6 ms·
I totally support this. It still amazes me that companies still do not delete/anonymize user accounts after periods of inactivity. Everything that is linked to
by johnnycerberus 5y ago
I totally support this. It still amazes me that companies still do not delete/anonymize user accounts after periods of inactivity. Everything that is linked to your email address should be purged after 3-12 months of inactivity, including ecommerce like Amazon, game platforms like Steam, cloud storages like Dropbox, or even Hackernews. Good luck trying to find old accounts that you have used years ago, what if they were breached and now they are used by people with bad intentions. In my country (Romania), even barber shops that store user accounts for longer periods than necessary are fined the shit out of them for not closing accounts due to inactivity. Some years ago, I woke up with an inactive G2A account telling me that I have to pay a fee for inactivity. NO! I don't have to pay anything, purge it!
- akersten 5y ago> Everything that is linked to your email address should be purged after 3-12 months of inactivity, including That is such a horrible idea, I go on vacations longer than that. My Dropbox should be deleted if I don't log in for 4 months?
- johnnycerberus 5y agoDo you have a paid account or a free account? If I store my documents on a free account for a one time send to the university application and then I forget about it, then Dropbox should purge it after a time to protect my data, as I don't have any "contract" with them like a subscription or something. The same for G2A, I have bought from them some game keys at a cheap price sometime ago and then I totally forgot that I have one, I couldn't even find the activation mail in my inbox, lol. One day in the summer I woke up with a mail that I have to pay an inactivity fee even if I'm just a row in their database and I have no contractual obligation with them.
- fiddlerwoaroof 5y agoI had a family member go through a major life event that left his OneDrive account unused for about a year. When we needed to access tax documents on it, Microsoft had deleted it. I’m strongly against non-user initiated account deletion.
- saurik 5y agoYeah: I would take the opposite stance to this whole "accounts should be deleted due to inactivity" BS and say that a company that you entrusted your data to now has a moral responsibility to do everything they can to hold on to that data until such time as you explicitly relinquish them of that duty, and if the cost of such a requirement is scary you shouldn't put yourself in a position to hold on to other peoples' data in the first place.
- ivan_gammel 5y agoThey do not have such moral responsibility. Their responsibilities are defined by laws and their T&Cs, which are known to the customers and customers explicitly opt in. If I say in my T&Cs that I delete data after certain period of account inactivity, then this is how it is going to work and user shall not expect anything else.
- saurik 5y ago> Their responsibilities are defined by laws and their T&Cs, which are known to the customers and customers explicitly opt in. You seem to just not believe in morals I guess? ;P Like, yes: the law says you can do something... but I am claiming it isn't moral to do that. You can assert your terms of service let you, but I am claiming that it wasn't moral of you to put that in your terms of service in the first place. (And to the extent to which the law requires you do the opposite, that is us arguing over what the law should say, given that the entire point of this thread is about a changing law.) And like, the user of course should expect you to do the things you claim you will do, but I also think it is fair for users to expect you to claim you will do moral things in the first place. If you are going to pull stunts like deleting data users entrusted to you, hopefully your service is sufficiently optional and unimportant that they can just not use your service without losing out on anything at all in life. I see you work in medicine. Your field collects data on people all the time and then hoards it from them. You take X-rays and then just put them in some filing cabinet. To get a copy of MY X-ray I have to argue with people about it and then I usually get some low-quality shit copy. Meanwhile, you purge your records and delete MY data because I somehow have the gall to not need your specific service for some number of years until I get old and suddenly wish I could get my X-ray and you destroyed it :/. You should frankly be REQUIRED to give people their data to take with and not take it yourself, a step you can't be trusted to not put it in your terms of service that you get to both hoard it and delete it on a whim. If you must insist on holding it yourself, you should be required to have a trust set up that you make regular deposits into to ensure that the data you are holding will survive at least as long as all of your patients. That's what I will claim is "moral", and to the extent to which either laws or the terms of service of your organization fails to match then the lawmakers, lawyers, or entrepreneurs are being horrible people. If you believe in a religion that has a place similar to hell, maybe that's where all of the people who push for, allow, or take part in stuff like this will end up :/.
