{
  "compartment_id": "section-18",
  "number": "Section 18",
  "title_local": "A GDPR access request closed without data",
  "title_english": "A GDPR access request closed without data",
  "source_url": "https://phishdestroy.io/steam_dossier/#gdpr-live-case",
  "source_document": "index.html",
  "content": {
    "html": "<section class=\"border-t border-gray-800 pt-6 accountability-section\" id=\"gdpr-live-case\">\n<div class=\"max-w-7xl mx-auto space-y-8\">\n<div class=\"case-section-heading section-head section-head-balanced\"><div class=\"section-head-primary\">\n<span class=\"kicker\">Part C — Legal frameworks · Section 18 · GDPR Article 15 request</span>\n<h2>The request. The reply. The missing comparison.</h2>\n\n</div><div class=\"section-head-intro\"><p class=\"lede\">He asked for four things, one of them the log that would name whoever put an API key on his account. <strong class=\"text-white\">Three days later the ticket was closed with a link to a page that holds none of them</strong> — and the sentence used to close it is contradicted by Valve's own lawyers.</p></div></div>\n<div class=\"bg-gray-950 border border-gray-700 rounded-lg p-5 space-y-3 ds-5012029ff72c\">\n<div class=\"text-xs font-mono text-gray-400 uppercase tracking-widest font-bold\">Whose account this is · Provenance &amp; Limits</div>\n<p class=\"text-sm text-gray-300 leading-relaxed\"><strong class=\"text-white\">These screenshots are not PhishDestroy's.</strong> They come from an ordinary Steam account holder — one respondent to a short survey run by this project, who filed the request himself and supplied the captures. The account is his, the ticket is his, and the correspondence is between him and Steam Support. This project did not submit the request, holds no account on the platform, and is not a party to this ticket.</p>\n<p class=\"text-sm text-gray-300 leading-relaxed\">On 16 September 2026 he filed a GDPR/CCPA Article 15 subject access request asking specifically for API-key registration logs, login history with IPs, device authorisation history and trade history. On 17 September agent \"Logen\" referred him to the self-service Account Data page. On 18 September he stated that the requested categories were not on that page and asked for escalation to the Privacy Team or DPO. On 19 September agent \"Kal\" closed the ticket with the same referral. Both screenshots are preserved below (requester e-mail redacted; SHA-256 in <code>steam_tos_assets/screenshot-manifest.json</code>).</p>\n<p class=\"text-sm text-gray-300 leading-relaxed\">He is a fitting requester for an ordinary reason: <strong class=\"text-white\">his account carries a Steam Web API key he did not create, registered to <code class=\"text-amber-300\">localhost</code></strong>. <strong class=\"text-white\">When it was created is not known</strong> — not to him, and not from anything Valve has made available to him, because the single record that would date it is the API-key registration log, which is exactly the category the closure withheld. The key is not new: it predates his awareness of it by an interval he cannot measure, for the same reason.</p>\n<p class=\"text-sm text-gray-300 leading-relaxed\">Other account holders are filing the same request. Any reply that arrives will be added here on the same terms as these two — ticket number, capture date, SHA-256, requester redacted — whether it supplies the categories or refuses them.</p>\n<p class=\"text-[11px] text-gray-400 leading-relaxed font-mono\">This project takes no position on why the ticket was closed. No reason was stated in it, and none is inferred here.</p>\n</div>\n<div aria-label=\"The request. The response. The comparison.\" class=\"story-scene\" data-story=\"\"><div class=\"story-scene-header\"><strong>The request. The response. The comparison.</strong><span>FOLLOW THE RECORD</span></div><div class=\"story-lane\"><div class=\"story-route\"><div class=\"story-node\" data-story-step=\"0\"><small>THE REQUEST</small><strong>Specific categories</strong><span>API-key, login, device and trade records</span></div><div class=\"story-node\" data-story-step=\"1\"><small>THE RESPONSE</small><strong>Account Data reference</strong><span>Inspect the support exchange</span></div><div class=\"story-node\" data-story-step=\"2\"><small>THE TEST</small><strong>What was supplied?</strong><span>Compare each requested category</span></div></div></div><div class=\"story-caption\"><p data-story-caption=\"0\" hidden=\"\">Read the preserved request to see which categories the account holder asked for.