• [^] # Re: Sauvegarde et RGPD

    Posté par (Mastodon) . En réponse au journal Reddit a subi une attaque informatique. Évalué à 10. Dernière modification le 13 août 2018 à 13:52.

    À priori tant que les données utilisateurs sont purgées de la base "active", que les procédures de restoration excluent (ou prennent en compte un cleanup) des données des utilisateurs ayant demandés l'oubli et que ceux-ci sont informés de la durée de rétention définie, il n'y a pas d'obligation à détruire les backups avant la fin de ladite rétention:

    The GDPR is open to interpretation, so we asked an EU Member State supervisory authority (CNIL in France) for clarification. CNIL confirmed that you’ll have one month to answer to a removal request, and that you don’t need to delete a backup set in order to remove an individual from it. Organizations will have to clearly explain to the data subject (using clear and plain language) that his or her personal data has been removed from production systems, but a backup copy may remain, but will expire after a certain amount of time (indicate the retention time in your communication with the data subject). Backups should only be used for restoring a technical environment, and data subject personal data should not be processed again after restore (and deleted again).

    http://blog.quantum.com/backup-administrators-the-1-advice-to-deal-with-gdpr-and-the-right-of-erasure/#.Wv7qy0xFwy9

    When individuals request the erasure of their personal data, controllers should be transparent with them about what will happen to the backups:

    Primary instances of their data in production systems will be erased with all due speed
    Their personal data may reside in backup archives that must be retained for a longer period of time – either because it is impractical to isolate individual personal data within the archive, or because the controller is required to retain data longer for contractual, legal or compliance reasons.
    The individual can be assured that their personal data will not be restored back to production systems (except in certain rare instances, e.g., the need to recover from a natural disaster or serious security breach). In such cases, the user’s personal data may be restored from backups, but the controller will take the necessary steps to honor the initial request and erase the primary instance of the data again.
    Backup archives containing personal data will be protected with strong encryption, so that even if criminals were able to steal the archive, its contents would remain useless to them.
    Retention rules have been put in place so that personal data in backup archives is retained for as short a time as necessary before being automatically deleted.
    Records of all data subject requests regarding their personal data will be retained, as will audit logs that record all activities on backup archives containing personal data. This means that the user can be confident that their personal data has been backed up in accordance with GDPR principles of security by design and by default, as well as data minimization, and that their rights, including the right to be forgotten, have been honored.

    https://www.acronis.com/en-us/blog/posts/backups-and-gdpr-right-be-forgotten-recommendations

    Alors certe dans ce cas précis il y'a à priori eu une erreur de faite car à moins qu'il y'ait des besoins légaux je ne vois pas l'intérêt pour un site comme Reddit de garder des archives aussi longues et en tout cas pas sur des serveurs "en ligne".

    Après, faire une erreur ne veut pas dire qu'on "trompe" les utilisateurs.