drx - Fotolia
The General Data Protection Regulation, which went into effect earlier this year, is designed to ensure the responsible handling of data pertaining to EU residence. One of the trickier parts regarding GDPR is the right to be forgotten and backups.
According to the GDPR, an EU resident can request the removal of his or her data from a company's IT systems. Removal requests can potentially be inconvenient, but there isn't anything especially challenging about removing a record from a database. Backups, however, pose a much tougher issue.
Imagine that an organization creates a full backup of a particular database. The next day, the organization receives a request to remove a certain individual's records from that database. Even if the company complies with the request, the records will still exist within the previous day's backups.
The right to be forgotten and backups present compliance problems. Backup software generally does not have the ability to interact with the data that it is backing up. If a database is included in a backup job, the backup software will back up that database without regard for the data within it. In other words, the backup software neither knows nor cares whether or not the data is fully GDPR compliant.
It would theoretically be possible for a backup vendor to create a tool to remove certain database records from a backup. However, this workaround for the right to be forgotten and backups would present at least two problems:
- Having a tool to purge certain data from a backup could undermine the integrity of the backup. Just imagine all of the ways that such a mechanism might be exploited by malware or by a rogue employee. Someone with bad intent might use a data removal feature to remove all of the data from a backup.
- The tool wouldn't scale well. For example, if a company uses tape backup and has 50 cartridges with old backups, would it really be realistic to expect the company to remove data from all of those tapes? Never mind that such an operation might corrupt the tape contents in the process.
One approach for companies regarding the right to be forgotten and backups is to notify customers that their right may not apply to backups. In doing so, however, a company would need to find a way to remove those who wish to be forgotten in the event of a data restoration.
Dig Deeper on Data backup security
Related Q&A from Brien Posey
Your organization could accomplish Microsoft Exchange backup with native protection or through third-party offerings. It all depends on what you are ... Continue Reading
Edge data storage backup has become a key component of data protection plans. File sync-and-share software can complement this important backup ... Continue Reading
Some older file formats continue to find life in the enterprise decades after they were developed for their versatility -- in certain situations. Continue Reading