10 ms·
Absolutely! I remember asking to export my data from one of the services and the support pretty much ignored me (they replied in general but “forgot” to mention
by beyondcompute 5y ago
Absolutely! I remember asking to export my data from one of the services and the support pretty much ignored me (they replied in general but “forgot” to mention anything related to that question).
- varispeed 5y agoCompanies think that the data that is portable is your email address, profile picture, address, IP addresses - but other things like posts, comments are not. It is actually not well defined in GDPR and if portability means transferring your profile (e.g. username, email and some details about you only), then GDPR is pretty much useless in that regard.
- account42 5y ago> Companies think Which ones have you tried exporting your data from?
- grishka 5y agoI wanted to get my data out of ask.fm because I answered quite a lot of questions there back when it was fun. The GDPR export option was nowhere to be found. Opened a support ticket, they asked me for a EU ID... Well, yeah, I don't have one, I'm not a EU resident, I wanted to piggyback on the laws of countries that actually care about their people. But it just struck me that they hate their users this much. Even Facebook didn't go this low. On an absolutely unrelated note, I reverse engineered ask.fm's client API back when I was actually using it.
- wizzwizz4 5y agoUnder GDPR I think they're not allowed to require an EU ID. So just say “I'm not required to give you my personal data for this”.
- johndough 5y agoDo you have a source for this? In my experience, many large companies ask for ID. I am not quite sure which is correct since, on the one hand, they should verify that a request comes from the legitimate account holder, but on the other hand, they should practice data minimization.
- grishka 5y ago> they should verify that a request comes from the legitimate account holder Facebook and Google do this by asking you to enter your password again. The ID thing is clearly there to impose a limit based on your nationality.
- scrollaway 5y agoYou can be an eu citizen with a non-eu ID so it makes no sense.
- anticensor 5y agoHow?
- scrollaway 5y agoIf you have a right of permanent stay in the EU, you're a citizen, even if you're from a non eu country. If you have dual nationality between an eu and non eu country you might have two IDs as well. Lots of cases like these. I'd call them edge cases but they're really not.
- sushibowl 5y agoI suppose this is a UK source but it should apply to GDPR generally https://ico.org.uk/for-organisations/guide-to-data-protection/guide-to-the-general-data-protection-regulation-gdpr/right-of-access/what-should-we-consider-when-responding-to-a-request/ https://ico.org.uk/for-organisations/guide-to-data-protectio... > You should also not request formal identification documents unless necessary. First you should think about other reasonable and proportionate ways you can verify an individual’s identity. You may already have verification measures in place which you can use, for example a username and password. The GDPR doesn't state explicitly how to do identification for subject access requests, only that “The controller should use all reasonable measures to verify the identity of a data subject who requests access, in particular in the context of online services and online identifiers.” In the case of ask.fm it seems like if the person's identity can be verified by the fact that they can access their account, it's not reasonable to require an official ID.