JanoRis,

Have been asking this myself lately.
People always seem to get defensive about this topic, but if an instance gets challenged on a GDPR investigation it could have a huge fine associated to it.
It is good to have this sorted out, so instance owners don't enter a life changing financial risk.

Currently we probably are too small and fly under the radar, but this could become a big problem as the fediverse scales.

Issues I wonder about:

  1. How safe is the Fediverse? Is there a way for a federated instance to misuse the user data? Or can such activity be detected and cause a defedaration.
  2. How easily can all user data be deleted if a request comes in to remove all personal data? Wouldn't that request have to be extended to all instances your instance is currently federated with?
  3. Instances probably wouldn't be able to handle a bad actor (for example Meta, or spez) that decides to start a mass request attack.
  4. Corporations have lawyers that deal with this stuff, I don't feel like most instance owners have the same kind of protection here.
trouser_mouse, (edited )
@trouser_mouse@lemmy.world avatar

Totally agree, there is really valuable discussion to be had and collectively it needs to be resolved and approached holistically and consistently across as many instances as possible. Just because you’re someone running a tiny server doesn’t mean you can’t get absolutely dragged over the coals for breach and or non-compliance.

Even things like reporting incidents and breaches of the service for each instance - it is very unlikely tiny servers can or will comply with so many aspects of GDPR.

I think the fact that someone could maliciously (or actually, genuinely) report instances now using a relatively straightforward process should be grounds to get the wheels moving on this really!

For example, you can report non-compliance with cookie information in a one page form here: ico.org.uk/…/report-cookie-concerns/. The process for consumers to kick off a potentially serious enforceable action is very straightforward.

static,
static avatar

The issue for lemmy is the same as mastodon

The Mastodon.social privacy policy covers a lot of this, https://mastodon.social/privacy-policy

This is the least every lemmy site should have

redditcunts,

That makes no mention of GDPR or the ability to have data deleted.

Kichae,

You don't need to mention the law in order to be beholden to the law.

redditcunts,

GDPR states you must have a specific GDPR policy. It’s absurd all theses comments from uneducated users. Like 1 in 10 have brought in useful pertinent information. This is stuff a privacy office would know on day one fresh out of school.

static,
static avatar

It does

You can request and download an archive of your content, including your posts, media attachments, profile picture, and header image.

You may irreversibly delete your account at any time.

If this server is in the EU or the EEA: Our site, products and services are all directed to people who are at least 16 years old. If you are under the age of 16, per the requirements of the GDPR (General Data Protection Regulation) do not use this site.

preciouspupp,

How are instances not complying?

redditcunts,

Where are the compliance pages? That’s literally step 1.

preciouspupp,

Yes, the only thing some instances don’t have. My home instance has it.

awderon,

Disclaimer: I have no law degree and everything in this post is speculative.

After reading up on GDPR (en.wikipedia.org/…/General_Data_Protection_Regula…) it deals with the transfer of personal data to entities outside the EU or EEA for processing. The definition of personal data would be the main point to see if/how GDPR is applicable to lemmy instances. (en.wikipedia.org/wiki/Personal_data)

Your IP address and EMail address could be classified as personal data from my point of view. But this won’t be shared or processed outside of the instance as far as I can tell. If your username and associated posts are classified as personal data I can’t say, but there seems no connection of these to your IP or Mail outside the instance. According to this TechDispatch (edps.europa.eu/…/2022-07-26-techdispatch-12022-fe…) the instances still must adhere to GPDR, but as there is not much or no processing of personal data taking place this should pose no issue.

All of this is based on a bit of research, so please enlighten me if I made any mistakes.

redditcunts,

but this won’t be shared

How do you know that? No registered entities, no policies, no assurance what so ever.

awderon,

But this won’t be shared or processed outside of the instance as far as I can tell.

At least use the whole sentence when quoting to avoid confusion.

Looking through the activityStreams definition it seems only Usernames are shared (www.w3.org/TR/activitystreams-core/#actors), which is already personal Data according to another comment (lemmy.world/comment/929906)

trouser_mouse,
@trouser_mouse@lemmy.world avatar

In the UK a screen name is an identifier. See ICO here. I am in the UK. Therefore combined with other data being collected, e.g. IP. Lemmy and instances I interact with are handling personal data. If it is transferred between instances when I search or view content from one instance to another, there are GDPR implications.

awderon,

I agree, there is definitely work to be done regarding compliance.

HeartyBeast,
HeartyBeast avatar

I hope you never send an e-mail overseas. Your e-mail provider would be in breach.

trouser_mouse,
@trouser_mouse@lemmy.world avatar

How would they be in breach?

Kichae,

You send the exact same kind of information when you send an email.

Username, host, and IP.

Jajcus,

But e-mail is sent from one entity to another, through servers providing service for one or the other party. Most of Lemmy and Mastodon activities are publicly broadcasted and can be received and collected by any federated server.

HeartyBeast,
HeartyBeast avatar

Just to be clear - I don't think it is in breach but you have federated servers in various countries, some of which may be owned by entities that do business in the EU making copies of and forwarding messages that contain PII .

rodhlann,
rodhlann avatar

If a screen name is an identifier doesn't that make literally every social website or forum a potential breach? That seems a bit harsh

trouser_mouse,
@trouser_mouse@lemmy.world avatar

Not if they are compliant and handle the data correctly, but yes it is a minefield and pretty strict with potential huge fines for non compliance and breaches! I would not want to be in charge of trying to get it all straight for Lemmy!

Jajcus,

Non-federated services keep data on their servers or share it with well-defined set of partners. This can be be done in accordance to GDPR. In fediverse that data is broadcasted to anybody who wants to listen (this make the network open). That is a big difference.

