Hacker News new | ask | show | jobs
by ahofmann 1901 days ago
Do you have a source for this? I thought for the gdpr it was enough that data is not easily accessible. For example, it is not necessary to delete PII from backups unless they can be automatically restored (and are reasonably encrypted). Hashing PII thus falls under this category.
1 comments

i don't have a source i can link here, this is guidance i have gotten from lawyers.