Earlier quoted context omitted.
If the records no longer contain PII, then they've arguably satisfied their duties under the law, haven't they? Has a court held otherwise?
But the records do. > Your account showing your name, address, credit card, etc can still be accessed whilst the token stored in the cookie is still valid
PSA: HelloFresh doesn't delete data when asked, only changes the email address
51–54 of 54 posts
Re: PSA: HelloFresh doesn't delete data when asked, only changes the email address
#52They do the same, and you can check, go make an account with your e-mail, and then ask to delete it, they just change it to name@domain.com-wrongpleasefix
You can no longer log in and the account is still there.
Re: PSA: HelloFresh doesn't delete data when asked, only changes the email address
#53Right. For most (American) companies (I don’t know about GDPR-folks), “delete” means “hide from requesting user” not “remove data from internal system.” Data is (at least a big part of) their business and they don’t further that end by removing data. Of course it’s shitty, but it’s industry standard practice. It’s similar to the Facebook shadow profile you have when you don’t even have a Facebook account: you can ask…
Also, if they do delete it from "current db," they likely have years of backups. I find it difficult to believe someone like FB (or any other) would unarchive multiple terrabyte archives from storage, restore them (db, etc), delete the data, and rearchive them, for each daily/weekly/monthly/yearly backup my data is contained within.
Re: PSA: HelloFresh doesn't delete data when asked, only changes the email address
#54Since I have an catchall for my own domain I received spam on those addresses after they lost customers data.