Although, messages that used to @mention the user don't have their UID mangled (since @mentions are really `<@userid>`), so it'd be easy to correlate someone @pinging a deleted user and that deleted user responding to the ping. Seems like fixing this would be pretty challenging (logistically and computationally) given you'd have to arbitrarily edit other peoples' messages.
Otherwise non-profit making companies could do any privacy BS and not be fined.
If you send email to me and then delete it in your end, I'm allowed to store your email as a whole (sometimes legally obliged).
The difference is in what Discord’s responsibility is.
If Discord claimed to have deleted an account, then they shouldn’t still be publishing a post from a user. Especially if such a post could still be tied back to the historical user id.
I can understand why they’d want to keep the data (sometimes you need to keep an archive of posts for legal reasons - for a limited time). But making an archived post visible to the public is the problem.
If I delete my email account, and/or remove it from the list, there's no expectation that my prior emails are deleted for any of the other list subscribers.
The mailing list archive isn't pruned of my account and everything I ever sent will still be visible.
With Discord, all messages are in the “central archive”, there are no individual copies.
On discord there are no 200 individual "they" storing it. It's stored by discord. (Or I guess people could be manually logging their own chats, but that's not the issue at hand here.)
At first pass it might sound like some minor technical squabble about implementation details, but there is intentionality in design decisions. The legal system can not be blind to those.
Discord chose a design that put them in control of the data. I'm not saying the highly centralized nature of their design is bad, wrong, or wasn't the best choice for the product they want to build. What I am saying is that when the legal system looks at the nature of a product, it has to look beyond what's presented in the pretty UI and marketing materials. It will look at the business' processes too.
The design of email means there is an argument for the legal system that gmail is a very very popular post office. That email is a system wherein users have disparate storage areas for receiving/archiving emails, and gmail is one of many organizations that offers users the service of managing their individualized storage area on their behalf.
In the service that is email, there is nothing inherently special about gmail. In the service that is discord, discord is discord.
IRC enables Text & Attachments in text form (ie links)
Email Enables Attachments in visual (html emails)
Discord Enables Voice, Text and Attachments (Asynchronous sockets)
That's all it is. Present a Video, Picture, Voice to your visitor and you've got a new product. Just as facebook,twitter,myspace have been.
Assuming all this is correct, if a GMail user requests their account to be deleted, Google should delete that data.
Taking a mailing list as an analogy: If there is a central archive of the mailing list, you can request removal of your messages from that archive, but not from the individual recipients who originally received the message.
1. With email you send messages to a specific, finite list of recipients.
2. With email change of recipient list will not send them past messages whereas once you have access to discord channel you get access to history too.
Discord is none of that. They never tell you that your messages and media are forever. If you get banned from a server or leave, all of your stuff is still there. There is no reason for this other than eventually selling that data or other evil purposes.
It would be stupid if someone closing their cellular account would somehow reach into my phone and delete their contact, their messages, and replace their phone number with all zeros and this is semantically the same, the implementation shouldn’t matter.
If you send a message to a group chat those messages are now owned collectively by the group and individually by each member, the gpdr is forcing companies to delete my data because someone else asked to delete theirs.
In this case, Discord is a very centralised service. They store all of the messages centrally, so can easily comply with the request.
Other services like email may not be able to do that, so they could use that as a defence when asked why they aren't deleting all data.
But I don't see any particular reason for where exactly the line between the two should be - why wouldn't it be that I could make anything I shared with you ephemeral, a-la Snapchat? And going back to email, it was actually MS Exchange who have supported the option to "Recall this message" [0] for many years, while gmail decided to not implement anything like that.
[0] https://support.microsoft.com/en-us/office/recall-or-replace...
My thoughts:
If it's in my inbox (whether on my physical phone, or hosted for me by a service provider), I own it and I get to control it regardless who sent it / how it got there (as long as other legal pre-requisites are met, i.e. not child porn etc)
If it's in my outbox, and I want to delete my account, THOSE instances of those artifacts should be removed, whether from my physical phone or by the service provider hosting them for me. If I've sent them to others, fair game, they own THOSE instances; but I expect the service provider to remove, upon my request, the artifact instances I solely own.
The question is whether this law is closer to fuck you than it is reasonable regulation of bad behavior.
If we work on a Google Doc together should deleting your account delete my document as well? They’re both on Google’s servers and on the backend we don’t have separate copies.
I am not sure if GDPR should apply if that can't be used to trace back to you at first place.
And if this should apply. I think everyone on the earth that connect to internet are probably in danger. You visit my site and leave a message. And I am suddenly a target of GDPR, what?
Also, do GDPR actually care about internally logs? I think the requirement is the data on that platform can no longer be used to trace back to the user. But logs aren't even exposed to users.
Since GDPR, PII (Personal Identifiable Information) data has become radioactive, the less you touch it easier your life is.