G59,

Geez, check out OP’s comment history…

redditcunts,

Definitely dealing with a lot of copium around the reality of running web services.

Brisolo32,

Never seen so many negative points

WalrusDragonOnABike,

Mutant might see that as a challenge.

Kichae,

OP is nothing more than a corporate boot licking troll, if would seem. That makes this post concern trolling.

Hey OP, if you actually cared about this issue, you'd be trying to help people. But you're not helping anyone anywhere on the network.

You clearly don't want to be here. So, log off and just don't come back.

Molecular0079,

Yikes, you’re right. Definitely corporate troll. Either that or he’s just so deep in his own cynicism he can’t help himself.

animist,

Can you provide specific and detailed examples

redditcunts,

Can you point my to where the GDPR policy for lemmy.world is?

animist,

maybe

awderon,
redditcunts,

That is a tos not GDPR.

awderon,

Then message the server admins or you create a PR on the lemmy github page with the missing information. The missing legal footnotes is an issue you have to take up with them or the upstream lemmy repo on github.

trouser_mouse, (edited )
@trouser_mouse@lemmy.world avatar

This is just at a really high level. Take for example lemdro.id. I am in the UK.

  • I do not get cookie information / consent
  • How do I make a SAR request, it isn’t stated
  • What is their data retention and privacy policy, it isn’t stated
  • How do I make a data sharing request as a member of law enforcement or government
  • How is data processed if I am under 16/13
  • Is data transferred from an EU to non-EU server if I search their content from another instance? Are the correct controls and risk assessments in place
  • If I delete my .id account under right to be forgotten, how is my request propagated between other instances to ensure my data isn’t retained somewhere on another instance which has pulled the data
  • If I use an account from another instance and post an image on .id, and then delete my account, is the image I posted deleted from their server and backups etc

GDPR is very serious and an absolute minefield. I am pretty sure Lemmy and individual instances are not compliant, and I am not sure they can be fully - it may have to be on a best-endeavours basis. Be interesting to see how that holds up under a challenge.

animist,

Holy shit that is quite a lot

WalrusDragonOnABike,

If I delete my .id account under right to be forgotten, how is my request propagated between other instances to ensure my data isn’t retained somewhere on another instance which has pulled the data

There's no way GDPR can tell we hosts they are responsible for other platform's copy of data, right? Wouldn't that mean Twitter has to remove tweets from every news article that makes copies, for example, if someone deleted their account under that right?

trouser_mouse,
@trouser_mouse@lemmy.world avatar

It will be interesting to find out!

fkn,

I mean… It’s pretty explicit in gdpr that the “transfer to non-eu servers” part means you can’t send it via federation in the first place to non-eu servers unless those servers also adhere to gdpr: …europa.eu/…/what-rules-apply-if-my-organisation-…

The answer is that currently federation and Lemmys use of it are not gdpr compliant and the first gdpr case against any Lemmy instance in the eu will force that instance to defederate from all non-eu servers.

Kichae,

I actually question whether GDPR is up for the task of distributed systems like this.

Like, if you put in a right to be forgotten request to your host server, it's not at all clear that they're responsible for the copies of your content that are being hosted elsewhere, any more than asking a news website to remove your personal information from an article requires them to also hunt down anyone else who has copied and spread the story to remove it, too.

Different Lemmy websites are independently owned and operated, and your local admin holds no authority over other admins. They can request deletion on your behalf, if that's a legal requirement, but they cannot compel action. I'm not even sure they can act as your proxy, given that there's no formal relationship between admins.

trouser_mouse,
@trouser_mouse@lemmy.world avatar

Totally, I do wonder how compliant these systems can be!

preciouspupp,

Why would there be a need for a cookie constent?

trouser_mouse,
@trouser_mouse@lemmy.world avatar

It’s law to comply with GDPR and the ePrivacy Directive.

  • Receive users’ consent before you use any cookies except strictly necessary cookies.
  • Provide accurate and specific information about the data each cookie tracks and its purpose in plain language before consent is received.
  • Document and store consent received from users.
  • Allow users to access your service even if they refuse to allow the use of certain cookies
  • Make it as easy for users to withdraw their consent as it was for them to give their consent in the first place.
awderon,

There is only one cookie present when I inspect the Cookies with my browsers dev tools. Which seems to be the auth token for my account.

trouser_mouse,
@trouser_mouse@lemmy.world avatar

As far as I am aware, a user authentication cookie is classed as personal data and therefore subject to GDPR!

awderon,

Receive users’ consent before you use any cookies except strictly necessary cookies.

Wouldn’t the auth cookie fall into the strictly necessary category?

norgur,
@norgur@discuss.tchncs.de avatar

Which “nation” are we talking about and which laws do you mean specifically?

Molecular0079,

GDPR is an EU law and CCPA is a California law.

norgur,
@norgur@discuss.tchncs.de avatar

Yes, I know Yet, can you be more specific as to which parts of those laws (or better groups of laws, GDPR is not one single law as every EU member state does things slightly differently) Lemmy instances are at odds with?

Molecular0079,

I am not OP soooo…🤷‍♂️

I am assuming he’s talking about the data deletion issues that happen with federation?

  • All
  • Subscribed
  • Moderated
  • Favorites
  • fediverse@lemmy.world
  • kavyap
  • ngwrru68w68
  • osvaldo12
  • DreamBathrooms
  • mdbf
  • magazineikmin
  • thenastyranch
  • Youngstown
  • khanakhh
  • everett
  • slotface
  • tacticalgear
  • rosin
  • cisconetworking
  • JUstTest
  • Leos
  • GTA5RPClips
  • ethstaker
  • InstantRegret
  • cubers
  • modclub
  • Durango
  • anitta
  • tester
  • normalnudes
  • megavids
  • provamag3
  • lostlight
  • All magazines