| This policy seems purposefully vague. "Explain its data retention/deletion policies and describe how a user can revoke consent and/or request deletion of the user’s data." My first question before looking into it was, "What an auth tenant or some other service that stores user data?" or, "what about like a banking or healthcare app that is just a portal for another system?" And, "What does deleted even mean? IsDeleted=1?" It would appear Apple's stance on those answers is a shrug emoji. I'm no appstore developer but I got a kick out of reading a lot this for the first time. This rule bearing no exception to a trend that for most part seems intended to give Apple the license to eliminate bad actors. I got a new one for Apple.
"Like, do what you gotta do but don't be a jerk." |
Deleted means removing as much PII as you reasonably have authority to do so. It means purging all that data from all databases with a guarantee that you will be removed completely from all snapshots in a reasonable amount of time.
This should be the default, normal understanding of what it means to delete your account.
It doesn't mean set a flag in a database so when your company gets acquired in a few years your new owner has a nice little trove of data to mine of people that explicitly opted out.