Last week I received an email from Meta Plattforms Inc about their new ToS and Privacy Policy addressed to my first Name.

But I don’t have any accounts on any services from Meta Platforms (I deleted them a few years ago). Therefore I contacted the DPO and requested a copy of my personal data and asked them to delete it according to GDPR.

They told me that there is no account associated to my email, I should provide my account details to the account in question, which I don’t have. They are unable to help me with the data I provided and I should contact the irish or my local data protection authority and bring my claims before court.

So they obviously have at least my first name and my email address and refuse to comply with GDPR.

Has anyone had any simmilar experiences or any recommendations on my further actions?

I don’t have the time and money to sue Meta, but I will contact my local data protection authority.

  • WhoRoger@lemmy.world
    link
    fedilink
    English
    arrow-up
    19
    ·
    edit-2
    1 year ago

    Well they have to, regardless of account status. If they don’t, then as you say they’re in violation and therefore you can report them to your local GDPR bureau, which every EU country has.

    You don’t have to sue Meta, the bureau has the authority to enforce compliance and give fines for every day they don’t. Dunno how effective it is against entities like Meta, but they’ve been in hot water in a couple countries already.

    Ed: ok I guess it’s important how identifiable the data is. Monoliths like Meta do collect a ton of data which they technically can claim is anonymous… We’ll see how that turns out eventually. But email and name are definitely personal data.

    • blue_zephyr@lemmy.world
      link
      fedilink
      arrow-up
      12
      ·
      edit-2
      1 year ago

      There’s a really low bar for what is considered personal data. If they collect location data coupled to an “anonymous” ID, it’s still personal data, because it shows you moving to your house and place of work every day. If you can infer a person’s identity from the data, it’s personal data.

      So yeah them collecting your personal e-mail address and refusing to delete it is a clear violation of the GDPR.

      • Em Adespoton@lemmy.ca
        link
        fedilink
        arrow-up
        3
        ·
        1 year ago

        And in this case, they demonstrated they held email address linked to first name, and linked to account status. Having all that PII and refusing to both hand it over and to purge it is an open/shut violation. And the only way the fines will scale is if enough people report these violations. Meta counts on most people just ignoring them.