How do I permanently delete my account?
facebook.com
facebook.com
https://en.wikipedia.org/wiki/General_Data_Protection_Regula...
It has the potential to completely change the way tech giants are able to provide their services. Each "purpose" that data is collected for must be individually consented, and it's prohibited for purposes to be withheld if others are not consented to. This allows a user to allow the purposes that are a cost on the company, and deny those that are revenue earners.
Will be very interesting to see how these heavily data based companies adapt.
I guess companies can charge money for services that cost them money, and give you money if you enable certain services.
Of course, I don't see Facebook actually doing this, but just food for thought.
Article 7.4 "When assessing whether consent is freely given, utmost account shall be taken of whether, inter alia, the performance of a contract, including the provision of a service, is conditional on consent to the processing of personal data that is not necessary for the performance of that contract."
Recital 43 "...Consent is presumed not to be freely given if [...] or if the performance of a contract, including the provision of a service, is dependent on the consent despite such consent not being necessary for such performance."
Companies can deny services that cost them money unless you pay; but if you make "consent" as a condition for everyone then it's assumed that it's not freely given consent. You can deny service to everyone, but you can't require consent from everyone. That's not a new thing - that's exactly how the law works already regarding e.g. spam restrictions; you can have opt-in confirmation only if it's optional, if you make it mandatory to "opt-in" (e.g. deny registration unless the opt-in is checked) then it's not consent.
Also, even if you have consent, it can be revoked at any time (e.g. 5 minutes after the user received what they wanted), and you have to unconditionally remove the private information from your systems, even if you gave them a discount because they had "consented" at that moment.
Also, the customer may give you consent to process their data as such (e.g. include in your service) but object to their use in targeted marketing.
Article 21 (Right to object) "... (2) Where personal data are processed for direct marketing purposes, the data subject shall have the right to object at any time to processing of personal data concerning him or her for such marketing, which includes profiling to the extent that it is related to such direct marketing. (3) Where the data subject objects to processing for direct marketing purposes, the personal data shall no longer be processed for such purposes." - so it should be expected that even if you have consensually obtained the data, then you cannot use it freely, you can use it only for particular purposes; and things like EULAs can't override that.
Or substituting in first names of friends in paid content ("<person with same name as your friend> give the following reasons to vote x!/buy this").
Not to mention that if advertising works - then it undermines the idea of a free marked where purchases are made by informed independent agents (I think that's a fantasy anyway, but it seems to be a somewhat popular idea).
Is there anything inherently bad about a stalker passively observing and recording your every move, as long as they don't disturb your daily routine or pass the data along?
Even if you find the stalking behavior (cross-site tracking) of ad companies acceptable, there is a significant risk that your data leaks or is stolen. So, I should be able to decide who I trust with saving intimate data and who I don't.
(An Android ad blocker would probably work best, but getting one running on my ancient phone was more hassle than I wanted.)
I rarely see ads on my android (I do use ad blocker for Web browsing).
I have an incentive to block that as hard as humanly, or computationally, possible.
I see parallels to the 3rd class rail (or coach-class air) problem. If you improve the conditions of the lowest service class, nobody upgrades to higher levels of service. So the lowest class is intentionally bad.
This seems like it would give a market advantage to Google, because they have products that people want and can likely get a fair number of people to consent if the consent was among useful consents. But smaller advertising companies would have a much harder time getting consent, especially if people don't recognize the name as providing anything useful.
And how does this apply to logs? It's common for web servers by default to record urls visited and IP addresses. Would that be legal without explicit consent?
By the way: it's still a topic of heavy debate how much of this can be done through terms and conditions after all.
Disclaimer/source: working for large Google customer, involved in GDPR compliance. Edit: spelling.
How about this, what if I own a.com and embed an image from b.com (a completely different organization from me). And then b.com tracks the users' IP addresses, urls, referers, etc. Do I need to get permission for that? I'm not the one doing the tracking. Does b.com need to get permission for that? There's no opportunity for b.com go get permission, the user never is on a website controlled by them, there is never an opportunity to click an accept button for b.com . The user likely has never heard of b.com .
