Armanillo_RoK
New Contributor III
Hi there,
   I spent the last while building a metadata-driven GDPR retention and right-to-erasure framework on Databricks Unity Catalog.
 
The core decision: policy lives in a small set of governance tables (what's PII, retention rules, active legal holds, erasure requests), and a job engine just walks them. Adding a new table to the framework means inserting registry rows, not writing new code.
 
For base retention we adopted the new Auto-TTL feature, layered with a hold-aware override so litigation holds or open erasure requests can gate pure age-based expiry. RTBF requests hit redaction before physical purge, so we have a defensible "stopped processing this data on date X" answer well before storage cleanup runs.
 
Structure inspired by Snowflake-Labs' sfguide-data-retention-and-purge (Apache 2.0), adapted for Unity Catalog with automatic PII discovery and Auto-TTL added.
 
Still open: propagating an erasure request across systems where the same person shows up under different source-system keys. The framework assumes one entity, one key today. If you've solved that cleanly, I'd like to hear how.
 
Happy GDPRing!

Commodore 64 - Ninja crush 'em all
https://youtu.be/RBvhfVGMsLQ?si=OfwbqWeygGUd_qU5