4 ms·
I'm not a lawyer, but my understanding is that GDPR requires companies to remove user data upon request in reasonable time-frame. If you keep not deletable back
by mixedbit 6y ago
I'm not a lawyer, but my understanding is that GDPR requires companies to remove user data upon request in reasonable time-frame. If you keep not deletable backups for one month in order to improve reliability of your service, then my understanding is that it is fine to fulfill the GDPR data deletion requests withing one month period, not immediately.
- microcolonel 6y agoFiltering this stuff from a master transaction log is kinda ludicrous, not looking forward to implementing that.
- richardwhiuk 6y agoI don't think the GDPR imposes a requirement to actively filter backups.
- microcolonel 6y agoIt's not a backup, it's the authoritative dataset.
- dividedbyzero 6y agoIt's sometimes easier to encrypt everything sensitive with a user-specific key and destroy the key.
- Ensorceled 6y agoThat's how I've done it as well. The files are backed up for as long as we want, they are just useless once the user's secret is trashed. You can do the userid blocklist's on database restores etc. but for long term backup file storage it becomes silly.