It will likely mean some development work as well as we are going to need a reliable auditable way of wiping data.
Despite it making work for us all I can say is about damn time.
It will likely mean some development work as well as we are going to need a reliable auditable way of wiping data.
Despite it making work for us all I can say is about damn time.
One step we've had to take is to stop using copies of the live database in our dev environments (I suspect that practice is fairly common!). Instead we've build an automated rule-based system that produces 'munged' copies of the data (i.e. realistic size and type, but with no useful information), transferring that to our build and dev systems nightly - and reporting on what steps have been taken.
Shameless plug - we're also in the process of building plugins for platforms like Wordpress[1] to simplify some of this for smaller projects.
It's bonkers how often I've seen that over the years.
The reason I ask is that all "Big Four" auditors has been on my company that we need to be able to wipe customer data, but at the same time there are other laws saying we must keep a record of all data (financial) for many years. None of them can say what law will rule over the other one though since they are not compatable...
You also won't be able to keep backups of this data longer than is necessary for operational restore purposes (more on that below).
The rule is that you shouldn’t keep personal data for longer than is necessary for the purpose for which it was collected.
There are five exceptions to this, one of which is:
2) for compliance with a legal obligation which requires processing by Union or Member State law to which the controller is subject or for the performance of a task carried out in the public interest or in the exercise of official authority vested in the controller.
This addresses the need to meet other regulatory requirements that you mentioned.
You'll need to keep a metadata record of what you have deleted.
In the event that you have to restore data from a backup for operational purposes, you need to cross reference it to the record of deletions that occurred since the backup was created to ensure that any such data is either not restored, or is immediately deleted again.
This is only a fraction of an organization's obligations under GDPR, being those most directly relevant to your question.
Disclosure: I work for a company that provide solutions in this space.
I'm still finding everywhere we store data and fixing as much security stuff as fast I can (some of it I'm not sure programmers on here would believe).
It's a gargantuan task.
Which company do you work for if you don't mind me asking? (If you do no worries :) )
If it contains personal data on an EU natural person regardless of where the company is based is based, or on any natural person anywhere if the company is EU based, it is subject to the GDPR.
If you're providing a storage service to a business that handles personal data, your a data processor, not a data controller.
If you're the data controller, you need a classification technology that can identify personal data in those documents (amongst other capabilities).
As always, there are exceptions, but that's the general rule.
In terms of technical implementation it'll be a bastard (or result in us holding backups for a shorter period), dumping your DB backups will mean that you still have the data outside of the period (for a lot of places).
It's going to be interesting.
This (slightly ironically) will require keeping a record of what data has been deleted from production systems in response to "right to erasure" requests.