Background
Part of data handling and GDPR compliance requirements and best practices
Goal
What questions does this ticket need to answer?
- What encryption at rest options exist for our DB?
- How would this impact the various teams' operations?
- How would that go hand in hand with our current process and operations, e.g., (data anonymization, deletion, etc. )
- What's the performance/latency impact?
- How would that change our testing process, if at all?
- What's the migration path for existing data?
- Key management approach?
Scope
- Explicitly out of scope: implementation, rollout, code changes
- In scope: research, POC/spike code if needed, cost/performance benchmarks, vendor doc review
Acceptance Criteria
- A written recommendation covering the recommended approach, tradeoffs, estimated effort, risks, rollback/migration plan.
- Answers to open questions above
Follow-up tickets created for actual implementation