Article 20, Section 1 states:
The data subject shall have the right to receive the personal data concerning him or her, which he or she has provided to a controller, in a structured, commonly used and machine-readable format and have the right to transmit those data to another controller without hindrance from the controller to which the personal data have been provided[...]
Separately, Article 2 states:
In exercising his or her right to data portability pursuant to paragraph 1, the data subject shall have the right to have the personal data transmitted directly from one controller to another, where technically feasible.
This part specifically mentions the controller you originally gave data to, but says nothing about whom you now want to import it to:
> without hindrance from the controller to which the personal data have been provided
It's implied that the importing side will make this work on their own since they only benefit from allowing data imports to onboard new customers while the exporter is losing their customer.
> For especially severe violations, listed in Art. 83(5) GDPR, the fine framework can be up to 20 million euros, or in the case of an undertaking, up to 4 % of their total global turnover of the preceding fiscal year, whichever is higher.
> “the concept of an undertaking encompasses every entity engaged in an economic activity, regardless of the legal status of the entity or the way in which it is financed”
These services have no economic activity whatsoever, or if they do it's in the forms of donations to keep the lights on. Who do you propose that the GDPR hammer strikes?
This is an interesting intersection of services that aren’t necessarily a business. A lot of modern privacy laws are built around the idea that you’re making money from people, and stand to lose that income. I’m not sure that GDPR offers anything different.
It does not seem to make any difference whether the service is engaged in commercial or professional services.
Interesting question. Would it be?
If I now move to mastodon.example.com and somehow migrate my messages, that server's admin would be able to read them, but you never consented to them having access to (part of) your private messages.
It's similar to email, but we tend to put high requirements on running an email server (concerning data / privacy). I have no idea how that works out on Mastodon, whether it's closer to email or closer to Twitter DMs. E2E messages would probably be best, but then you make it harder for yourself to combat spam and harassment, I assume.
> If I now move to mastodon.example.com and somehow migrate my messages, that server's admin would be able to read them, but you never consented to them having access to (part of) your private messages.
Why do you think there's consent in the first case but not the second case? You voluntarily choose your new instance just as much as you did your old instance.
I choose it, but you didn't, and if I migrate private messages exchanged between us, that would affect your personal information.
Just migrating my public posts will not be an issue. I don't know if private messages would be. §20 states in 4 "The right referred to in paragraph 1 shall not adversely affect the rights and freedoms of others."
Anyway, the ability to import public posts would be a big improvement.