Some discouraging anecdotes on how services handle account deletions
ctrl.blog
ctrl.blog
* accounts are never deleted, period *
At most there's a column in the table which specifies whether the account is alive or not. That's it.
Even if you sanitize/delete the account holder record, you can’t delete the transactions themselves (as it would screw up your accounting) nor the merchant association.
Now let’s say you have a very particular customer that always goes to a very specific restaurant at pretty much the same time every day consistently.
That pattern alone is enough to single out that particular person (and deanonymize them by correlating with other records such as cell phone location data, etc).
If you understand the GDPR exclusively based on legal precedent, you'd probably conclude the GDPR doesn't exist.
Wherever possible a business should delete relational data upon request. However, relational data is special because it cannot be effectively deleted by overriding user data with random values as Confluence seems to do.
Even if banks were allowed to delete customer data, they would face the same problem as social or booking services in that their relational data must be truly 'removed' rather than just overridden.
It took 4 years and a non-profit making lots of noise for a brazen, obvious and malicious GDPR breach to be investigated despite it being plastered on every single website out there (I’m talking about non-compliant consent popups).
To date, the accumulated fine amount over the 4 years and all fined companies is around a billion. Now lookup the profit that just one top adtech vendor makes in a year.
The spirit of the GDPR is great but its enforcement is severely lacking.
I think the system improved the web as a whole for EU with new options for consumers despite.
It is however a risk, too. The drives are encrypted, without power and not even networked but they can still be stolen together with the encryption key from the same building. But then probably you have bigger problems.
This also forces the systems that test the backups to be also offline, which is a huge hassle.
I’m sorry, I didn’t have time to find a good specific reference, so I just linked to the whole document.
I suppose that a technical solution is to encrypt all backups of user data with one key per user. Then you only have to erase that user’s key if necessary.
Source : talked with people who implemented gdpr deletion at some companies.
Also, given that the EU has been taking increasing action against companies for non-compliance, I wouldn't bet on it remaining unchecked forever. In the intermediate term, I'd bet on there being third-party compliance checks and certificates, with companies that don't use such getting more attention.
In other words, you don't need to wipe backups but you can't use them without processes in place to ensure you comply with your customers' rights granted under the GDPR.
As a side note, the CNIL also clarified things the author have issues with, for instance "without undue delay" is set to 30 days. In the UK, I've read they backups for specific users must be deleted when technically possible. I'm not sure how that works in practice.
Put another way do you see any backup service/software advertising the ability to wipe data from backups to conform with GDPR DSAR requests? Its virtually impossible with existing tech services and legislators, law enforcement and the like are covering this up!
- Their account changes and passports
- Their own wishlists, including all items added
- Any claims they've made on other wishlists
- Any item suggestions they've added to other wishlists
- The checked status of any item suggestions they've checked on other wishlists
- Removing them as partners on collaborative wishlists created by others
- The user
I'm not sure why someone would _want_ to keep user data around, as that seems more of a liability than an asset.
Want to just add my voice to others who’ve already said this isn’t true.
I work at a company where the task to ensure that every last shred of a person’s data is deleted when they leave the service took a whole team more than a year to develop. It includes all backups and databases, and is complete shortly after 45 days have elapsed (which is in our T&C to ensure that users have enough time to migrate their data, or even reverse their decision).
Not only they do delete everything upon request and it's effective after a given number of days ; but they also made sure we correctly updated a person's consent in the middle of a marketing campaign if they _withdrew_ it. They could occasionally get an additional text or email if they sent their withdrawal after they were drafted in the current batch, but that's about it. It was disclosed to the customer as well.
Some do care about this stuff.
That's sketchy, especially if you don't own the domain but you're on a multi tenant domain like Gmail
Then you ask ServiceX to delete your account, and they instead change your email address to example-deleted@gmail.com or something like that.
I doubt GMail are going to stop you registering accounts that have arbitrary portions of your email being another registered user.
I’m unable to edit my previous comment now and correct it. Will add a note as a reply anyway.
Thanks also to @paranoidrobot for the additional explanation.
- google play developer updates
- google cloud service updates
- your billing info has expired! update it now or else!
despite the fact I can't log into the account because it doesn't existI suppose actually deleting anything goes against google's DNA
That's because Apple requires it. They won't approve my app, unless there's a "full-fat delete" option.
If a user of the app deletes, it completely nukes their entire account, down to the last byte.
I have seen apps that delete an entire thread, when a root comment is deleted; including responses by other people. I think SMF did that.
In the case of our app, we leave communication between users to other apps (like Mail and Messages), so we sidestep that problem.
Actually, the reason we deliberately push communication out to other apps, is so we’re not on the hook for it. There’s no reason for us to have the users communicating with each other, via our app. Long story, but privacy is a real big deal, with our user base. I’m super tinfoil about security.