I'm not certain on the details, but in eg Norway that is already much in line with the GDPR ip addresses are considered personal data, and as such regulated. However, there are provisions for storing such information for auditing purposes (both security, technical and financial/invoicing) - but would likely require explicit consent. ("i accept"/"i will not use this service" - more of an informational confirmation - like signs stating a shop is under camera surveillance - and you could choose not to shop the (even if: good luck finding a shop w/o surveillance cameras)).
In general "personal data" is anything that can significantly help identify a single individual (time/place, ip, phone number/date, address, full name, email, etc).
Ed: regarding logging ips for auditing - there's usually a fixed time limit. It's longest afaik for financial purposes (and the data storage directive explicitly states/stated minimum duration - effectively being lobbied into a tool to go after amateur copyright infringement by forcing isps to keep records longer than before). But from a data protection viewpoint, you can't say/get consent for "we log for auditing" and then keep the data indefinitely . More like 6 or 12 months.
Also, say, I want to collect data about the performance of the web application. Can that be collected, or does it require explicit consent as well?
Also rember that one of the goals is to avoid illicit linking - so being able to verify that ip n.n.n.n is the same as slow_hash(salt+other-ip) won't fly as "not storing".
In general, anonymizing data in sparse populations is tricky - where "small" can be quite large. Just imagine building a bitfield of variables like: sex,age +/-50;2 bits. Rough location (easily 6 bits), browser (2 bits), mobile? 1 bit - that's already 12 bits etc. See also NYC taxi dataset, eg (not the article I had in mind, but seems to cover similar points):
https://research.neustar.biz/2014/09/15/riding-with-the-star...
And how granular do these consents have to be? Would there be a page with 100 consent boxes, with a top box saying "accept all" for people too lazy to sort through all of the boxes?
My personal opinion is that there's no such thing as a "good" ad.
Has the US State Department stated a position on the matter?
The US State Department does not really get to have a stated position other than diplomatic.
Will I as a developer or US business owner need to proactively disallow all users from outside the US (since I am not familiar with their laws) to avoid potential legal troubles, or will other countries block my site/service without me needing to do anything?
If you are, they can drag you to court. End of story.
If you aren't then they will first rely on your cooperation and if that doesn't work, probably issue arrest orders which will make it a bit inconvenient to enter the EU for a while. And they'll probably tell ISPs to block you, yeah.
That analogy is what I take issue with. It's clear that Facebook, selling ads to European buyers, is doing business there. But is every random web site with a few European users? Does putting up a web site suddenly mean you're doing business in every country in the world, subject to the jurisdiction of all of them simultaneously?
"The US State Department does not really get to have a stated position other than diplomatic."
Diplomacy is what it does, and its diplomatic position on trade issues is relevant.
> It is inaccessible to other people using Facebook.
The wording does sound very convincing but I really don't think we can just believe their word. After all it's Facebook.
We don't know that. If you're feeling charitable you could believe they're being honest, but if you not then you just have to wonder. There is no way Facebook could prove they don't have a secret server with your data on it somewhere. Proving that would be impossible.
It may take up to 90 days to delete data stored in backup systems. Your info isn't accessible on Facebook during this time.
Copies of some material (example: log records) may remain in our database but are disassociated from personal identifiers.
[Updated: fix year FB was launched]
There's also a hidden link in the support pages somewhere that's supposed to actually delete your account (which is what's linked here)
It's not practical to perform a delete in some environments. It's certainly not practical to go through backup files and delete references in others. Everybody goes through a data recovery scenario at some point.
What you should expect is best effort. Nobody is going to re-train their neural networks that referenced your data. It's doubtful that any provider would delete what they have gleaned about you simply because you wanted your account removed.
Then there's the practicality of things. If you delete your account here on HN, would you expect all conversations that you participated in to be removed? All references to your comments? Or all comments that you made removed? Do you expect them to push that change out to google? Do you expect your references in access logs removed? There's always a trail.
Facebook isn't uniquely evil. They have the same problems as everyone else, and they have those problems at an incredible scale.
