8 ms·
The problem isn’t so much as there’s a cost to implementing GDPR, but that the tech community has been “move fast and break things” and refused to handle things
by yzmtf2008 8y ago
The problem isn’t so much as there’s a cost to implementing GDPR, but that the tech community has been “move fast and break things” and refused to handle things properly before.
If all you do about my PII is “set delete = 1” (which one could argue isn’t even the best practice in every scenario), then I probably don’t want you to handle my PII at all.
To your example, you could easily not switch to a CASCADE, but instead set delete=1 and rewrite every sensitive field with a special value. Doesn’t even require a DB migration.
If your attitude to properly handling sensitive information is “it’s too complicated and costly, so we’ll just not handle it and YOLO”, perhaps GDPR is a good reflecting moment for you.
[edit:typo, edit:clarification]
- mbob88 8y ago>properly handling sensitive information But the thing is that GDPR affects all PII not just sensitive one so your random small useless app/blog/game/forum that has some personally identifiable but harmless and unimportant data stored is now under the same restrictions like your email or FB data.
- lox 8y agoLike, say, a personality quiz on Facebook?
- deleted 8y ago[deleted]
- pilsetnieks 8y ago> your random small useless app/blog/game/forum that has some personally identifiable but harmless and unimportant data Unimportant like your email address and your one password you're reusing everywhere? Yes, they should know better but that's neither here nor there.
- txsh 8y ago“Move fast and *break things.” Although, GDPR seems to be throwing on the brakes.
- codexon 8y agoMerely setting a delete flag is not compliant with the GDPR, that's why a cascading delete is necessary. Any programmer worth their salt knows mass random deletes and updates are extremely inefficient.
- yzmtf2008 8y agoI encourage you to read my comment again, and point out where I mentioned merely setting a delete flag. Any reader worth their salt will point out that it’s not what I suggested at all.
- codexon 8y ago"you could easily not switch to a CASCADE, but instead set delete=1 and mark every sensitive field with a special value"
- dbpatterson 8y agoyou ignored "and mark every sensitive field with a special value", which is the key part. As long as all sensitive data has been essentially zero'd out (for some value of zero), all is fine.
- codexon 8y agoMarking a field sounds to me like labeling and not zeroing it out.
- jachee 8y agoWhat if "a special value" == NULL?
- namibj 8y agoIf you choose that value, and it's the only, or one of the few values that break your software, then it's your fault.
- 8y ago
- strken 8y agoThis may be an edgy and rebellious sentiment that makes me a radical anti-privacy activist, but unless you're storing levels of information on me that are similar to facebook/google/etc., I do not give a damn whether you're soft-deleting or hard-deleting my IP address and my user account. If your web app is just a web app, and not one component of a vast surveillance octopus which puts tentacles on almost every website using social media buttons and GA.js, I don't think it matters in the slightest. It feels like all these tiny companies, one-man shops, and early-stage startups are going to be collateral damage to a regulation designed to stop facebook and google from knowing a horrific amount about everyone. In fact, it feels like a regulatory moat that will do very little to impede any big tech company while forcing me to do twice as much work for any side project I try to develop. There's so much smugness about the GDPR being a "good reflecting moment", etc. which makes me think that people who support the GDPR believe that there's no way detractors could disagree with it in good faith or for good reasons.
- hekfu 8y ago> This may be an edgy and rebellious sentiment that makes me a radical anti-privacy activist, but unless you're storing levels of information on me that are similar to facebook/google/etc., I do not give a damn whether you're soft-deleting or hard-deleting my IP address and my user account. If your web app is just a web app, and not one component of a vast surveillance octopus which puts tentacles on almost every website using social media buttons and GA.js, I don't think it matters in the slightest. > It feels like all these tiny companies, one-man shops, and early-stage startups are going to be collateral damage to a regulation designed to stop facebook and google from knowing a horrific amount about everyone. In fact, it feels like a regulatory moat that will do very little to impede any big tech company while forcing me to do twice as much work for any side project I try to develop. If you don't store PII, you don't have to do any work. Done. If you need to have PII for your webapp to function, you barely have to do any work besides giving the that care people their rights > There's so much smugness about the GDPR being a "good reflecting moment", etc. which makes me think that people who support the GDPR believe that there's no way detractors could disagree with it in good faith or for good reasons. I think it's mainly a difference in viewpoint: this is my data for me. Not yours. GDPR makes it easier for me to enforce that. From my perspective I don't care about you violating my rights "in good faith", just like most people don't cares if you trespass on my property and steal something "in good faith".
- ww520 8y agoAnd going through all the backups to overwrite the data? Backups that would have been written to CD or tapes?
- talaketu 8y agoYour backup retention policy should comply with GDPR, and you should be prepared to justify extended retention periods.
- wlll 8y agoYep, you have one month. If you are storing backups for longer than this then perhaps you have to ask yourself why. For instance, the last company I worked for deliberately didn't keep database backups past 30 days and had that policy for some years prior to GDPR. The idea being that it would be expected by a user that when they hit "delete" on something in the web app it would actually be deleted. (Additionally there is a whole minefield of crap that could happen if you got subpoenaed and had to due process on months or years worth of backup data, but this wasn't the primary driver of the policy) This is a pretty good read on the matter: https://ico.org.uk/for-organisations/guide-to-the-general-data-protection-regulation-gdpr/individual-rights/right-to-erasure/ https://ico.org.uk/for-organisations/guide-to-the-general-da...
- Hermel 8y ago> If all you do about my PII is “set delete = 1” (which one could argue isn’t even the best practice in every scenario), then I probably don’t want you to handle my PII at all. Are you aware that setting “delete=1” is essentially what file systems do when deleting a file? What file system do you suggest companies to use when they want to comply with GDPR?
- yzmtf2008 8y agoI’m well aware of that, but are you aware of any SQLi that can output a deleted file? There’s a big difference between the two things you’re trying to equalize.
- berti 8y agoDoes the GDPR actually draw that line somewhere above the filesystem, but below the database?
- henrikeh 8y agoIt is simple. You have to apply reasonable measures to delete the data. That is vague, for sure, but hopefully you have the engineering skills and domain knowledge to make a good call. Dealing with credit card data? Think a lot about it. Dealing with movie preferences? Deleting from the database should be adequate. Dealing with attendants from a local conference? Delete the files when you don’t need them. (And remember: nobody will ever show up with a fine one day. It will always start with a warning and a chance to improve before any fine is applied – unless there is serious neglect.)
- philjohn 8y agoTotally different. deleted=1 would be like adding a tag to a file saying "hey, this file is deleted" and never doing anything again. A filesystem will remove the entry pointing to the data on disk, and mark that region as free and ready to be reused - and it will get overwritten.
- wruza 8y agoFrom technical perspective, overwriting values is more deleting than deleting itself. God knows when DELETEd records will be overwritten in the database file. I once found very interesting remains in our ‘cleared copies’ of financial databases during the restoration process.