Jump to content

Recommended Posts

Posted

Here's something which caught my eye - and filled me with panic! - while reading up on the GDPR:

 

Say you have a member of staff with a complaint and they exercise their rights to see the data you hold on them. This would include any data held in email conversations and attachments. Don’t forget meeting minutes; these contain personal data' date=' too. What if this leads to the need to delete an entry under their right to “rectify” or “erasure”? This change has to apply to all copies of the data, including copies held in backups. [/quote']

Source https://england.magazine.tes.com/editions/edition_edition_edition_5233.england/data/335717/index.html

 

Can we really be expected to delete things from backups? And that's before you go near amending every copy of a Word document which has been emailed out, potentially downloaded and is in who-knows-how-many Downloads folder and their backups. Plus, nothing is truly deleted from Google, and we couldn't remove something from the Revision History of a doc.

Posted
Here's something which caught my eye - and filled me with panic! - while reading up on the GDPR:

 

 

Source https://england.magazine.tes.com/editions/edition_edition_edition_5233.england/data/335717/index.html

 

Can we really be expected to delete things from backups?

Reach into backups to delete and correct data, yes - you will need to be able to do that.

And that's before you go near amending every copy of a Word document which has been emailed out, potentially downloaded and is in who-knows-how-many Downloads folder and their backups.

I think this is confused. If you are sending data to someone and they are acting as a processor on your behalf, then you will need to be able to correct that data. If you sent a document to someone who needed the data for their own purposes, then you are not the data controller and so you are not obliged to correct that data. You do need to ensure that the data you supply is accurate at the time it was supplied, but you have no obligation to then track changes to that data and inform everyone you ever sent the data of a correction to it.

 

Plus, nothing is truly deleted from Google, and we couldn't remove something from the Revision History of a doc.

 

I'd say in the case where you cannot truly delete data, that correcting it (so that the revision history shows the correction and the current version shows the correct data) would comply. However, there is a workaround to that, just download the document using (say) RTF (or any format which has no ability to track changes), delete the original and then re-upload.

Posted

One of the questions that needs some expanding on, actually.

 

Going back to basics, we have to first ask where the right to remove conflicts with the need to retain.

Posted

I imagine that a complainant will expect everything - including backups - to be removed if a data deletion request is made and honoured because it's justified. And I also think the law would expect it too.

 

The right to be forgotten doesn't include the right for someone to trawl through old backups and reinstate ... it means the right to be forgotten completely.

  • Thanks 1
Posted
Reach into backups to delete and correct data, yes - you will need to be able to do that.

 

How?! Do you know of any backup systems where that is possible?

Posted
I imagine that a complainant will expect everything - including backups - to be removed if a data deletion request is made and honoured because it's justified. And I also think the law would expect it too.

 

The right to be forgotten doesn't include the right for someone to trawl through old backups and reinstate ... it means the right to be forgotten completely.

 

They cannot be completely forgotten. Schools have legal requirements to retain certain data.

 

This is where I get worried ... as I have seen no advice yet about what can and can't be retained.

 

No had an update to my query to ICO on it, but expecting it to be to wait for DfE instruction

Posted (edited)

I asked this question at a GDPR presentation and they claimed you are expected to delete requested data from backups as well. I think ultimately backup providers and database vendors will improve their software to accommodate these type of requests.

 

In the interim it simply isn't realistic to delete entire school/company backups just because they may contain an individual file or record which someone has requested you remove.

Edited by flyinghaggis
Posted
One of the questions that needs some expanding on, actually.

Going back to basics, we have to first ask where the right to remove conflicts with the need to retain.

Sensible approach. As far as I know, there is no right to be removed in DPA or GDPR and Data Processors are not obliged to "delete" your data (perhaps confusion arises from the EU's so called "right to be forgotten"). The usual request for deletion is probably something like "delete my data and do not contact me again" - but if they delete your data they will lose the fact that they should not contact you again. Data Processors may also be obliged to retain your data to meet legal requirements. So really the obligation (IMO) is that the data you store is correct and is being used as per the registration.

Posted
How?! Do you know of any backup systems where that is possible?

Sure. Any backup system should be capable since any backup system should be capable of being restored to an operational state (if it is not, it is not a backup), the data corrected and then committed back to the backup media.

Posted
Sure. Any backup system should be capable since any backup system should be capable of being restored to an operational state (if it is not, it is not a backup), the data corrected and then committed back to the backup media.

 

That's a very tape-centric answer. Our backup is, in part, Volume Shadow Copy. I don't think you can delete files from those backups. Full DR backups are also taken by our datacentre provider. We don't have access to these backups, as they contain VMs hosted for other customers, but I can't imagine them wanting to restore all those VMs somewhere, delete a few Word docs then re-take the backup image (assuming it is even possible, depending on how they themselves are storing those backups).

 

Also, I don't have a "spare server" that I could use for a recovery-correction-restore as you describe even if I was using the kind of backup media which would permit it.

Posted (edited)
Sure. Any backup system should be capable since any backup system should be capable of being restored to an operational state (if it is not, it is not a backup), the data corrected and then committed back to the backup media.

 

What if you have a backup of a SQL database (as pretty much every MIS system is) and you need to delete an individual student/etc from every backup?

 

Even if that can be done what if your backups are on tapes/etc or even on write once media for archiving? It feels like there are so many instances where it's not practically possible to actually remove sensitive data without compromising the integrity of the backups themselves.

Edited by flyinghaggis
Posted

Just chased and had a response.

 

Yes, the DfE are the people who will give further advice about data that is required to be processed, data that has to be retained (and agreed periods) and so on.