People think about these things as if they are files or entries in a simple SQL database that can simply be removed. They may use databases, but to think that all of your data exists in a singular database or that all of your data only exists in databases is simply not extrapolating what you know about technology to their environment.
If google were to remove a website from their index, how long would it take for all of their environments to no longer have a record of it? And would that actually be desirable? There aren't faceless drones working on these kinds of problems. There are very smart people and most of them have a conscience and care about end users. I don't think you would find that any large group of people at facebook, google, amazon, microsoft, or any of the big companies are completely apathetic to end user concerns. I'm sure plenty are far too busy to address individuals directly, but they certainly are not apathetic.
<sorry... I seem to have rambled off on a tangent>
Training of neural networks is probably a gray area, and a potential issue for many companies. Example: Think of the recorded audio messages from Siri/GoogleNow/Cortana that gets processes and potentially stored and not deleted thereafter on their (and third parties like Nuance) servers. If one deletes an account, one would assume it also and especially also deletes all private data like messages, voice and video recording.
They do that? And is that legal? How will facebook prevent me from registering again, if they deleted all PII that they had on me? That'd be clear proof that they didn't respect my GDPR request for deletion, and I could sue them easily.
My data is mine not yours. If I withdraw my consent to you having it just delete it. If you can't do this then don't collect my data in the first place.
There's been few debates here about the definition of to 'delete' which I won't get into. However, as a user, it rubs me wrong when companies equate simple username disassociation with deletion. It's not a user's place to wonder about the practicality of deletion at scale. A user has the right to have removed all content they've produced regardless of whether it's linked with other posts.
Do they though? Maybe I'm understanding it wrong, but I thought the GDPR only applies to personally identifying information, not all data ever generated by a user. So by disassociating the user name and the post, the post has suddenly ceased to be personally identifying information and no longer needs to be deleted.
What major sites behave in a way that you find acceptable?
"This IP License ends when you delete your IP content or your account unless your content has been shared with others, and they have not deleted it."
"When you delete IP content, it is deleted in a manner similar to emptying the recycle bin on a computer. However, you understand that removed content may persist in backup copies for a reasonable period of time (but will not be available to others)."
This sounds like they properly delete it but only so long as you haven't given another user a copy of it (such as sending a message perhaps).
Also while the US has essentially no privacy protections whatsoever, I don't think a "deleted=true" would fly under EU regulations.
I deleted it again, and it finally “took” this time, but I have no idea what happened before. My best guess is that iOS was still logged into it through its facebook integration and that counted me as having logged in before the grace period expired. Either way it left a really bad taste in my mouth.
(I was a facebook user in 2005 and kinda stopped using it around the time they stopped letting you have your “news feed” just be a simple time-sorted list of your friends’ posts. Neither of my attempts to delete my account were any kind of statement — the site was just boring to me and I never found myself posting much.)
I'd like to know how thorough they are with deleting you, however. With stories of "ghost" profiles that they build on individuals who don't have accounts (and/or are not logged in), I would be surprised if they actually delete everything they know about you.
I found the process easy to complete using the directions in the link. It was quite liberating to have my account deleted, actually. Don't miss it at all, although it left some friends and my mom scratching their heads.
I have not read the Facebook ToS since then; assuming that line remains the same, if they do not delete your data and you decide to sue, it's about whose lawyers cam make a better case for whether a reasonable amount of time has passed.
Does anyone know if GDPR (or similar law in the future) will actually force HN and other sites that don't have this feature, to remove accounts, at least EU ones, upon request?
However, IIRC, there is not much of a requirement of having a dedicated form of it. An email is sufficient notification you want this to happen (and you're of course free to ensure the user's identity).
After that they have to delete all data and take note of the deleted datasets so in case of a backup recovery the data will stay deleted.
HN would invite a lot of trolls with this an would make it really difficult to create a submission archive that makes sense.
Now I don't know how it handles account deletion but reddit handles that well, a deleted account will retain its comments without a name if the user hasn't deleted all their comments. That makes sense and works well.
