I also have hundreds and hundreds of logins and my issue is that every week now some site gets breached. A lot of them are super old and I'd prefer to have the site delete all my info, but it's too time consuming to manually do that.
That /well-known/ idea is great. There should be a /well-known/permanently-delete, so that my password manager can scrub my old accounts with one click.
Cleaning accounts from your password manager and cleaning your accounts from the internet are two very different things. The article and my comment were about the former.
I agree with you though, that a well-known url for delete would be good. However, there's likely to be a high correlation between sites that get breached and sites that don't follow best practices, including implementing optional URLs like that.
In general, it's also easy to see why a lot of (non technical) site/product owners wouldn't want to implement that: "why do I care about making things easier for people that want to terminate doing business with me?" Until a majority of users are using a browser/plugin that warns about this ("non trustworthy site: this site does not implement well-known password change or delete account interfaces") I suspect there won't be much adoption, unfortunately. This proved to work well to get SSL widely deployed, so the question is if there can be enough momentum to do it again for these functions.
I don't think sanitizing or deleting online accounts is that time consuming. I have about 600 accounts listed in my password manager, about 300 of which are categorized as either offline or deleted.
Starting late last year I went through my accounts and started either deleting the ones I have no intention of using in the future or, if deletion is not an option, sanitizing them. It doesn't take that long to sanitize 10 accounts, and takes even less time to identify whether a website is still online. I've probably sanitized or deleted around 100 accounts now, starting with the ones I guessed would have the most data on me.
I've also been pleasantly surprised by how helpful most webmasters have been with removing or sanitizing PII if they won't let you delete an account.
One notable exception: Airbnb. They claim online that they will delete your account if asked but refuse if you do ask. I had no intention of using Airbnb in the future, but now I'll actively discourage others from using Airbnb.
I know (from your site) that you're not european, but to any EU citizens out there reading: Know your rights. You can unrequivocably request deletion of your personal data, including your account, if it's known to be stored somewhere on the internet (edit: or even off the internet. Physical records are covered!). There are rare exceptions (eg. financial data required for tax purposes, security/compliance, …), but I've never seen it be an issue. And if it is an issue, there are enforcement organizations that will help.
Too bad that almost all sites you'd actually want to use or have used are outside of the EU. Unless it's a big site they probably have no EU presence and there would be no way for the EU to do anything.
I don’t know if you are right. Being hosted outside the EU doesn’t seem to exemt companies that handle EU citizens data from complying with EU privacy laws.
On paper that's not correct. In practice, what you're saying is likely sometimes true, but I have yet to encounter it.
Smaller sites generally have people on hand and are still human enough that they will at least try to accomodate you manually if needs be. And if they're being annoying with you, and you are pretty explicit about the nature of your request, specific about your rights under GDPR, etc they'll either get scared enough to do it, or figure you're not worth the trouble and do it so you stop complaining.
Really the most annoying services I've dealt with GDPR-wise are in fact large corps with EU presence (sometimes EU-only!), that just don't have enough human elements in their chain to talk to you like a person. And this is something where it's very comforting to know you do wield a lot of legal power to rectify these issues.
That /well-known/ idea is great. There should be a /well-known/permanently-delete, so that my password manager can scrub my old accounts with one click.