this post was submitted on 19 Jun 2023
158 points (98.8% liked)
Technology
37747 readers
169 users here now
A nice place to discuss rumors, happenings, innovations, and challenges in the technology sphere. We also welcome discussions on the intersections of technology and society. If it’s technological news or discussion of technology, it probably belongs here.
Remember the overriding ethos on Beehaw: Be(e) Nice. Each user you encounter here is a person, and should be treated with kindness (even if they’re wrong, or use a Linux distro you don’t like). Personal attacks will not be tolerated.
Subcommunities on Beehaw:
This community's icon was made by Aaron Schneider, under the CC-BY-NC-SA 4.0 license.
founded 2 years ago
MODERATORS
you are viewing a single comment's thread
view the rest of the comments
view the rest of the comments
I think an option for full data deletion would be nice for those who want it, otherwise people should also expect others recording their data, which can be published later on.
Parts of it may actually be required under EU law. GDPR requires that anyone holding data on EU citizens comply with certain things, including a request to delete certain kinds of data. The EU has shown themselves willing to go after sizeable corporations for violations; most Lemmy instance operators are much smaller. This should probably be addressed before people find themselves on the wrong end of lawsuits.
GDPR likely doesn't apply to public facing forums in the way you're thinking, if you post actual personal data (which has a strict definition) yes it's murkier, but in general just posting on a public facing forum is extremely unlikely to qualify under right to be forgotten under GDPR.
Notably, GDPR is extremely unclear about this specific circumstance, and will likely fall to practicality. The user can make requests for their data to be deleted, those should in general be followed no matter who's server it's on, but they have to be given to each server by the user. Following the deletion requests is generally advisable, but again, it's highly unlikely GDPR applies here. Feel free to get a GDPR lawyer to actually weigh in though.
Part of it will depend on what data you're holding, and part will depend on who's running the instance. A lot of people won't be covered, but I'd wager there's some here and there who need to consider it.