https://github.com/LemmyNet/lemmy/issues/4433

Should i repost this to any other /c/'s meant for this kind of things ?

EDIT: In case anyone don’t understand what this is it is an issue raised by someone on lemmy git that when an account is deleted or banned it should also delete the data the data posted by the user. And one of the main dev nutomic is blowing it of like it won’t affect me and maltfield is remainding him that it is illegal under the EU law and it also affects lemmy and moreover it is not ethical or moral . And i thought that was what lemmy was built on privacy, ethics and morals now i am dissapointed.

EDIT : For everyone saying there is no way i am not really ap roggrammer or anything but couldn’t this work :

They could just roll it out on a new version and i think most instances won’t mod it to remove that maybe some oddball ones will but not most. I know saved copies will be there but who cares no one is saving my 1000 comments but that is not the case with this .

It is copy pasted from one of my replies.

EDIT: Also it is not my intention to point finger to lemmy devs and i can differentiate their political stance and their work my only intention was to see that if this post gained enough traction they will reply or fix the issue.

EDIT : Relevant comment from @[email protected] about what if other instance don’t delete your data.

So maybe those instances are breaking the law, but Lemmy by default should comply. You could say the exact same thing about any social media - scrapers can and do archive everything they can - but that doesn’t absolve the original platforms (e.g. Twitter) from having to follow the law.

EDIT : As just a person i can’t do anything about it but i am certain if everybody pitch in the lemmy devs will listen and even though everyone seems to hate lemmy devs political stance i can differentiate with politics and their work and i find @[email protected] to be very responsive so i am gonna mention him and see what he thinks about it instead of trashing lemmy devs on speculation (i don’t know nutomic’s id) even though i don’t agree wuth nutomic’s response in this case i don’t share the views of many people in the comments and don’t associate this post with them.

EDIT : I just want an option to purge my data when deleting an account that you can enable or disable.

EDIT:Ok i just woke up and am catching up with some of these replies and i wanna say i don’t share any of their views nor am i affliated with them i never wanted to trash on the dev and that is one of the main reason i posted this on casual conversation i didn’t think this would get this uncasual . All i wanted to so was draw attention to this problem so devs will act on it faster but since then i have learned lemmy politics does’nt work like that and as i am not the mod or anyththing i can’t do anything about some of the comments except make it clear i have no affliations with them. Just keep it casual people. I too want these changes but maybe geemtting on the nerve if devs isn’t the best way to achieve it.

Something @[email protected] chimed in .Your comments can be public, but your data is yours. That’s the whole point of GDPR. Think of an art gallery. The gallery does not own the art a lot of the time, they simply show it. The art is owned by the artist. If they want to take it down they can. The same thing applies here. Your data, you get to choose what happens to it in the eyes of the law.

EDIT:

I accidently left this part out so uploading it.

  • THE MASTERMINDOP
    link
    fedilink
    English
    129 months ago

    But him blowing it off like that was spezy we should be better than reddit and let users delete their data if they want to .

    • @rdyoung
      link
      English
      27
      edit-2
      9 months ago

      That would be ideal but reality is that because of the way the fediverse works there is no way to control what we post to instances that aren’t our home one and we definitely can’t undo the thousands of copies of those comments/posts that get copied across the fediverse.

      This is a concept that was understood in the early days of the internet and seemed to have gotten forgotten over the years. The basic concept of not being able to unring a bell.

      Basically even if a local instance lets us delete our account and all comments/posts, it would be up to every other federated instance to honor that delete transmission, we have no way to enforce that.

      • @pixxelkick
        link
        English
        49 months ago

        there is no way to control what we post to instances that aren’t our home one

        This doesn’t give the home instance a get out of jail free card for also failing to comply.

        This is pure whataboutism.

        • @rdyoung
          link
          English
          -19 months ago

          First off. That’s not the definition of whataboutism. Second. It’s simply the reality we live in. It’s clear in posts like this who actually understand code and software at their core and who wouldn’t be able to name even 1 coding language aside from an oldy like cobal.

          I’m not justifying anything or saying that the right to be forgotten isn’t a worthwhile goal to strive for. What I am doing is attempting to explain reality and the unlikelyhood of OPs dream happening in the fediverse any time soon, if at all.

          I’ll close by pointing out that it’s clear you nor OP read or understood what I said about someone scraping an instance and having a copy of everything posted up to that point and the undeniable fact that you can’t delete anything from that data even if every single instance respected the delete command.

          • @pixxelkick
            link
            English
            69 months ago

            The fact you bring up scraping at all indicates you have no idea what this is about.

