At least in the EU it is required that data is only stored as long as it is needed and the user actively consents to it. An active consent can expire if the user isn’t engaged for a long time (how long depends on the type of data and service). Obviously it is also required to send warning emails before deleting anything, so I guess this didn’t happen here.
howrar@lemmy.ca 6 days ago
Surely, this can’t apply for maintaining data on what a user “owns”, right?