The Illusion of Erasure: Why GDPR’s Right-to-be-Forgotten Fails on Facebook

Efficacy of GDPR’s Right-to-be-Forgotten on Facebook

2018-01-01
Vishwas T. Patil, R. K. Shyamasundar
Summary
Problem
Method
Results
Takeaways
Abstract

This paper evaluates the practical efficacy of the GDPR's "Right-to-be-Forgotten" (RTBF) within the Facebook ecosystem. It explores how Facebook’s data-driven business model, architectural design, and the diffusion of personally identifiable information (PII) into "Inversely Private" knowledge-bases make total data erasure technically and economically undecidable.

TL;DR

Can you truly vanish from the internet? While the GDPR grants EU citizens the legal "Right-to-be-Forgotten" (RTBF), this paper argues that on platforms like Facebook, total erasure is a technical impossibility. Due to "shared ownership" of social data and the mutation of personal details into deep behavioral insights, your digital ghost lingers long after you hit the delete button.

Background: Data as Digital Gold

In the modern data economy, Online Social Networks (OSNs) act as "Gold Mines." Facebook doesn't just store your name; it tracks every "Like," every App interaction, and even your off-platform browsing behavior. This information feeds a massive value chain designed for one thing: Precision Persuasion.

The Problem: The Diffusion of the Identity

The authors point out a critical flaw in how we think about privacy:

  1. Shared Ownership: If you delete a photo, but your friend’s comment remains, who owns that data?
  2. Inversely Private Data: This is metadata you don't even know exists—like a profile of your personality traits (Openness, Neuroticism) inferred from your behavior. You can’t ask to delete what you can’t see.

Methodology: The Information Value Chain

The paper breaks down how Facebook transforms your simple identity into a permanent, "un-erasable" asset through a four-step process:

  1. Voluntary Labeling: Data you provide (name, birthday).
  2. Observational Labeling: Data Facebook "sees" (IP address, device type, location history).
  3. Analytics & Mutation: This is the core. Facebook uses psychometric models (like the OCEAN model) to turn your clicks into "Knowledge."
  4. Monetization: Using this knowledge to sell your attention to advertisers.

Data Transformation Process Above: The mutation of PII into actionable knowledge.

Why You Can't Be Forgotten

The authors identify two specific scenarios where the law fails:

1. The App "Leakage" Problem

When you use Facebook to log into an app (SSO), that app becomes a "Data Controller." Even if you invoke the RTBF on Facebook, the app may still hold your data. Furthermore, if your friends use the same app, they may unknowingly "re-upload" your contact info, effectively resurrecting your profile in the app’s database.

2. Behavioral Fingerprinting

Even after account deletion, Facebook’s tracking pixels (embedded in millions of websites) can identify "non-users." By correlating your IP address, browser version, and hardware specs, the platform can link your "anonymous" session to the deep behavioral profile it built when you were a member.

Multivariate Analysis Above: How facts are extrapolated into inferred knowledge through empirical evidence.

Critical Insight: Contradictory Goals

The paper concludes with a stark reality: Targeted advertising and the Right-to-be-Forgotten are fundamentally contradictory. For Facebook to truly "forget" you, it would have to actively label you as a "Forgotten User" and link that label to your hardware to ensure it stays forgotten—a move that would break its business model of high-conversion ad delivery.

Conclusion & Future Outlook

The RTBF is currently a "legal stick" hitting a "technical ghost." To make it work, the industry needs a new framework for Identifier Provenance. We must track not just what data was collected, but how it was transformed. Until then, deleting your account is merely a cosmetic change; the "Knowledge" of who you are remains in the system.

Takeaway for Researchers: The challenge of the next decade isn't just encrypting data—it's managing the life cycle of inferred traits that outlive the raw data they were born from.

Find Similar Papers

Try Our Examples

  • Examine recent legal or technical papers that define the boundaries of "Inversely Private" data and its status under current GDPR and CCPA jurisdictions.
  • What are the state-of-the-art methods for "Shadow Profile" detection and how do OSNs reconstruct non-user identities using metadata correlation?
  • Search for technical frameworks that implement "Right-to-be-Forgotten" in Graph Databases or Social Network architectures and how they handle shared data ownership.
Contents
The Illusion of Erasure: Why GDPR’s Right-to-be-Forgotten Fails on Facebook
1. TL;DR
2. Background: Data as Digital Gold
3. The Problem: The Diffusion of the Identity
4. Methodology: The Information Value Chain
5. Why You Can't Be Forgotten
5.1. 1. The App "Leakage" Problem
5.2. 2. Behavioral Fingerprinting
6. Critical Insight: Contradictory Goals
7. Conclusion & Future Outlook