3 ms·
I have worked at well known tech companies and I personally dealt with some less-valuable-but-still-PII. We didn't store the PII because we cared about exploiti
by pfarnsworth 7y ago
I have worked at well known tech companies and I personally dealt with some less-valuable-but-still-PII. We didn't store the PII because we cared about exploiting it or because we wanted to somehow sell this data to outsiders, that's not how we made our money. We took and continue to take the security and privacy of our customers very seriously. We made sure we were GDPR compliant as well.
Instead, the small PII we had was used for fraud signals and for logging/debugging. Very frequently we would get complaints about things not working and we would have to go digging through logs to figure out exactly what happened, and without that data it was hard to figure out exactly what happened if something went wrong.
Most of the data was TTLed in our logs between 7 to 90 days so that took care of most of the issues. Other data that got logged into a data warehouse needs to be deleted via Spark jobs, which takes several days to scour all the data.
Like I said, the companies I've worked at don't need user data for its primary product and even then it took time to fully delete a user's data upon request, so I can imagine it taking a lot of time for a company like Google where extensive use of user's data is widespread throughout the company.