• 0 Posts
  • 15 Comments
Joined 1 year ago
cake
Cake day: June 14th, 2023

help-circle














  • IANAL, but he GDPR is quite reasonable and if Lemmy did the right thing © it would not be a problem I think. Transferring data to a jurisdiction, like for example the US, where people do not enjoy the same level of data protection comes with risks for any eu citizen. Therefore, it is important that any new user of Lemmy/ActivityPub is educated on what’s actually going on here and the consequences of posting on Lemmy for their personal data. Article 49, 1a) of the GDPR provides an exemption for the rule this posting is about if

    the data subject has explicitly consented to the proposed transfer, after having been informed of the possible risks of such transfers for the data subject due to the absence of an adequacy decision and appropriate safeguards

    Why can’t we have that? Add a step to the signup process that explains the basics of how a decentralised community works: even if you sign up to a German Lemmy instance, Lemmy is a global community, your data may be transferred to any place in the world and that means that you won’t be able to enjoy the rights and protection you may expect on a German server. Click the “accept the risks” button to continue. Go to this link if you ever change your mind to stop federation of your content and attempt to remove it from any place it has already been federated to.

    Even cooler if we can somehow record the jurisdiction of instances and build mechanics that act on that information, e.g. during federation.