Big companies do this but it requires some technical maturity. If you operate in Europe you have to implement proper data deletion. I would be more worried about small companies that large ones tombe honest.
You've also added (possibly substantial) latency to every single operation that operates on user data.
Yes you would need to carefully design the system that allows deletion of keys while minimizing chances of data loss, but it can be done, and it's going to be cheaper and less complex to do so on a tiny subset of the data.
Latency considerations are also down to design, it's not a given that there will be significant overhead imposed.
The problem is that it infected the mindset of almost every company. Those that worked at companies who needed it brought the mindset everywhere. And like many technologies, people who study what big companies do mimic it everywhere, even where it's not needed.
So your simple stupid SaaS company has some simple object that a user wants to delete that ends up living in a db somewhere... forever.
This seems like a reasonable compromise to me. It offers a safety net, while still getting the job done.
With as many data breaches as we see these days, I want my data gone. If someone gets a dump of the DB, a delete flag doesn’t matter.
This was the primary reason I never got a DNA test, even though I want to see what my results would be. I never trusted the companies to store that data long term. If I could get a test where a company didn’t store the results after they were provided to me, I’d get one tomorrow.
One hard delete can expose months worth of bugs.
Exaggerating here, but I do think soft deletion practices can be partially blamed on real business problems. I'm not sure why anyone would think that using soft deletion on an actual burn account function would be sensible though.
If you have data for a user, who wants to delete it, you can soft delete to allow recovery to prevent complaints.
On the other hand, 5 years from now your system gets hacked, and now you have to email some person you haven't done business with in 5 years to tell them their data that you claimed was deleted was leaked.
Sure you can do soft deletions with some hacky actual delete schedule but it doesn't really solve the problem, only reduces the timeline.
Discord (and many other places) allow you to recover your account within a specific period of time, but they do not delete anything, you just simply lose access and your name gets changed (and avatar and status removed), but all your DMs are there, all your messages are there (although I understand why, especially in servers (guilds)).
There is a way to bulk save and delete messages from Discord, however.
That's on you though - shouldn't have sent spam pretending to be transactional email.
Internet is not what we used to have years ago, currently the majority of users are not tech literate and that creates new problems now.
I'm not talking about unsolicited email, but legitimate transactional email related to the account that only triggers off a user action.
- you have legal obligations no matter what the customer wants, eg, Amazon and storing transactions for tax reasons
- you do actively delete most of their data, eg profiles, but “deleted=true” on their central account record is needed to propagate the deletion to other systems, eg, customer analytics
- you tombstone it for efficiency reasons and only periodically delete the records as part of your checkpoint/backup procedure; similarly CDN deployments
- you delete all the live copies, but tell customers “retained up to 90 days” because you need backups to age out
I’m not saying companies are all innocent — but there are some legitimate reasons that deletions aren’t fully instant.
When the data has value to the company and it is legal to keep it it seems very sensible to keep it (out of the perspective of s.o. acting in the interest of the company).
I'm not at all saying that soft deletion shouldn't exist. I'm arguing that hard deletion should be the default, and then soft deletion practices should have some justification.
Instead the industry chose to just soft delete everywhere, which is good for the industry, and bad for users.
It should just be followed up by hard delete several days or weeks later. The general policy should never be to hold things indefinitely.
As a practical example I have soft deletion for more or less everything on my desktop. There are periodic filesystem level snapshots and those stick around until I manually GC them. It has saved me more than once.
Deleting something you should not have: potentially a business extinction event. And a fine as well.
The question, of course, is whether that same functionality is applied to residents of other states wishing to delete their data…