This is for UK and EU due to GDPR that requires companies delete all user data for inactive accounts. It’s a unintended consequences of the law and other gaming companies including Xbox have similar clauses.
The law says they can’t keep your PII after you stop being a customer, not anything about linking your email address to purchases for an entirely legitimate ongoing reason.
Email addresses are PII under GDPR, aren’t they? So linking email addresses to purchase history is explicitly retaining PII and data about someone they can identify.
You are explicitly allowed to retain PII for critical business purposes. So in this case as a key component that the software licence is attached to they can retain it forever anyway.
The law covers personal data not PII and is much broader than PII that is defined under the US Office of Privacy and Open Government which has no bearing on the GDPR.
As for personal data, email addresses are covered and even user names could be considered personal data depending on if it’s linkable to a person and since your account is linked to your email and linked to you user name potentially, when they have to delete personal data the have to delete all of those foreign keys in their database that says your email once got a receipt for that game you bought digitally.
Except they don’t have to delete any of that as long as you hold ongoing software licenses with them, as that’s a legitimate interest. This is malicious compliance posing as “well they made us do it”, same as all the GDPR banners on the web.
This is for UK and EU due to GDPR that requires companies delete all user data for inactive accounts. It’s a unintended consequences of the law and other gaming companies including Xbox have similar clauses.
https://playfront.de/en/psn-kontoloeschung-sony-loescht-inaktive-accounts-asutomatisch-nach-3-jahren/
The law says they can’t keep your PII after you stop being a customer, not anything about linking your email address to purchases for an entirely legitimate ongoing reason.
I’m not here to defend the corporations.
Email addresses are PII under GDPR, aren’t they? So linking email addresses to purchase history is explicitly retaining PII and data about someone they can identify.
You are explicitly allowed to retain PII for critical business purposes. So in this case as a key component that the software licence is attached to they can retain it forever anyway.
Hah! I guess Sony argues that “who bought what” is not a “critical business purpose”…
The law covers personal data not PII and is much broader than PII that is defined under the US Office of Privacy and Open Government which has no bearing on the GDPR.
As for personal data, email addresses are covered and even user names could be considered personal data depending on if it’s linkable to a person and since your account is linked to your email and linked to you user name potentially, when they have to delete personal data the have to delete all of those foreign keys in their database that says your email once got a receipt for that game you bought digitally.
Except they don’t have to delete any of that as long as you hold ongoing software licenses with them, as that’s a legitimate interest. This is malicious compliance posing as “well they made us do it”, same as all the GDPR banners on the web.