{"id":8247,"date":"2019-01-07T16:35:37","date_gmt":"2019-01-07T21:35:37","guid":{"rendered":"https:\/\/www.thesslstore.com\/blog\/?p=8247"},"modified":"2020-11-24T09:40:09","modified_gmt":"2020-11-24T14:40:09","slug":"deleting-data-for-gdpr-could-encryption-do-the-trick","status":"publish","type":"post","link":"https:\/\/www.thesslstore.com\/blog\/deleting-data-for-gdpr-could-encryption-do-the-trick\/","title":{"rendered":"Deleting Data for GDPR: Could encryption do the trick?"},"content":{"rendered":"\n<h2 class=\"wp-block-heading\">A new article in CIO magazine proposes an outside-the-box method for GDPR\ndata deletion. Here\u2019s why that\u2019s not a good idea\u2026<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">After <a href=\"https:\/\/www.thesslstore.com\/blog\/preparing-gdpr-introduction-1\/\">writing exhaustively about GDPR compliance<\/a> for the better part of 2018, we figured why not kick 2019 off with a little more discussion about the EU\u2019s General Data Protection Regulation. Specifically the \u201c<a href=\"https:\/\/www.thesslstore.com\/blog\/right-to-be-forgotten\/\">right to erasure<\/a>,\u201d and what that actually portends for most organizations.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Let\u2019s be honest, while the GDPR\u2019s right to be forgotten\/right to erasure are a big win on the side of personal privacy, from a business standpoint this is a huge pain in the rear. I know this because I help handle deletion requests for The SSL Store and its subsidiaries. I see it first-hand. And generally the folks requesting the deletion are less than polite. They\u2019re often disgruntled and generally threaten to be litigious.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The point I\u2019m making is that despite what it does for personal privacy, these edicts are not business-friendly. And many companies and organizations are actively looking for better ways to comply with the rights afforded by the GDPR while minimizing the work that must be done on their end. <\/p>\n\n\n\n<p class=\"wp-block-paragraph\">So today we\u2019re going to look at the GDPR\u2019s right to erasure,\nwhether there could be an encryption solution and then we\u2019ll finish by\ndiscussing why that solution would likely be a bad idea. <\/p>\n\n\n\n<p>Let\u2019s hash it out.<\/p><span id=\"newline\"><\/span>\n\n\n\n<h2 class=\"wp-block-heading\">The GDPR\u2019s Right to Erasure<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Let\u2019s start out by defining <a href=\"https:\/\/www.thesslstore.com\/blog\/right-to-be-forgotten\/\">what the GDPR says about the right to be forgotten\/the right to erasure<\/a> and what organizations must do to comply with it.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Let\u2019s start with the nomenclature, <a href=\"https:\/\/gdpr.algolia.com\/gdpr-article-17\">Article 17 of the GDPR<\/a>, which lays out the rights of the data subject, refers to it as the \u201cRight to Erasure (\u2018right to be forgotten\u2019).\u201d So the two are basically interchangeable.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Article 17, as well as some advice from Articles 12 &amp; 23,\nplus recitals 55 &amp; 56, outline the requirement for organizations to erase\ninformation at the behest of \u201cdata subjects.\u201d<\/p>\n\n\n\n<blockquote class=\"wp-block-quote is-layout-flow wp-block-quote-is-layout-flow\"><p>1.&nbsp;&nbsp;&nbsp;The data subject shall have the right to obtain from the controller the erasure of personal data concerning him or her without undue delay and the controller shall have the obligation to erase personal data without undue delay where one of the following grounds applies:<\/p><\/blockquote>\n\n\n\n<p class=\"wp-block-paragraph\">Now, those grounds (and I\u2019ll summarize for the sake of brevity)\nare:<\/p>\n\n\n\n<ul class=\"wp-block-list\"><li>The data is no longer necessary<\/li><li>Data subject withdraws consent for processing<\/li><li>The organization can\u2019t satisfy its reason\n(legitimate interests) for processing<\/li><li>The data was unlawfully processed<\/li><li>Erasure is required to comply with a legal\nobligation<\/li><li>Consent was wrongfully obtained from a minor<\/li><\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">When a data subject appeals to your organization for erasure\nof their personal data on one of those grounds, and you don\u2019t have a superseding\nreason to keep it, not only are you obligated to delete it, but you\u2019re also\nobligated to notify any partners you may have shared it with to delete it, too.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Obviously, this is not a productive use of company time and\nwhat many data subjects don\u2019t realize is that deleting data from any website,\nlet alone from a multi-headed corporate hydra is not all that simple. Where is\nall the data stored? What databases have copies? Is there any of this data that\nwe are obligated legally or by industry standards to keep?