Hacker News new | ask | show | jobs
by BiteCode_dev 23 days ago
The GDPR does not say that controllers must always delete personal data on request. Article 17(1)(a) — erasure is required only when:

"the personal data are no longer necessary in relation to the purposes for which they were collected or otherwise processed"

https://gdpr-info.eu/art-17-gdpr

It's like the cookie banner all over again. This law never, ever required a cookie banner.

The big companies are master in malicious compliance that benefit them, and let them blame the EU for it.

Rules of thumbs, international billion dollars company should be assumed to be the ones being the bad guys until proven otherwise. They have lost the benefit of the doubt decades ago.

2 comments

If it’s malicious compliance and not required why does the EU Commission website have it?

https://commission.europa.eu

Because if enough idiots do it, stupid managers think it's the standard. The EU Commission is unlikely to know anything about their website, it's made by some department that blindly follows a manager's order that just looked at what others did and copied it.

We could all have used the DNT header as a bypass when the GPDR came out, and you can still use cookies for non tracking purposes without any banner.

So the EU commission put out a rule that you say has been widely misunderstood and implemented via malicious compliance. Where is the EU statement and education on this? Why aren’t they louder in explaining this isn’t what they wanted? And they allow their own websites to do the very thing that they supposedly don’t want?

Do you maybe want to reconsider? Perhaps instead companies are putting in a good faith effort to comply. I have been invoked in discussions around legal compliance of all sorts of regulation and trust me: no one has ever ever expressed “let’s do some terrible thing because we disagree with regulation”. It’s conspiratorial thinking.

No need for a conspiracy. There was the DNT standard, companies made more money from not taking it into consideration.

That's it.

They chose the annoying banners, then they chose dark patterns on those banners.

It is a choice.

At best they were lazy and greedy. At worse they were malicious.

Don’t change the topic.

The general council (lawyers) at companies are making the decisions around cookies banners and the like, not the folks trying to make money. Regardless of how you might interpret the law and requirements around GDPR, the legal profession as a whole seems to think the crap we live with today is necessary. If it isn’t, it’s on the EU technocrats to clarify in communications, written rules, and on their own damn website what it is supposed to look like.

Two things can be true.

And clearly, you think billion-dollar companies making dark patterns, ignoring web standards and choosing to track people left and right are less to blame the inconvenience of a banner (that warns you they do) than the people trying to protect your privacy and did it imperfectly.

I have made enought web sites and app that don't have a banner to know it's perfectly possible, even today.

I have implemented DNT support and know it was a great solution before it was taken away.

I have worked with enough clients to know why they chose the banner anyway.

Unlike you I actually read the law, and worked at implementing it. Including with and without a banner.

So I have to conclude you are not an honest actor in this debate, and you are clearly angry as well.

So I'll leave you at that.

In practice most of the purposes you'd encounter in the wild are directly linked to user activity, so account deletion means most of the reasons to keep it disappear.

You still need to keep it if there's a law saying that you need to have that data, of course, but that's the exception.