Technical data life cycle
Automated retention
Each data type has a retention period and an expiry mechanism (TTL, scheduled job).
# /etc/cron.d/purge-sessions: daily purge of expired sessions
15 3 * * * app psql -c "DELETE FROM sessions WHERE expires_at < now() - interval '30 days';"
Soft vs hard delete: a deleted_at column destroys nothing. Plan a scheduled physical purge after the grace period.
Secure destruction
- Encryption + key destruction (crypto-shredding): destroying the key makes data unreadable; practical on SSDs and in the cloud.
- Physical media: certified erasure or destruction; overwriting is unreliable on SSDs.
- Cloud providers: obtain contractual confirmation of deletion.
- Backups: set an expiry cycle; document the delay between deletion and disappearance of copies.
Pseudonymization vs anonymization
| Pseudonymization | Anonymization | |
|---|---|---|
| Reversible | Yes (with the key or a cross-reference) | No |
| Legal status | Still PI | Out of scope if criteria are met |
| Example | user_id instead of name |
Aggregates with no possible re-identification |
Anonymization must be irreversible and serve serious and legitimate purposes (s. 23 and Anonymization Regulation). An unsalted email hash is not anonymization.