One point that wasn't mentioned in the podcast, but that I thought of, was that if you had sort of blockchain that meant the data could not be deleted.
I don't know whether it would hold up in court though, but it's an interesting idea. With a private block chain, the risk would be a lot smaller that a single leaked key (i.e. the customer accidentally releasing it) would result in big problems. I've recently talked with a lawyer friend of mine about a similar topic, but he didn't know immediately whether that's legally sound.