Apache Druid and Imply Best Practices for GDPR and CCPA Compliance

Jan 08, 2020
Rob Meyer

If you are using Apache Druid to analyze customer-oriented data you are probably familiar with the General Data Privacy Regulation (GDPR), which went into effect May 25, 2018. However, you may be less familiar with a new law, the California Consumer Privacy Act (CCPA), which went into effect January 1, 2020 and is likely become a de facto standard in the US.

If you are not familiar with these regulations, you need to learn about them, right now. The reason you need to enforce GDPR and CCPA in your Druid or Imply implementation are the fines: up to 4% of global revenue or 20 million Euro, whichever is bigger. You do not want to bring this onto your company or your career.

GDPR impacts any company globally that captures and stores any personally identifiable information (PII) of any EU citizen. CCPA provides similar protections for California residents. PII is no longer just a social security number or other ID. It is any information that can be used to identify an individual in any way.

The regulations state how you have to protect the data, control access to it and keep an audit trail. Additionally, you are obligated to remove an individual’s data upon request and verify that it has been removed.

The good news is that Druid and Imply have both evolved over the years to make compliance easier. A seasoned Druid practitioner who has worked on many larger customer-facing deployments put together this technical note.

Other blogs you might find interesting

No records found...
Nov 12, 2025

The Breaking Point for Observability Leaders

Observability is at a crossroads For years, observability has promised to give teams the visibility they need to keep digital services resilient. But as data volumes explode, many leaders are realizing the...

Learn More
Nov 04, 2025

The State of Log Management 2025

Logs are exploding. Costs are climbing. Performance is stalling. If you manage logs, you’re in the hot seat Every app, every integration, every security risk—it all generates more data. And when something...

Learn More
Oct 29, 2025

The next evolution in observability: How architecture is following in BI’s footsteps

Modern observability systems are hitting the same wall business intelligence did a decade ago. As data volumes explode, the traditional model — where a single product handles ingestion, storage, compute,...

Learn More

Ready to decouple your observability stack?
No workflow changes. No migrations. More data, less spend.

Request a Demo