3 ms·
The GDPR allows you to force companies to delete data that was knowingly and willingly commited, though, via article 21 and 17c GDPR [1], except if there are "o
by schroeding 4y ago
The GDPR allows you to force companies to delete data that was knowingly and willingly commited, though, via article 21 and 17c GDPR [1], except if there are "overriding legitimate grounds for the processing" of the data. I doubt there are, at least for low-profile, personal websites and historical WHOIS data.
You could IMO also make an argument that the collection and scraping of WHOIS data without consent was unlawful processing as a whole, as the data was not provided to the domain NIC with explicit consent for third-parties to collect and save them forever, which would even make any overriding legitimate grounds for processing moot.
17a may also apply: The reason for WHOIS is to find out who owns a domain now, right? There is no version history. Historical WHOIS data does not serve this purpose anymore.
It's quite the can of worms.
[1] https://gdpr-text.com/de/read/article-17/ https://gdpr-text.com/de/read/article-17/