6 ms·
Once the export is done and I see something I don't want to exist anymore, where do I request that data be permanently removed (GDPR style)? Asking as I honestl
by sdwolfz 6y ago
Once the export is done and I see something I don't want to exist anymore, where do I request that data be permanently removed (GDPR style)? Asking as I honestly don't know.
- amelius 6y agoI think Google Takeout is not meant to give an exhaustive overview of what Google knows about you. It is meant as a service for backup, and migration to other services.
- lopis 6y agoExactly. Unfortunately GDPR failed to realize that most data companies hold about us is inferred. Data takeouts usually provide you with all data you willingly provided (uploads, reviews, likes, playlists, etc). But most interesting information is missing. How often did I watch each video? When did I open each e-mail? There's so much data that companies collect about your behaviour that is never given back to us.
- jakubp 6y agoGDPR does cover inferred data. Source doesn't matter. Only whether this is data about a specific identifiable person and whether it's covered by the list of protected types of data.
- aboringusername 6y agoIt's entirely possible to collect information to identify a unique human without it being considered PII - combine it all together and maybe add a sprinkle here and there (perhaps public domain info, buying "anonymized" info) and boom, you know who it is. Yet, if you're audited, it's just a series of IDs and numbers, nothing identifying there...Right? If you ask Spotify for your data dump, you'll notice in a lot of the .JSON files the information is encrypted such that you can't understand it (it's just numbers). It's impossible to say whether it's actually stored like this or if they encrypt it before they provide the archive to you. Meta data is almost impossible to legislate against, and as far as I can see, is entirely legal to collect and use as you see fit. How many people in the world are on hackernews, named "lopis", use Firefox 65, have an IP address in $country, use this screen resolution etc etc Easy enough to identify who you are.
- hyperman1 6y agoAFAIK the GDPR already does this: See first definition of https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CELEX:32016R0679&from=EN#d1e1489-1-1 https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CEL... You are identifiable by combining multiple factors, even if every individual factor is not enough to be identifiable. If I understand it correctly, the EU 'personal data' (PD) concept is much wider than the US 'Personally Identifiable Information' (PII) concept. You are touching one of the differences here.
- cj 6y agoThis is correct. For GDPR purposes, data is PII if it can be used in combination with any other data to identify an individual. Doesn’t matter if the individual data points are not themselves identifying. One thing I’ve been curious about is whether AI and algorithms that can potentially take a huge amount of anonymous data and “identify” a user (but not explicitly), only identify in the sense that the output of the AI was only possible by correlating individuals granularity enough. I’m almost certain the answer is yes. I’m not clear on whether GDPR addresses that issue or not.
- 6y ago
- kace91 6y agoMy gdpr requests have usually included inferred data. I'm not sure if it was facebook or tinder's that showed a giant list of categories they thought I fitted in, which was btw hilariously wrong (I'm a 30 y/o single male and I was categorised as a single mom, for example).
- fauigerzigerk 6y agoYou'd have to go to the specific Google service that stores the item you want to delete. You can delete emails in Gmail, photos in Google Photos, etc.
- aboringusername 6y agoThis is the wrong answer. Right answer: You can go to [1] and [2] and [3] and ask them to delete your information. It's important to retain a copy in writing that they have removed your information. If a copy is ever found online (in a data breach or otherwise) you would be able to enact legal rights as a result of their GDPR breach. I would encourage people who upload data to leave "fingerprints" in their accounts, such as certain photos, emails, and other data that you have ONLY created on this service (for example, email your own gmail account a unique email, if it's ever leaked, you know where it came from). It's the same way Spotify's GDPR tool does NOT give you all the information they store, yet if you ask via their DPO (usually privacy@) you get a lot more data, rather sneaky way of hiding their true data collection. ALWAYS use email or a physical letter, ALWAYS get a reply by the organization when enacting your GDPR rights, your lawyer/legal authority will be very thankful ;) AND NEVER EVER USE AUTOMATED TOOLS! The chances are, there is data that isn't included within them. For example, go ahead right this second and submit a SAR for "technical log information" to Google, this data is NOT included in their official tools and you will be amazed how much they're storing!! [1]: https://support.google.com/policies/answer/9581826?hl=en https://support.google.com/policies/answer/9581826?hl=en [2]: https://support.google.com/policies/contact/sar https://support.google.com/policies/contact/sar [3]: https://support.google.com/legal/troubleshooter/1114905?p=privpol_remove https://support.google.com/legal/troubleshooter/1114905?p=pr...
- H8crilA 6y agoRE [2]: You mean "About which Google product" -> "Other", "What personal data are you seeking?" -> "technical log information" ?
- yoaviram 6y agohttps://yourdigitalrights.org/d/google.com https://yourdigitalrights.org/d/google.com This service will generate an email with a general deletion request. Modify it to ask for the specific information you want deleted. Disclaimer: I'm the creator of this service.
- thatsnotmepls 6y ago> If you do not normally deal with data protection requests, please forward this email to your Data Protection Officer, or relevant member of staff. Please note that you have 30 days to comply with this request. Google: "Listen here you little sh*t"
- cromantic 6y agoOptions are GDPR which applies to European Union residents and CCPA which applies to Californians. Is there anything for people within the US who are residents of the other 49 states?