TenthFleet:GDPR

From TenthFleet
Revision as of 14:16, 17 August 2026 by CMagnani (talk | contribs) (removed from Category:Policy; added to Category:Policies; corrected Category:TenthFleet to Category:Tenth Fleet)
(diff) ← Older revision | Latest revision (diff) | Newer revision → (diff)
Jump to navigation Jump to search
📖 PolicyThis page describes one of the policies and guidelines of the Tenth Fleet Wiki. Please read it to familiarize yourself with our common practices and rules. Questions or suggestions can be raised on the talk page.

This page explains how the Tenth Fleet wiki handles personal data in its historical record. It is a statement of our record-keeping policy, not legal advice.

Data Protection and the Historical Record is the policy governing how personal information is kept, redacted, or restored in the Tenth Fleet wiki, which serves as an indexed archive of orders, directives, awards, and unit histories for The Royal Manticoran Navy: The Official Honor Harrington Fan Association.

Our commitment

We respect the data-protection rights of every member. This includes the rights granted under the European Union's General Data Protection Regulation (GDPR), the equivalent United Kingdom regime (the UK GDPR together with the Data Protection Act 2018), and comparable laws elsewhere. Where a member asks us to correct or remove their personal data, we take that request seriously and act on it.

At the same time, TRMN keeps an accurate historical record in the public interest. Our orders and directives are the primary source used for command lineage, unit histories, promotion and award records, and training examinations. That record only works if it is complete and faithful to what was actually issued. Data-protection law recognizes this kind of tension directly, and provides for it. This policy explains how we balance the two.

The right to erasure, and why it is not absolute

Under Article 17, paragraph 1 of the GDPR, a person generally has the right to erasure (sometimes called the "right to be forgotten"): the right to ask an organization to delete personal data it holds about them.

That right is not unlimited. Article 17, paragraph 3 lists situations where it does not apply. The one that matters for an archive like ours is Article 17, paragraph 3(d), which removes the erasure right to the extent that keeping the data is necessary:

"for archiving purposes in the public interest, scientific or historical research purposes or statistical purposes in accordance with Article 89, paragraph 1 ... in so far as the [erasure right] is likely to render impossible or seriously impair the achievement of the objectives of that processing."

In plain terms: if deleting a name would break a genuine historical record that is kept for the public good, the law lets the record stand. Article 89, paragraph 1 is the companion rule that requires such archives to be handled responsibly, keeping only what the record actually needs and nothing more.

Why this exemption exists

The purpose of the archiving exemption is to stop the right to erasure from quietly erasing history. Public registries, museum catalogs, muster rolls, and official orders are all records where the identity of the people involved is part of the fact being recorded. If a ship's commissioning order could later have the commanding officer's name struck out, the order would no longer be a truthful record of who commanded that ship. The exemption keeps the archive honest while still limiting how that data may be used: it may be kept and consulted as history, but not repurposed to make decisions about the individual or to build a profile of them.

That is exactly how we treat it here. A member's name appears in our archive only as it appears in the official record of their appointments, commands, promotions, and awards. We do not expand those entries into personal biographies (see also our practice that this is not a biographical site), and we do not use the record to make any judgment about a living person.

The United Kingdom position

Because much of the Honorverse fandom and TRMN's own framing is British, members sometimes ask whether the United Kingdom keeps the same exemption after leaving the EU. It does.

  • The UK retained the GDPR as domestic law (the UK GDPR). Article 17, paragraph 3(d) survives in the same words, so the archiving and historical-research exemption to the right to erasure applies in the UK just as it does in the EU.
  • The Data Protection Act 2018, section 19 sets the UK safeguards for this kind of processing (the Article 89 conditions). Importantly, section 19 says the exemption is not available where the processing is likely to cause substantial damage or substantial distress to a person, or where it is used to make measures or decisions about a particular individual. An archive of historical orders does neither.
  • The Data Protection Act 2018, Schedule 2, paragraph 28 separately sets aside several other data-subject rights (such as access, rectification, restriction, portability, and objection) for personal data processed for archiving in the public interest.

So under both the EU and UK regimes, a faithful public-interest archive may retain names that appear in its official records, subject to handling the data responsibly and never in a way that harms the individual.

Other jurisdictions and non-profit status

TRMN's membership is international, so members ask how privacy laws outside the EU and UK apply. Two facts shape the answer. First, TRMN is a United States non-profit, tax-exempt as a social and recreational club under Internal Revenue Code section 501(c)(7); it is a volunteer hobby organization, not a commercial business. Second, none of the major non-EU regimes grants a "delete everything" right as broad as the GDPR's, and each contains exceptions, thresholds, or scope limits that commonly place a small non-profit outside their reach or preserve a truthful historical record. The summaries below are general and not legal advice.

