Earlier quoted context omitted.
How is this done in practice? Do you all just do backups different? What percentage of deleted data still exists, obfuscated as user1029387 in the tables? With "deleted" boolean column obviously set to true. The very idea that it's possible to delete all your data from any service not running everything on tmpfs is funny to me.
Its not even funny, its just dangerously naïve, on hacker news from all. I can bet half of my salary that absolutely none of those records are deleted forever, and even anonymization is probably very soft and reversible, if done at all. I work at a bank, one of major ones. We have various regulations stating to keep client records for 5 years. We have trainings that specifically say that we shouldn't keep client reco…
Also i "permanently" deleted a facebook account 2 years ago, and through a quirk on a cellphone facebook immediately brought the account back like it had never been deleted. I issued another "permanent delete" for that account a week ago, but i bet dollars to doughnuts in 5 weeks i will still be able to "oops i forgot my password, send me an SMS" will reactivate the account again.
If facebook can't or won't do it, i don't really think anyone handles this correctly.
Except people like me that store everything that users upload in tmpfs, and whenever i feel like it, i bounce the box. Good luck recovering any PII from that system. Unfortunately it doesn't have access control (there is no access to the system - that is, ssh, login, shell, whatever - from outside.), so i can't claim hipaa compliance. That and it doesn't log, so after a bounce i can't even verify who did what.
Most users won't stand for this kind of thing, but the users that can, depend on my random reboots if they forget a delete key (usually reloading the tab will "forget" the delete key.)