GDPR Data Deletion

The cluster focuses on debates about GDPR requirements for deleting user data, including challenges with backups, immutable storage, right to be forgotten, and compliance strategies like tracking deletion requests for restores.

📉 Falling 0.4x Legal
3,616
Comments
19
Years Active
5
Top Authors
#6984
Topic ID

Activity Over Time

2008
5
2009
24
2010
23
2011
66
2012
50
2013
86
2014
70
2015
71
2016
86
2017
166
2018
594
2019
281
2020
299
2021
294
2022
469
2023
344
2024
365
2025
270
2026
53

Keywords

e.g US excision.html CCPA openai.com HIPAA REB CISO IMO ycombinator.com gdpr data delete deleted deletion retention backups store 90 days law

Sample Comments

hutrdvnj May 25, 2021 View on HN

What happens if you have to delete some data e.g. due to law?

alkonaut Aug 14, 2020 View on HN

Data that I wanted to delete isn't necessary for the functioning of the service, so doesn't that mean the GDPR requires it to be hard-deleted within a reasonable time?

jeremyt May 26, 2018 View on HN

How do you keep track of what info needs to be deleted on restore without violating GDPR?

andrepd Jun 19, 2018 View on HN

Doesn't GDPR require them to really delete?

sterlind Feb 3, 2021 View on HN

Under GDPR I'm fairly certain that they've implemented actual deletion. GDPR even requires companies to go so far as to scan old tapes to delete user records on request by a 30-day deadline, iirc.

CydeWeys Mar 20, 2023 View on HN

Retaining data that you said you had deleted is a major liability, especially now with GDPR.

andor Feb 20, 2022 View on HN

No, they actually have to keep the data safe for their users. Deleting the data is a GDPR violation.

sschueller Jun 16, 2023 View on HN

Yes, you can't keep deleted data indefinitely.

chopin Apr 24, 2018 View on HN

You don't keep the backup forever. GDPR forces you to reasonable measures for deletion.You could also keep a record of "to-delete" primary keys in event of a restore along with your backups.All of this should have been implemented a long time ago, some European countries demanded this already.I am surprised by the lack of imagination of people if they don't want to implement something (too burdensome, technically impossible,...) who can come up with decent sol

Kbelicius May 22, 2023 View on HN

I think that they have to delete the data per your request to be GDPR compliant since no law requires keeping such date.