this post was submitted on 23 Feb 2024
800 points (98.9% liked)

Privacy

32120 readers
352 users here now

A place to discuss privacy and freedom in the digital world.

Privacy has become a very important issue in modern society, with companies and governments constantly abusing their power, more and more people are waking up to the importance of digital privacy.

In this community everyone is welcome to post links and discuss topics related to privacy.

Some Rules

Related communities

much thanks to @gary_host_laptop for the logo design :)

founded 5 years ago
MODERATORS
you are viewing a single comment's thread
view the rest of the comments
[–] promitheas@iusearchlinux.fyi 21 points 9 months ago (4 children)

Ive been engaged in discussion with my country's data protection officer since the summer, and the reply I got was that I should delete comments myself. There are 2 comments that appear on my profile only if viewed while I am signed out, and when I raised the concerns with her I basically got the reply that "there is no personal information contained within and once you delete your account there is no username attached to them so you cant be linked with them". Is she right, and how do I handle this situation?

[–] Blackmist@feddit.uk 11 points 9 months ago (3 children)

As I understand it:

As long as the link between data and user is severed, they are compliant with GDPR. Anonymising data (proper non-reversable anonymisation, rather than pseudo-anonymisation) is as good as deleting. As long as it's not personally identifiable, it's OK.

I suspect anyone else expecting the EU to purge reddit of their comments will be equally disappointed.

[–] sibachian@lemmy.ml 4 points 9 months ago (1 children)

what about the whole knowing who is who based on word pattern/habit, and connected content and/or opinion?

[–] Blackmist@feddit.uk 4 points 9 months ago

None of that really seems to count for GDPR. And good luck picking any one person out of a sea of a million orphaned comments.

[–] LWD@lemm.ee 3 points 9 months ago

According to how the UK's Matrix/Element "privacy" messager app acts, that is correct. If, for example, you request a GDPR compliant data deletion of your messages in a room that contains 100 people, they will continue storing your data and delivering it to those 100 people, as well as propagating your data across any other servers where those people may be.

If you've lost access to any of those rooms, screw you, your data doesn't belong to you but it does belong to anybody who was there at the time.

[–] jarfil@beehaw.org 2 points 9 months ago (1 children)

As long as the link between data and user is severed, they are compliant with GDPR. [...] As long as it's not personally identifiable, it's OK.

Wrong.

In the US, data protection refers to "personally identifiable" data, so severing the link is enough. Under the GDPR, all "personal" data is protected, doesn't matter if it has a link or not to identify the person.

The test under the GDPR, will be whether a comment has any personal data in it. If it's a generic "LMAO", then leaving it anonymous might be enough; if it is a "look at me [photo attached]" or an "AITA [personal story]", then the person can ask for it to be removed, not just anonymized.

[–] LWD@lemm.ee 1 points 9 months ago (1 children)

That sounds like it places an undue burden onto the user to determine and explain why data might be personal. Is a particular writing style personal? Something that identifies their IP address, or time zone, or three separate messages that can be used to pinpoint someone's identity or narrow it down significantly?

To build on the Matrix example I mentioned, they give you the ability to "redact" messages but it's your job to hunt them down across their entire platform, and obviously you can't look at any messages in any rooms you've been kicked out of (and I'm pretty sure an API call to redact them, even if you correctly guessed the ID, would be rejected).

[–] jarfil@beehaw.org 2 points 9 months ago* (last edited 9 months ago) (1 children)

places an undue burden onto the user to determine and explain why data might be personal

The other way around: all data originating from a person, is by default "personal data", and the burden of explaining which one is not, lies with whoever is keeping it.

you can't look at any messages in any rooms you've been kicked out of

If they're keeping them, then you can request a GDPR export of ALL your data. Doesn't matter whether some interface or application allows you access to the data or not, or even if you've been banned from the whole platform; as long as they keep the data, they have an obligation to honor your rights of:

  • Access
  • Correction/Modification
  • Removal

Even during obligatory data retention periods, when they can't remove the data and only make it inaccessible, you still have the right to get a copy of your own personal data.

[–] LWD@lemm.ee 1 points 9 months ago (1 children)

I really hope I'm wrong and you're right here! I agree with you entirely in terms of what should be allowed, if it isn't already allowed. And I definitely hope you're correct. I haven't recently requested a data export from my languishing Matrix account, but I might give it another go to see what kind of data is stored on my home server.

[–] jarfil@beehaw.org 1 points 9 months ago

I've had to deal with this on the data collection end, and it's a PITA to build in the mechanisms to fully follow the law. If you're an EU resident, and especially if the server is in the EU or has to follow EU agreements, then they'd risk some quite high penalties if they didn't follow it.

[–] AlteredStateBlob@kbin.social 8 points 9 months ago

The DPAs have discretion on how they interpret the laws and what guidance they give. This is something you could only really pursue through litigation beyond what reply you're getting from your DPA. Personally, I am not trusting reddit to actually, truly delete anything. But there would need to be proof for that, beyond my suspicions.

If deleted was truly deleted, I'd say they're right on an individual case.

The issue I'm outlining is however of a different nature, so I am somewhat hopeful at least some DPA will take this issue on.

[–] xor@infosec.pub 0 points 9 months ago

wrong because "deleting" your data doesn't make it disappear