What is frankly baffling is that after the past two decades someone would still believe more money equals better customer service, or that VC-funded companies care even the smallest bit about you.
From their privacy policy page:
Data Protection Officer: Bluesky has appointed a Data Protection Officer (DPO). You may contact our DPO at Ametros Group Ltd, Lakeside Offices, Thorn Business Park, Rotherwas Industrial Estate, Hereford, Herefordshire, HR2 6JT, dpo@ametrosgroup.com.
Data Protection Representative: Bluesky has appointed a Data Protection Representative (DPR) for both the UK and EU. You may contact Bluesky's EU Representative at Ametros Ltd, Unit 3D, North Point House, North Point Business Park, New Mallow Road, Cork, Ireland, gdpr@ametrosgroup.com. You may contact Bluesky's UK Representative at Ametros Group Ltd, Lakeside Offices, Thorn Business Park, Rotherwas Industrial Estate, Hereford, Herefordshire, England, HR2 6JT, gdpr@ametrosgroup.com.
This shows that the author should file a complaint with the Irish DPA (assuming they're an EU national) or the UK's DPA if they're from there. Bluesky repeatedly exceeded the applicable legal deadlines.They seem to have outsourced their compliance to https://ametrosgroup.com/ which would probably explain why it takes forever to get them to comply; the people dealing with the legal paperwork don't have access to the API to run a data export because they're a completely different company.
> the author should file a complaint with the Irish DPA
Good luck with that. If you follow the work done by noyb, what you quickly learn is the Irish DPA loves US companies and giving them a pass. They even argue on their behalf. The new Irish DPC commissioner is a former Meta lobbyist.
https://noyb.eu/en/former-meta-lobbyist-named-dpc-commission...
Hey, when somebody sends you an email asking for personal data, how do you verify that the person making the request is the same as the person who uses the email.
Is the email "From" field safe to trust? Can it be spoofed?
Is it legal to assume that the controller of an email address is the same as the person who created the account using the email address?
If a users inbox has been compromised, can somebody just use GDPR to get all the DMs and data from every other service despite not having passwords to those services?
irusensei•1h ago
pjc50•1h ago
I don't think that matters in this context where the rules apply regardless of decentralization. However, I believe that you can in fact just use the protocol without any of the "age verification" nonsense the UK government has imposed on us.
RobotToaster•39m ago
dpatterbee•26m ago
I also think the private DMs might be hosted externally to ATProto because that is all meant to be public information or something.
I would assume that the age verification is built at the app layer, so you could use an alternative app (I think they call them AppViews?) to get around the age verification thing. Don't know if alternatives really exist today though, there are probably some.
cykros•9m ago