Live data from Hacker News

We caught companies making it harder to delete your personal data online

themarkup.org

41–50 of 76 posts

Re: We caught companies making it harder to delete your personal data online

#41

And as important: making it impossible or very hard and annoying to export and own your data.

Yes, I am happy I can export my data with google but boy it is annoying to do.

I tried to for a number of years after they added it and my download always expired before I was able to complete it since it didn't support restarting. Eventually I got locked out of my account so I just lost all the data.

These days I think of every account as ephemeral, anything I don't have in git on my local machine will disappear one day.

Re: We caught companies making it harder to delete your personal data online

#42

And as important: making it impossible or very hard and annoying to export and own your data.

We didn't set out to hide our GDPR requests, we put them behind our Support/Legal button. But we got sued anyway, and we lost. Now we have to have the "delete my data" and "request my data" as part of our main settings list. Result: flooded with requests. People are clicking the buttons just because they are there. For me it's not a big deal, I automate all the requests. But, I still feel like this went too far.

Users have basic bare bones functionality that all applications should support is "too far"?

If the user can create and account, they should be able to delete one. One is not harder or further than the other.

We just don't view it that way because we're all parasites who feed off the current status quo.

Re: We caught companies making it harder to delete your personal data online

#43

And as important: making it impossible or very hard and annoying to export and own your data.

We didn't set out to hide our GDPR requests, we put them behind our Support/Legal button. But we got sued anyway, and we lost. Now we have to have the "delete my data" and "request my data" as part of our main settings list. Result: flooded with requests. People are clicking the buttons just because they are there. For me it's not a big deal, I automate all the requests. But, I still feel like this went too far.

> People are clicking the buttons just because they are there.

I think this isn't a very charitable opinion of why people click buttons.

> But, I still feel like this went too far.

Why?

Re: We caught companies making it harder to delete your personal data online

#44

Here's how the law should work. You own the data you produce, both intentionally (writing, making videos) and unintentionally ("metadata", logs). You have to explicitly give others permission to use that data for any purpose where money exchanges hands (and many where it does not). You can limit or revoke the permission at any time.

> You have to explicitly give others permission to use that data for any purpose

This is already the case. All the contracts and terms of service documents already contain these permission clauses. People don't even read such things.

The funniest contracts are the ones that say "by using this site, you agree to [surveillance capitalism]". People have to navigate the site in order to even read the contract so it's logically equivalent to writing "by reading this contract, you accept it".

People need to start making laws that invalidate these silly documents.

Re: We caught companies making it harder to delete your personal data online

#45
post #30
post #15

Earlier quoted context omitted.

Some companies somehow blatantly get away with not allowing any export at all. For example, Amazon eero, the overpriced WiFi router that doesn't even work (without phoning back home and having an app installed on your phone). They had an outage like a year ago, and during said outage, all your existing ad blocking stopped working, too, even if you never rebooted during the outage, and even though said blocking is sup…

> Does anyone know how exactly does Amazon get away with not providing data export for their eero product? I checked eero.com. It seems info about the product other than “it’s a secure WiFi router that doesn’t require users to manage it” is in the videos, if it is on that site at all, but I couldn’t get the videos to play, so I may be wrong, but why would a WiFi router have personal data on the device? It will have t…

If you share data locally that's almost certainly over HTTP. Also DNS is usually over HTTP.

So that's all your websites you visit, plus any data transmitted from your phone to computer or google TV or whatever the fuck.

Re: We caught companies making it harder to delete your personal data online

#46

And as important: making it impossible or very hard and annoying to export and own your data.

We didn't set out to hide our GDPR requests, we put them behind our Support/Legal button. But we got sued anyway, and we lost. Now we have to have the "delete my data" and "request my data" as part of our main settings list. Result: flooded with requests. People are clicking the buttons just because they are there. For me it's not a big deal, I automate all the requests. But, I still feel like this went too far.

> People are clicking the buttons just because they are there.

The reasons why they click the buttons are utterly irrelevant to anyone except them.

Let them click the buttons. It's their right.

> But, I still feel like this went too far.

Not far enough. I think data should be a massive liability. It should actively cost you lots of money to know any fact at all about any person anywhere on the planet.

In other words, in an ideal world you would be scrambling to press that button on their behalf the second your business with them was concluded. "Can we please forget everything we know about you please?" and only their explicit affirmative consent would allow you to not delete their data.

Re: We caught companies making it harder to delete your personal data online

#47

Earlier quoted context omitted.

We didn't set out to hide our GDPR requests, we put them behind our Support/Legal button. But we got sued anyway, and we lost. Now we have to have the "delete my data" and "request my data" as part of our main settings list. Result: flooded with requests. People are clicking the buttons just because they are there. For me it's not a big deal, I automate all the requests. But, I still feel like this went too far.

> People are clicking the buttons just because they are there. I think this isn't a very charitable opinion of why people click buttons. > But, I still feel like this went too far. Why?

Yeah, as long as there's eg a confirmation to prevent misclicks "Are you sure you want to delete", I don't really see what's the problem.

Re: We caught companies making it harder to delete your personal data online

#48

Of course you did. I've been submitting GDPR subject information requests to companies that spam me - and most of them ignore me. The ones that do take the time to reply usually say "We've deleted your personal data now", which is not at all what I want. I want to know what details they have about me, where they obtained it, and why they think spamming me is acceptable. I've got a folder where I keep printouts of the…

Er, you're going to file multiple small claims in the US against (suspected) firms outside the US?

Be prepared to be disappointed. There is 0 evidence/elements of damage in the eyes of the archaic courts in this case, as you have no evidence of being damaged. You may be annoyed, but you're not at psychical or monetary risk due to the actions of another.

I disagree^ with the above, we live in the future where comm-spam is an inherent risk. However, I lost a small claims case where documented over 5 years Mazda put the wrong oil in my car. I found out after pouring through paperwork and seeing the line items/overcharging (22 instances of this.)

Judge dismissed it due to no "damage." 3rd cylinder died a week later.

Re: We caught companies making it harder to delete your personal data online

#49

Here's how the law should work. You own the data you produce, both intentionally (writing, making videos) and unintentionally ("metadata", logs). You have to explicitly give others permission to use that data for any purpose where money exchanges hands (and many where it does not). You can limit or revoke the permission at any time.

This is the case.

In every aspect of life in which personal data is indexed/transmitted, the point of origin at least is some place you've explicitly indicated approval of this process. IF you walk into walmart, you are granting them the ability to sell your facial data and card metadata to whoever.

No third party is calling your mobile provider to ask them to leak info. They are PAYING the mobile provider to leak them info that we provided express written consent for them to do so. TO avoid these ToS and binding agreements, you would need to live a disconnected agrarian lifestyle. Literally, can't walk into any corporate store.

yay!

Re: We caught companies making it harder to delete your personal data online

#50
post #21

Earlier quoted context omitted.

Those pricks throttled the download to 30 kbps. When I tried to download with aria, after a few failed attempts (not straight forward ofc) I got a message saying I can only download it 6 times, and that I should send a new request. This is evil.

I have downloaded my data with google takeout dozens of times without a single issue. Speed was very high (maximum possible for my connection) and never had a download error. I’m talking about multi-gigabyte exports of my email and my drive.

Different experience for me, ~500Gb so about 10 chunks of 50Gb (largest chunk size) that had to be downloaded by hand because of their auth. When the download got interrupted I had maybe 4 more tries, might have been more, but after trying to many times the entire takeout expired. Automating the process, and using smaller chunks didn't work at the time because of their opaque API and its auth.

I feel like this has been made a shitty experience intentionally.

Post reply on HN