Removing trolls personal details with a GDPR request

HJW

Active member
What do you do when someone trolls your board, you spam clean them then they demand to remove personal data as per GDPR?

I don't want to delete their email address as then they could just sign up again, ditto the IP addresses.

For GDPR would it still count as the data is needed even if they try to revoke it?

They obviously just do this to be a pain.
 
You dont remove anything for GDPR when its a case of abuse. They have very few GDPR rights. And conversely depending on where you are located you are required to protect your site against abuse, hate speech, etc. I would deny the demand.

 
You are fine to keep their details as it's for "operational" reasons, i.e. maintaining that ban and preventing them rejoining. As long as your privacy policy states that you're fine.

You DO need to inform them for how long you'll keep those details and it can't be indefinitely. We had someone try the same and it went to the Information Commissioner and they said we had to specify a period (e.g. 5 years) for which we'd keep that data.
 
Back
Top Bottom