7 ms·
It comes after around 40,000 alerts relating to European criminals were removed from the same database, the PNC, following Britain's post-Brexit deal with the E
by codeulike 6y ago
It comes after around 40,000 alerts relating to European criminals were removed from the same database, the PNC, following Britain's post-Brexit deal with the EU.
Right so reading between the lines they needed to do some post-Brexit data cleaning and someone messed up the WHERE clause.
But where are the backups? Surely accidentally deleted data should be fairly easy to recover from historical backups which they surely surely must have?
- randunel 6y agoWouldn't such international data removal agreements also include backups? What's the point in removing PII from one of the databases, if it remains in their backups?
- codeulike 6y agoYou have a point but I have doubts that any organisation on the planet has the capability/willingness/resources to surgically remove data from historical backups. I think its more likely that no backups exist, or that, say, no backups exist past X days in the past. Or worse, that backups exist, but they have been found to be unrestorable.
- codeulike 6y agoUnder GDPR right-to-erasure you dont necessarily have to erase data from backups but must be clear about how long it will hang around. The key issue is to put the backup data ‘beyond use’, even if it cannot be immediately overwritten. You must ensure that you do not use the data within the backup for any other purpose, ie that the backup is simply held on your systems until it is replaced in line with an established schedule. https://ico.org.uk/for-organisations/guide-to-data-protection/guide-to-the-general-data-protection-regulation-gdpr/individual-rights/right-to-erasure/#ib5 https://ico.org.uk/for-organisations/guide-to-data-protectio...
- tremon 6y agoYou could handle such requests by tombstoning the user ID (in addition to deleting the data). By keeping the tombstone records in separate storage (it's usually only kB, just a list of hard-removed user IDs), you can guarantee (re-do) the erasure even after having to do a full database restore.
- vidarh 6y agoBackup. Encrypt the backup. Run the deletion. Verify you haven't lost anything. Verify it again. Put the backup encryption key beyond use other than in the case of a suitably agreed emergency (e.g. in the case of an agreement with another party, hand them the key). Then after a suitable grace period, once you're sure everything is ok, you destroy the backup.
- nightcracker 6y ago> Put the backup encryption key beyond use other than in the case of a suitably agreed emergency (e.g. in the case of an agreement with another party, hand them the key). Like search warrants? We know those never get abused. > Then after a suitable grace period, once you're sure everything is ok, you destroy the backup. But we need a search warrant to access the backup anyway so we don't really have to delete it. Best keep it, just in case.
- vidarh 6y ago> Like search warrants? We know those never get abused. No, like catastrophic loss of data, hence why I outlined a process of a doing this temporarily in the case of agreement with a another party to put the data entirely beyond your own use unless the party you've agreed the deletion with agrees the situation is serious enough. > But we need a search warrant to access the backup anyway so we don't really have to delete it. Best keep it, just in case. If you don't trust the party to delete the data, then adding in a temporary period of retention makes no difference, because in that case they could just as well have ignored the demand for the initial deletion entirely.