<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">It\u2019s not as easy as just pulling up a profile and clicking \u201cdelete.\u201d\n<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">And unfortunately, not much has been done to define exactly\nhow an organization should go about an erasure. This is, in my opinion, one of\nthe greatest weaknesses of the GDPR. In its earnest attempt to have the GDPR be\nuniversally applicable the EU has failed to properly define certain aspects of\nits new regulation that really do require some specifics. <\/p>\n\n\n\n<p class=\"wp-block-paragraph\">And that has led to some rather interesting ideas on how to\ndo it in the least disruptive way possible.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Don\u2019t encrypt your data and throw away the key instead of deleting it<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">In an <a href=\"https:\/\/www.cio.co.nz\/article\/651002\/7-business-analyst-certifications-advance-your-analytics-career\/\">article of New Zealand\u2019s edition of CIO Magazine<\/a>, a group of lawyers discuss how the GDPR\u2019s right to erasure jives with the immutability of data recorded on a blockchain. <\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Now, I\u2019ll preface with this: blockchain is an incredibly\ninteresting technology that is far less useful than a lot of the marketing and\ncrypto bros out there want you to believe. It is not a panacea. It can\u2019t solve\nany business problem. And most of the people who mention it all the time couldn\u2019t\nexplain it to you in a concise way to save their lives. <\/p>\n\n\n\n<p class=\"wp-block-paragraph\">That little outburst aside, Russell McVeagh (a prominent New Zealand-based law firm) lawyers Liz Blythe, Michael Taylor, Rachel O&#8217;Brien and Zoe Sims came up with a rather unique solution to the problem: how do you satisfy the GDPR\u2019s right to erasure requirement on a blockchain?<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Their answer: encryption. <\/p>\n\n\n\n<blockquote class=\"wp-block-quote is-layout-flow wp-block-quote-is-layout-flow\"><p>Could personal data stored on a blockchain be effectively &#8216;deleted&#8217; by <a href=\"https:\/\/www.thesslstore.com\/blog\/12-enterprise-encryption-key-management-best-practices\/\">encrypting it and then destroying the private key<\/a> so it can never be read? There is currently no firmly established answer, but there are reasons to be hopeful that this would be an acceptable solution.<\/p><\/blockquote>\n\n\n\n<p class=\"wp-block-paragraph\">The reasons they offer are that (a.) it would be ironic if\nGDPR thwarted the \u201cpromise of blockchain,\u201d (b.) as mentioned earlier the GDPR \u201cis\nvague as to when exactly personal data is \u201cerased,\u201d\u201d and (c.) \u201cthe concept of\nencryption is already recognised [sic] in the GDPR.\u201d<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Now, in fairness they also offer three points of caution, centering around logistics, the patchwork of legal regulations in various jurisdictions and the threat of the future. <\/p>\n\n\n\n<p class=\"wp-block-paragraph\">And I applaud the unorthodox thinking that led to such a unique approach.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">But this is a bad idea.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">If, as so many politicians in Western nations have called for, encryption that makes use of backdoors or key escrow is \u201c<a href=\"https:\/\/www.thesslstore.com\/blog\/deputy-attorney-general-rod-rosenstein-responsible-encryption\/\">responsible encryption<\/a>,\u201d encrypting something and then purposely deleting the key so it can never be decrypted would probably be \u201cirresponsible encryption.\u201d <\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Frankly, if you\u2019re looking for a purely one-way process the\nbetter answer might be to hash the data, but encrypting it is definitely not\nthe way to go.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">And the reason for that is in their final \u201cnote of caution.\u201d<\/p>\n\n\n\n<blockquote class=\"wp-block-quote is-layout-flow wp-block-quote-is-layout-flow\"><p>3. In theory, any type of encryption can be broken given enough time, energy and processing power. What is considered secure today may not be secure in the future. Merely encrypted data is therefore at risk \u2013 and working out the nature and extent of that risk will be an important part of the discussion.