Architecting a Centralized Platform for Data Deletion at Netflix

QCon San Francisco 2025

Session Architecture

Architecting a Centralized Platform for Data Deletion at Netflix

Monday Nov 17 / 03:55PM PST, Ballroom A at Hyatt Regency, San Francisco

Abstract

What does it take to safely delete data at Netflix scale? In large-scale systems, data deletion cuts across infrastructure, reliability, and performance complexities. Data lives in many datastores, each with different trade-offs and requiring ad-hoc solutions, leaving users with fragmented behavior, inconsistent outcomes, and costly operational overload. As data volumes grow and data stores become increasingly distributed and complex, ensuring safe deletion becomes an even greater challenge. Without a centralized architecture, teams often develop isolated solutions, resulting in inconsistent practices, duplicated effort, and growing operational overhead.

At Netflix, we have developed an architecture for managing data deletion across diverse data stores, addressing these challenges while improving overall system resilience. The centralized and extensible platform provides the end-to-end data deletion lifecycle from identifying the data to verifying and executing deletion. The platform includes configurable deletion controls, journaling, observability, and data recoverability to ensure safe and reliable operation.

In this talk, we share the design and execution tradeoffs behind the data deletion platform. We explain how we have used various techniques to build a reliable and auditable deletion system, and we highlight key engineering tradeoffs, including how we balance throughput, safety, and scalability across diverse systems while maintaining resilience under live traffic.

Key Takeaways:

  • Understand the architectural challenges of data deletion and why a centralized approach is essential.
  • Learn how orchestration, observability, journaling, and recoverability enable safe deletion across diverse data stores.
  • Explore the tradeoffs Netflix made to balance throughput, safety, and scalability under live traffic.
  • Gain practical insights from real-world engineering decisions in building and operating large-scale deletion workflows.

Topics

Architecture Data Infrastructure Platform Engineering Reliability Resilience Privacy and Compliance
76% senior dev or higher
1:11 speaker ratio
60+ practitioners

QCon San Francisco 2025 is a three day conference for senior software engineers, architects and team leads. An international program committee of working engineers selects every session. Patterns and practices, not products and pitches.

Share

From the same track

Monday 17 November

10:35 Ballroom A Session Architecture How to Build an Exchange Frank Yu Director of Engineering @Coinbase, Previously Principal Engineer and Director @FairX 11:45 Ballroom A Session Durability Compiling Workflows into Databases: The Architecture That Shouldn't Work (But Does) Jeremy Edberg, Qian Li 13:35 Pacific DEKJ Session Architecture Parting the Clouds: The Rise of Disaggregated Systems Murat Demirbas Principal Research Scientist @MongoDB Research, Previously Principal Applied Scientist @AWS and a Professor of Computer Science at the University at Buffalo (SUNY) 14:45 Ballroom A Session Platform Engineering Building Resilient Platforms: Insights from 20+ Years in Mission-Critical Infrastructure Matthew Liste Head of Infrastructure @American Express, Previously @JPMorgan Chase and @Goldman Sachs 15:55 Ballroom A Session Architecture Architecting a Centralized Platform for Data Deletion at Netflix Vidhya Arvind, Shawn Liu 17:05 Seacliff D Unconference Unconference: Architectures You've Always Wondered About