- ivan_gammel 5y agoIn fact you have the contract with the services where you sign up. Even if you did not read T&Cs, you have accepted them and only then your relationship with the service started on their terms. You are not just a row in the database, you are a customer getting service in exchange for something. You have at least opted in to their data retention policy, and you have to opt out explicitly. If services will be required to purge the customer data after period of inactivity by default, chances are high that free accounts will simply cease to exist. In any case, quite significant share of customers would prefer to opt out from purge and they will be important enough from commercial perspective to make this opt out default in T&Cs acceptance process.
- nickff 5y ago>"If I store my documents on a free account for a one time send to the university application and then I forget about it, then Dropbox should purge it after a time to protect my data, as I don't have any "contract" with them like a subscription or something." I found this sentence interesting, as it contained positive and normative statements that I disagree with, with a non-sequitor between them. You say that you have no contract with them, even though you agreed to some sort of 'user agreement'. Then you say that you forgot about it, and that makes your faulty memory their problem. They have to make sure your data is secure for you because you... just don't bother to pay any attention to where you're leaving it? Should they also be responsible for checking your password against known breaches, to make sure it's not compromised? Where does this end?
- _hzrk 5y agoYes, they should check for any possible breaches. As any other responsbile company already does, like AWS for example which not only checks for breaches, but also scans public repositories like GitHub and GitLab for leaked credentials. A company should also warn a user from time to time that the respective needs to update his password, some companies are so careless that they don't even pay attention to this latter small detail. Or at least to warn an account holder that he still has an account with them. > and that makes your faulty memory their problem It is not only memory that is flawed in humans. Hence the protective measures I'm proposing. > against known breaches What about the unknown ones? How do you protect your user's account when under GDPR Dropbox is the controller of the data? By sending mails ocassionally to update the password, to adopt 2FA, by locking account due to suspicious activity or to purge it in the end if no further action is taken. It ends with the deletion of the user.
- lexandstuff 5y agoSo you'd like Dropbox to "protect your data" by deleting it? I'd rather see my family photos leaked to hackers than see them purged from existence forever because I forgot to log in enough.
- inetknght 5y ago> I go on vacations longer than that. That's the bigger injustice, tbqh.
- Breza 5y agoI completely agree with you. There are plenty of reasons that someone might not use a website for a long time. I didn't use Amtrak from March 2020 through November 2021 and I'm glad I didn't lose my account status. "Sorry, you can't log into this NCAA bracket website because you haven't used it since last year." "Why would I use it more than once a year?"
- luckylion 5y agoIf so, please make it opt-in. Let users set the auto-delete date themselves, because I don't want to have to make sure that I log in every other week to keep my account alive.
- b112 5y agoThis could work, along with a default setting, and if the config was easy to find. Or not purposefully obscured.
- peakaboo 5y agoWhy does it amaze you that companies want to keep user data when we know it's extreamly valuable?
- nine_k 5y agoWhat is extremely valuable about data on an account which is dormant for years?
- usrusr 5y agoYou can fake relevance if you want to sell the company without actually lying. Coincidentally there's a certain class of company that is in a permanent state of being sold and whose communication is under particular scrutiny wrt truthfulness. Seen from any other angle I fully agree, random user data value tends to be greatly overestimated.
- notimetorelax 5y agoWe’ll this is not what the OP is proposing. Data removal after 3 months or a year seems too fast. I game on steam once every two years - do I have to buy all my games each time?
- pomian 5y agoyou are not alone ! (sometimes longer...)
- robbedpeter 5y agoHow do you think profiling is done? If a data aggregator can create a timeline of an individuals life, watching personality traits, social graphs, income, travel, routine, biometrics and health, stress and recreation, political affiliation, brand and taste preferences, savings, debt, credit, and social media influence traces, local, regional, and national cultural influences, and so on... that email archive is gold. You can then create predictive models that let you target products, politics, music, media, and so on. It's not about spying on individuals, it's about manipulating populations. It's about rent extraction and wealth consolidation using tools of influence that negate consent. It augments abuses by law enforcement, corrupting the principles by which democratic governments are supposed to operate by hiding tyranny behind EULAs and TOS and private sector proxies. Imagine a gpt-3 type model, except that instead of predicting text, it's designed to predict behaviors and psychological effects. That gives you a tool that's got a Darren Brown level of manipulation potential that you can scale. It's never going to be 100% accurate at the individual level, but you can target huge collections of individuals to modulate their lives through advertising and media sequencing.
