Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

I believe the GDPR allows a company to refuse (or delay) processing your request to delete their data about you if they have a legitimate reason, and being legally obligated to hold onto that data is one of the legitimate reasons. However, GDPR is a big law and I am not a European lawyer (I am neither, in fact), so I'm curious if my understanding is wrong. What section of GDPR are you thinking of and what exceptions does it have?


The GDPR regulation has some exceptions for legal requests and generally puts itself below local laws and regulations that specify further, to my knowledge, if you get a letter from the police/state that says some data is needed for a court case, you can safely ignore all deletion requests for that data until such time that the state/police request is no longer valid (ie, they copied it off your server).

However, once they have the data (and after asking the forensics team if it's okay) you can certainly follow up on the request and it's probably good manners to inform people that there is a legal obligation holding up the deletion of some data (unless the warrant prohibits that).


This again raises the issue of speech vs absence of speech. What if a cloud provider has applications that confirm deletions that are initiated by the user? A secret warrant prohibits disclosure of the warrant’s existence, but now we’re talking about a requirement to actively lie to users. I really don’t think that this hair-splitting.


Then you'll have to lie to the user. Simple as that.




Consider applying for YC's Fall 2026 batch! Applications are open till July 27.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: