# מדוע אין אפשרות ל'מחיקת חשבון' מוצעת אוטומטית לכל המשתמשים בכל העתות?

**URL:** https://meta.discourse.org/t/why-is-delete-account-not-offered-automatically-to-all-users-at-all-times/308706
**Category:** UX
**Created:** [29 בנובמבר,‏ 2022,‏ 5:44pm UTC](https://meta.discourse.org/t/why-is-delete-account-not-offered-automatically-to-all-users-at-all-times/308706 "2022-11-29T17:44:51Z")
**Posts on this page:** 20
**Page:** 1

<div class="post-metadata">

### Author: ![mcliquid](https://avatars.discourse-cdn.com/v4/letter/m/57b2e6/32.png) [@mcliquid](https://meta.discourse.org/u/mcliquid)
#### Post date: [29 בנובמבר,‏ 2022,‏ 5:44pm UTC](https://meta.discourse.org/t/why-is-delete-account-not-offered-automatically-to-all-users-at-all-times/308706/1 "2022-11-29T17:44:51Z")

</div>

Hello,

I would like to address this issue again, because in a forum I use there are also problems with deletion requests from users.

I would like to understand more about this.

1. Why is it not possible in discourse to delete your own profile with a few clicks?  
Is there any background to this that I don’t understand or has not been disclosed yet? I would assume that the technical implementation is not the problem.  
Are there any reasons from a user experience perspective that support this?

Or is it already planned that there will be an easy way for all users to delete their own account on their own?

1. Can there be problems in relation to the GDPR if no transparent communication and possibility is offered regarding the deletion of one’s own account?

Thank you for answers and clarification!

---

<div class="post-metadata">

### Author: ![Canapin](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/canapin/32/119591_2.png) [@Canapin](https://meta.discourse.org/u/Canapin)
#### Post date: [29 בנובמבר,‏ 2022,‏ 6:32pm UTC](https://meta.discourse.org/t/why-is-delete-account-not-offered-automatically-to-all-users-at-all-times/308706/2 "2022-11-29T18:32:57Z")

</div>

A bit of info:

> [@Add Account Deletion](https://meta.discourse.org/t/add-account-deletion/191233/3):
>
> None of the regulations require deletion or anonymization to be self-service, so the self service options are locked out after they would become disruptive to the community. You can ask the forum administrators to delete your account, but they may respond by anonymizing it instead.

And a related theme component:

> [@Account Deletion Request](https://meta.discourse.org/t/account-deletion-request/245037):
>
> information_sourceSummary Add Account Deletion Request dropdown to account page.hammer_and_wrenchRepository [GitHub - VaperinaDEV/discourse-account-deletion-request: Add Account Deletion Request dropdown to account page. · GitHub](https://github.com/VaperinaDEV/discourse-account-deletion-request)questionInstall Guide [How to install a theme or theme component](https://meta.discourse.org/t/how-do-i-install-a-theme-or-theme-component/63682)open_bookNew to Discourse Themes? [Beginner’s guide to using Discourse Themes](https://meta.discourse.org/t/beginners-guide-to-using-discourse-themes/91966) Hello wave This is a theme component to add an account deletion request dropdown to the accoun…

---

<div class="post-metadata">

### Author: ![mcliquid](https://avatars.discourse-cdn.com/v4/letter/m/57b2e6/32.png) [@mcliquid](https://meta.discourse.org/u/mcliquid)
#### Post date: [29 בנובמבר,‏ 2022,‏ 7:46pm UTC](https://meta.discourse.org/t/why-is-delete-account-not-offered-automatically-to-all-users-at-all-times/308706/3 "2022-11-29T19:46:01Z")

</div>

I am already familiar with the two links. Unfortunately, they do not explain why this function does not yet exist or whether there are plans to implement such a function. I am acting here purely from a UX point of view and would also like to leave the legal glasses off.

User Story: As a Discourse user, I would like to delete my account quickly and easily and receive immediate positive feedback.

