4 ms·
I'm pretty sure you can "soft-delete" for GDPR compliance. So this concern is sort of a non-issue. Besides that: 1. If you're using an immutable structure, as
by rodocite 7y ago
I'm pretty sure you can "soft-delete" for GDPR compliance. So this concern is sort of a non-issue.
Besides that:
1. If you're using an immutable structure, as long as you use references, you can obfuscate data. Blockchains ran into this problem before GDPR requirements and that's essentially all they do.
2. ^ "Update" strategy for event sourcing is the same as above. Essentially a copy of the log or the log slice then a re-indexing to remove/update streams, events, projections, etc. Greg Young talks about the indexing internals (for Event Store) in the 2012 video.
- nchase 7y agoCan you describe more precisely how you're defining "soft-delete" here?
- rodocite 7y agodata is still stored somewhere but any routing to the data is disabled and the entity is disassociated.
- GordonS 7y agoCould you point towards an authoritative source for this claim? As a consumer, if I request deletion of my data, I expect it to be actually deleted - not just have a "deleted" flag set. With soft-deletion, the data is still right there, ready to be abused after a breach.
- lawik 7y agoSoft delete in the sense of removing availability but keeping the data shouldn't be GDPR compliant from what I've seen. Not in regards to right to be forgotten and restrictions on keeping PII.
- the_gipsy 7y ago"soft-delete" is not GDPR compliant.