I was banned the same way as the OP, few months ago. They(humans)collected my Id, bank details, personal address, original invoice of the items I was selling, some calls, to finally ban my 15+ year user.
In effect, it lets you revoke your consent for the company to store and process your data. But it also provides for cases where your data can be processed without your consent. It's not an unlimited carte blanche, but fraud prevention is explicitly given as an example of a legitimate purpose.
Businesses are allowed to retain information necessary to operate. Which would include things like names, email addresses, IP addresses, etc of people who are banned (to prevent them from returning).
If GDPR required a company to delete everything, it would be impractical. (E.g. imagine you request a company delete your info, and then you immediately sue them for something that happened while using their product/service… the company wouldn’t be able to defend themselves unless they retained a record/logs of your usage.
You can submit a deletion request, but in most cases much of your data won’t actually be deleted.
I'm not sure about that. The company might reason it needs this data to operate, but you should be able to contest that with a data protection authority.
The data that you can not request to delete is for example money transaction data, which the company has to retain for 10 years or so due to other laws.
The spam stopped.
A bit over 10% (and probably somewhat higher than 10% on HN) of Americans do have something like GDPR. California Consumer Privacy Act. I'm not including Colorado, Virginia, or Utah because I'm not sure how equivalent their laws are.
GDPR applies to all individuals in the EU, not just citizens.
At the very least, I'm sure eBay lawyers would be happy to argue the point.
https://ico.org.uk/for-organisations/guide-to-data-protectio...
Mind you, there's nothing to stop eBay from having someone now look at your data and go 'nope'.
GDPR specifically carves out keeping data for "legitimate business needs" including fraud prevention and so on. Whatever data Ebay (thinks it) has about this person that they are using to enforce the ban would be data that they would argue falls under this clause.
You might have a chance to successfully challenge the termination by legal means, if you actually did not violate Ebay's terms and conditions.
In this context the more relevant aspect of GDPR, which I think receives too little attention and more so enforcement, is article 22 (Automated individual decision-making, including profiling)
But when you see it again you have personally identified the individual have you not? Doesn’t that by definition mean it is identifiable if you are able to determine the identity later?
This is something that advertisers/supermarket points schemes etc used to do when they didn’t have consent to share personal data, hash it and align it with what they already had so effectively they shared the subsets of interest anyway. I remember at university when some guys from yahoo sponsored a hack event, they literally gave a guest lecture boasting about doing this with Sainsbury’s to squeeze through a legal loophole back in 2013.
If your original delete request was followed so that everything they knew about you was deleted, they would not be able to relink everything that GUID linked to. It should be gone now. However, if that hashed value lives in a BANNED_ACCOUNTS table, then all they have to do is create the hash, check the table, disallow new account. You can even do it in good faith by not storing any of the new info rather than storing it and forcing a new delete request.
In a large entity such as Google, you almost need to outsource ID verification to ensure it's not abused by other (advertising/marketing) parts of Google. Of course all of this requires good faith on the part of the implementing entity, which is certainly not guaranteed.