Removing data everywhere.
WHY IT IS HARD
Data spreads to every system it was sent to.
WHAT TO KNOW BEFORE YOU CAN DELETE
Where it went.
WHAT THAT REQUIRES
A record of every recipient.
WHAT TO BUILD
A process removing a person's data from every connected system.
WHAT IT MUST COVER
Your own database Backups, or a policy about them Caches Analytics External providers Logs Files
WHY LOGS ARE FREQUENTLY MISSED
They contain far more than people assume.
WHAT TO DO ABOUT BACKUPS
Decide and document: usually, they expire rather than being edited.
WHY
Editing backups is impractical and risks corrupting them.
WHAT TO STATE
That deletion applies to live systems, with backups expiring within a stated period.
WHAT TO ASK PROVIDERS
How deletion is requested, and how long it takes.
WHAT TO CHECK
That it actually happened.
WHAT TO RECORD
Every deletion request, and its completion.
WHY
You may need to demonstrate compliance.
WHAT TO BUILD INTO INTEGRATIONS FROM THE START
A deletion signal, propagated like any other event.
WHY FROM THE START
Retrofitting it across many systems is far harder.