I asked them to delete my data, they said "Install our app"
A few days ago I sent a GDPR request to some company to delete my personal data. They said to install their app and send a ticket from the app.
The email was sent from the email address to which the account is registered.
Is this even legal?
No, it’s not at all legal for the company to do this. Reply and remind them they have one calendar month to comply from the date of your original request, otherwise you will make a complaint to which ever information regulator is correct for the juridiction they’re operating in.
I’m a lawyer specialising in Data Privacy, reply here if you need more help on this one.
My first thought was "they probably want to ensure they are who they say they are and so want an authenticated request" - while that's against GDPR, not everyone is as educated as they should be, and not every mistake is a nefarious activity.
There's no reason an app should be more trustworthy than the email.
It's pretty standard for scummy companies to make the process as annoying as possible.
The individual responding isn't the issue. They haven't made any decision to respond like this, they are following a script.
The script is written by people who should know exactly what they are doing, so the result is either malice or negligence. Either way it's unacceptable where the law is concerned.
Think of the poor corporation! If they get punished for their illegal buisness practices, it'll hurt the economy and people will be less inclined to start a small buisness. Didn't you study piss down economics?
"WHAT ABOUT THE TRUE VICTIMS HERE! WHY DOESN'T ANYONE CARE ABOUT THOSE HARDWORKING, SALT-OF-THE-EARTH SHAREHOLDERS! ARE YOU PEOPLE FUCKING COMMUNISTS?!"
Or maybe they just want to disclose as little of their personal information, including services relied on, on an open platform like this. Idk if that's the case, but playing devil's advocate here
Why should they not? They posted an inquiry, looking for advice. That is their reason for posting.
They do not owe personal information beyond what is required to answer the question. And typically, with regards to anything resembling a legal matter, the less information posted publicly, the better.
That reminds me, I might have to put in a formal complaint for a somewhat similar matter.
Bought concert cards years ago, and was never able to unsubsribe from the newsletter. I sent requests to every mail address I could find, and never even got a response. Still got newsletters every now and then though.
They also just make it unnecessarily hard to contact them, so at this point I'm not sure my messages even reached them, which hopefully is what explains their failure to comply.
Genuine question: Aren't you supposed to say "this is not legal advice?" if you identify yourself as a lawyer but you're not their legal council? Or am I mistaken?
The purpose of that disclaimer is for the lawyer to not expose themselves to malpractice lawsuits from OP, which seems VERY unlikely to be relevant here