Information has been permanently deleted, for small values of permanently

原始链接: https://devblogs.microsoft.com/oldnewthing/20250625-01/?p=111308

As part of a periodic purge of unused online accounts, I deleted my account from a company ten months ago. Let’s call that company Contoso. I received a confirmation that said, “Your personal information and items associated with your account have now been deleted. This action is permanent and cannot be reversed.” Yesterday, I got an email from Contoso informing me that they have updated their Privacy Policy. So I guess their “confirmation” of “permanent” and “irreversible” deletion of my personal information was premature, seeing as they still have my email address.

The Hacker News thread discusses the complexities of data deletion, spurred by a Microsoft employee's experience receiving a confirmation email after supposedly deleting his account. Users express skepticism that data is ever truly deleted due to backups, legal requirements, and potential negligence. Solutions like encrypting user data with user-specific keys are considered, but these also face challenges during backup processes. GDPR is mentioned as a regulation that requires companies to have a verifiable data deletion strategy, but enforcement and verification remain difficult. Some suggest editing data instead of deleting it, while others propose end-to-end encryption with keys held in secure enclaves for verifiable deletion. The discussion highlights the tension between user expectations of complete data erasure and the practical and legal constraints faced by companies. Some argue that companies should be transparent about what data is retained and why, while others acknowledge that simplified customer-facing wording is often preferred over complex legal explanations.
相关文章

原文

As part of a periodic purge of unused online accounts, I deleted my account from a company ten months ago. Let’s call that company Contoso. I received a confirmation that said, “Your personal information and items associated with your account have now been deleted. This action is permanent and cannot be reversed.”

Yesterday, I got an email from Contoso informing me that they have updated their Privacy Policy.

So I guess their “confirmation” of “permanent” and “irreversible” deletion of my personal information was premature, seeing as they still have my email address.

联系我们 contact @ memedata.com