• designatedhacker
    link
    fedilink
    English
    arrow-up
    40
    arrow-down
    1
    ·
    7 months ago

    If you still have DNA data with them, delete your account and the DNA along with it. It really is valuable and you bet your ass it’s going to get sold if it’s still there at bankruptcy time.

      • Bonehead@kbin.social
        link
        fedilink
        arrow-up
        19
        arrow-down
        7
        ·
        edit-2
        7 months ago

        It’s cute that you think the GDPR actually protects you and companies don’t keep your data rather than simply preventing you from seeing it, just like Reddit tried to do poorly.

        • Patches@sh.itjust.works
          link
          fedilink
          English
          arrow-up
          16
          ·
          edit-2
          7 months ago

          It’s the best we’ve got ¯\_(ツ)_/¯

          I know the companies I worked for - took it seriously.

        • Ephera@lemmy.ml
          link
          fedilink
          English
          arrow-up
          13
          arrow-down
          1
          ·
          7 months ago

          The company I work for also takes it seriously.

          The fun part is that our national privacy law beforehand wasn’t even that different. The most significant change that the GDPR brought, is that the maximum fine went up from 300,000€ to now 20 million € or 4% of annual turnover.

          And yeah, that change made all the difference.
          Now it’s a simple business decision to (mostly) comply with the GDPR, because there is a calculable risk+damages, which are higher than the cost for implementing the bare minimum in protections. They’re also definitely higher than the potential revenue, you could pull out of a single customer’s data.

      • designatedhacker
        link
        fedilink
        English
        arrow-up
        4
        ·
        edit-2
        7 months ago

        I’ve seen some GDPR code. The easiest thing to do is delete anything associated with a deleted user after N days. Adding a condition on the country they told you they’re from without actual KYC is asking for trouble.

        Sure aggregate anononymized data sticks around. Maybe the anonymization isn’t built right, but it isn’t literally your DNA data unless they really fucked up GDPR compliance.

        I will caveat that a sufficiently motivated company might put in the hours to use at least billing info or shipping address. https://customercare.23andme.com/hc/en-us/articles/360004944654-What-s-In-Your-Account-Settings

        They actually talk about opting you out of Research and discarding the sample (on the linked privacy page). The word delete isn’t explicitly used about the DNA data 🤔.

    • Hawke@lemmy.world
      link
      fedilink
      English
      arrow-up
      14
      arrow-down
      1
      ·
      7 months ago

      delete … the DNA along with it.

      Did you just tell people to kill themselves?