</p><p data-story-caption=\"1\" hidden=\"\">The preserved reply points to Account Data. The screenshots show the wording and the ticket outcome.</p><p data-story-caption=\"2\">He asked for four named categories. The Account Data page he was referred to is Valve's own self-service export, and this project cannot enumerate its contents for someone else's account — so no full category-by-category comparison is published here. What is on the record is his statement of 18 September that the categories were not there, and the closure of 19 September that repeated the referral without addressing them.</p></div><div class=\"story-controls\" hidden=\"\"><button data-story-play=\"\" type=\"button\">Replay the sequence</button><button data-story-next=\"\" type=\"button\">Start again</button><span aria-live=\"polite\" role=\"status\"></span></div></div>\n<div class=\"grid grid-cols-1 lg:grid-cols-2 gap-4 items-start\">\n<figure class=\"evidence-figure space-y-2\">\n<div class=\"text-xs font-mono text-gray-400 uppercase font-bold tracking-wider\">Screen 1/2 — Request (16 Sep) and first reply, agent \"Logen\" (17 Sep)</div>\n<div class=\"overflow-y-auto max-h-[360px] rounded border border-gray-800 bg-black/40 p-1\">\n<img alt=\"GDPR ticket HT-2YBP-F7JP-D4VB — request and first response\" class=\"mx-auto max-w-full rounded\" height=\"800\" loading=\"lazy\" src=\"steam_tos_assets/gdpr-ticket-1.png\" width=\"1280\"/>\n</div>\n<figcaption class=\"evidence-caption\">Source: help.steampowered.com, ticket HT-2YBP-F7JP-D4VB · captured 16–17 Sep 2026 · requester e-mail redacted 2026-09-21 · File: <a href=\"steam_tos_assets/gdpr-ticket-1.png\">gdpr-ticket-1.png</a> · SHA-256 <code>da940c731ab9869d226e9d06ccc8a1b393738766b7b0c445a56662623e025a66</code> (<a href=\"steam_tos_assets/screenshot-manifest.json\">screenshot-manifest.json</a>).</figcaption>\n</figure>\n<div class=\"space-y-2\">\n<figure class=\"evidence-figure space-y-2\">\n<div class=\"text-xs font-mono text-gray-400 uppercase font-bold tracking-wider\">Screen 2/2 — Escalation request (18 Sep) and closure, agent \"Kal\" (19 Sep)</div>\n<div class=\"overflow-y-auto max-h-[300px] rounded border border-red-900/40 bg-black/40 p-1\">\n<img alt=\"GDPR ticket HT-2YBP-F7JP-D4VB — escalation request and closure\" class=\"mx-auto max-w-full rounded\" height=\"800\" loading=\"lazy\" src=\"steam_tos_assets/gdpr-ticket-2.png\" width=\"1280\"/>\n</div>\n<figcaption class=\"evidence-caption\">Source: help.steampowered.com, ticket HT-2YBP-F7JP-D4VB · captured 18–19 Sep 2026 · File: <a href=\"steam_tos_assets/gdpr-ticket-2.png\">gdpr-ticket-2.png</a> · SHA-256 <code>44844ea7b251f7fd7d79f87ee1578a846606a97b9659d3a53b322120c422219b</code> (<a href=\"steam_tos_assets/screenshot-manifest.json\">screenshot-manifest.json</a>).</figcaption>\n</figure>\n<div class=\"bg-red-950/30 border border-red-800/30 rounded p-3 font-mono text-xs space-y-1.5\">\n<div class=\"text-red-400 font-bold uppercase text-xs\">Closing response, 19 Sep (verbatim):</div>\n<div class=\"text-gray-300 italic leading-relaxed\">\"The data Steam retains can already be found in your Account Data page. As there's no further information Steam Support can offer, <strong class=\"text-red-300\">this request will be closed.</strong>\"</div>\n<div class=\"text-gray-400 text-xs pt-1\">No data supplied · no legal basis for refusal stated · no escalation outcome shown</div>\n<div class=\"text-red-300 text-xs pt-2 border-t border-red-900/40 mt-2 leading-relaxed not-italic\"><strong class=\"text-red-400\">That sentence is false, and Valve's own lawyers prove it.</strong> Counsel's letter of 1 October 2025, paragraph 1.9, describes device-level correlation linking one device to dozens of accounts (<a class=\"underline\" href=\"#official-memorandum\">Appendix A</a>). The same response carried 830 pages of retained records (<a class=\"underline\" href=\"#academic-response\">Appendix B</a>). None of it is on the Account Data page.</div>\n</div>\n</div>\n</div>\n<div class=\"bg-gray-950 border border-amber-700/40 rounded-lg p-5 space-y-3 ds-5012029ff72c\">\n<div class=\"text-xs font-mono text-amber-400 uppercase tracking-widest font-bold\">Why this account asked for the API-key log</div>\n<p class=\"text-sm text-gray-300 leading-relaxed\">He did not pick those four categories at random. The <code class=\"text-amber-300\">localhost</code> key on his account is <strong class=\"text-white\">the mark of a script, not of a person typing a real domain into the developer page</strong> (<a class=\"underline\" href=\"#vulnerability-profile\">Section 5</a>, <a class=\"underline\" href=\"#hijack-simulation\">Section 6</a>). The one record that shows who created it and from where is the API-key registration log. That was the first thing he asked for. That is what the closure withheld.