GDPRposting, shitpost, jokeTo change the name and gender of your user account, you'll need to supply us with an up-to-date copy of your ID-Document attesting to t-:neodog_bonk:WRONG! Art. 16 GDPR Right to rectification :neocat_flag_trans: You have 1 month. The clock's ticking!
re: GDPRposting, shitpost, joke@star I think this only applies when they didn't require you to provide one in the first place, but you may need to fight them and if they're based in ireland the authorities don't give a shit so...
However I have successfully used this to change my name at the "you need to visit in person to update your details" ISP over email. This involved sending photos of my ID card over plaintext email (this is considered normal here, this country is horrible and cursed, we have digital signatures that contain your names and PESEL but why would anyone use that right?), apparently this dipshit ISP in particular just always wants your ID card for unclear reasons.
re: GDPRposting, shitpost, joke@idnorton Likely a mix of people not being aware, corporations telling them that they have to do XYZ and also making potential contact addresses hard to find
Although Germany is considered a country of data protection, corresponding authority activity in enforcement is often not apparent. In five years of the GDPR, the German authorities have not made a name for themselves either through particularly high penalties or through consistent law enforcement across the board. In the proceedings conducted by noyb, the authorities also tend to rely on "informal" solutions with companies rather than consistent enforcement with a general preventive effect. Complaints are regularly "informally closed" even when the law is broken. The authorities, in turn, place a strong focus on information and counselling work, vis-à-vis citizens, companies and state agencies
That said, it's still a great tool to pressure companies.
re: GDPRposting, shitpost, joke@idnorton@star ime mostly because, unless you actually threaten them with lawyers, the companies don't really give a fuck about it and will just straight up ignore you lol
re: GDPRposting, shitpost, joke@ptrc@idnorton@star Having had the displeasure of trying to close a Bungie (Destiny 2) game account (they don't have a normal account deletion flow because fuck you that's why), just opening a support ticket with scary-looking quotes from the GDPR was enough.
It's worth a shot, even if not always (or often) successful.
re: GDPRposting, shitpost, joke@ptrc@idnorton@star That's the neat thing, with the GDPR you don't need a lawyer, you can just let the data protection authority do the threatening for free.
re: GDPRposting, shitpost, joke@jstsmthrgk@idnorton@star that adds several layers of complexity though, especially if the data processor is not in the same jurisdiction
re: GDPRposting, shitpost, joke@ptrc@idnorton@star You can still complain through your local DPA and they will forward it for you.
So if your local DPA has good UX (like the Austrian one with a well made online form) it is not too complex to do. (even though it might get a bit complex for them, but it isn't for me)
From experience companies immediately start complying the moment they get a message from the DPA.
@m i am not a lawyer, but it does say that in the legal text. perhaps other laws may override this in certain situations like idk finance law but in a lot of low-stakes cases, the "requirement" as made up by the service provider just exists in their ToS/mind and has no legal basis
@star And then the legacy infra of Regulated Industries now has a dilemma: comply with GDPR and correct the info as required, or comply with the (much stronger) Know Your Customer and anti-fraud requirements of being able to "strongly" match a government ID by legal name...
This shouldn't be a problem for any competent service though, as "display name" and "legal name" should always be two separate fields, and WTF do they even have a "gender" field for? The former shouldn't require strict verification beyond "are you actually the person in question" and the latter should only ever be used for cross-referencing with identity documents and government systems.
(I'm reminded of that post where someone transitioning accidentally convinced their company HR to drop the gender field from the system altogether because that was easier than figuring out a way to update it. All it takes is someone going "why do we actually store that?")
@nobody maybe for like banking or finance in general, sure, but lots of services that shouldn't ever need my ID in any way shape or form impose this dumb arbitrary requirement which is not grounded in any law whatsoever
GDPRposting, shitpost, joke@star "Please change this on my account." "No." "I'm sorry that my usage of the word 'please' made you think that you had any say whatsoever in this, so I will correct my sentence: change this on my account, as obliged by law"