United States (California and other states)

California's Consumer Privacy Act, as amended by the California Privacy Rights Act, gives residents a right to delete personal information (Civil Code section 1798.105), subject to exceptions that preserve free speech and research in the public interest. Crucially, the Act applies only to a "business", defined as a for-profit legal entity that meets revenue or data-volume thresholds. A tax-exempt 501(c)(7) social club is not a for-profit business, so the CCPA and CPRA deletion right does not reach TRMN's member records. Information drawn from public records is also typically outside the law entirely.

California was first, but by 2026 roughly nineteen states have comprehensive consumer-privacy laws, and every one of them includes a right to delete: Virginia, Colorado, Connecticut, Utah, Iowa, Indiana, Tennessee, Montana, Oregon, Texas, Delaware, New Jersey, New Hampshire, Nebraska, Kentucky, Maryland, Minnesota, and Rhode Island, alongside California. For TRMN, two features run through nearly all of them:

  • Non-profit treatment. Most of these laws exempt non-profit organizations outright, just as California does. A few do reach non-profits, notably Colorado, Oregon, Delaware, New Jersey, and Minnesota (some only in narrow categories such as insurance-fraud groups). But even in those states the law only applies above high thresholds: typically the personal data of 100,000 residents of that state in a year, dropping to 25,000 only for an organization that earns a quarter or more of its revenue from selling personal data. "Consumers" here means residents of the single state in question, so TRMN's members in any one state are a small fraction of its several-thousand worldwide membership, well under 100,000. TRMN also does not sell personal data, so the lower threshold cannot apply. It therefore falls below the applicability thresholds of these laws.
  • Deletion exceptions. Where any of them could apply, each carries the same kinds of exceptions California does, allowing personal data to be kept to comply with a legal obligation, to exercise or defend legal rights, for internal uses consistent with the context in which it was provided, and, in several, for public-interest or record-keeping purposes. A faithful historical archive fits comfortably within these.

Canada (PIPEDA)

Canada's Personal Information Protection and Electronic Documents Act does not provide a general right to erasure; it is consent-based and its narrow correction right concerns inaccurate or outdated information. PIPEDA applies to organizations that collect, use, or disclose personal information in the course of commercial activity, and it expressly does not apply to information used for journalistic, artistic, or literary purposes. A volunteer non-profit's non-commercial member record-keeping generally falls outside PIPEDA's scope.

Australia (Privacy Act 1988)

Australia's Privacy Act and the Australian Privacy Principles do not grant a general right to erasure. APP 11 asks that personal information be destroyed or de-identified once no longer needed, but with an exception where it sits in a record the organization is required or authorized to keep. The Act has also long exempted small businesses and many non-profits below a turnover threshold (set at A$3 million), a carve-out now being narrowed by reforms underway. A small volunteer organization has generally sat outside the Act.

A note on the EU and UK

Unlike the laws above, the GDPR and UK GDPR do not exempt non-profits: they apply to any organization that processes personal data, TRMN included. Non-profit status is therefore not what protects the record here. That protection comes from the archiving and historical-research exemption described earlier (Article 17, paragraph 3(d), read with Article 89, paragraph 1; in the UK, Data Protection Act 2018, section 19), which lets a faithful public-interest archive keep the names its official records contain.

Children's personal data is always redacted

There is one line we do not cross, regardless of the exemption above: we do not publish the personal data of children.

Data-protection law gives children's data special protection (GDPR Recital 38 notes that children "merit specific protection"), and the UK safeguard against causing "substantial distress" weighs even more heavily for a minor. Where a name in an order belongs to a child member, identifiable by a youth rank such as Cadet Ranger, that name remains redacted even though the surrounding order is preserved as historical record. The command or crew entry is kept; the child's name is not.

How this looks on the wiki

  • Orders and directives are preserved as issued. Where a name was previously removed and has been restored under the historical-record exemption, or is deliberately withheld, the entry carries a short note linking back to this policy.
  • Restored entries are the names of adult members as they appear in an official appointment, command, promotion, or award.
  • Withheld entries are children's names, and any data still subject to an active erasure decision that the exemption does not cover.
  • We honor erasure and correction requests except to the extent the archiving exemption applies, and children's data is redacted in every case.

Making a request

A member who wishes to correct or remove their personal data, or who has a question about how their data appears in the record, should contact the wiki administrators or the appropriate TRMN officer. We will review each request individually and apply this policy in good faith.

References and sources