Hacker News new | ask | show | jobs
by akvadrako 2423 days ago
Not really - you need a way to scrub user data on demand from backups and they should also have limited duration.
1 comments

You do not require a way to “scrub user data on demand from backups”. This is just untrue; please don’t spread it.
What are you talking about? Part of GDPR is deleting personal data on demand.
You have misunderstood the requirements of the GDPR. CNIL, for example, has made it explicitly clear that so long as an effective retention policy is in place then PII does not need to be removed from backups on demand.
If by that you mean backups need to be deleted after a certain period then it's effectively the same thing.