this post was submitted on 06 Mar 2024
307 points (88.9% liked)

Fediverse

28555 readers
935 users here now

A community to talk about the Fediverse and all it's related services using ActivityPub (Mastodon, Lemmy, KBin, etc).

If you wanted to get help with moderating your own community then head over to [email protected]!

Rules

Learn more at these websites: Join The Fediverse Wiki, Fediverse.info, Wikipedia Page, The Federation Info (Stats), FediDB (Stats), Sub Rehab (Reddit Migration), Search Lemmy

founded 2 years ago
MODERATORS
307
submitted 9 months ago* (last edited 8 months ago) by deadsuperhero to c/fediverse
 

Highlighting the recent report of users and admins being unable to delete images, and how Trust & Safety tooling is currently lacking.

you are viewing a single comment's thread
view the rest of the comments
[โ€“] [email protected] 1 points 8 months ago (1 children)

The issue I see is that if my instance is on the hook for the fediverse at large, and I operate on an allowlist basis, malicious actors can scrape PII and ignore the GDPR, and that would make me the one on the hook for that, isn't that right?

[โ€“] Badeendje 1 points 8 months ago

There is plenty of jurisprudence and clarity needed, so..... maybe. Hence the importance for the framework itself to be as GDPR compliant as possible and not store PII if not nessecary and remove it once no longer nessecary. (Storing someone's IP for login, and post validation, bans etc should be limited to the period that makes sense, not infinitely.)

And in your example, the 'malicious' part of the 3rd party probably makes it different. Maybe then it is a dataleak.