Skip to content

[GDPR] Right to be forgotten/erased #9766

@rodrigok

Description

@rodrigok

Description

Also known as Data Erasure, the right to be forgotten entitles the data subject to have the data controller erase his/her personal data, cease further dissemination of the data, and potentially have third parties halt processing of the data. The conditions for erasure, as outlined in article 17, include the data no longer being relevant to original purposes for processing, or a data subjects withdrawing consent. It should also be noted that this right requires controllers to compare the subjects' rights to "the public interest in the availability of the data" when considering such requests.

Comment

This can be a web page / option to delete the account + all user generated content - exactly how this should be done can be hard, but it is the GDPR rights for the user to do this

Solution (draft)

  • We already have that option, but we do not remove the messages from public and private rooms, we only remove the DM messages
  • It should be an admin option so the work is:
    • Create a new admin option to enable delete messages from not direct rooms when a user is deleted
    • Delete the user's messages if the setting is enabled

Effort

  • 3h of work

Metadata

Metadata

Assignees

Labels

Type

No type

Projects

No projects

Milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions