Earlier quoted context omitted.
GDPR is very good in fact. If you read through it as a person, it is basically the way we should have operated from the start. Reading it while wearing the hat of my role in my company, I can see all the points where we are collecting data without a well defined process and clear understanding from the end users. It is hard to fix this, but it is for my own good as a person.
Can you explain to me how the deletion policies work? If you ask for your data to be deleted does that include your address in my contacts? Does it include your messages to me? Does it include your posts that appeared on my feed? In the physical world all of those would be mine. Addresses: It would be my paper address book with your address written in it. Email: would paper letters you sent to me that I keep in my fi…
If that address is visible to you because I gave you access to my data, then yes.
If that address is visible to you because I gave it to you and you put it there by yourself, then no.
> Does it include your messages to me?
No. Messages I wrote to you are yours. I gave them to you. You can keep them. They get deleted when/if you ask for your account to be deleted.
> Does it include your posts that appeared on my feed?
Yes. My posts are mine. If I make them public or share them with you, you can look at them, copy them, do what you want with them (depending on the license). If I remove my account they get deleted from my account. If you made a copy for yourself, you can keep the copy.
> It's not clear to me how those are handled by the GDPR and at what point things sent digitally from you to me end being my property and no longer your property.
As always, ask a lawyer.