The question remains: What are the arguments against adding a button that does just that?

---

<div class="post-metadata">

### Author: ![Canapin](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/canapin/32/119591_2.png) [@Canapin](https://meta.discourse.org/u/Canapin)
#### Post date: [29 בנובמבר,‏ 2022,‏ 8:02pm UTC](https://meta.discourse.org/t/why-is-delete-account-not-offered-automatically-to-all-users-at-all-times/308706/4 "2022-11-29T20:02:33Z")

</div>

> [@Add Account Deletion](https://meta.discourse.org/t/add-account-deletion/191233/3):
>
> the self service options are locked out after they would become disruptive to the community.

This is the part that got my attention. My understanding is that deleting a user deletes all their message and lead to incomplete topics with “holes” in the remaining information on the forum. And it wouldn’t delete parts of the user’s messages quoted by other users, so the information quality would be decreased even more (and still could be linked to the user even after deletion if the user’s name or any other public information they shared was quoted by others).

Again, that’s what I understand but I could be wrong, and also I completely understand your concerns. 🙂

---

<div class="post-metadata">

### Author: ![mcliquid](https://avatars.discourse-cdn.com/v4/letter/m/57b2e6/32.png) [@mcliquid](https://meta.discourse.org/u/mcliquid)
#### Post date: [30 בנובמבר,‏ 2022,‏ 8:02am UTC](https://meta.discourse.org/t/why-is-delete-account-not-offered-automatically-to-all-users-at-all-times/308706/5 "2022-11-30T08:02:02Z")

</div>

Disruptive is a bit harsh in my view in this context. No one insists that all posts must be deleted in the process. Only the username would have to be removed and instead “Deleted user” should be displayed.

Users can report posts here, like, bookmark, share and so on although this is not required by law. So there is also functionality here that makes it easier for a user to use the software, even though this is not required by law. So why not delete your own account via button or at least anonymize it and block the login?

---

<div class="post-metadata">

### Author: ![riking](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/riking/32/170938_2.png) [@riking](https://meta.discourse.org/u/riking)
#### Post date: [8 בדצמבר,‏ 2022,‏ 5:25am UTC](https://meta.discourse.org/t/why-is-delete-account-not-offered-automatically-to-all-users-at-all-times/308706/6 "2022-12-08T05:25:27Z")

</div>

> [@mcliquid](#):
>
> Only the username would have to be removed and instead “Deleted user” should be displayed.

That is what the “anonymize user” functionality does and why it was created 🙂

As for why anonymize user isn’t self service, there are several reasons and I don’t remember all of them right now. What I can think of:

1. GDPR, obviously, demands that deletion is accomplished within 30 days of you giving proper notice. 30 days is plenty of time for a human response and does not demand user-accessible automation _(… that’s why they wrote the law like that …)_.
2. Mistakes. This would be a button that stops you from ever logging into the account again. It’s notable that Facebook, Twitter, etc account deactivation is reversible (though Facebook makes reactivation _too_ smooth). In general, the “destroy my data button” is something the software engineering industry has started to realize is a Bad Idea.
3. The human touch is actually nice sometimes, which ties into…
4. Wanting to leave a community so badly you don’t want your name associated with it at all is something that the admins should know about and feel when it happens. Can they fix the cause for the next person?
5. The conversation is a chance to offer alternative remedies, such as timed suspension (for people worried that they’re addicted to the forum) or performing a detailed scrub of sensitive information in posts.
6. Account hijacking attacks are a thing that can happen. If we suppose a widespread account hijacking incident that doesn’t nab any moderator accounts, Anonymize Account is easily the most destructive available action after this proposal. This is one of the major reasons that individual post deletion is rate limited.
7. SSO - the user’s data might be replicated to other systems that Discourse doesn’t know about that the moderators also need to trigger cleaning in.

None of these are “hard never” reasons, but I hope this gives you a good sense of the balance of concerns.

