This but unironically.
If people or bots or the NSA want to keep records, let them scrape and cache 'em.
I actually think it should all be P2P, but that would kill the thin shell of a business model that exists.
It would be perfectly fine if Discord stored messages from users (for brevity, assuming that's personal data), made it searchable and available as long as the user exists on the platform, provided that they specify this as the purpose of processing, and the user explicitly gave informed consent. Should Discord want to perform any other processing besides that designated purpose, they would (again) have to receive the user's explicit, informed consent. Otherwise, it's simply not allowed.
No need to remove messages in such a case. Of course, technically they could process that data for a different purpose than specified, but that's illegal and may eventually result in a fine that can be based on a percentage of total global revenue.
Not profit or loss, revenue. Then suddenly it becomes a really interesting business decision to do other than defined things with the data at hand.
(and something something purpose limitation, data minimization etc.)
I wonder at what point analytics, queries, or ML to determine age gets in the way of actually keeping them from getting into things they shouldn't...
Under age users aren't going to just tell you their age honestly, so you'd have to use some method to derive their age.
You could use something like that and it would be counted as “legitimate interest” under GDPR, but:
- you wouldn't need (and then would be forbidden) to do segmentation between more categories than “too young”/“old enough”. This is not what they are doing here.
- you'd still need to tell the users that you're doing it, and provide a way for the users to modify that data upon request
> Under age users aren't going to just tell you their age honestly, so you'd have to use some method to derive their age.
You don't have a legitimate interest of knowing their age, only for knowing if they are underage or not.
In the UK it already is under the Online Safety Bill.