Hello, I wrote a mail template which I send to websites that don’t have an easy process of deleting an account.
Maybe it helps you, maybe you will use it too for when you want to delete your unused accounts and maybe you can contribute to it. The better the message gets and the more websites offer an easy way to delete accounts, the safer we’ll be online.
If you can influence the deletion policy, please read on. Otherwise, please forward this to someone that can influence this process.
It’s better for the business to offer an easy way to delete an account. Ideally, it would be good to delete accounts which weren’t active for more than say 5 years, with a mail notification beforehand. Why? Here are the main reasons:
- There are higher operation and maintenance costs because you have unused accounts in your databases.
- The services load slower, with a performance penalty, because each user-related query has to go through many unused users.
- The people opinion of your services decreases, because you don’t offer an easy way to delete accounts
- People might change their mail to a throw-away address and leave the account open, thus producing more waste than necessary.
- In case of a security breach, the amount of compromised data is higher than in case you regularly delete accounts, which might lead to financial penalties.
- The information you get out of a database with active accounts is much more precious than the information from a stale database, or one with obsolete data.
I hope this information helps and that you will change your policy of deleting accounts. Each website that does this, contributes to a better, safer ecosystem.
Okay, I understand so far.
What I am struggling with is the limitations of duristriction.
So the EU finds the Australian company in breach of their rules. They send a notice of intent to pursue damages to the Australian company. And they tell the EU to kick rocks.
Surely laws made up in one country don’t apply in all. The internet makes this a muddy area, as it’s fully connected and nothing is stopping Joe in Netherlands from signing up to a service hosted in Vietnam. The Vietnam company can just ignore GDPR, ignore requests, ignore fines.
That’s a valid point and relates to a nation’s sovereignty. If they don’t recognise an EU legislation, it will be difficult. That’s why overarching legal frameworks exist to allow one country to enforce court decisions in another country. The EU uses this: https://eur-lex.europa.eu/legal-content/EN/ALL/?uri=CELEX%3A32012R1215. Other countries have treaties.
In other cases, if no treaty exists it could require starting legal proceedings in the country where the company resides. For instance, Australia. And through local arbitration enforce a court decision, based on the legal framework of the country of residence. It needs no explanation this is expensive and time consuming.
I’m not a lawyer and not sure if a EU-Australia treaty exists but wouldn’t be surprised. It’s more complex than just having or not having a treaty.
Thank you. That is a good explanation.
Basically nothing happens in most cases. In your example of a local Australian company, no they are generally not forced to comply with any EU law unless they also do business there in some way.