3 ms·
The issue with GDPR is right to erasure, which is tricky in conventional systems. But in ES systems, naively implemented, it is not possible. If you are writing
by ddek 5y ago
The issue with GDPR is right to erasure, which is tricky in conventional systems. But in ES systems, naively implemented, it is not possible. If you are writing PII in plain text, an immutable log won't let you remove it. OTOH I have two options: store PII in a separate database, and just delete or nullify when requested; or use per-user encryption, and delete the key.
- EdwardDiego 5y agoYeah, for GDPR compliance when you're using Kafka, the key is to use, well keys, and log compaction. Then you can retrieve PII for a GDPR if needed. Or, remove it entirely by submitting a "tombstone" record with key -> null, then log compaction removes it. Which basically means, don't mix PII into transnational data.
- lucian1900 5y agoThe GDPR concept is "personal data", partly since it doesn't just refer to ways to identify a person. PII is a similar but different US concept.