrypt the data in a way that allows you to make records inaccessible.
by tscs37 8y ago
Is it truly a WORM store that cannot delete any data ever never? If so, you'll need to encrypt the data in a way that allows you to make records inaccessible.
If the WORM store rotates out old data (webserver logs, tape backups with retention and rotation, etc.) then you simply inform the user of that and that's it.
- jimktrains2 8y ago> If the WORM store rotates out old data (webserver logs, tape backups with retention and rotation, etc.) then you simply inform the user of that and that's it. Can you point me to where that's allowed? What if retention is reasonably long (a year)? or not (10 years)? > s it truly a WORM store that cannot delete any data ever never? If so, you'll need to encrypt the data in a way that allows you to make records inaccessible. So now I can't perform impromptu analysis of my own data in any computationally easy way? Security analysis? Analyzing shipping information to optimize in the future?
- tscs37 8y agoAcronis, a german corporation, is implementing the GDPR too [0] and they recommend that if possible, you split backups per customer, if that is not practical atleast do your best to protect the data and don't keep it for unnecessary time frames. You should have a retention policy and encrypt your backups. [0]: https://www.acronis.com/en-us/blog/posts/backups-and-gdpr-right-be-forgotten-recommendations https://www.acronis.com/en-us/blog/posts/backups-and-gdpr-ri... [A0]: http://www.gdprarticles.com/gdpr-articles/data-subject-rights/gdpr-right-to-be-forgotten-include-backups/ http://www.gdprarticles.com/gdpr-articles/data-subject-right... [A1]: GDPR Art. 5 §1 a, b, c and f, §2 [A2]: GDPR Art. 17 §1 b and c, §3 b and e >So now I can't perform impromptu analysis of my own data in any computationally easy way? Security analysis? Analyzing shipping information to optimize in the future? Any analysis will have to be done in a way to make sure you're not exceeding the bounds of network security or you're outside legitimate interest. Analyzing shipping information is the same, as long as you do everything to make sure the data is pseudonimized or not otherwise in risk of leaking personal data, it's fine or alternatively you ask customers about it. >What if retention is reasonably long (a year)? or not (10 years)? Use your own judgement of what is reasonable, worst case you get a letter from the EU asking you to reduce the retention timeframe as long as you made an actual effort to implement the regulation.
- jimktrains2 8y agoMy question wasn't so much about doing the analysis, but about being unable to do it without fetching keys and decrypting on a per-log-entry basis. Not only would this be insufferably slow, I've not seen a feature like this in any COTS software and quite frankly seems incredibly difficult to write properly and securely, specifically the key management portion.
- acdha 8y ago> Not only would this be insufferably slow Why do you think that's a given? It seems like an implementation detail with a couple of easy solutions such as caching or batching, and it should encourage better system design in many cases where the analysis doesn't require PII and thus it's better from a security perspective not to have access to it there to begin with. There have been a ton of breaches over the years where reporting or test systems had data which they didn't even need but which had been loaded anyway since it was less work than subsetting the data.
- jimktrains2 8y ago> analysis doesn't require PII and thus it's better from a security perspective not to have access to it there to begin with. Unless I'm pulling from a raw dump of shipping I've bought, which would contain the address so that it can be cross-checked if there is an issue and I didn't know ahead of time that I wanted to perform this analysis.
- tscs37 8y agoIf you want this analysis you should plan for it. Mozilla does this for example. Any kind of profiling or monitoring goes through several layers to ensure the minimum amount of data necessary is collected. If you want shipping analytics you'll have to decide that ahead of time. That way you reduce the risk for your customer in case you don't want to do this and if you do want it you still make an effort to reduce the data necessary. You should keep in mind that the basic premise of the GDPR is that the shipping address isn't yours to begin with. It's personal data of your customer and ultimately belongs to them. If they don't allow you to use it for analytics, tough luck.