3 ms·
You don't have to do it this way, you can just use encryption at rest with a different key for each user and throw the key when a user ask for deletion of their
by Znafon 6y ago
You don't have to do it this way, you can just use encryption at rest with a different key for each user and throw the key when a user ask for deletion of their data. No need to get all the backup back to scrub them one by one.
- londons_explore 6y agoOur lawyers didn't think that sufficient to cover ourselves. Upon finding out it wasn't going to cost many millions to simply scrub the actual data rather than the keys, they came back that it was money well spent to delete the actual data. It was mostly because a user might share data with another user, for example two users at the same postal address. Our fraud team needs to be able to look stuff like that up, so there need to be database keys on stuff like that, both in the backups and in production. If one of the users with a specific address has a GDPR deletion, we need to delete that users data, but if another user has the same address, we still need to keep the address itself. Yet if both users have a GDPR deletion apply to them, as well as deleting the address, we need to delete the fact both deleted users had the same address (even if we don't know the address, because the pattern of which deleted users shared info with other deleted users could identify them) See... it's complex! Simplest solution properly delete the data and rewrite the backups!