A multinational corporation uses a cloud-based data lake to store aggregated analytics data. The security team needs to ensure that data subjects can exercise their right to erasure under GDPR, even when data is replicated across multiple cloud regions and stored in immutable backups. Which strategy best addresses this requirement?
Crypto-shredding makes data unrecoverable by destroying the unique encryption key, even if ciphertext remains in backups or replicas. This effectively satisfies the right to erasure because the data cannot be decrypted. It works across regions and immutable backups without needing to physically delete every copy.
Why this answer
Crypto-shredding is the most effective way to satisfy erasure requests when data is replicated and backed up immutably. By destroying the unique key for a data subject, the ciphertext becomes useless, achieving erasure without needing to locate and delete every copy. This approach is scalable and works across regions.
Exam trap
The trap here is assuming that deleting data from primary storage fulfills erasure, ignoring immutable backups and cross-region replicas.