this post was submitted on 05 Mar 2024
72 points (86.7% liked)

Privacy

31798 readers
282 users here now

A place to discuss privacy and freedom in the digital world.

Privacy has become a very important issue in modern society, with companies and governments constantly abusing their power, more and more people are waking up to the importance of digital privacy.

In this community everyone is welcome to post links and discuss topics related to privacy.

Some Rules

Related communities

Chat rooms

much thanks to @gary_host_laptop for the logo design :)

founded 5 years ago
MODERATORS
 

I dont really use it much tbf just thought it was a cool project but I've just read about how lemmy instances can be fined for not complying with GDPR Read more

you are viewing a single comment's thread
view the rest of the comments
[–] [email protected] 15 points 8 months ago* (last edited 8 months ago) (6 children)

Technically he must still comply especially with data subject rights / request for deletion.

Now I wonder how that would work in practice, considering the underlying technology which is akin to what I manage (telco / isp) and where a lot of principles are still vague to implement.

Like when we get request to delete personal data sometimes some has been transmitted by nature of the service and a lot of actors have legitimate interest in processing / keeping the data for a while.

But generally it’s not about the content of a transmission but more the attached metadata used for billing and such.

Anyway it’s very interesting to watch, preferably from a distance.

[–] [email protected] 6 points 8 months ago (5 children)

Unless he gets a direct request he’s not bound by the requests other instances get. Which actually brings up something interesting. Because of the way the data is shared, someone wanting to delete data would have to contact all instances one by one which is function impossible.

[–] [email protected] 2 points 8 months ago (4 children)

Yeaahhhh I don’t know about that… likely all instances are processors. And the on he subscribe to would be controller. Somewhat because to my knowledge no one really decides of particular treatment of the user data (it’s all rather communist architecturally). So maybe every instance would be join controller…

And in the end up to the (join) controller to cascade the request. That’s part of why it’s a thing of beauty to watch it happen on the feddiverse 😅

[–] [email protected] 1 points 8 months ago

It's definitely not impossible to contact all instances; it's a finite list. But we should have a tool to make this easier. Something that can take a given username or post, do a search, find out all the instances that it federated-to, get the contact for all of those instances, and then send-out a formal "GDPR Erasure Request" to all of the relevant admins.

load more comments (3 replies)
load more comments (3 replies)
load more comments (3 replies)