I dont really use it much tbf just thought it was a cool project but I’ve just read about how lemmy instances can be fined for not complying with GDPR Read more
I dont really use it much tbf just thought it was a cool project but I’ve just read about how lemmy instances can be fined for not complying with GDPR Read more
Is this a private instance with no other user accounts? If so I would not worry.
Removed by mod
Unless he gets a direct request he’s not bound by the requests other instances get. Which actually brings up something interesting. Because of the way the data is shared, someone wanting to delete data would have to contact all instances one by one which is function impossible.
Removed by mod
It’s definitely not impossible to contact all instances; it’s a finite list. But we should have a tool to make this easier. Something that can take a given username or post, do a search, find out all the instances that it federated-to, get the contact for all of those instances, and then send-out a formal “GDPR Erasure Request” to all of the relevant admins.
And for any of those “processors” outside of the EU? Good luck. I could stand up a processor anywhere outside the EU, get all of the feed data and 1) good luck finding it, me, or where it’s at. And 2) removing it. There’s no centralized authority to fine.
Removed by mod
“Now the execution / collection would be a bitch”. That’s my point. It’s basically unenforceable as they would have to go after every federated instance on the internet, including knowing every single person that spun up their own instance, so basically this law would be pointless. It’s better leveraged against companies, not small individual entities, so good luck utilizing it.
Im the only one that uses this instance but its federated