▲ | mrkeen 4 days ago | |||||||
What are the tricks for investigating customers' data that don't violate privacy? | ||||||||
▲ | hdjrudni 4 days ago | parent | next [-] | |||||||
IANAL but two ideas come to mind: 1) What I do for my small app is make a copy of the prod database and randomize nearly all the data. All the PII, phone numbers, email addresses, names, etc. All the relationships between the data are preserved so I can usually still repro whatever issue. I don't know if this would satisfy the lawyercats but I think it's a decent start. 2) If I had more time/money I'd build a specialized "Customer Support" app that gives limited access to customer data. Customer would have to provide consent before support worker could access their data, and this would be logged/audited. No one would have direct access to the prod DB. | ||||||||
| ||||||||
▲ | carlhjerpe 4 days ago | parent | prev [-] | |||||||
https://postgresql-anonymizer.readthedocs.io/en/stable/ can be helpful, though I don't know if it scales to the parents standards. |