<\/p><\/blockquote>\n\n\n\n<p class=\"wp-block-paragraph\">That is 100% true, if a little bit understated. Most of our current cryptosystems will be <a href=\"https:\/\/www.thesslstore.com\/blog\/post-quantum-encryption\/\">under immediate threat from quantum computing<\/a> when it becomes viable in about a decade. RSA is already facing challenges from various exploits, <a href=\"https:\/\/www.thesslstore.com\/blog\/bleichenbachers-cat-rsa-key-exchange\/\">it\u2019s already ill-advised to use it for key generation<\/a>, and it\u2019s really only a matter of time before we have to discard it entirely.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">What\u2019s ultimately going to be needed if there\u2019s any possibility for this idea to be viable are post-quantum cryptosystems. And there is some work being done on that front. Organizations like ISARA are hard at work developing post-quantum or quantum-proof encryption and we\u2019re already seeing some of the fruit of that labor in its <a href=\"https:\/\/www.thesslstore.com\/blog\/quantum-safe-encryption-digicert\/\">partnership with DigiCert<\/a>, where they\u2019re creating digital certificates for IoT devices with both a standard cryptosystem and a post-quantum one to ensure the long-term health of the devices they\u2019re installed on.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">We would need to consider something similar for this to\nwork. And even then, there will be a finite time before those cryptosystems are\ncompromised. There will likely never be a completely unbreakable cryptosystem,\nand that itself is the fatal flaw with this suggestion.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Because if anyone were to try this method \u2013 encrypting data\nto delete it and then throwing away the key \u2013 they would really just be\ncreating a treasure trove of data to mine once the cryptosystem that was used\nis compromised. <\/p>\n\n\n\n<p class=\"wp-block-paragraph\">You\u2019re not really deleting it, you\u2019re just deleting it \u201cfor\nnow.\u201d <\/p>\n\n\n\n<p class=\"wp-block-paragraph\">That\u2019s not really in the spirit of the regulation and it\u2019s also not a good idea from a compliance standpoint. As much as it stinks, just delete the data (or come up with a bulletproof reason not to). Just don\u2019t encrypt it and throw away the key or you\u2019re only inviting trouble down the line.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><em>As always, leave any comments or questions below&#8230;<\/em><\/p>\n\n\n\n<figure class=\"wp-block-image\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"267\" src=\"https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2018\/08\/bigstock-222348568-1024x267.jpg\" alt=\"Hashed Out by The SSL Store is the voice of record in the SSL\/TLS industry.\" class=\"wp-image-7276\" srcset=\"https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2018\/08\/bigstock-222348568-1024x267.jpg 1024w, https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2018\/08\/bigstock-222348568-300x78.jpg 300w, https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2018\/08\/bigstock-222348568-768x200.jpg 768w, https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2018\/08\/bigstock-222348568.jpg 1559w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/figure>\n","protected":false},"excerpt":{"rendered":"<p>A new article in CIO magazine proposes an outside-the-box method for GDPR data deletion. Here\u2019s why that\u2019s not a good idea\u2026 After writing exhaustively about GDPR compliance for the better&#8230;<\/p>\n","protected":false},"author":6,"featured_media":8249,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"inline_featured_image":false,"footnotes":"","tve_updated_post":"","tve_custom_css":"","tve_user_custom_css":"","tve_globals":{},"tcb2_ready":0,"tcb_editor_enabled":0,"tve_landing_page":"","_tve_header":"","_tve_footer":""},"categories":[130],"tags":[240],"class_list":["post-8247","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-everything-encryption","tag-quantum-computing","post-with-tags"],"views":16042,"jetpack_featured_media_url":"https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2019\/01\/bigstock-Pencil-Eraser-Pencil-Eraser-R-156224015.jpg","_links":{"self":[{"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/posts\/8247","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/users\/6"}],"replies":[{"embeddable":true,"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/comments?post=8247"}],"version-history":[{"count":0,"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/posts\/8247\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/media\/8249"}],"wp:attachment":[{"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/media?parent=8247"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/categories?post=8247"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/tags?post=8247"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}