Learn Labs
1. Trade-Offs in Data Systems Architecture

1.4 Data Systems, Law, and Society

Architecture is shaped by human and legal needs, not just technical ones.

Architecture is shaped by human and legal needs, not just technical ones.

  • GDPR (2018, EU) and CCPA (California) give people control and legal rights over personal data. The EU AI Act adds restrictions on how personal data can be used.
  • Automated systems make consequential decisions: who gets a loan or insurance, who gets a job interview, who is suspected of a crime. Social media changed news consumption → political opinion → election outcomes.
  • Legal requirements are reshaping system design foundations. GDPR's right to be forgotten (erasure on request) collides head-on with designs built on immutable append-only logs. How do you delete data in the middle of a file that is supposed to be immutable? How do you handle data already baked into derived datasets, like the training data of an ML model? These are unsolved engineering challenges.
  • Regulations deliberately don't mandate technologies (tech changes too fast) — they state high-level principles subject to interpretation. So there's no checklist for "GDPR-compliant architecture."

Cost-benefit of storing data must include: liability and reputational damage from a leak, legal costs and fines from non-compliance, and the fact that governments or police may compel you to hand data over. When data could reveal criminalized behavior (homosexuality in several countries; seeking an abortion in several US states), storing it creates real safety risks for users — travel to a clinic is revealed by location data, or even by a log of IP addresses over time.

Data minimization (Datensparsamkeit): decide some data is not worth storing and delete it. This runs directly counter to the "big data" philosophy of hoarding speculatively. It aligns with GDPR: personal data may be collected only for a specified, explicit purpose, cannot later be used for another purpose, and must not be kept longer than necessary.

Industry compliance analogues: PCI (payment card industry) with frequent independent audits; SOC 2 Type 2 for software vendors, also third-party audited.