            Data privacy and protection isn’t about that.

            “Some third party could just…” is indeed trying to whataboutism it, it’s completely irrelevant.

            Other instance owners are completely irrelevant.

            You’ll need to wrap your head around the fact that legally lemmy has to support the takedown request per instance, not federation wide.

            If I truly wanted my data gone I’d have to make the request to each individual server. That’s fine.

            Data privacy and protection compliance means that I can request specifically server A take down my data, and still be fine with server B retaining a copy.

            If I wanted both to drop the data, I’d have to request it from both individually.

            Scrapers aren’t involved here.

            The protection isn’t about “oh no people on the internet can see my posts”

            It’s more about “oh man it came to light Server B’s owner is selling people’s data and I don’t want my data included in that”

            This is a legal requirement, id recommend lemmy instance owners check in with their local lawyers about this, because a lack of compliance could get individual instance owners in hot water, and if multiple large instance owners realize this, it should put more pressure on the debs to fix that shit.

            • @rdyoung
              link
              English
              -69 months ago

              You really are having a hard time here. I’m too tired to deal with this level of idiocy. You have a nice day now.

      • THE MASTERMINDOP
        link
        fedilink
        English
        -39 months ago

        They could just roll it out on a new version and i think most instances won’t mod it to remove that maybe some oddball ones will but not most. I know saved copies will be there but who cares no one is saving my 1000 comments but that is not the case with this .

        • Nomecks
          link
          fedilink
          English
          119 months ago

          It’s not an issue until it’s an issue. Someone will need to attempt to exercise their GDPR rights to get a change made. As others have said, it’s not so black and white as removing posts from something like Spezddit or Shitter, so the EU may need to weigh in if/when it becomes a legal issue.

        • @rdyoung
          link
          English
          -2
          edit-2
          9 months ago

          A new version of what? This is open-source software, anyone can modify and compile their own version and stay federated so long as it stays compatible. Basing compatibility on the deletion of posts/comments/accounts is way more complex than you may think and would only lead to all kinds of unforeseen issues down the road.

          All of this also doesn’t stop anyone from scraping and storing a local copy of any public available instance. Somewhere in my collection of software I have one from a couple of decades ago that does exactly that, it pulls down an entire site just based on a url, it will basically mirror a site.

          I think we would be better off focusing on 2 slightly at odds concepts.

          1. Getting used to whatever we say is out there forever and learning to be comfortable with that and not saying anything that we would be bothered by friends and coworkers seeing.

          2. Teaching people to be truly anonymous on the webs and being careful to not share enough info to be identified by their collective posts (which is easier than people realize).

          • THE MASTERMINDOP
            link
            fedilink
            English
            -49 months ago

            I get that but why do you think any of the instance admin do that ? It is aldready very costly for then to host an instance unless they are selling our data i don’t see the need to and in that case there’s nothing we can do about it.

            • @rdyoung
              link
              English
              -29 months ago

              Do you not see how this comment is a polar opposite of your initial post and other comments?

              No, you probably don’t and that’s what I have had to deal with online for over 30 years.

    • @[email protected]
      link
      fedilink
      English
      69 months ago

      It’s not possible.

      By design, everything you posted is shared to hundreds of other servers, all of which are capable of doing anything they want with it. I can guarantee you that there are several that are archiving anything and everything that gets federated to them and will not remove that content when the original server does.

      • @[email protected]
        link
        fedilink
        English
        139 months ago

        I can guarantee you that there are several that are archiving anything and everything that gets federated to them and will not remove that content when the original server does.

        So maybe those instances are breaking the law, but Lemmy by default should comply. You could say the exact same thing about any social media - scrapers can and do archive everything they can - but that doesn’t absolve the original platforms (e.g. Twitter) from having to follow the law.

          • @[email protected]
            link
            fedilink
            English
            7
            edit-2
            9 months ago

            Pseudonymisation means something different from what you think in the context of the GDPR. Usernames are not pseudonyms, they are personal data (see art 4/1. “online identifiers”). Pseudonyms are something the processor introduces to disassociate data from the username like an user database ID.

            And pseudonymisation is only a method introduced to further protect data, you still need a reason to keep it. If you have no legitimate basis to keep that data, and the data subject requests a deletion, pseudonymous data also needs to be deleted.

            Also, legal practice has confirmed that social media posts absolutely do qualify as personal data.

          • @[email protected]
            link
            fedilink
            English
            39 months ago

            But some people do use pseudonyms that are easy to tie to their real identity. Or sometimes, just their name. (I haven’t encountered it on Lemmy but there’s absolutely nothing to stop it from happening)