4 ms·
> If all you do about my PII is “set delete = 1” (which one could argue isn’t even the best practice in every scenario), then I probably don’t want you to handl
by Hermel 8y ago
> If all you do about my PII is “set delete = 1” (which one could argue isn’t even the best practice in every scenario), then I probably don’t want you to handle my PII at all.
Are you aware that setting “delete=1” is essentially what file systems do when deleting a file? What file system do you suggest companies to use when they want to comply with GDPR?
- yzmtf2008 8y agoI’m well aware of that, but are you aware of any SQLi that can output a deleted file? There’s a big difference between the two things you’re trying to equalize.
- berti 8y agoDoes the GDPR actually draw that line somewhere above the filesystem, but below the database?
- henrikeh 8y agoIt is simple. You have to apply reasonable measures to delete the data. That is vague, for sure, but hopefully you have the engineering skills and domain knowledge to make a good call. Dealing with credit card data? Think a lot about it. Dealing with movie preferences? Deleting from the database should be adequate. Dealing with attendants from a local conference? Delete the files when you don’t need them. (And remember: nobody will ever show up with a fine one day. It will always start with a warning and a chance to improve before any fine is applied – unless there is serious neglect.)
- philjohn 8y agoTotally different. deleted=1 would be like adding a tag to a file saying "hey, this file is deleted" and never doing anything again. A filesystem will remove the entry pointing to the data on disk, and mark that region as free and ready to be reused - and it will get overwritten.