(no title)
tybit
|
4 years ago
At big tech companies I’ve seen and heard about, the answer is crypto shredding.
Encrypt all PII at rest with a per user data key.
GDPR deletion requests can then delete the data key.
This isn’t perfect, but it’s a step in the right direction IMO. Unfortunately I don’t see it being feasible for a typical company anytime soon.
salawat|4 years ago