Hacker News new | past | comments | ask | show | jobs | submit login

I follow a similar procedure, with one more step:

1) If I never signed up goes immediately to SPAM.

2) If I did signed up I make the effort of going through their unsubscribe procedure.

3.1) If I still get e-mails after (2), I file a request for my personal data under the GDPR (EU citizen here).

3.2) Once I got that, I use the GDPR to delete all of the data associated with my account / e-mail address.

4) If I still get e-mails after (3), it goes to SPAM.

With step 3, I hope that I can make them notice their bad behaviour. My goal is to drive up the costs of that behaviour (so they get incentivised to change it). Also, I'm generally interested in the personal data that a service has associated with me.




if u still get mail after 3, you should contact the privacy authority of your contry, because someone lied to you about deleting the data.


That would be the way to go, indeed. It didn't happen yet. I'm not sure if I'd take it to the privacy authority, since that would involve much more work, I think.


Nearly any business that gets more than a handful of GDPR requests has fully automated it.

It costs them nothing to process your request - you're wasting far more of your time crafting the request than of theirs.


You might be surprised. I worked for an organisation that got ~1000 requests a year up until recently, each request involved going into every system manually, taking screenshots, tagging files etc. Quite often a good few hours per request and on a few memorable occasions, several days work for a single request. It definitely does cost many larger companies, but to varying degrees.


In the few cases that got a GDPR request, I actually talked to humans. Also, a human has to read my mail in the first place.

Note that I'm also doing this because I'm interested in the data, so its much less waste of time.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: