Comment on Valve emailed about a cyberattack against their shipping partner CEVA Logistics in Europe
PonyOfWar@pawb.social 4 days ago
Got the email too. Oh well, guess my data got leaked again. Seems almost impossible to avoid these days if you ever want to buy something on the internet. At least it didn’t include my passport number this time, like when Interrail was hacked…
I have to say, though, that I don’t really get why Valve’s shipping partner needed to retain my data for months after shipping out my products.
DupaCycki@lemmy.world 4 days ago
Most likely due to GDPR requirements. Depending on the type of data, companies are legally required to retain some or all of it for anywhere between 3 and 12 months, if I remember correctly.
You know, in case you ever turn your Steam Deck into a bomb - they’ll be able to track it to you. Think twice.
soulsource@discuss.tchncs.de 3 days ago
This sounds pretty much like the opposite of what the GDPR aims for.
IANAL, but as I understand Article 5(1)(e), shipping companies need to give good reasons why they would be storing data after they have delivered the package:
My best guess is for handling of complaints. Like, people receive the package, but only open it some time later, just to realize that the contents have been damaged during transport.