---

<div class="post-metadata">

### Author: ![RBoy](https://avatars.discourse-cdn.com/v4/letter/r/2bfe46/32.png) [@RBoy](https://meta.discourse.org/u/RBoy)
#### Post date: [12 בספטמבר,‏ 2023,‏ 1:59am UTC](https://meta.discourse.org/t/why-is-delete-account-not-offered-automatically-to-all-users-at-all-times/308706/7 "2023-09-12T01:59:45Z")

</div>

Adding my 2 cents to this feature request. The decision as to whether users should be allowed to delete their own accounts (irrespective of how long they’ve been around etc) should ultimately lie with the site administrator. The responsible thing to do would be to allow the administrator to allow or disallow account deletion (or anonymization) to comply with regulations and company policies. It shouldn’t be forced upon them by discourse (or made to do hoops to achieve this basic feature).

Cross linking, 2 options that are sorely required in discourse to comply with regulations and company policy:

> [@How to always allow users to delete their own accounts?](https://meta.discourse.org/t/how-to-always-allow-users-to-delete-their-own-accounts/278348/15):
>
> Thanks for clarifying that. Would it possible to include this option as a configurable option in the admin settings UI? It would be super helpful have 2 options available for the site admins: Always allow users to delete their accounts and all posts permanently Always allow users to delete their accounts and anonymize all posts It would be very valuable add for compliance as ease to maintenance. Are these hard to implement?

---

<div class="post-metadata">

### Author: ![kDE](https://avatars.discourse-cdn.com/v4/letter/k/a6a055/32.png) [@kDE](https://meta.discourse.org/u/kDE)
#### Post date: [9 באפריל,‏ 2024,‏ 8:18am UTC](https://meta.discourse.org/t/why-is-delete-account-not-offered-automatically-to-all-users-at-all-times/308706/8 "2024-04-09T08:18:32Z")

</div>

I see critical issues with all those shiny arguments.

- Holes in the Threads are annoying, that’s understandable but the “right to be forgotten” (GDPR) is above all in the law sense (privacy \> comfort / functionality)
- Self-service is unavoidable and there is no legitimate interest not having it

The regulation does not talk about self-service directly but the intent of the law, which counts, implies that a self-service is unavoidable.

Technically, all websites having registration and account (management) without that self-service are rejecting the user’s legal authority over the own private data (or PII), including posts where the person is identifiable and therefore are probably violating the GDPR, which is to interpret in widest possible extent.

I do believe that German law is also violated, as our interpretation of the GDPR is much deeper and “wider” than the original GDPR. People have on German platforms always the right to delete all their data all the time. The only exceptions are legal and security purposes. Both legitimate causes can’t be justified here.

I do agree that a the owner/super admin should decide whether this functionality is active or not, but it should be by default enabled for all discourses that have German or EU users.

Having a button that asks the admin to anonymize is a nice tool and might be sufficient under U.S. law.

In anyway just anonymizing the account is not enough. It probably keeps the E-Mail, IP addresses etc. which is probably illegal in most cases.

---

<div class="post-metadata">

### Author: ![kDE](https://avatars.discourse-cdn.com/v4/letter/k/a6a055/32.png) [@kDE](https://meta.discourse.org/u/kDE)
#### Post date: [9 באפריל,‏ 2024,‏ 8:31am UTC](https://meta.discourse.org/t/why-is-delete-account-not-offered-automatically-to-all-users-at-all-times/308706/9 "2024-04-09T08:31:37Z")

</div>

> [@riking](#):
>
> 30 days is plenty of time for a human response and does not demand user-accessible automation

That’s half-way correct. GDPR allows that time BUT only under extreme circumstances e.g. when you’re Facebook. Under all other circumstances the deletion process must be completed ASAP. The GDPR is not forgiving in that sense and it must be interpreted in the most extent. The safety, morale and legal rights of the user are the main thought of this regulation.

> [@riking](#):
>
> In general, the “destroy my data button” is something the software engineering industry has started to realize is a Bad Idea

It was never the idea of the Software Industry in the first place, and yet as developer and hacker I love those buttons. People will always opt for it, and it is a human and legal right providing it. But we can debate about the action behind the button click.