- slickdork 5y agoMildly related: In America, e-mails stored on a server for over 180 days are considered 'abandoned' and can be viewed by law enforcement without warrants. [0] [0] https://en.wikipedia.org/wiki/Electronic_Communications_Privacy_Act#Criticism https://en.wikipedia.org/wiki/Electronic_Communications_Priv...
- Matticus_Rex 5y agoThe bill to fix this relic of a time where people stored emails in noticeably-finite inboxes, the Email Privacy Act, passed the House this session but got knocked out of the bill in the Senate. https://en.wikipedia.org/wiki/Email_Privacy_Act https://en.wikipedia.org/wiki/Email_Privacy_Act
- goodpoint 5y agoHow comes there are no ongoing protests? This is appalling.
- largbae 5y agoI wonder the same thing. Civil Asset Forfeiture is at least as awful and should offend everyone regardless of their stance on current political hot topics. Yet it appears to go on unaddressed.
- CodeMage 5y agoPeople can't protest what they don't know about, and this kind of thing isn't talked about at all.
- kelnos 5y agoI think for most people in the US, this wouldn't make their top 50 list of things wrong with the US, or our legal system in particular. And many of those people would probably read about this, shrug, and think "eh, nothing in my old emails that I care if the government sees". It's actually super weird, because US culture has a strong component of distrust of government. But the government is pretty good at making people fear crime, terrorism, etc., which allows them to get the people to "trust" them with mass surveillance and other privacy invasions.
- pjc50 5y agoThis would be a disaster for a lot of people.
- 323 5y ago> In my country (Romania), even barber shops that store user accounts for longer periods than necessary are fined Those most be some fancy barber shops that you need online accounts for.
- Tijdreiziger 5y agoNot Romanian, but you usually need to make an appointment at a barber (especially now that they can't/don't want to have too many people in their shop at once, due to COVID regulations). If you make the appointment online, then you can usually create an account to view/rebook/cancel it later, if necessary.
- valdiorn 5y agoI book my hair appointment online. they ask for name, email and mobile phone number. They need the name to know who to expect for the appointment. They ask for email and/or phone to send you a reminder (which is nice, IMO). Very reasonable and totally with the GDPR rules as well, as long as they purge the data after a certain time.
- samus 5y agoEmail and phone number should be optional though. People can set up reminders on their phones by themselves.
- wowokay 5y agoI don't want to lose all my steam games just because I am inactive for a time. That us a terrible idea, I purchased those digital goods, that's like saying crypto markets should dump data from time to time.
- Schroedingersat 5y agoThen fight for digital purchases to be actual purchases, not renting until you lose that account.
- renewiltord 5y agoWhat, why would I do that? I don't want to fight for something I already have. I'd rather fight against people who would take it from me.
- ajmurmann 5y agoSo what would your ideal scenario look like? I buy the game download it, backup on S3, pay for that and then lost access when I don't access it in a few months? I'm super happy I don't have to worry about storage for my large Steam collection.
- kevinventullo 5y agoStrongly disagree, for Steam in particular. I played a lot of computer games in high school and early college, then stopped for about 7 years. When I finally bought a new computer, I somehow remembered my old Steam password and was thrilled to find that all the old games were still on my account, ready to download. In comparison, I had long lost any physical copies of games I had purchased as a youth. As a bonus, I get the “bragging rights” of having nearly the oldest possible steam account (it can now vote).
- tluyben2 5y agoI have accounts over 20 years old I use every few years. I would not be very amused if your suggestion takes off. I can see simple things happening though that work towards this; for my pet project I just coded a feature that hashes email addresses of inactive (3 months without any interaction) and using another differently salted hash of their email address (which we then no longer have after this) to encrypt their data. They can still login, which restores their account and data without them noticing, but they will never receive email and possible breaches hurt less.
- robbedpeter 5y agoNobody is suggesting you can't consent to long term storage, we're advocating for a sane, privacy respecting default.
- ThrustVectoring 5y agohttps://steamcommunity.com/id/ruakai/recommended/582660/ https://steamcommunity.com/id/ruakai/recommended/582660/ This is the sort of experience that you want. In case you don't want to click through, this is someone with over 1700 hours in an MMO who lost all their progress and items because they took a break and missed the GDPR-related opt-in to get their account transferred.