Hacker News new | past | comments | ask | show | jobs | submit login

Yes. Forget about just not rendering the data in projections. Article 5.1e states: “Personal data shall be kept in a form which permits identification of data subjects for no longer than is necessary for the purposes for which the personal data are processed [...]”

Article 5 contains concrete rules and also sets out the basic principles.

In short, you must be able to remove all information that may enable you to “single out” an individual (a physical individual by eg name or an online identity such as a particular web visitor by eg a cookie id).




So, if you're building your infrastructure in a way that you need to access a separate datastore to discover which individual is linked to which event in a stream. Then, leaving the stream of event as it is, but removing all referred keys in the joined datastore would be "GDPR-compliant"?




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: