# ElasticSearch deleting data to comply with the GPDR

**URL:** <https://discuss.elastic.co/t/elasticsearch-deleting-data-to-comply-with-the-gpdr/193755>\
**Category:** Elasticsearch\
**Created:** [August 5, 2019, 8:42am UTC](https://discuss.elastic.co/t/elasticsearch-deleting-data-to-comply-with-the-gpdr/193755 "2019-08-05T08:42:11Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![notStan](https://avatars.discourse-cdn.com/v4/letter/n/a8b319/32.png) [@notStan](https://discuss.elastic.co/u/notStan)\
**Post date:** [August 5, 2019, 8:42am UTC](https://discuss.elastic.co/t/elasticsearch-deleting-data-to-comply-with-the-gpdr/193755/1 "2019-08-05T08:42:11Z")

</div>

Hello.  
I have a question/concern about the workings of Elasticsearch and the GPDR. In the GPDR you have the right to be forgotten. Let's say I am a server owner and I have some personal information, which the owner has requested to remove. When I mark the data for removal, the data isn't immediately removed from the disk, but removed at searchtime later. Can this be a problem when looking at GPDR compliance?  
Technically if you mark something as removed, then turn off the cluster for 1 year, you could still read the data from the disk which was supposed to be removed. Where can I find specific information about this topic?

---

<div class="post-metadata">

**Author:** ![notStan](https://avatars.discourse-cdn.com/v4/letter/n/a8b319/32.png) [@notStan](https://discuss.elastic.co/u/notStan)\
**Post date:** [August 13, 2019, 2:28pm UTC](https://discuss.elastic.co/t/elasticsearch-deleting-data-to-comply-with-the-gpdr/193755/2 "2019-08-13T14:28:11Z")

</div>

Bump.  
I'm unsure if I've looked at this correctly. Can anyone have a look at the question?

---

<div class="post-metadata">

**Author:** ![DavidTurner](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/davidturner/32/22453_2.png) [@DavidTurner](https://discuss.elastic.co/u/DavidTurner)\
**Post date:** [August 26, 2019, 1:54pm UTC](https://discuss.elastic.co/t/elasticsearch-deleting-data-to-comply-with-the-gpdr/193755/3 "2019-08-26T13:54:00Z")

</div>

The following is not legal advice; I am not a lawyer and certainly not your lawyer, so please seek proper help before taking any action based on this response.

The question of "soft" data deletion and its interaction with the GDPR is not unique to Elasticsearch. Even if you deleted some files from disk you may still be able to recover their contents at a later date. It is also usually impractical to remove all traces of a data subject from historical backups. The GDPR doesn't really define what it means to "erase" some data, and there is a school of thought that it's sufficient simply to have a policy that forbids recovery techniques like the one you describe.

---

<div class="post-metadata">

**Author:** ![notStan](https://avatars.discourse-cdn.com/v4/letter/n/a8b319/32.png) [@notStan](https://discuss.elastic.co/u/notStan)\
**Post date:** [August 28, 2019, 1:08pm UTC](https://discuss.elastic.co/t/elasticsearch-deleting-data-to-comply-with-the-gpdr/193755/4 "2019-08-28T13:08:42Z")

</div>

Thank you for your extensive answer. I'll do the additional research to ensure we comply with the law.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [September 25, 2019, 1:08pm UTC](https://discuss.elastic.co/t/elasticsearch-deleting-data-to-comply-with-the-gpdr/193755/5 "2019-09-25T13:08:44Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
