That’s a bit misleading to say like that. Go to the website, scroll to the footer and click on “Legal”. Your instance, feddit.de, has a legal notice, with a privacy contact person, mentioning you can request data erasure, and detailing where your data goes. Mine, lemmy.world, has a number of in depth legal documents attached there.
However, yes, other instances they are federated with might not take it as seriously though, and if all your data is going there too, then that’s a hole in your data privacy.
The GDPR notice on feddit.de is not GDPR compliant, and the link isn’t even visible on mobile.
If you request deletion, they can’t guarantee that the data is deleted on federated servers. They can send deletion messages, but federation is constantly not working correctly, other instances can decide themselves whether they do delete stuff, and if an instance is unreachable for a while, the deletion message will be dropped.
Lemmy, or even ActivityPub are designed to be non-GDPR compliant. (Probably not on purpose, but the way it works makes it basically impossible to be GDPR compliant.)
I imagine that this calls for a feature that can erase your data on every other federated server. If the activitypub protocol can send data from one server to another, it should be able to delete it or find a way to disable viewing said data.
That already exists. The person who created a post or comment can delete it. But it only works sometimes, since federation is constantly not working correctly.
That’s a bit misleading to say like that. Go to the website, scroll to the footer and click on “Legal”. Your instance, feddit.de, has a legal notice, with a privacy contact person, mentioning you can request data erasure, and detailing where your data goes. Mine, lemmy.world, has a number of in depth legal documents attached there.
However, yes, other instances they are federated with might not take it as seriously though, and if all your data is going there too, then that’s a hole in your data privacy.
There are two issues with that:
Lemmy, or even ActivityPub are designed to be non-GDPR compliant. (Probably not on purpose, but the way it works makes it basically impossible to be GDPR compliant.)
But if I request it there, after its federated everywhere, what happens?
I imagine that this calls for a feature that can erase your data on every other federated server. If the activitypub protocol can send data from one server to another, it should be able to delete it or find a way to disable viewing said data.
Giving servers the ability to delete each others shit would be interesting to watch when an online war breaks out
That already exists. The person who created a post or comment can delete it. But it only works sometimes, since federation is constantly not working correctly.