Deletion commitments become difficult when identity is copied into many analytical paths.
Teams must remove what cannot remain while preserving the aggregate history that still serves legitimate analysis.
Who you’d be doing this for
“I need a deletion request to mean deleted everywhere—not just in the first system we check.”
Nikos Christodoulou · Data Privacy Product Manager
Leads privacy readiness for a regulated customer that needs deletion obligations reflected in its product analytics workflows.
What is at stake
Replay tests show deletion finishing at the source ledger while stale results linked to identity stay reachable through a few cohort and cache paths. You have to settle tombstone versus rewrite before the storage migration starts.
Why it isn’t already fixed
Every obvious fix costs something else. That’s the part you’d have to decide.
- deletion certainty vs. analytical continuity
- physical purge vs. derived-data integrity
- migration commitment vs. incomplete dependency evidence
- privacy assurance vs. customer workflow stability
Why Amplitude
At Amplitude, this often matters because behavioral insight depends on both rigorous data controls and reliable analytical continuity.
Written with these in mind
Not your kind of problem? 6 more at Amplitude, or browse every organization.
This is the setup. The work is inside.
Running it puts you in the room: the full situation and its constraints, stakeholders who push back in their own words, and the decisions that are yours to make. What you produce becomes a Day One Plan — work you can show someone instead of describing.