 

General rule of thumb, if it is data where consent has to be given to process, then removal of consent means you stop processing it and you should destroy the data within the timelines in your agreed policy. If it goes a step further and needs to be erased sooner (right to be forgotten) then that is processed as per your policy. Relevant departments should help with example policies in due course.

 

As for backups ...

 

Backups are generally on re-writeable media, and the database holds the information where the data sits. Backup software should be able to remove from the backup instead of restore ... and some companies are coming out of the woodwork to say that they can do x, y and z for you ... but often as part of a large information management piece which is completely unaffordable for school. I love the stuff K2 are doing ... but it is just not feasible in most schools.

 

I might make a separate thread where people can put in Backup vendors and folk can volunteer to go off and ask about what their software is capable of doing.

Posted
That's a very tape-centric answer. Our backup is, in part, Volume Shadow Copy.

I'm glad you said "in part". Hopefully you mean "in a small part"!

I don't think you can delete files from those backups. Full DR backups are also taken by our datacentre provider. We don't have access to these backups, as they contain VMs hosted for other customers, but I can't imagine them wanting to restore all those VMs somewhere, delete a few Word docs then re-take the backup image (assuming it is even possible, depending on how they themselves are storing those backups).

 

Also, I don't have a "spare server" that I could use for a recovery-correction-restore as you describe even if I was using the kind of backup media which would permit it.

So how do you actually test your backups are viable (can be properly restored)?

 

I guess some people will just be impacted more than others with this, perhaps to the extent that they will need to change how they do backups.

Posted (edited)
What if you have a backup of a SQL database (as pretty much every MIS system is) and you need to delete an individual student/etc from every backup?

Well, if you are compelled to delete data (and I'm not clear you are), you are compelled to delete it. You are compelled to correct data and to all intents and purposes the implications are the same (deletion could be thought of as simply updating with correct data which is now null).

Even if that can be done what if your backups are on tapes/etc or even on write once media for archiving? It feels like there are so many instances where it's not practically possible to actually remove sensitive data without compromising the integrity of the backups themselves.

Then I guess your backup system will not be able to comply with the needs of the business and you will need to change it. I don't think people saying "it is not practicable for us to do that" will trump the rights data subjects have been grated by law.

 

If I was asked to do this, I'd probably propose that we simply correct the data in the live system, take a new backup, mark the old backups as "DNR" (do not restore) and allow the old data to be overwritten (effectively deleted) in the normal manner. The key thing would be that we ensure the MIS (our source for that data) is correct and that the backups are KNOWN to contain data that MUST NOT be restored to a live system. The system would take a while to get the data 'corrected' entirely but I don't foresee a major problem with that.

Edited by pcstru
Posted
I'm glad you said "in part". Hopefully you mean "in a small part"!

Small part but still integral. Due to how the datacentre backups are taken, the shadow copies are the only ones we have access to, so are where we go when someone wants something recovering. Let's be honest, 99.9% of the time, file recovery is requested because someone did a Silly Thing and accidentally deleted or overwrote a file, not because of system failure.

 

So how do you actually test your backups are viable (can be properly restored)?

We don't, but the datacentre hosts do.

 

If I was asked to do this, I'd probably propose that we simply correct the data in the live system, take a new backup, mark the old backups as "DNR" (do not restore) and allow the old data to be overwritten (effectively deleted) in the normal manner.

You're still thinking backups in terms of physical removable and reusable media to which you have access. Not all backups are like that. I accept our datacentre model isn't commonplace, but it isn't completely alien either, and with the growth of Google Apps, Office 365 etc., schools will increasingly not have access to all the backups of their data.

Posted
And how will this work with Azure Backup? Working to 180 days (my retention policy), I could have 180 different copies of a single file, amended everyday.
Posted

Don't worry about it. It is well outside of our control. The are plenty of CIO level types who will ensure sanity prevails in this matter.

 

It is possible that all backup vendors will produce tools to enable the implementation of 'remove this information from backup', but I doubt it.

 

What may be required: an audit trail of request about removal of information, and demonstrations that during restores, previous requests remain honoured.

Posted
You're still thinking backups in terms of physical removable and reusable media to which you have access.

I think you should read what I wrote again. The key element is procedural and not particularly tied to any technology.

Posted
It is possible that all backup vendors will produce tools to enable the implementation of 'remove this information from backup', but I doubt it.

I suppose the easiest way to do that is for backup vendors to implement per-file encryption? To remove files from every single backup all we would have to do is delete the relevant decryption key(s) making it impossible to recover the files even though they remain on disk/tape/in the cloud.

Posted (edited)

 

If I was asked to do this, I'd probably propose that we simply correct the data in the live system, take a new backup, mark the old backups as "DNR" (do not restore) and allow the old data to be overwritten (effectively deleted) in the normal manner. The key thing would be that we ensure the MIS (our source for that data) is correct and that the backups are KNOWN to contain data that MUST NOT be restored to a live system. The system would take a while to get the data 'corrected' entirely but I don't foresee a major problem with that.

 

I suppose the question here is would be is it OK to keep data on a backup where you've been asked to remove it as long as you never use the backup (and have a note that in the event that you do restore it you need to immediately remove that data once it has been made live)?

 

Technically you still have the data you've been asked to delete but you have a note to never use it nor make it live again. Would that satisfy the GDPR requirements.....!

 

I'm guessing not but I can't think of a workable solution unless backup/database providers are going to start building the functionality into their systems.

 

:confused:

Edited by flyinghaggis
Posted
This is as stupid as the data protection act covering index cards or a filing cabinet. What happens with data your asked to removed but you are supposed to hold on to?

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...