Data Privacy — Professional¶
GDPR defines purpose limitation and data-subject rights; envelope encryption systems separate data and key control; Apache Iceberg and Delta Lake snapshots show why logical deletion does not immediately remove physical files. At scale, lineage, backups, derived data, and vendor propagation dominate.
Design and operations checklist¶
- Maintain data inventory, purpose, owner, and residency.
- Minimize and segregate sensitive data.
- Control access and key lifecycle.
- Implement retention, deletion, and legal hold.
- Audit vendors and recovery paths.
- Test rights requests and breach response.
Test yourself¶
- Design verified deletion across backups and a lakehouse.
- How can derived features retain personal information?
- Which key design supports regional isolation?
- What evidence supports a regulator audit?
Further reading¶
- GDPR principles and data-subject rights.
- NIST Privacy Framework.
- Cloud KMS envelope-encryption guidance.