Also I don't think having the ability to delete your profile invites trolls. Usually one deletes their account because they post something wrong but which they genuinely believe is true then get downvoted and / or trolled into oblivion. These people we should probably be working to retain because while they might have been wrong, their contribution did improve the content on the site due to the corrections that followed. However sometimes the negative rep and / or harshness of the replies can make the corrections a bitter pill to swallow. So I think there should be a downvote cap for incorrect posts (or even disallowing downvoting for all but rudeness and spam) and working harder on improving forum etiquette.
Of course, likely as not this post itself is invisible. Likely as not the GDPR is as uninteresting as user's needs. Likely as not, Hanlon's razor applies. Although I would not brag about the last possibility.
As far as I know, the GDPR is more of a clarification (along with some explicit guidelines for fines), than it is new legislation - so hn and similar sites would already be in breach, if they didn't allow the deletion of all profile data. I'm not certain that having to email someone at hn to do it, would be in breach of current data protection regulation. It may be that not clearly stating: "to get a record of all data hn has stored on you, make correction or delete all data - please email (...)" will be in breach of GDPR.
But afaik hn does no business in the EU - so it's not clear what sanctions would be applicable.
It's different for companies that does business in the EU / EEC.
I was told — via email — this functionality would be coming in the future, but it’s been about six months and nothing yet.
Since EU citizens are registered users, it applies.
"This won't apply to every U.S. business — just the ones that are knowingly, and actively, conducting business in the EU. In this vein, EU courts have the discretionary ability to determine if a U.S. company was purposely collecting EU resident data and subverting GDPR compliance."
0. https://community.spiceworks.com/topic/2007530-how-the-eu-ca...
edit: This means it applies to EU citizens regardless of where the processor is located and to non-EU citizens if they are currently in the EU
Not really, the wording is quote clear. As is "processing the data of EU citizens".
I doubt any minor eshop or online service will appoint a representative, they will however still have to conform to the GDPR rules.
On a side note, the cp filter is scary - as the infrastructure implies the existence of censorship infrastructure ready for abuse in the event of a power shift.
HN does none of that. So, to me, it seems like a really different situation.
It's fair for people to change their mind and ask for functionality to delete data that's associated with them. I don't think the internet would be nearly as useful as it is now if everyone had to be anonymous from the start in case they want to stop other people seeing the content they created later.
However, that said, it's also reasonable to suggest people shouldn't be able to say appalling things and just delete their account later with impunity. There's a strong argument that someone's internet history should be available as a record.
This is not a straightforward problem.
GDPR only covers personal information. So it only covers the IP and username in case of hackernews (unless someone adds their name into some sort of signature)
Some alterations, though...
EDIT: But it's also likely that they will enable the protections for everyone in the world, because the risk of accidental non compliance is huge. Similar to how the cookie notification is just displayed everywhere now.
[0] At least to all appearances. Of course, Facebook could secretly be keeping it, as is discussed elsewhere in this thread.
Unless laws are passed in the US to force their hand, this sort of behaviour will continue.
Anything and everything you post on the internet, is FOREVER.
Because chances are some dev somewhere has simply flipped an IsDeleted bit to true / 1 in the site's database :)
The law goes into effect in May 2018.
Why? What possible purpose does this serve?
A: They'll tell you.
Someone I knew was tasked with removing large quantities of image data that had proved inopportune. There was limited support for doing this, though a method was developed. My understanding is that the caching service provider hadn't had to deal with such matters at that scale previously, though this information is incomplete. I strongly suspect that this is more frequently encountered now.
I'm not excusing Facebook (and generally avoid doing so), but one of the interesting things about scale is, well, its sheer scale, and what seem like simple operations become complex.
EDIT: I'm not complaining, I'm literally asking what there is that people find interesting about this link, since I feel like I must have missed it. Though feel free to keep downvoting through the floor.
It is stupidly worded, perhaps intentionally so to discourage deletions, but I just did this recently.
This might sound a little over the top and conspiracy theorist, but this is all part of Facebook's and rain man Zuckerberg's psychological warfare. Facebook hires people who work in the gambling industry to make their product more addictive. Zuckerberg is playing us all. Facebook is a major (if not number one) contributing factor to the polarization, narcissism, depression, constant outrage (both sides), and dividing of the US and frankly world.