enjay Posted June 26, 2017 Posted June 26, 2017 Here's something which caught my eye - and filled me with panic! - while reading up on the GDPR: Say you have a member of staff with a complaint and they exercise their rights to see the data you hold on them. This would include any data held in email conversations and attachments. Don’t forget meeting minutes; these contain personal data' date=' too. What if this leads to the need to delete an entry under their right to “rectify” or “erasure”? This change has to apply to all copies of the data, including copies held in backups. [/quote'] Source https://england.magazine.tes.com/editions/edition_edition_edition_5233.england/data/335717/index.html Can we really be expected to delete things from backups? And that's before you go near amending every copy of a Word document which has been emailed out, potentially downloaded and is in who-knows-how-many Downloads folder and their backups. Plus, nothing is truly deleted from Google, and we couldn't remove something from the Revision History of a doc.
Snoochieboochies Posted June 26, 2017 Posted June 26, 2017 My guess is that people's requests to have data deleted from backups is so rare that it almost never happens.
pcstru Posted June 26, 2017 Posted June 26, 2017 Here's something which caught my eye - and filled me with panic! - while reading up on the GDPR: Source https://england.magazine.tes.com/editions/edition_edition_edition_5233.england/data/335717/index.html Can we really be expected to delete things from backups? Reach into backups to delete and correct data, yes - you will need to be able to do that. And that's before you go near amending every copy of a Word document which has been emailed out, potentially downloaded and is in who-knows-how-many Downloads folder and their backups. I think this is confused. If you are sending data to someone and they are acting as a processor on your behalf, then you will need to be able to correct that data. If you sent a document to someone who needed the data for their own purposes, then you are not the data controller and so you are not obliged to correct that data. You do need to ensure that the data you supply is accurate at the time it was supplied, but you have no obligation to then track changes to that data and inform everyone you ever sent the data of a correction to it. Plus, nothing is truly deleted from Google, and we couldn't remove something from the Revision History of a doc. I'd say in the case where you cannot truly delete data, that correcting it (so that the revision history shows the correction and the current version shows the correct data) would comply. However, there is a workaround to that, just download the document using (say) RTF (or any format which has no ability to track changes), delete the original and then re-upload.
GrumbleDook Posted June 26, 2017 Posted June 26, 2017 One of the questions that needs some expanding on, actually. Going back to basics, we have to first ask where the right to remove conflicts with the need to retain.
JJonas Posted June 26, 2017 Posted June 26, 2017 I guess how far you go with this is down to what action the complainee is willing to accept.
elsiegee40 Posted June 26, 2017 Posted June 26, 2017 I imagine that a complainant will expect everything - including backups - to be removed if a data deletion request is made and honoured because it's justified. And I also think the law would expect it too. The right to be forgotten doesn't include the right for someone to trawl through old backups and reinstate ... it means the right to be forgotten completely. 1
enjay Posted June 26, 2017 Author Posted June 26, 2017 Reach into backups to delete and correct data, yes - you will need to be able to do that. How?! Do you know of any backup systems where that is possible?
GrumbleDook Posted June 26, 2017 Posted June 26, 2017 I imagine that a complainant will expect everything - including backups - to be removed if a data deletion request is made and honoured because it's justified. And I also think the law would expect it too. The right to be forgotten doesn't include the right for someone to trawl through old backups and reinstate ... it means the right to be forgotten completely. They cannot be completely forgotten. Schools have legal requirements to retain certain data. This is where I get worried ... as I have seen no advice yet about what can and can't be retained. No had an update to my query to ICO on it, but expecting it to be to wait for DfE instruction
flyinghaggis Posted June 26, 2017 Posted June 26, 2017 (edited) I asked this question at a GDPR presentation and they claimed you are expected to delete requested data from backups as well. I think ultimately backup providers and database vendors will improve their software to accommodate these type of requests. In the interim it simply isn't realistic to delete entire school/company backups just because they may contain an individual file or record which someone has requested you remove. Edited June 26, 2017 by flyinghaggis
pcstru Posted June 26, 2017 Posted June 26, 2017 One of the questions that needs some expanding on, actually. Going back to basics, we have to first ask where the right to remove conflicts with the need to retain. Sensible approach. As far as I know, there is no right to be removed in DPA or GDPR and Data Processors are not obliged to "delete" your data (perhaps confusion arises from the EU's so called "right to be forgotten"). The usual request for deletion is probably something like "delete my data and do not contact me again" - but if they delete your data they will lose the fact that they should not contact you again. Data Processors may also be obliged to retain your data to meet legal requirements. So really the obligation (IMO) is that the data you store is correct and is being used as per the registration.
