I dont really use it much tbf just thought it was a cool project but I’ve just read about how lemmy instances can be fined for not complying with GDPR Read more

    • a4ng3l@lemmy.world
      link
      fedilink
      arrow-up
      16
      ·
      edit-2
      10 months ago

      Technically he must still comply especially with data subject rights / request for deletion.

      Now I wonder how that would work in practice, considering the underlying technology which is akin to what I manage (telco / isp) and where a lot of principles are still vague to implement.

      Like when we get request to delete personal data sometimes some has been transmitted by nature of the service and a lot of actors have legitimate interest in processing / keeping the data for a while.

      But generally it’s not about the content of a transmission but more the attached metadata used for billing and such.

      Anyway it’s very interesting to watch, preferably from a distance.

      • ramble81@lemm.ee
        link
        fedilink
        arrow-up
        7
        ·
        10 months ago

        Unless he gets a direct request he’s not bound by the requests other instances get. Which actually brings up something interesting. Because of the way the data is shared, someone wanting to delete data would have to contact all instances one by one which is function impossible.

        • a4ng3l@lemmy.world
          link
          fedilink
          arrow-up
          2
          ·
          10 months ago

          Yeaahhhh I don’t know about that… likely all instances are processors. And the on he subscribe to would be controller. Somewhat because to my knowledge no one really decides of particular treatment of the user data (it’s all rather communist architecturally). So maybe every instance would be join controller…

          And in the end up to the (join) controller to cascade the request. That’s part of why it’s a thing of beauty to watch it happen on the feddiverse 😅

          • ramble81@lemm.ee
            link
            fedilink
            arrow-up
            1
            ·
            10 months ago

            And for any of those “processors” outside of the EU? Good luck. I could stand up a processor anywhere outside the EU, get all of the feed data and 1) good luck finding it, me, or where it’s at. And 2) removing it. There’s no centralized authority to fine.

            • a4ng3l@lemmy.world
              link
              fedilink
              arrow-up
              2
              ·
              10 months ago

              As long as they process data of European citizens it’s applicable. See all gdpr fines imposed…. Now the execution / collection would be a bitch but I could imagine à order to stop processing the data imposed to European instances…

              I mean pretty crazy things can happen. See the various adequacy decisions / appeals by Mr Schrems; I cannot give guidance with a life expectancy of more than 1 year given the instability of the application of the regulation.

              Not that I’m complaining ; it feeds me :)

              • ramble81@lemm.ee
                link
                fedilink
                arrow-up
                1
                ·
                10 months ago

                “Now the execution / collection would be a bitch”. That’s my point. It’s basically unenforceable as they would have to go after every federated instance on the internet, including knowing every single person that spun up their own instance, so basically this law would be pointless. It’s better leveraged against companies, not small individual entities, so good luck utilizing it.

          • maltfield@monero.town
            link
            fedilink
            arrow-up
            1
            ·
            10 months ago

            It’s definitely not impossible to contact all instances; it’s a finite list. But we should have a tool to make this easier. Something that can take a given username or post, do a search, find out all the instances that it federated-to, get the contact for all of those instances, and then send-out a formal “GDPR Erasure Request” to all of the relevant admins.