Naughty List - Tech companies that won't delete your information

Naughty List is a list of tech companies that won't delete your information

services with the highest rank have the worst policies.

Add a comment

Replies

Best
Step 1. Send this list to the GDPR watchdogs Step 2. Sit back and enjoy the show
😂👀
yep! May 25th is going to prove a very good day for us all :) albeit a scary one for those of us having to manage the Data Protection at our organisations! ðŸĪŠ
Facebook might be in actual breach of GDPR, because when you delete your account, the people you have messaged still have access do your messages, even though it is supposed to be deleted 🙂 It's removed from your end, but not those you have been in contact with.
not really. They need to delete or anonymise your personal information, in other words information that can identify you. Your messages without metadata are gdpr compliant.
Occasionally I go through my password manager to do a cleanup of accounts I no longer use. For the simple reason that if any one of those services get hacked, I don't want to lose credit card- or personal information, and have that end up in the hands of somebody who shouldn't have it. In trying to delete a few accounts, some services outright refused to delete my info, without giving any reason. Therefore, I decided to create a naughty list of tech companies who don't respect your right to your own information. There are already 283 sites in the list, but let me know if there are any other services you think I should add.
23andme needs to be on that list. If your genetic data is linked to one of their studies, they will never delete your data.
Do you have more info and a source to that? Feel free to share it on slack:
Regardless of whether you delete your account, your data will never be removed from 23andme. It makes sense, but I doubt most people are aware of that. "If you no longer wish to participate in our Services or no longer wish to have your personal information be used, you may close your account by sending a request to Customer Care. When closing an account, we remove all Genetic Information within your account (or profile) within thirty (30) days of our receipt of your request. As stated in any applicable Consent Document, however, Genetic Information and/or Self-Reported Information that you have previously provided and for which you have given consent to use in 23andMe Research cannot be removed from ongoing or completed studies that use the information. Our contracted genotyping laboratory may also retain your Genetic Information as required by local law and we may retain backup copies for a limited period of time pursuant to our data protection policies. In addition, we retain limited Registration Information related to your order history (e.g., name, contact, and transaction data) as long as your account is active or as needed to provide you services, as well as for accounting, audit and compliance purposes." To be fair, it's not just 23andme. It's probably every company providing health and ancestry services based on your genotype data. e.g. HomeDNA, AncestryDNA, Helix, GoForward. I just haven't personally confirmed it yet.
Interesting, added.
Are you getting data to judge companies from their public policies or is it shared by contributors solely?
It's based on the policy of the individual services, but also as reported by individuals.
Missing Win Azure. Was very surprized when i had to realize that they don’t let close me my account. They heavily advertise to be GDPR compliant.
You mean Microsoft Azure?
Yes. Thats the correct name.
Added.
To me, this is very useful. No one knows what these companies do with our private info. They can share it without our consent, the government can track our lives... who knows?
It's good to know what's going on, so people can have the information they need to make the best decisions in an open market.
definitely agree
It's odd that Google products are inconsistent with the tracking considering they're all linked to the same account.
You are right, thanks for pointing that out. I made changes to Google Drive. Any other services I should correct?
Nothing else I saw
Such a useful resource! Would be good to have more information about how you decide which policies are 'naughty' :)
Absolutely, sources to all decisions will be included in the next major release 🙂 However, I do include some of the sources in the change log when possible:
We’d love to see this expanded one day to companies that also engage in or allow for resale of user data in their privacy policy vs those that don’t. But definitely thIs is super useful. Thank you!
Duly noted 🙂
Oh man, for some reason, this made me laugh so hard. Such a great list!
me: oh cool, I wonder who's first... I bet it's linkedin site: linkedin me: YUP... knew it.