Learn

Guides to PII, GDPR, and proving deletion.

Plain-English explainers and technical deep dives on personal data, the right to erasure, data subject access requests, retention, and how to delete customer data across a data warehouse — and prove it.


All guides

What is PII?

PII is any data that can identify a person. This guide explains direct vs. indirect identifiers, special-category data, and why it matters under GDPR and CCPA.

DSAR

A data subject access request (DSAR) lets people ask what data you hold about them. Learn GDPR timelines and how to answer without missing hidden copies.

Data retention

GDPR storage limitation means you cannot keep personal data forever. Learn how to set retention periods and build defensible deletion schedules.

Pseudonymization vs. anonymization

Anonymized data falls outside GDPR; pseudonymized data does not. Why encryption and crypto-shredding are pseudonymization, not anonymization.

Ghost data

Ghost data is personal data that landed in your warehouse without being registered or governed. Learn why it's an audit risk and how to detect it early.

Delete PII in BigQuery

BigQuery DML deletes are slow, leave copies in time travel, and produce no evidence. Learn a crypto-shredding approach that deletes and proves erasure.

Delete PII in Snowflake

Snowflake DELETEs leave copies in Time Travel, Fail-safe, and zero-copy clones, with no evidence. Learn a crypto-shredding approach that proves erasure.

CCPA vs. GDPR

Both laws give consumers a right to delete personal data, but the scope, exceptions, and proof burden differ. A side-by-side guide for compliance teams.

dbt PII package

Build a PII registry, field-level lineage map, and shred-readiness verdicts from dbt graph metadata — zero bytes scanned. Fail CI on undeclared PII.

Crypto-shredding

Crypto-shredding destroys the encryption key so every row that referenced it becomes unreadable instantly — no row scans, no missed copies.

After you sign up

A plain-language walkthrough of the loop every Chameleon customer runs: protect data on ingest, declare PII, run a deletion request, get signed proof.

GDPR right to erasure

Article 17 requires complete, verifiable deletion of personal data on request. Learn what auditors check and how to produce proof that survives review.