I'm looking into the erasing of personal details to meet the requirements of Europe's GDPR regulations. Specifically, the right to erasure requirements under GDPR's article 17 – also known as the "right to be forgotten".
Obviously in Moqui we generally don't delete ContactMech or related records, rather we expire the PartyContactMech record. In addition, we disable parties rather than delete them. My understanding is that that is not sufficient in certain cases under these regulations.
My current train of thought has been towards deleting the party's Person or Organization entries, and then searching through existing and expired PartyContactMech records for the ContactMechs and associated addresses and phone numbers to completely delete them too.
Is that an acceptable solution, and/or perhaps I might not be understanding correctly why PostalAddress and so on is immutable?
Any insights on this much appreciated. Thanks.