Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Yes and no. PII needs to be removed. The rest of the data needs to be anonymized. Right?


But an email is PII so clearly this would breach GDPR.


Keep a hash instead of the original email address?


Whatever for? Just delete it. Keep the account tombstoned so its name can't be reused. Keep what content you can and want. Delete the PII and any metadata you're contractually and/or legally required to.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: