Hacker News new | ask | show | jobs
by martinohansen 1105 days ago
I think that’d be illegal for EU citizens at least
1 comments

Hard-delete isn't required by GDPR. The data itself just has to be made non-identifiable. You don't actually have to remove the database records, for instance.
Every (collection of) comments is eventually identifiable
There’s identifiable and sufficiently deidentified to meet the legal standard. Removing the userid meets the GDPR definition, but I bet you could reidentify based on patterns or fingerprints, if you really wanted to.