Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

The solution is to keep a list of "things to exclude" if a backup is ever restored. This is reasonable. Rewriting old backups is not reasonable.


Would such a list not by nature consist of PII?


Not necessarily. It might consist of user IDs (integers, UUIDs) or hashed values of something that can be mapped to the user...


User ID's are considered PII though. If it can be mapped to the user, it's by definition identifying information


Identifiers that have no meaning outside of your system are not PII.


Reading https://ec.europa.eu/info/law/law-topic/data-protection/refo... I would agree, of course if that identifier is not in some other database, that maps it to a person. If you have just ids in a backup and you remove the person-ID mapping this should be fine.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: