Home/Labs/Crypto-Shred Erasure Lab
All 280 Labs
INTERACTIVE LAB🗑️

GDPR Crypto-Shredding vs Physical Deletion Lab (Interactive)

Delete one user from ten terabytes of immutable Parquet: rewrite the lake or shred the key. Compare decompress-filter-recompress cost in hours and dollars against an 8 ms UDEK deletion that renders Kafka, S3, and Glacier copies mathematically unreadable.

GDPR Erasure: Physical Rewrite vs Crypto-Shredding

User 942 clicks "Delete My Account". Their PII already lives in 10,000 immutable files. Choose how it dies.

Stores holding user 942

Key deletion latency

8 ms (KMS DELETE)

Erasure coverage

100%

9.9 TB immutable copies affected

Rewrite cost per request

$1638

× hundreds of daily deletions = 491.5k USD/mo

GDPR Art. 17 SLA

MET

one month, without corrupting analytics

State of user 942 per store

PostgreSQL primarySHREDDED — unreadable
Kafka event logSHREDDED — unreadable
S3 Parquet lakeSHREDDED — unreadable
Glacier archivesSHREDDED — unreadable

Crypto-shredding: legal erasure by key destructionDeleting the 32-byte UDEK_942 from the key vault turns every historical Kafka segment, Parquet file, and Glacier tape containing that user into AES ciphertext no one can ever produce again — EU data-protection authorities accept cryptographic erasure as permanent deletion. Cost: managing millions of UDEKs, and the terrifying property that an accidental key delete is unrecoverable data loss for a live user.

Pair shredding with residency: geo-partition the primary (CockroachDB PARTITION BY LIST (country_code) pinned to region=europe-west3, S3 CRR excluding EU buckets) so an EU erasure request never traverses US shards. Spotify runs exactly this pattern at petabyte scale — key delete in BigQuery's KMS sanitizes years of analytical history in milliseconds.

How It Works Under the Hood

GDPR Article 17 collides with append-only architecture: one user's rows are scattered through thousands of compressed Parquet files, Kafka segments, and Glacier tapes, where physical deletion means terabyte rewrites costing hours of Spark, real money per request, and pipeline corruption risk, still unable to touch tape. Crypto-shredding inverts the problem: PII is encrypted at ingest under a per-user data encryption key, so deleting that 32-byte key from the KMS converts every immutable copy into 2^256-hard ciphertext noise, recognized by regulators as permanent erasure, done in milliseconds with an auditable key-deletion event. The cost is architectural honesty: managing millions of UDEKs and accepting that a mis-deleted key is unrecoverable loss for a live user. Geo-partitioning (CockroachDB list partitions pinned to EU regions) keeps the whole problem inside its legal borders.

Core Architectural Principles

  • Rewrite mode prices decompress-filter-recompress time across workers and leaves immutable stores uncovered.
  • Shred mode deletes one UDEK (~8 ms) and flips every selected store to unreadable-ciphertext status.
  • Per-user keys at ingest are a precondition: plaintext data cannot be cryptographically erased after the fact.
Interview Round Script

When asked how GDPR deletion works with Kafka or Glacier backups, answer crypto-shredding verbatim: per-user encryption keys, delete the key, data becomes unreadable, regulators accept it. Then prove depth with the caveats, UDEK lifecycle management, irreversibility, and Article 25 design-time encryption, plus geo-partitioning for residency.

Key Trade-Offs

Crypto-shredding buys instant O(1) erasure across immutable storage but inherits a million-key estate where one wrong delete is unrecoverable.

Related Curriculum Chapter

Data Privacy & Compliance Architecture: GDPR, CCPA, & HIPAA

Read Full Chapter Blueprint

Explore More Interactive Labs

View All 280 Labs