pcstru Posted June 26, 2017 Posted June 26, 2017 How?! Do you know of any backup systems where that is possible? Sure. Any backup system should be capable since any backup system should be capable of being restored to an operational state (if it is not, it is not a backup), the data corrected and then committed back to the backup media.
enjay Posted June 26, 2017 Author Posted June 26, 2017 Sure. Any backup system should be capable since any backup system should be capable of being restored to an operational state (if it is not, it is not a backup), the data corrected and then committed back to the backup media. That's a very tape-centric answer. Our backup is, in part, Volume Shadow Copy. I don't think you can delete files from those backups. Full DR backups are also taken by our datacentre provider. We don't have access to these backups, as they contain VMs hosted for other customers, but I can't imagine them wanting to restore all those VMs somewhere, delete a few Word docs then re-take the backup image (assuming it is even possible, depending on how they themselves are storing those backups). Also, I don't have a "spare server" that I could use for a recovery-correction-restore as you describe even if I was using the kind of backup media which would permit it.
flyinghaggis Posted June 26, 2017 Posted June 26, 2017 (edited) Sure. Any backup system should be capable since any backup system should be capable of being restored to an operational state (if it is not, it is not a backup), the data corrected and then committed back to the backup media. What if you have a backup of a SQL database (as pretty much every MIS system is) and you need to delete an individual student/etc from every backup? Even if that can be done what if your backups are on tapes/etc or even on write once media for archiving? It feels like there are so many instances where it's not practically possible to actually remove sensitive data without compromising the integrity of the backups themselves. Edited June 26, 2017 by flyinghaggis
GrumbleDook Posted June 26, 2017 Posted June 26, 2017 Just chased and had a response. Yes, the DfE are the people who will give further advice about data that is required to be processed, data that has to be retained (and agreed periods) and so on. General rule of thumb, if it is data where consent has to be given to process, then removal of consent means you stop processing it and you should destroy the data within the timelines in your agreed policy. If it goes a step further and needs to be erased sooner (right to be forgotten) then that is processed as per your policy. Relevant departments should help with example policies in due course. As for backups ... Backups are generally on re-writeable media, and the database holds the information where the data sits. Backup software should be able to remove from the backup instead of restore ... and some companies are coming out of the woodwork to say that they can do x, y and z for you ... but often as part of a large information management piece which is completely unaffordable for school. I love the stuff K2 are doing ... but it is just not feasible in most schools. I might make a separate thread where people can put in Backup vendors and folk can volunteer to go off and ask about what their software is capable of doing.
pcstru Posted June 26, 2017 Posted June 26, 2017 That's a very tape-centric answer. Our backup is, in part, Volume Shadow Copy. I'm glad you said "in part". Hopefully you mean "in a small part"! I don't think you can delete files from those backups. Full DR backups are also taken by our datacentre provider. We don't have access to these backups, as they contain VMs hosted for other customers, but I can't imagine them wanting to restore all those VMs somewhere, delete a few Word docs then re-take the backup image (assuming it is even possible, depending on how they themselves are storing those backups). Also, I don't have a "spare server" that I could use for a recovery-correction-restore as you describe even if I was using the kind of backup media which would permit it. So how do you actually test your backups are viable (can be properly restored)? I guess some people will just be impacted more than others with this, perhaps to the extent that they will need to change how they do backups.
