Hacker News new | ask | show | jobs
by VWWHFSfQ 1106 days ago
Hard-delete isn't required by GDPR. The data itself just has to be made non-identifiable. You don't actually have to remove the database records, for instance.
1 comments

Every (collection of) comments is eventually identifiable
There’s identifiable and sufficiently deidentified to meet the legal standard. Removing the userid meets the GDPR definition, but I bet you could reidentify based on patterns or fingerprints, if you really wanted to.