Video description as of 2023-06-23 10:15 PDT:

This video shows that Reddit refused to delete all comments and posts of its users when they close their account via a CCPA / GDPR request. Posts and comments may contain PII. Specifically, Reddit tells users that they must delete the content themselves, which isn’t realistic if a user creates a lot of posts. Even if a user does delete their content, Reddit restores the content within a few days.

Video transcript:

  • 2023-06-13 @ 15:15 PDT: user states he deleted all posts and comments
  • 2023-06-16 @ 10:15 PDT (3 days later): user states all posts and comments have been restored
  • 2023-06-19: user decides to submit a legal request under CCPA to delete content
  • 2023-06-19 @ 11:07 PDT: user receives reply from “Reddit Legal Support” (RLS) which states they will delete the account but not the content associated with the account. It is up to the owner of the account to remove the content [e-mail contents reproduced below]
Reddit Legal Support (Reddit Support)
Jun 19, 2023, 11:07 PDT

Hello,

We would be happy to help you delete your Reddit account if you have one. Before we proceed please note:

 1. Account deletion is irreversible.
 2. Posts and comments must be separately deleted before deleting your account. If not separately deleted, the content of the posts and comments will remain visible and disassociated from any account. If you want your posts and comments removed, follow the instructions on our help page. 

Once the above mentioned information is removed to your satisfaction, please submit your deletion request by using your Reddit account and this form so we know it's really you making the request.

More information about account deletion is available in our Privacy Policy.

Kind regards,

Reddit Legal Support
  • 2023-06-19 @ 12:02 PDT: user replies back to RLS stating it is unrealistic expectation for end user to manually delete and alleges violation of CCPA [reply reproduced below]
Hello,

If I understand your response properly, you are refusing to delete all data associated with my account. I believe this is illegal and in violation of the CPR. In this case the onus is on you, Reddit, to delete all of the content associated with my account. 

It is besides the point but last week I already deleted all of the posts and comments associated with my account. However Reddit has since restored most of the content.

It is untenable to demand all users to manually delete content when Reddit itself does not provide a self-serve mechanism to mass-delete content. Some users have thousands of posts and millions of comments. 

Just as a reminder, my CPA request to delete my account and all associated data was made on June 19th 2023 and must be completed by August 3rd 2023.
  • 2023-06-24 @ 10:45 PDT: user has not received a reply from RLS. He decided to painstakingly delete all posts and comments while screen recording the effort. Video continues with the user manually deleting posts for his account (https://www.reddit.com/user/nucleocide). Then fast forwards to the end of the segment where the last posts are deleted
  • 2023-06-25 @ 10:25 PDT: user discovers posts and comments are restored, again

User concludes video and clarifies why this is a violation of CCPA:

At this point it appears impossible to manually delete posts and comments on Reddit and expect them to stay deleted. 

By not deleting all posts and comments in an automated way there is no way to guarantee that no PII [Personally Identifiable Information] has been left behind.

For example ...

<user gives example of a comment from 6 months ago on his account which includes his real first name and last name. Screen capture shows the comment was edited recently>

Since there is no guarantee that every single post and comment is free from PII, Reddit must delete all comments and posts from an account upon receiving a GDPR / CPA request.

Reddit Discussion on “/r/videos”: https://old.reddit.com/r/videos/comments/14je01k/reddit_may_be_violating_the_fucking_ccpa/

[2023-06-23 14:52 PDT] edit ~ formatting, fix title typo

  • @ozillator
    link
    English
    -371 year ago

    How does one go about holding a US based company accountable violating an EU law that they aren’t required to comply with?

    • @romaselli
      link
      English
      73
      edit-2
      1 year ago

      They are required to comply with it if they want to offer services to European customers. If they don’t comply with the local regulation they will face fines and if they don’t pay them and become compliant, they might have their access blocked from within the EU.

      The same is true for Brazil, which has similar legislation to the GDPR to protect Brazilian users from online services abusive practices regarding their data. Services can and have been blocked in Brazil for failing to comply with local regulations.

      • @Gabu
        link
        English
        101 year ago

        Adding to this, while there are certainly ways to bribe the Brazilian regulatory and supervisory bodies, they’re pretty damn heavy handed and pro-consumer to begin with. One agency has recently fined Netflix for their bait-and-switch marketing to what is estimated as several hundred million USD, with even bigger fines to come.

      • @jcg
        link
        English
        31 year ago

        Has this ever actually happened?

        • @romaselli
          link
          English
          33
          edit-2
          1 year ago

          In Europe fines have been dealt but no blocking yet as far as I am aware. Just the fine and threat of a block happening is usually enough to make companies comply because they don’t want to lose out on the market share.

          Edit: Link to Europe statistics: https://www.privacyaffairs.com/gdpr-fines/

        • Jon-H558
          link
          fedilink
          61 year ago

          A lot of local.usa news sites region block EU ipaddresses to premptivly as they do a lot of tracking.etc that would.violate it so they just chose not to have the hassle of eu visitors

          • @jcg
            link
            11 year ago

            Yeah I read about that but it seems to be voluntary. I haven’t read anything about anyone actually being blocked, but it seems to be because the threat of a fine and blocking is enough. Another commenter pointed out they have offices within the EU so I guess EU officials could chase them up there.

      • @mallocOP
        link
        English
        -101 year ago

        So Brazil has the equivalent of China’s firewall? Or is this something implemented at the ISP level?

        • @romaselli
          link
          English
          111 year ago

          It’s implemented at the ISP level, Brazilian courts can mandate all nationally operating ISPs and mobile carries to block certain websites or services if they fail to comply with for example a judicial warrant. This has happened twice with WhatsApp for instance, and Telegram was threatened with it as well because they refused to hand over the identities of neonazi domestic terrorist groups.

            • @Gabu
              link
              English
              71 year ago

              The average user doesn’t even know what a proxy is. At that point, you’ve killed profitability.

            • @romaselli
              link
              English
              51 year ago

              I am aware, but businesses generally don’t want their users to jump through hoops to be able to access their services.

    • @SuperIce
      link
      English
      341 year ago

      They are required to comply with the GDPR to operate in Europe.

      • @sudneo
        link
        English
        151 year ago

        Even more, they are required to comply if they target European countries as a market. For example, if you have registration open and you have translations in - say - French, Italian, German etc. It is already enough to force you to comply, as there is the clear intent of targeting European users.

    • @phx
      link
      English
      291 year ago

      The same way they have with Facebook, Google etc. If they continue to do business in Europe with European users, they comply with European law or get fined significant amounts.

      • @HamSwagwich
        link
        English
        81 year ago

        That Irish sandwich corporate structure (that’s really a thing , I’m not making it up) to dodge taxes is coming home to bite them in the ass. How delicious…

    • Anti-Antidote
      link
      English
      131 year ago

      It’s either comply with laws regarding EU users or get blocked from operating in EU countries, I’m not sure of the entire process though

      • @Cannacheques
        link
        English
        11 year ago

        Internet empires like Facebook and Reddit have a lot of grey area to be honest

    • @SuperIce
      link
      English
      11 year ago

      deleted by creator