In my view, if I say I want to "delete" my account, I don't want a single trace of my existence on that platform from then on. No emails, no backups, nothing.
In my view, if I say I want to "delete" my account, I don't want a single trace of my existence on that platform from then on. No emails, no backups, nothing.
While the data is likely inaccessible forever in this case, the reason the company can't just say it's been deleted is if they actually do need to restore one of these backups, the data you deleted will come back.
* Encrypt each user's data to a user-specific key
* Keep the key in hot replicated storage
* When you get a deletion request, delete the key
Backups aren't just about replication/redundancy, they also protect you from bugs and other sources of corrupted data.
A backup that can be edited to delete data like an encryption key instantly when the user tells it do is also a backup that can be easily lost or corrupted.
Either way that clause showed a hint accountability from Amazon that I haven't seen too often. Not that I've spent much time comparing ToS either.