> [@riking](#):
>
> This is one of the major reasons that individual post deletion is rate limited.

The best defense against account hijacking attacks is educating the users! Not limiting actions that should be limited anyways (per rate-limiting) for the sake of the general app security of the site.

> [@riking](#):
>
> Wanting to leave a community so badly you don’t want your name associated with it at all is something that the admins should know about and feel when it

So we are not allowed to leave when we want so? Despite admins should have common sense and a feeling for that, I have a personal right to leave when I want to leave with or without telling anyone. The same you can’t just lock me in your room because you want to know why I am leaving.

---

<div class="post-metadata">

### Author: ![traceymoko](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/traceymoko/32/483235_2.png) [@traceymoko](https://meta.discourse.org/u/traceymoko)
#### Post date: [9 באפריל,‏ 2024,‏ 8:33am UTC](https://meta.discourse.org/t/why-is-delete-account-not-offered-automatically-to-all-users-at-all-times/308706/10 "2024-04-09T08:33:11Z")

</div>

> [@kDE](#):
>
> In anyway just anonymizing the account is not enough. It probably keeps the E-Mail, IP addresses etc. which is probably illegal in most cases.

For info on that:

> [@Anonymizing Users in Discourse](https://meta.discourse.org/t/anonymizing-users-in-discourse/86929/1):
>
> Their email, name, date of birth and avatar will be removed. Their password will be replaced with a secure, random password.

> [@Anonymizing Users in Discourse](https://meta.discourse.org/t/anonymizing-users-in-discourse/86929/1):
>
> ### IP History
> 
> Discourse will retain the user’s IP addresses in our logs associated with the anonymous user. However, there is a new mechanism to clear those out too available to developers.

---

<div class="post-metadata">

### Author: ![kDE](https://avatars.discourse-cdn.com/v4/letter/k/a6a055/32.png) [@kDE](https://meta.discourse.org/u/kDE)
#### Post date: [9 באפריל,‏ 2024,‏ 8:35am UTC](https://meta.discourse.org/t/why-is-delete-account-not-offered-automatically-to-all-users-at-all-times/308706/11 "2024-04-09T08:35:52Z")

</div>

Alright! And what about the PII in the posts?

---

<div class="post-metadata">

### Author: ![kDE](https://avatars.discourse-cdn.com/v4/letter/k/a6a055/32.png) [@kDE](https://meta.discourse.org/u/kDE)
#### Post date: [9 באפריל,‏ 2024,‏ 8:37am UTC](https://meta.discourse.org/t/why-is-delete-account-not-offered-automatically-to-all-users-at-all-times/308706/12 "2024-04-09T08:37:15Z")

</div>

I’d like to highlight the following aspect of Art. 7 GDPR ([Art. 7 GDPR – Conditions for consent - General Data Protection Regulation (GDPR)](https://gdpr-info.eu/art-7-gdpr/)):

> The data subject shall have the right to **withdraw his or her consent at any time.** The withdrawal of consent shall not affect the lawfulness of processing based on consent before its withdrawal. Prior to giving consent, the data subject shall be informed thereof. **It shall be as easy to withdraw as to give consent.**

If the registration is easy, the deletion (consent withdraw) must be easy as well.

---

<div class="post-metadata">

### Author: ![Moin](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/moin/32/554653_2.png) [@Moin](https://meta.discourse.org/u/Moin)
#### Post date: [9 באפריל,‏ 2024,‏ 8:39am UTC](https://meta.discourse.org/t/why-is-delete-account-not-offered-automatically-to-all-users-at-all-times/308706/13 "2024-04-09T08:39:35Z")

