Another update and possibly a solution for some case where posts were not properly deleted. Seems I jumped the gun on this and the restores haven’t been intentional - at least not in this particular case.

There is a limitation in the popular Powerdelete that apparently prevents mass editing. Here is a link to a new version with a build-in delay and some other alternatives:
https://www.reddit.com/r/ModCoord/comments/145fico/comment/jnl4xmr/

There are other reported cases where manually deleted post reappeared or other scripts have been used, so this doesn’t solve all issues but explains how posts that were both edited and deleted withPowerdelete weren’t properly deleted and reappeared after subs went back live.

Update: As some have pointed out: the restores can be rollbacks from the server issues or post haven’t been properly deleted due to subs being private during blackouts. Many have experienced the same issue, I can’t explain how this happens. I’ll just run the script again, try the GDPR request and delete my account.

Also worth noting: according to the ToS Reddit can actually do whatever they want with existing content, apparently we agreed to this when signing up.

#redditblackout #redditmigration #kbin #lemmy

  • Worth noting is that a number of US states also have strong protection laws. So, delete you comments manually and then, if you’re really trying to ensure that they delete your data, submit a data removal request that cites your locale’s law on data removal.

    Theeeeeen in 6 months or so, send a data retrieval request to make sure they followed through… and report them if they did not comply. Might as well make them pay for that data if they can’t follow the rules.

    •  tal   ( @tal@kbin.social ) 
      link
      fedilink
      14
      edit-2
      1 year ago

      Assuming that this is, in fact, not legal and if they have money that can be gone after, I assume that someone may start a class action suit. In theory, they’re worth multiple billions, so…

      An individual probably doesn’t care much about whatever harm is done, as the damage is too small. But this is the kind of thing where a lawyer can walk away with a big payday by aggregating cases of many users and then getting a percentage of any payout.

      I am not at all certain that it is not legal, though.

  • This could be worse than anything else they’ve done. If they claim they own the data, are they then not responsible for it like newspapers? Is it in their terms and conditions they are free to do whatever with posted information, do they have the rights to edit users comments but in doing so become a content provider and therefore responsible. Kicking mods out doesn’t land you in court this seems high risk to be manipulating content. Doesn’t matter why it was deleted or edited it was deleted or edited who gets to decide what version to restore. Either you are hands off or you own the data and are responsible for it and upheld to media standards.

    Edit: found a snippit of the terms and conditions in a German GDPR thread, It appears it is their terms and conditions that after you post it they can do with it what they like, even adapt it. Either way that’s not a reason to be gone.

    • There was that kerfuffle ages ago about u/spez editing comments in r/thedonald, iirc. It’s not like it would be that much of a stretch for him at least.

      But it looks like from OP’s edits it may be unintentional. I’ll withhold my rage for now.

    • I picked up a permanent ban, after 15 years for saying ‘Go outside fatso’ to someone who said I couldnt read. Not my proudest moment, but there you go.

      The reason I mention it, is that it adds a different dynamic if they are trying retain (and prevent me from editing) data which they hold about me. They might argue that doesn’t extend to post where I’ve written “cats > dogs” - but anything where I’ve refered to where I live, whether I have kids, what my political views are, are all clearly personal details which they are not allowed to hold without retaining my consent.

      Clear contraventions on GDPR in EU.

      https://commission.europa.eu/law/law-topic/data-protection/eu-data-protection-rules_en

    • I think we should actively keep track of Reddit restoring user’s content without people’s permission. Screenshots, timestamps, everything. Monitor it all.

      Maybe if Reddit go ahead with their API change whilst treating their users like such disposable crap, we could reach out to the EU to inform them of Reddit’s GDPR breaches. Maybe that’d lead to their new revenue from API charges disappearing into hefty EU fines.

      Update: Maybe there’s going to be some loophole about actually having to use the data deletion request via Reddit’s UI for there to be an actually GDPR breach though thinking about it. Going to ask around some Law friends for advise

    • I’m not sure it’s ok in the GDPR rules?

      That would probably be related to “right to erasure”.

      But even this has limits, since sometimes the data can be necessary for a service (for example, you might be unable to get invoice data erased before X years, as a legal requirement)

      Since messages on forums can be considered “needed” to understand a thread, it’s usually advised to make all messages anonymous if a user requests complete deletion.

      I guess here it’s a little different, since the messages were removed by users, so it’s not a gdpr request. Not sure how it works in that case.

      Other issue is if the messages themselves contain personal information… Someone going through my old reddit profile could probably figure out my identity since I mentioned one of my (very uncommon) previous job a few times.

      Best way to figure out how it works here would probably be to contact the gdpr authority for your country… And they might have trouble with it too.

      • But even this has limits, since sometimes the data can be necessary for a service (for example, you might be unable to get invoice data erased before X years, as a legal requirement)

        But then it still needs to be marked as a “DO NOT TOUCH”. you aren’t allowed to use it then for any other purpose.

  • Would this actually be a GDPR breach? I was thinking about the right to erasure/to be forgotten earlier in relation to a post I saw about how your posts aren’t deleted on other federated instances, if you delete them on your home server. But I figured it wasn’t applicable because it’s not personal data and I’m thinking the same about this Reddit issue. Can anyone set me straight?

      • Thanks, that’s a good point and sets a precedent. I had a reply in another thread with the definition of personal data from GDPR and it would seem to include social media posts:

        ‘personal data’ means any information relating to an identified or identifiable natural person (‘data subject’); an identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person;

        https://kbin.social/m/reddit@lemmy.ml/t/34167/Reddit-is-restoring-deleted-posts#entry-comment-141186

  • I deleted all my content but I did it over the span of a few days, to let the different caches around reddit to update with the new void, and my content is still deleted (so far).

    I said it before and I say it again: if you have the patience to do so then make sure you overwrite your content with chatgpt generated content, as the future AI that will feed on your post HATE feeding on already AI generated stuff. It makes the AI diverge.

    edit: Filling your previous content with random generated content also make it harder to restore because it is harder to spot, compared with the comments which are simply “deleted”. Also, if all of it is really true, congratulation to reddit for demonstrating to everyone and specially the USA how useful the GDPR is for the citizen.

  • Also worth noting: according to the ToS Reddit can actually do whatever they want with existing content, apparently we agreed to this when signing up.

    Been thinking about that. I don’t think that overrules laws like the GDPR though - law triumphs over ToS. And under GDPR, consent can be withdrawn, you can’t give an irrevokable consent.

  •  9Volt   ( @9Volt@kbin.social ) 
    link
    fedilink
    10
    edit-2
    1 year ago

    Wow, out of everything that’s happened involving Reddit over the past few weeks, this to me is the most damning and deserves the most attention.

    I’m really curious to see how they try to spin this in the next PR piece and what the reactions will be.