Hence it may be reasonable to request that all data be removed.
There is public evidence that a lot of apps lie on their privacy labels and they seem to get away with it.
Most times, that’s usually a server, of some kind, but it could also be something like an iCloud data account, I guess; which would be a challenge, as the data could be in many places.
The guidelines do state that it should be a full delete. In my experience, Apple has never checked or asked to verify if a user account was fully deleted on apps I've worked on, which involve PHI. It's been a part of HIPAA compliance for our apps since the beginning (and we do actually fat delete, FWIW). It's a relatively new requirement from Apple's end, though. The deadline was actually extended from January 31st 2022 to now June 30th 2022. Enforcement or stringency on Apple's part could change around then, but I don't see Apple having the resources or willpower to do much of an increase here.
Full guidelines are here: https://developer.apple.com/news/?id=i71db0mv
Edit: This comment is in response to the suggestion that all apple apps delete all local data which after rereading the parent they were only suggesting for their app.
Are you sure about that?
I'm not an iOS developer but as a user I noticed a few years ago that deleting google apps, even all google apps, off my phone and from icloud still resulted in a freshly installed google app suggesting I log in using the account I was last using.
My best guess after doing some searching is re-identification was done using a "Keychain Access Group"[1] which does not automatically get deleted on app uninstall. Though it is stated [2][3] that this is an implementation detail and not a guaranteed behavior. If I recall correctly the only way to reset the Keychain Access Group if the app doesn't do it is to wipe the phone.
It is also possible to persist data if an app is part of an "Application Group" and one of the apps in that group is still installed on your device then data shared via that approach will not be automatically deleted unless all apps in that group are uninstalled (from what I have read).
Apple does have the "DeviceCheck"[4] framework which significantly limits the amount of bits which can persist across app reinstalls which prevents / severely limits an app's ability to reidentify users but still enable some useful use cases. However until "Keychain Access Group" persistence is removed there is not a lot motivating a developer to use this framework.
1: https://developer.apple.com/documentation/security/keychain_...
2: https://developer.apple.com/forums/thread/36442?page=2 and for some prior history see https://developer.apple.com/forums/thread/72271?page=2
3: https://stackoverflow.com/questions/60485419/ios-keychain-da...
I wrote every line of code in the server that manages users’ PID (which is held under conditions that would drive most HNers into fits). I use a modified variant of my BAOBAB server[0]. It’s pretty tightly bolted down. The security of the system is enforced on the server[1].
I also wrote every line of the native Swift frontend app. I use the keychain for some stuff, and persistent prefs[2] for other stuff. The keychain can live between installs, so I have to explicitly delete that, as well as the persistent prefs. Since it only holds login info for a deleted account, it’s not an enormous risk (unless the user is one of those folks that reuses passwords).
So, yeah. I’m sure.
[0] https://riftvalleysoftware.com/work/open-source-projects/#ba...
[1] https://riftvalleysoftware.com/BAOBAB/PDFs/Security.pdf (downloads a PDF).
[2] https://riftvalleysoftware.com/work/open-source-projects/#RV...
My anecdote: Collage.com - I tried it, was unsatisfied with the results so I requested that they delete my account under CCPA (being a Californian). They said they completed. My account was renamed from email@domain.com to email@domain.com-deleted12344843223432 . My session wasn't even terminated, so not only could I see this, I could still see my not-deleted photos AND all the sharing links still worked.
I fought with them at length and their support insisted it was deleted and that this was just something on my computer. Logout/clear cookies/cache/reboot and it'll be all good. I know that's BS.
Even when they "escalated" the issue to a manager who said "Your account has been deleted and will not be reopened." - I could still take screenshots of my account homepage. At which point they stopped responding to me.
And yes, I should have filed a complaint with the California AG but I never did for unrelated reasons. Too late now.
Regulators and legislators are the only people who can do something about this. If you want to make a difference, politick, vote, or lobby.
I feel like this will basically be "pretty much every company out there". A more useful list might be companies who actually do truly delete accounts.
So that's how a huge company deals with "data deletion". I hope the DPA will come down on them hard but of course this clown will then just go and do this circus at another company, now promoted to high heavens.
I hate that privacy and security are full of snake oil peddlers, and it pays of extremely handsomely to be a snake oil peddler. It's not in anyone's interest for you to get caught (who wants to advertise their security is bad/they don't abide by GDPR?), so even if it becomes painfully obvious you've been selling snake oil, you'll only be asked to hand in your resignation, allowing you to do the same (but at an even higher level) at another company.
> It would seem there is no end to how far businesses can take white-labeling and outsourcing.
> I’m sure engineering time to manually delete data must be more expensive in the long run than creating processes and tools for customers and customer support representatives to handle delectation requests.
> 11 of these were smaller niche online stores.
