3 ms·
> They do this to comply with European GDPR regulations In this case, they actually satisfy the two requirements: 1. "ongoing legitimate interest". They are s
by trwaway02 4y ago
> They do this to comply with European GDPR regulations
In this case, they actually satisfy the two requirements:
1. "ongoing legitimate interest". They are still in a dispute with the customer. Deactivating an account does not require deleting data, so long as the case it not closed. There is no "30 day" limit in this case, and it seems like an arbitrary time period imposed by someone who hasn't thought of the consequences.
2. "users permission". In this case they do have the user permission to keep the content, because the user wants to keep access to the account.
> they don't have the capability to implement any other option.
As mentioned above, you can deactivate an account without also deleting it. It may of course be easier for Google to just delete it instead of introducing a new state, but I would argue that a company such as Google does have the capability to implement this option. I would go so far as to say this is a failure of Google to not have such a process in place.
- londons_explore 4y agoUnfortunately, when they deactivate the account, they lose any ability to communicate with the customer. Anyone who emails claiming to be the customer may or may not be the same person. That works both ways - as well as not being able to get the customers permission to keep the data, they also would not be able to get the customers request to delete the data if they were to keep it 'just in case'. Until they have built some functionality to communicate with the customer behind a suspended account, they have to delete the data within 30 days.
- londons_explore 4y agoEven building functionality to communicate with the person behind a suspended account is hard... For example, if the login requires a password and SMS 2fa, but the SMS is to a Google Fi phone number, then you're going to have to also enable the Google Fi account for that user to be able to login. Or what if they need to use email password resets to another suspended account? (remember you will probably suspend all accounts of a user at once if you suspect something illegal). Making a special 'chat' tool inside the login flow that only requires a single factor (the account password) which allows presenting evidence to a google rep seems like the obvious solution (or requesting the account suspension be delayed, or that the data be deleted). Building and staffing that sounds like quite a lot of work though, which would be hard to justify for the tiny number of impacted accounts and zero revenue potential.
- reitanqild 4y agoYou make it sound like this is inevitable. It isn't as far as I can see. IMO it is just Google trampling over peoples rights while trying to use a weird reading of GDPR as excuse. I'm so ready for EU to start punishing more of the blatant abuse of GDPR that we see, especially by the big players in the market.