jman6495

@jman6495@kbin.social
jman6495,

The GDPR doesn't just apply to legal persons (companies), it also applies to natural persons (individuals). If a Lemmy server is hosted in the EEA (EU+Norway, Lichtenstein, Iceland) and Switzerland it should have to comply with EU data protection laws.

For this Lemmy would need to implement deletion. As the feature does not exist the admin would likely have some initial legal protection (grounds of impossibility), but I'm not sure how much, in particular if there are repeated requests. That would probably lead to Lemmy being deemed illegal in the EEA and switzerland (32 countries)

Concerning federation, if Lemmy implements deletion and a federated server does not respect the deletion, that server is liable, not the original Lemmy server.

jman6495,

I think it depends, given the data available on Lemmy, and the context of federated services I highly doubt that an instance could be held liable for another server not federating deletion.

jman6495,

Being individually run doesn't mean you are not beholden to the GDPR

jman6495,

The GDPR is implemented by 31 countries (EU27+Norway, Iceland, Lichtenstein, Switzerland). The UK also currently implements it, and both Californian and Chinese data protection laws are inspired by it.

jman6495,

Sure, but EU data protection laws may require EU based Lemmy instances to block instances that dont honour deletion requests.

This is why mastodon was built GDPR compliant by design.

  • All
  • Subscribed
  • Moderated
  • Favorites
  • β€’
  • JUstTest
  • ngwrru68w68
  • everett
  • InstantRegret
  • magazineikmin
  • thenastyranch
  • rosin
  • Durango
  • ethstaker
  • Youngstown
  • slotface
  • khanakhh
  • kavyap
  • DreamBathrooms
  • Leos
  • osvaldo12
  • tacticalgear
  • cubers
  • cisconetworking
  • anitta
  • provamag3
  • modclub
  • mdbf
  • GTA5RPClips
  • tester
  • megavids
  • normalnudes
  • lostlight
  • All magazines