If I'm a "niche online store", am I somehow excused from these rules? I would think there would be a market for white-labeled online stores for niche online stores, but that's somehow Bad™? But having an in-house engineering team develop the platform and respond to development needs as they arise (to handle the first account deletion request) is also Bad™?
https://help.crypto.com/en/articles/3640569-how-to-close-cry... (note: as of today the link to their selfie requirements is dead)
The entire process took 45 days to resolve because their e-mail support is fucking terrible.
Valuable lesson was next project I will likely have to figure out how to effectively shard and round robin containers across diverse cloud providers, as I don't forsee ever affording to be able to be treated that poorly again.
Having worked at a couple of cloud companies... the GDPR deletion timeline within our systems was 90 days. I assume that legal had vetted that timeline.
Say I am leaving my job, and want my personal information to be purged from this 3rd party service (Slack). They say [1] "Primary Owners of a workspace or org must contact Slack to request deletion of a deactivated member's profile information.". What if I contact the "Primary Owner" before leaving my job and they ignore my request, or better yet I have already left my job and I don't know how to contact them or who they are? Why can't I request my personal information to be deleted from a completely 3rd party American company's database myself?
[1] https://slack.com/help/articles/360000360443-Delete-profile-...
- Is my full name, birth date, telephone number, job and other details Slack collects company property?
- Can they also sell this to other 3rd parties along with my social security number which was also collected by the company during company time?
- Is Slack also free to sell this data to other parties afterwards?
- Does GDPR protect your personal information if you gave it away during your free / unemployed time using your personally owned devices and only to services you have admin access to?
Try telling a friend a sufficiently spicy secret and then tell me there's a delete. It's just as much a falsehood as imagining you can un-break a window.
It's refreshing to see that tech is now heading in a more socially responsible direction, but the industry still has a long way to go.
Actually deleting accounts means you're losing very valuable information about [past] customers, their behavior, geo, etc. Also some people may suddenly decide to delete their account and request its reactivation after a while.
It also means you cannot use this data for forensics which is not such a rare occurrence.
Storage is cheap, information is expensive.
what are examples of tech heading in a more socially responsible direction?
These are, of course, unrelated to account deletion, but it shows that big tech is at the very minimum aware that social responsibility is becoming a more important part of business.
As exemplified by, for example, Google firing the two heads of their Ethical Artificial Intelligence Team...who had been researching bias? [1]
[1] https://www.theverge.com/2021/4/13/22370158/google-ai-ethics...
What? Absolutely the opposite is true. Tech is now doing evil shit that was unthinkable ten years ago. Like Facebook using the phone number you put in as part of your 2FA for marketing purposes [1]. The only thing that's happening right now is tech companies are paying more lip service to giving a fuck about users, not actually giving a fuck about them.
[1] https://techcrunch.com/2018/09/27/yes-facebook-is-using-your...
Whether they'll do anything tangible about it is another matter (in the UK the answer is absolutely not), and same for whether they are able to do anything tangible about it (good luck if the offender is shielded behind the crooked Irish DPA).
I requested an account deletion, and because my cookies and session were still active, they simply changed to xxxxxxxxx@xxxx.xxx
The reality is doing this is messy and is going to remain so for some time. One cannot suddenly start after years of no incentives in the online economy to do this and get to cover all areas without huge cost. This requires giving up competitive advantage today. Mid to small organisations that were beyond startup state but not yet having 1000's of engineers, which have to balance growth and operational aspects are left in the most difficult situation. As the laws started taking hold, their incentive structure is still not fully aligned with this as the digital economy does not yet reward them for this enough nor does enforcement create a large enough risk yet. Same thing plays out with some of the larger orgs, just that they have more lawyers to help them stall this as humans are always biased to keep the status quo if it is beneficial to them.
Personally I think we've had a start but its going to take some time to get to where we need to be. I really applaud the idea of the privacy laws and the intent behind them. Its just that one has to recognise we won't be getting to a state of good behaviour within a few years after a couple of decades of not having those requirements baked in from the get go. Old habits have to be replaced as well. The enforcement is hard and that will be something that has to be bubbled upwards from the ground up by users themselves to create a digital economy where consumers/users reward those that respect their privacy. It is just not yet that way today, so why would the organisations change? The risk is low as enforcement is hard and the user demand is not enough.
Most successful would be attempts by large organisations such as Apple and laws like GDPR which forces developers and companies to change their thinking. By asking for change and continuing to iterate on that you can start seeing a slow move towards development practices that will have privacy by default. You need the whole chain of actors to move towards this: The product managers, the engineering leads and architects, the decision makers, the risk assessors. Once enforcement is more steady alongside more demand from users the balance will come. All of this moves slowly whether we like it or not.
(edit - grammar and made some long sentences shorted)