Google keeping "limbo" accounts is dystopian, and seems like a GDPR violation to me.
Google keeping "limbo" accounts is dystopian, and seems like a GDPR violation to me.
If a liquor store had caught me with a fake ID, I wouldn't consider it dystopian if they put my name on a list and kept it in the back.
It wouldn’t make sense to refuse to sell you liquor when you’re in your 80s though.
I agree with your statement though, but the GDPR issue is the retention time, not a DSAR issue.
If you work in the EU, have a chat with your DPO/Privacy team cause I bet they would actually find this an interesting conversation too.
The problem described in the post is that the user has a shadow, inaccessible disabled account that they can't do anything about, forever, and that's a problem.
>Isn't that just isomorphic to demanding Free Ban Evasion for All?
I think it would be isomorphic to Google implementing verification on account creation, thereby preventing this scenario from happening in the first place.
They did, though. They straight up asked the kid if he was 18, and he lied and said "yes". I don't know what you want here, you want Google to... protect it's customers from their own fraud? Does any other industry do that?
(full disclosure: I work there, but on open source firmware and know nothing about Adsense)
https://gdpr.eu/recital-47-overriding-legitimate-interest/
> The processing of personal data strictly necessary for the purposes of preventing fraud also constitutes a legitimate interest of the data controller concerned.
I have absolutely no idea and am not a lawyer, it just seems to me that the word "strictly" is meant to indicate that it isn't pixie dust companies can sprinkle on any piece of information as they choose. The rest of the language here seems to stress that there has to be some sort of test which demonstrates that the interests of the controller overrides the interest of the data subject.