Note: Sometimes the law/policy will make a carve-out exception for backups, if so, yay for you! I'm not currently aware of a law that does this.
Note: Sometimes the law/policy will make a carve-out exception for backups, if so, yay for you! I'm not currently aware of a law that does this.
Working in security I have been advising clients to make sure that they consider their obligations for retention periods. Not just so that you release user information you no longer need at the point you no longer need it, but also to reduce litigation if there were to be a data breach.
I am confused by these sentences. Sometimes the law does it, but you're not aware of a law that does it?
Policies are of course a different thing, and they may or may not apply to you, from industry regulations or cyber security insurance or just company or trade group policies that might apply.
Until a court or politician says otherwise, "Deleting data" means inaccesible, not physically destroyed.
AFAIK GDPR, CCPA don't specify deletion means physical destruction.
You can kill one or one-thousand backups with the same effort.
If data is on backup tapes you seem to be able to inform them of how long your retention policies are.
If you decide to go down this route, you should bear in mind that other supervisory authorities might be stricter and that you must be able to demonstrate that it’s impractical to delete backup data.
This will require, at the very least, a risk assessment, business impact assessment and data protection impact assessment.