</div>

> [@Questions about user anonymization and GDPR](https://meta.discourse.org/t/questions-about-user-anonymization-and-gdpr/299200/22):
>
> There is an exception to the “right to be forgotten”, which is stated in [GDPR article 17.3](https://gdpr-info.eu/art-17-gdpr/) Paragraphs 1 and 2 shall not apply to the extent that processing is necessary: for exercising the right of freedom of expression and information; [Recital 65](https://gdpr-info.eu/recitals/no-65/) #5 However, the further retention of the personal data should be lawful where it is necessary, for exercising the right of freedom of expression and information (which implies that the retention of personal data is lawful, even when the data …

---

<div class="post-metadata">

### Author: ![kDE](https://avatars.discourse-cdn.com/v4/letter/k/a6a055/32.png) [@kDE](https://meta.discourse.org/u/kDE)
#### Post date: [9 באפריל,‏ 2024,‏ 8:47am UTC](https://meta.discourse.org/t/why-is-delete-account-not-offered-automatically-to-all-users-at-all-times/308706/14 "2024-04-09T08:47:28Z")

</div>

If the user steps back from a statement it is not part of this exception anymore. So legally this would a very weird gray area that is extremely contradicting to the fundamental principles of the GDPR.

The idea of the ECHR, and thus GDPR freedom of expression and information inclusion is simply that you could strike every e.g. media or private blog owner if they put up PII regarding to a valid case that suits the public interest. I do not see that this would apply to forums.

Please consider Art. 85 regarding it. [Making sure you're not a bot!](https://gdprhub.eu/Article_85_GDPR)

So per case basis would be applied here, like when a user posts a statistical overview, such things could be kept but not the rest e.g. when a user posts a picture of themself.

I’ve also read in one post that was linked here:

> You can restore a backup made before the destructive action [the account deletion]

So because the “deletion” (anonymizing) is reversible this is technically not legal.

The GDPR must be interpreted in most extreme ways.

---

<div class="post-metadata">

### Author: ![Jagster](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/jagster/32/192154_2.png) [@Jagster](https://meta.discourse.org/u/Jagster)
#### Post date: [9 באפריל,‏ 2024,‏ 8:48am UTC](https://meta.discourse.org/t/why-is-delete-account-not-offered-automatically-to-all-users-at-all-times/308706/15 "2024-04-09T08:48:58Z")

</div>

> [@kDE](#):
>
> “right to be forgotten” (GDPR) is above all in the law sense (privacy \> comfort / functionality)

It has nothing to do with content deletion per se.

> [@Add Account Deletion](https://meta.discourse.org/t/add-account-deletion/191233/29):
>
> So because the “deletion” (anonymizing) is reversible this is technically not legal.

And that is not even remotely true. It is unlegal save backups until the world comes to its end. But it is legal to have backups resonable time. But sure, if a backup is restored then deletions must be done again.

---

<div class="post-metadata">

### Author: ![kDE](https://avatars.discourse-cdn.com/v4/letter/k/a6a055/32.png) [@kDE](https://meta.discourse.org/u/kDE)
#### Post date: [9 באפריל,‏ 2024,‏ 8:54am UTC](https://meta.discourse.org/t/why-is-delete-account-not-offered-automatically-to-all-users-at-all-times/308706/16 "2024-04-09T08:54:28Z")

</div>

> nothing to do with content deletion per se

Kinda depends! One could certainly argue that a user has all rights of the work they have posted. Therefore everything “belongs” to the user, and is thus indirectly connected to the identity, and therefore all the posts / information connected to it. I agree that this would be extreme.

The key point about deleting the account is that all connected PII or at least all links to the PII are safely deleted. The content can be kept it is totally open information and not leading to the user('s identity).

> But sure, if a backup is restored then deletions must be done again.

I agree! Like you say, you would have to do the deletions again, but the fact that you can restore the deleted users information is the key issue, although you have a right to do backups for maintaining the service and security. I do not believe anyone would sue for that or any prosecutor letting the legal proceedings continue. However, we have to bring law and technical aspects together if it comes to privacy.

