I believe EU has dug their own hole here. And the best move would be to pass more legislation to explicitly require the retention (and transfer, ideally) of purchased digital goods.
> Personal data shall be: kept in a form which permits identification of data subjects for no longer than is necessary for the purposes for which the personal data are processed. (..)
Note that this does not say "it must be stored for a limited amount of time" - it says "no longer than necessary".
Your basic account data (such as username and password, or an email for password recovery) is still necessary to log in to the platform and make use of your purchases. As long as there is no clear indication that the user will never log in again (such as due to death, or because they explicitly deleted their account), it would be reasonable to keep it around.
On the other hand, it may make sense to delete some data. For example, it may make sense to store your full name and address info to make checkout more convenient. If a user hasn't bought stuff in a while, it makes sense to delete it and have them re-enter it in the future.
There might be a bit of a gray space for things like game achievements (especially when there's a public profile) or savefile backups, but reading it as "you MUST delete all digital purchases because GDPR" is just not true.
Keeping "account X purchased game Y" forever is necessary for the purpose of tracking ownership.
Based on how big companies typically behave, I assume that they are storing a metric buttload of other data on their users, which is not necessary for that purpose, and which they aren't inclined to separate out.
This is just like the cookie popup nonsense. You don't have to ask for permission to store necessary cookies. Cookie popups are ubiquitous because sites would rather bother every single visitor so that they can store unnecessary cookies.
Is there evidence of the contrary? Maybe any store can just delete your personal data right after charging your card and claim GDPR prevents them from shipping your product.
Silly arguments work both ways. You just picked the one that confirms your bias.
GDPR under no circumstances forces processors to delete everything, it defines legitimate interest. Retaining a person's purchases is as legitimate as it gets so the data can be retained for as long as the purchase is valid. And the license itself isn't even the user's personal data, it's just a license, so Sony could give the option to export that license to be used later - even in a cryptographically secure format that can only work if e.g. the account is created with the same email address. If they delete the personal data and throw out the baby with the water, it's not GDPR forcing them to do it.
"the personal data are no longer necessary in relation to the purposes for which they were collected or otherwise processed"
https://gdpr-info.eu/art-17-gdpr
It's like the cookie banner all over again. This law never, ever required a cookie banner.
The big companies are master in malicious compliance that benefit them, and let them blame the EU for it.
Rules of thumbs, international billion dollars company should be assumed to be the ones being the bad guys until proven otherwise. They have lost the benefit of the doubt decades ago.
You still need to keep it if there's a law saying that you need to have that data, of course, but that's the exception.
We could all have used the DNT header as a bypass when the GPDR came out, and you can still use cookies for non tracking purposes without any banner.
Do you maybe want to reconsider? Perhaps instead companies are putting in a good faith effort to comply. I have been invoked in discussions around legal compliance of all sorts of regulation and trust me: no one has ever ever expressed “let’s do some terrible thing because we disagree with regulation”. It’s conspiratorial thinking.
That's it.
They chose the annoying banners, then they chose dark patterns on those banners.
It is a choice.
At best they were lazy and greedy. At worse they were malicious.
The general council (lawyers) at companies are making the decisions around cookies banners and the like, not the folks trying to make money. Regardless of how you might interpret the law and requirements around GDPR, the legal profession as a whole seems to think the crap we live with today is necessary. If it isn’t, it’s on the EU technocrats to clarify in communications, written rules, and on their own damn website what it is supposed to look like.
And clearly, you think billion-dollar companies making dark patterns, ignoring web standards and choosing to track people left and right are less to blame the inconvenience of a banner (that warns you they do) than the people trying to protect your privacy and did it imperfectly.
I have made enought web sites and app that don't have a banner to know it's perfectly possible, even today.
I have implemented DNT support and know it was a great solution before it was taken away.
I have worked with enough clients to know why they chose the banner anyway.
Unlike you I actually read the law, and worked at implementing it. Including with and without a banner.
So I have to conclude you are not an honest actor in this debate, and you are clearly angry as well.
So I'll leave you at that.