Video description as of 2023-06-23 10:15 PDT:
This video shows that Reddit refused to delete all comments and posts of its users when they close their account via a CCPA / GDPR request. Posts and comments may contain PII. Specifically, Reddit tells users that they must delete the content themselves, which isn’t realistic if a user creates a lot of posts. Even if a user does delete their content, Reddit restores the content within a few days.
Video transcript:
- 2023-06-13 @ 15:15 PDT: user states he deleted all posts and comments
- 2023-06-16 @ 10:15 PDT (3 days later): user states all posts and comments have been restored
- 2023-06-19: user decides to submit a legal request under CCPA to delete content
- 2023-06-19 @ 11:07 PDT: user receives reply from “Reddit Legal Support” (RLS) which states they will delete the account but not the content associated with the account. It is up to the owner of the account to remove the content [e-mail contents reproduced below]
Reddit Legal Support (Reddit Support)
Jun 19, 2023, 11:07 PDT
Hello,
We would be happy to help you delete your Reddit account if you have one. Before we proceed please note:
1. Account deletion is irreversible.
2. Posts and comments must be separately deleted before deleting your account. If not separately deleted, the content of the posts and comments will remain visible and disassociated from any account. If you want your posts and comments removed, follow the instructions on our help page.
Once the above mentioned information is removed to your satisfaction, please submit your deletion request by using your Reddit account and this form so we know it's really you making the request.
More information about account deletion is available in our Privacy Policy.
Kind regards,
Reddit Legal Support
- 2023-06-19 @ 12:02 PDT: user replies back to RLS stating it is unrealistic expectation for end user to manually delete and alleges violation of CCPA [reply reproduced below]
Hello,
If I understand your response properly, you are refusing to delete all data associated with my account. I believe this is illegal and in violation of the CPR. In this case the onus is on you, Reddit, to delete all of the content associated with my account.
It is besides the point but last week I already deleted all of the posts and comments associated with my account. However Reddit has since restored most of the content.
It is untenable to demand all users to manually delete content when Reddit itself does not provide a self-serve mechanism to mass-delete content. Some users have thousands of posts and millions of comments.
Just as a reminder, my CPA request to delete my account and all associated data was made on June 19th 2023 and must be completed by August 3rd 2023.
- 2023-06-24 @ 10:45 PDT: user has not received a reply from RLS. He decided to painstakingly delete all posts and comments while screen recording the effort. Video continues with the user manually deleting posts for his account (https://www.reddit.com/user/nucleocide). Then fast forwards to the end of the segment where the last posts are deleted
- 2023-06-25 @ 10:25 PDT: user discovers posts and comments are restored, again
User concludes video and clarifies why this is a violation of CCPA:
At this point it appears impossible to manually delete posts and comments on Reddit and expect them to stay deleted.
By not deleting all posts and comments in an automated way there is no way to guarantee that no PII [Personally Identifiable Information] has been left behind.
For example ...
<user gives example of a comment from 6 months ago on his account which includes his real first name and last name. Screen capture shows the comment was edited recently>
Since there is no guarantee that every single post and comment is free from PII, Reddit must delete all comments and posts from an account upon receiving a GDPR / CPA request.
Reddit Discussion on “/r/videos”: https://old.reddit.com/r/videos/comments/14je01k/reddit_may_be_violating_the_fucking_ccpa/
[2023-06-23 14:52 PDT] edit ~ formatting, fix title typo
Call them out on LinkedIn. Bet.
Decided to expand on the original video and include a transcription of the events in the video. Hope this helps our visually impaired folks.
Personally, I find this disgusting. Hope Reddit gets litigated up the ass.
deleted by creator
EU GDPR - where to report if someone refuses to delete personal data.
List of institutions for each EU member.: https://edpb.europa.eu/about-edpb/about-edpb/members_enI really hope the GDPR is put to full use here.
I’m curious though, what would happen if someone sent a GDPR deletion request to a Lemmy instance? The server admin would then delete the posts and account, but what if some other instances had defederated after the user made the posts, how would it be possible to make sure the posts are deleted from those instances as well? In theory that could be hundreds of servers. I guess the user would have to reach out to each instance?
Good question. Yes, it would be much harder because you’re basically shotgunning your posts all over the place when posting here. I would think it’s pretty much impossible to make sure that every single instance of it is gone.
As far as I can tell, GDPR is a defense against corporations who claim to own your data, and hold that data hostage. But it’s not a infallible tool to scrub data from the internet.
Think about a tweet that’s been screenshotted throughout the Internet. Twitter would have to delete the original post and and data they control, but I imagine they have no liability for the outsiders taking screenshots.
How GDPR applies to Lemmy may have to be explored in court.
But I’m just a layperson without specific knowledge of the law, so that legal framework may already exist.
This seems enough to me to sue them on grounds of violating the GDPR. Not sure where spez is going with this but paying GDPR fines will most definitely not do any good to reddit’s profitability lol
How does one go about holding a US based company accountable violating an EU law that they aren’t required to comply with?
They are required to comply with it if they want to offer services to European customers. If they don’t comply with the local regulation they will face fines and if they don’t pay them and become compliant, they might have their access blocked from within the EU.
The same is true for Brazil, which has similar legislation to the GDPR to protect Brazilian users from online services abusive practices regarding their data. Services can and have been blocked in Brazil for failing to comply with local regulations.
So Brazil has the equivalent of China’s firewall? Or is this something implemented at the ISP level?
Discord is worse. At least Reddit lets you delete everything you post. With Discord, if you are banned from a server, then there is no way to delete your posts in that server. That is insane to me in this day and age.
deleted by creator
deleted by creator
so the CEO known for sharing pornographic pictures of minors online does not respect people’s privacy after all? who would’ve thought
https://codepen.io/Deestan/full/gOQagRO/
Deletes all comments or swap them with anything eg “I’ve moved to Lemmy”
Doesn’t seem to work.
First off browser didn’t even allow to open embed website within none securely written website. With less secure setting old.reddit.com will refuse connection.
How to make it work?
Perhaps try a different browser. Worked fine for a couple of accounts in fire fox.
Firefox won’t let me open it within that tool.
Edge and Chrome will allow me to open it but old.reddit.com refuses the connection. I guess they countered it or something ?Yeah, I heard reddit stopped allowing it to delete posts, though mainly they’ve blocked it.
You tried moving the icon into the firefox bookmark toolbar then running it within reddit?