pcstru Posted June 26, 2017 Posted June 26, 2017 (edited) What if you have a backup of a SQL database (as pretty much every MIS system is) and you need to delete an individual student/etc from every backup? Well, if you are compelled to delete data (and I'm not clear you are), you are compelled to delete it. You are compelled to correct data and to all intents and purposes the implications are the same (deletion could be thought of as simply updating with correct data which is now null). Even if that can be done what if your backups are on tapes/etc or even on write once media for archiving? It feels like there are so many instances where it's not practically possible to actually remove sensitive data without compromising the integrity of the backups themselves. Then I guess your backup system will not be able to comply with the needs of the business and you will need to change it. I don't think people saying "it is not practicable for us to do that" will trump the rights data subjects have been grated by law. If I was asked to do this, I'd probably propose that we simply correct the data in the live system, take a new backup, mark the old backups as "DNR" (do not restore) and allow the old data to be overwritten (effectively deleted) in the normal manner. The key thing would be that we ensure the MIS (our source for that data) is correct and that the backups are KNOWN to contain data that MUST NOT be restored to a live system. The system would take a while to get the data 'corrected' entirely but I don't foresee a major problem with that. Edited June 26, 2017 by pcstru
enjay Posted June 26, 2017 Author Posted June 26, 2017 I'm glad you said "in part". Hopefully you mean "in a small part"! Small part but still integral. Due to how the datacentre backups are taken, the shadow copies are the only ones we have access to, so are where we go when someone wants something recovering. Let's be honest, 99.9% of the time, file recovery is requested because someone did a Silly Thing and accidentally deleted or overwrote a file, not because of system failure. So how do you actually test your backups are viable (can be properly restored)? We don't, but the datacentre hosts do. If I was asked to do this, I'd probably propose that we simply correct the data in the live system, take a new backup, mark the old backups as "DNR" (do not restore) and allow the old data to be overwritten (effectively deleted) in the normal manner. You're still thinking backups in terms of physical removable and reusable media to which you have access. Not all backups are like that. I accept our datacentre model isn't commonplace, but it isn't completely alien either, and with the growth of Google Apps, Office 365 etc., schools will increasingly not have access to all the backups of their data.
Michael Posted June 26, 2017 Posted June 26, 2017 And how will this work with Azure Backup? Working to 180 days (my retention policy), I could have 180 different copies of a single file, amended everyday.
psydii Posted June 26, 2017 Posted June 26, 2017 Don't worry about it. It is well outside of our control. The are plenty of CIO level types who will ensure sanity prevails in this matter. It is possible that all backup vendors will produce tools to enable the implementation of 'remove this information from backup', but I doubt it. What may be required: an audit trail of request about removal of information, and demonstrations that during restores, previous requests remain honoured.
pcstru Posted June 26, 2017 Posted June 26, 2017 You're still thinking backups in terms of physical removable and reusable media to which you have access. I think you should read what I wrote again. The key element is procedural and not particularly tied to any technology.
Arthur Posted June 26, 2017 Posted June 26, 2017 It is possible that all backup vendors will produce tools to enable the implementation of 'remove this information from backup', but I doubt it. I suppose the easiest way to do that is for backup vendors to implement per-file encryption? To remove files from every single backup all we would have to do is delete the relevant decryption key(s) making it impossible to recover the files even though they remain on disk/tape/in the cloud.
flyinghaggis Posted June 26, 2017 Posted June 26, 2017 (edited) If I was asked to do this, I'd probably propose that we simply correct the data in the live system, take a new backup, mark the old backups as "DNR" (do not restore) and allow the old data to be overwritten (effectively deleted) in the normal manner. The key thing would be that we ensure the MIS (our source for that data) is correct and that the backups are KNOWN to contain data that MUST NOT be restored to a live system. The system would take a while to get the data 'corrected' entirely but I don't foresee a major problem with that. I suppose the question here is would be is it OK to keep data on a backup where you've been asked to remove it as long as you never use the backup (and have a note that in the event that you do restore it you need to immediately remove that data once it has been made live)? Technically you still have the data you've been asked to delete but you have a note to never use it nor make it live again. Would that satisfy the GDPR requirements.....! I'm guessing not but I can't think of a workable solution unless backup/database providers are going to start building the functionality into their systems. Edited June 26, 2017 by flyinghaggis
GrumbleDook Posted June 26, 2017 Posted June 26, 2017 Thread started about backup software. Please contribute. Backup software responses https://www.edugeek.net/showthread.php?t=185805
nicholab Posted June 26, 2017 Posted June 26, 2017 This is as stupid as the data protection act covering index cards or a filing cabinet. What happens with data your asked to removed but you are supposed to hold on to?
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now