Its just a guess on my side what a possible rationale may be. Its equally likely that someone just put in a feature request for account expiry without really having a good reason and fully understanding the consequences.
My Yahoo! Mail account is from about 2001 and I still select “I’ll do this later” when I sign in on a new device. I think whatever new owner buys us next has to continue this.
Happened to me. Lost all my old emails from high school. Sure, that's on me for not having my own local backup, but they still did it with no warning that I ever saw.
:(
I tried it out on an alternate Yahoo! email address that I don't need and sure enough I got this message
> Setting up your mailbox
> A fresh mailbox is being created, since the old one was inactive for more than 12 months.
https://i.imgur.com/VMHxeyH.png
thank you for the heads up
It’s an interesting question and it has never been directly addressed, though Facebook and similar have enabled memorial pages.
I could see a service like steam allowing a death certificate and closure resulting in a $10 refund so they don’t have to maintain the database entry.
I mean, you can move inactive accounts to a separate table or something if you really want a small performance optimization. Delete them after 20 years. This is a very slow, very long-term problem.
A typical human lifespan is in the realm of ~80 years.
Maybe they just enable this "feature" only for ~80 year old accounts.
I can: MAU
To be on the safe side and to satisfy users I would allow users in such cases to download the digitally signed account data and offer the possibility to upload it again.
You could just as easily delete all of the PII in the account by sending someone an email saying "your licenses are now attached to these codes, please use them to reactivate your licenses with a new account if you want to access them" but they don't. They just delete them. There are many ways to square this circle.
Only if you can prove that there is not a person with access to the account and intention to access it can the account be deleted.
You're wrong here, both legally and technically (and in my opinion, also ethically).
In the bluntest possible way, even if you were correct (and you're not...): They could have just deleted the billing information and not the account.
Ubisoft designed products that require an online account to use - Ubisoft is on the hook for providing that online access for account holders because they paid for that product. Alternatively - in any region with good consumer protection laws, they're about to issue a lot of full refunds.
If this is too much hassle, they could instead sell a license to execute the software, regardless of how it is obtained (but offering a way to download for now, putting the purchaser in charge of backing up those files). Similar to what GOG are doing.
But no, that's not enough control for them either. They want to have their cake and eat it too.
Only angle I can see that this might work for is reducing the number of people you have to email when you get breached.
It could be easily argued that providing an end customer with access to digital products they bought is part of the service that data subjects signed up for, so retaining PII indefintely is 100% allowed (unless the data subject explicitly requets their account to be permanently deleted).
As a child you may leave your toy in playground, return back in 1 hour and it may still be there. If you come back in 10 years it would be an unjustified expectation to find it there. As an adult you buy a property, abandon it and in 30-40 years it is no longer yours. Why in the digital world it should not be the same?
If you can't keep first/last name, or birthday, just delete it.
However in pretty much every jurisdiction, keeping any kind of information FOR THE BENEFIT OF THE CUSTOMER is 100% allowed, encoded in the law, used as examples and is within the spirit of the law.
Any judge, lawyer or layman would laugh at the idea that GDPR can be used as an excuse to force users to re-buy products.
„For the benefit of the customer“ is too vague justification for it, you need a more specific reason.
You can keep data in your servers without consent if that data is there to serve the interests of user. In this case, the interest of the user is getting access to the games they purchased and paid for (!!!). This is called "legitimate interest".
A company can keep the address and phone of their customers if they're providing services that require address and phone. Package delivers don't even have to ask for consent to deliver a package to someone, for example. If you need email to guarantee that the user can access the games, it's fine to keep it. The law is not as stupid as Silicon Valley tries to paint it.
I'm pretty certain that Ubisoft is breaking GDPR and other similar laws in several places, but "keeping data to provide a service" is the one place they're not.
In real world nearly everything has an expiry date, beyond which product is no longer usable if you do not invest in maintenance. Who said that in digital world it should be different?
Reasonable expectation of account life time is the period when the user needs it, no more and no less, and it is not the same period as the life of the user.
As pointed out above, you are allowed to keep all data necessary to provide your customer what they purchased. Losing that data is not the customer's problem, but yours. If you cannot keep your customer data safe indefinitely, then maybe you should've settled on a business model that does not require keeping customer data indefinitely.
Passwords should be properly hashed. Heck, just delete the password and let the user ask for another if need be.
If there is ANY unnecessary data that was collected but that doesn’t need to be there, or that needs consent to be stored, just delete it. Easy peasy.
List of games owned? Email address? That doesn’t need consent, because it’s legitimate interest. It is 100% in the customer’s interest to have game ownership information long term, and deleting it would cause actual loss to the customer. That’s probably as bad as having PII leak!
And what's that “cost of maintaining accounts”? Less than a kb of data per customer, on average? Probably just a few database tables?
Once again, if there's unnecessary PII, just delete it.
This whole thing is just to force customers to re-purchase games.
> In real world nearly everything has an expiry date, beyond which product is no longer usable
That’s clearly not true. There are several products that don’t have it.
But in the case of games/software it is worse, because the expiration date is 100% artificial: since the games need authorization servers to run, the expiration is under control of the company.
1. I think this is a misunderstanding of the GDPR. You are allowed to keep and process PII, as long as you have a justification. Keeping the user‘s purchases around would be such a justification, as would be consent. 2. Even if you were right, they could still keep your account and games around, and just delete the billing info.
I was never prompted to change that, even though I would definitely like to. I would appreciate any insights you might have.
Change the username? Sure. Change the email associated with the account? Yeah.
But if you've got a near 20 year old steam account, you're still logging in with whatever email address you had near 20 years ago.
> we may immediately close inactive accounts to comply with local data protection legislation
I'm not sure if that's actually what their lawyers think, or if blaming GDPR is a convenient excuse. The fact that no other company seems to do this makes me think they know its BS.
[1] https://www.ubisoft.com/en-us/help/account/article/closure-o...