---

<div class="post-metadata">

### Author: ![Jagster](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/jagster/32/192154_2.png) [@Jagster](https://meta.discourse.org/u/Jagster)
#### Post date: [9 באפריל,‏ 2024,‏ 9:02am UTC](https://meta.discourse.org/t/why-is-delete-account-not-offered-automatically-to-all-users-at-all-times/308706/17 "2024-04-09T09:02:28Z")

</div>

> [@kDE](#):
>
> Kinda depends! One could certainly argue that a user has all rights of the work they have posted.

Kinda not. Those are two totally different things.

GDPR limits why, how, when and long a service can indetify users.

Copyright **and** ownership of publishing are totally different story and and has nothing to do with data protection and GDPR.

Any post in this topic is not such creativive content that could be protected by copyright somewhere in the world. But Meta has content that is protected, as blogs etc.

And then we step in the world of agreements and terms, and how content is licensed.

---

<div class="post-metadata">

### Author: ![kDE](https://avatars.discourse-cdn.com/v4/letter/k/a6a055/32.png) [@kDE](https://meta.discourse.org/u/kDE)
#### Post date: [9 באפריל,‏ 2024,‏ 9:05am UTC](https://meta.discourse.org/t/why-is-delete-account-not-offered-automatically-to-all-users-at-all-times/308706/18 "2024-04-09T09:05:00Z")

</div>

> flag your post and ask for deletion

But that’s contradicting the principles of the GDPR 👀 The idea is that I can easily remove my posts, account etc. Everything that is connected to my PII or identity.

> When the first post of a topic is deleted, the whole topic is deleted

That’s a special case where you could keep the post itself but replace the content with “user deleted this post”. Then the thread’s structure would remain.

> Would you like it if someone would just delete this topic including the whole discussion?

I’m split regarding this. On one hand the user has a right to do so.The privacy and liberty is above my interest to discuss, and sometimes even above the public interest. On the other hand I love to discuss, and if everything just vanishes I would be annoyed as well.

> These laws, as you point out, are open to interpretation.

Laws are always open for interpretation but we have to go by the interpretation of the courts, academics, and what the regulation says about itself. The ideology behind GDPR is pretty clear and leaves less space for interpretations.

---

<div class="post-metadata">

### Author: ![kDE](https://avatars.discourse-cdn.com/v4/letter/k/a6a055/32.png) [@kDE](https://meta.discourse.org/u/kDE)
#### Post date: [9 באפריל,‏ 2024,‏ 9:08am UTC](https://meta.discourse.org/t/why-is-delete-account-not-offered-automatically-to-all-users-at-all-times/308706/19 "2024-04-09T09:08:24Z")

</div>

Sorry, I think you misunderstood me. I pointed out that a combination of the mentioned laws leading to the same effect, and thus establishes a responsibility under GPDR. Of course is copyright (or similar) and PII, and the GDPR fully different things. Yet they still can be combined to establish a cause.

> Any post in this topic is not such creativive content that could be protected by copyright somewhere in the world.

I think you might confuse, copyright and ownership. Especially under German jurisdiction you have for everything you create a special ownership right, which you can enforce globally.

> we step in the world of agreements and terms, and how content is licensed.

Even there you can’t just strip a user of their ownership, and the biggest issue is still the PII connected to a post, depending on the content and nature of course.

---

<div class="post-metadata">

### Author: ![RGJ](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/rgj/32/523185_2.png) [@RGJ](https://meta.discourse.org/u/RGJ)
#### Post date: [9 באפריל,‏ 2024,‏ 9:26am UTC](https://meta.discourse.org/t/why-is-delete-account-not-offered-automatically-to-all-users-at-all-times/308706/20 "2024-04-09T09:26:33Z")

</div>

> [@kDE](#):
>
> Everything that is connected to my PII or identity.

The word order of your statement is wrong 😉 and it makes a huge difference.

Everything that is your PII, or is connected to your identity.

[Next page](https://meta.discourse.org/t/why-is-delete-account-not-offered-automatically-to-all-users-at-all-times/308706.md?page=2)
