speckytecky Posted June 19, 2018 Posted June 19, 2018 Today we had a hard drive swapped out under warranty. The server manufacturer is looking for the old hard drive to be collected by their courier tomorrow and returned to them. Clearly, there is no chance of securely wiping the disk before return and their policy stipulates no drilling or dismantling. The hard drive was physically HOT when I hot-swapped it so I'm sure it has blown but what advice is there coming from this Forum re GDPR implications of returning it, as it is, please?
googlemad Posted June 19, 2018 Posted June 19, 2018 HP keep nagging me to return a faulty SAN hard drive, I just told them they could have the ashes if they wanted but they didn't seem very interested in that idea! Don't get why they are so keen to have the old one back anyway, for starters it is only a 600GB and even then a 3.5" form factor which they no longer even provide as replacement! (You just get a 3.5" sized caddy with a 2.5" drive these days!) 1
FN-GM Posted June 19, 2018 Posted June 19, 2018 Dell will let you keep them. We encrypt all our server drives so if we are in this situation it wouldn't be a huge problem. 1
jmak Posted June 19, 2018 Posted June 19, 2018 This thread might move me towards the camp of encrypting server hard drives. I'd say there is a data protection issue - both under the old DPA and under GDPR. I'd suggest that you either say no and run the risk they take you to court over a knackered hard drive or insist that before you hand over the disk, you need a data transfer agreement and then a data destruction certificate within a time period you specify. And make it clear that you will report them to the ICO if they don't produce the certificate. 1
djrscally Posted June 20, 2018 Posted June 20, 2018 This thread might move me towards the camp of encrypting server hard drives. I'd say there is a data protection issue - both under the old DPA and under GDPR. I'd suggest that you either say no and run the risk they take you to court over a knackered hard drive or insist that before you hand over the disk, you need a data transfer agreement and then a data destruction certificate within a time period you specify. And make it clear that you will report them to the ICO if they don't produce the certificate. I think that this is the right answer. By taking your drive with data on they become a processor, and you need some agreement with them that they'll handle that data properly. 1
enjay Posted June 20, 2018 Posted June 20, 2018 I think that this is the right answer. By taking your drive with data on they become a processor, and you need some agreement with them that they'll handle that data properly. And handling it properly does NOT include giving it to a courier! 1
Koldov Posted June 20, 2018 Posted June 20, 2018 (edited) Dell will let you keep them. The following is a recent direct quote from Dell... > Our records do not show the defective exchange part being returned to Dell. Per your Warranty Agreement, all defective parts replaced under warranty are required to be returned. Parts that are not returned to Dell could be subject to a Service Tag Warranty hold. Should I have just said, "no... sorry.... GDPR..." ? Also, forgive the ill-informed question - but does GDPR take into account the risk/likelihood of a data being extracted from a random damaged server disk (from a RAID set) returned to DELL, being stolen from their processing plant, being put through hours/days of some sort of data retrieval, reading information from the reconstructed (password protected) SIMS SQL database, then parsing out all the info, to find out little Johnny has a free school meal.... I'm sure it's all possible, but is it probable? Or is the fact that it's possible putting the responsibility on me to prevent it? I sent the disk back (with a courier)... How worried should I be? What do they actually do with these disks anyway? Does anybody actually know? Does anybody really see someone as big as Dell (with the number of defective drives they must have returned) actually wiping each drive and producing a data destruction certificate? Edited June 20, 2018 by Koldov 1
enjay Posted June 20, 2018 Posted June 20, 2018 I can't imagine they're wiping the disks and re-using them but they might want them back so people don't use false warranty calls as ways of getting more space or spare drives. As for the risk/likelihood, yes GDPR is all about risk management - how likely is it someone would intercept the parcel from the courier and go through the steps you list for recovering the data? If someone did do that, what would be the impact? You're right - it certainly seems unlikely someone would do all that, but if they did, they would have access to a lot of information since the disk evidently came from your SIMS server. As the disk is going via courier not post and to a company like Dell, I'd be tempted to say it was an acceptable risk but it is something you should document, including why you took the decision you did, in case you need to justify it to the ICO should the extremely unlikely happen. If, as I suspect, Dell only want the disk back to ensure you're not trying to get a free upgrade, you could offer to destroy it (big magnet followed by Fun With Drills) and return them the carcass. The data is even harder to reach, and Dell know it was genuinely dead. 2
Koldov Posted June 21, 2018 Posted June 21, 2018 Well, I have fired this email off to them.... Hi, Can you please confirm you have received the part in question and this issue is now concluded? Also in light of recent GDPR legislation, (as this is a server disk with the possibility of it containing personally identifiable data) I will require confirmation of data destruction. Many thanks in advance. I'd say there is a data protection issue - both under the old DPA and under GDPR. . So..... possibly should have been doing this all the time... But hey I put GDPR in there now so that should work... right? Wishing I'd seen this thread a few weeks ago now.... 1
nicholab Posted June 21, 2018 Posted June 21, 2018 If it is part of a hardware raid array is the data readable? I understand if it use a a file system like zfs this might be different.
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now