Basically you either have hot backups you can delete from (this is bad for obvious reasons), or your backups expire in a given time (this is most common), or you have each record encrypted with an encryption key that is saved in other ways so you only have to destroy those to make the data irretrievable.
Of course, that system has to be backed up, etc, etc.
My theory is that you’re making a concession somewhere in the backups to a separate keyring system. Either there is no cold backup, or you don’t do cold backups at all, or your cold backup is actually semi-warm and needs to be hooked up to a system intermittently to be reconciled against production (in which case, the backups need backups to protect against a failure on the reconciler system.) The onus is on the answerer to tell me how they would avoid one of those concessions. Respectfully, anything else/less is just fluff like, “it’s totally possible.”
I'm confused. Are you saying those are small concerns? Because I'm saying the backup mechanism for the keys surely need to be resilient to all of those.
Ironically, I've responded to deletion requests made by email in which the person did not have any records in our systems, until receiving the deletion request containing their name and email address.
https://verasafe.com/blog/do-i-need-to-erase-personal-data-f...
Yeah, right. ANYTHING you put in the cloud or any other digital media no longer belongs to you. I suspect 23 sold this valuable data, that any insurance company would kill for, to the highest bidder. When will we learn we cannot trust any company with our info?!?
They say they provide your data to (to various levels, not necessarily genetic data):
- Service providers (Fedex knows you receive a shipment from 23&me, physical storage of your sample, someone hosts their servers)
- Sharing to people/entities at the users direction
- Any future commonly owned entities (23&me goes through a merger, new org has your data)
- Valid court orders ("23andMe will not provide information to law enforcement unless required by law to comply with a valid court order, subpoena, or search warrant")
> Delete your 23andMe account and personal data, including your personal information, genetic data, and other information collected through your use of the Service.
> Upon receiving your confirmation we will process your request to delete your data, and you will no longer be able to sign-in to your account. Please keep in mind it may take up to 30 days to fulfill your request.
What's your basis for your claim?
“The federal Clinical Laboratory Improvement Amendments (CLIA) of 1988 and California laboratory regulations require the lab store your de-identified genotyping test results and to keep a minimal amount of test result or analysis information,” an email from 23andMe said. “Our laboratory will retain your genetic information and a randomized identifier on their secure servers for a limited period of time, 10 years pursuant to CLIA regulations.”
I was friends with a former exec. At a party I remember him callously mentioning that you can’t delete data off their platform. I inquired a bit more and he pointed me to one of the laws referenced above
23andme is not lying in a legal sense. They seem to be deceptive though
So they delete everything they have under your name and the lab retains a copy of your sample and the sample results?
On paper, this is sufficient because a sample + results is no more useful to someone nefarious then a piece of hair found on the ground...
It only becomes a problem if they fail to delete any identifying information that could connect it to you...