Backups and the right to be forgotten in the GDPR: An uneasy relationship

被引:23
|
作者
Politou, Eugenia [1 ]
Michota, Alexandra [2 ]
Alepis, Efthimios [1 ]
Pocs, Matthias [3 ]
Patsakis, Constantinos [1 ]
机构
[1] Univ Piraeus, Dept Informat, 80 Karaoli & Dimitriou Str, Piraeus 18534, Greece
[2] Univ Piraeus, Dept Digital Syst, Piraeus, Greece
[3] Stelar Secur Technol Law Res, Hamburg, Germany
基金
欧盟地平线“2020”;
关键词
GDPR; Backup; Right to be Forgotten; DATA PROTECTION REGULATION;
D O I
10.1016/j.clsr.2018.08.006
中图分类号
D9 [法律]; DF [法律];
学科分类号
0301 ;
摘要
The recent enforcement of the GDPR has put extra burdens to data controllers operating within the EU. Beyond other challenges, the exercise of the Right to be Forgotten by individuals who request erasure of their personal information has also become a thorny issue when applied to backups and archives. In this paper, we discuss the GDPR forgetting requirements in respect with their impact on the backup and archiving procedures stipulated by the modern security standards. We specifically examine the implications of erasure requests on current IT backup systems and we highlight a number of envisaged organizational, business and technical challenges pertained to the widely known backup standards, data retention policies, backup mediums, search services, and ERP systems. (C) 2018 Eugenia Politou, Alexandra Michota, Efthimios Alepis, Matthias Pocs, Constantinos Patsakis. Published by Elsevier Ltd. All rights reserved.
引用
收藏
页码:1247 / 1257
页数:11
相关论文
共 50 条