</p>\n<p class=\"text-[11px] text-gray-400 leading-relaxed font-mono\">Source: the account holder, during this project's survey. The ticket screenshots above are hashed; the key page is not published.</p>\n</div>\n<div class=\"bg-gray-950 border border-gray-700 rounded-lg p-5 space-y-3 ds-66e6b652a695\">\n<div class=\"text-xs font-mono text-gray-400 uppercase tracking-widest font-bold\">Assessment · PhishDestroy</div>\n<p class=\"text-sm text-gray-300 leading-relaxed\">Closing a ticket with the question still open is not an accident here. It is the normal outcome. We hold <a class=\"underline\" href=\"steam_evidence_archive\">16,319 preserved complaint and support records</a> and <a class=\"underline\" href=\"steam_enforcement_evidence#support-records\">354 de-duplicated support exchanges</a> drawn from them. This ticket is one dated, fully captured example of the shape they take.</p>\n</div>\n<div class=\"grid grid-cols-1 lg:grid-cols-12 gap-6 items-start\">\n<div class=\"lg:col-span-5 space-y-4\">\n<div class=\"bg-gray-950 border border-amber-500/30 rounded-2xl p-6 space-y-4\">\n<div class=\"flex items-center justify-between border-b border-gray-800 pb-3\">\n<span class=\"text-xs font-mono text-amber-400 uppercase tracking-widest font-bold\">Support Ticket — Preserved</span>\n<span class=\"text-xs font-mono text-gray-400 bg-gray-900 px-2 py-1 rounded\">HT-2YBP-F7JP-D4VB</span>\n</div>\n<div class=\"space-y-3 font-mono text-xs text-gray-300\">\n<div class=\"grid grid-cols-2 gap-2\">\n<div>\n<span class=\"text-gray-400 block\">Request type</span>\n<span class=\"text-white font-bold\">GDPR Article 15 DSAR</span>\n</div>\n<div>\n<span class=\"text-gray-400 block\">Ticket status</span>\n<span class=\"text-red-400 font-bold\">CLOSED 19 SEP 2026 — NO DATA SUPPLIED</span>\n</div>\n</div>\n<div class=\"grid grid-cols-2 gap-2\">\n<div>\n<span class=\"text-gray-400 block\">Agents in the exchange</span>\n<span class=\"text-amber-300 font-bold\">\"Logen\" (17 Sep), \"Kal\" (19 Sep)</span>\n</div>\n<div>\n<span class=\"text-gray-400 block\">Filed</span>\n<span class=\"text-gray-400\">16 Sep 2026</span>\n</div>\n</div>\n<div>\n<span class=\"text-gray-400 block\">Data requested</span>\n<span class=\"text-white\">Who registered the Web API key linked to this account, and from which IP / device / timestamp</span>\n</div>\n<div>\n<span class=\"text-gray-400 block\">Legal basis cited</span>\n<span class=\"text-white\">GDPR Art. 15 — right of access to personal data</span>\n</div>\n</div>\n<div class=\"bg-red-950/30 border border-red-800/40 rounded-lg p-4 text-[11px] text-red-300 font-mono\">\n<strong class=\"block text-red-400 mb-1\">The legal frame:</strong>\n                                Article 12(3) gives the controller one month from receipt (extendable with reasons). That period had not expired at publication, and this dossier does not assert a deadline breach.\n                                The objection is to the substance: the closing response links to a self-service page but does not show that the four named data categories were produced, and if the controller declines to act, Article 12(4) requires it to state the reasons and the complaint routes. Neither appears in the closing response.\n                            </div>\n</div>\n<div class=\"bg-gray-950 border border-gray-800 rounded-2xl p-6 space-y-3\">\n<span class=\"text-xs font-mono text-cyan-400 uppercase tracking-widest font-bold\">Why this specific data matters</span>\n<p class=\"text-xs text-gray-400 leading-relaxed\">\n                                The Web API key event log is the record that shows whether a third party registered a key using a stolen session cookie —\n                                the mechanism described in the inventory-theft complaints preserved in this dossier's archive.\n                                Disclosing who registered an API key, from which IP, and at what timestamp, would:\n                            </p>\n<ul class=\"text-xs text-gray-400 space-y-2 list-disc pl-4\">\n<li>Allow the victim to compare the API creation IP against their own login history</li>\n<li>Reveal data-centre IPs linked to known phishing / gambling bot infrastructure</li>\n<li>Produce evidence usable in civil or criminal proceedings against the actor</li>\n<li>Show whether the account holder was notified when the key was created</li>\n</ul>\n<div class=\"bg-amber-950/30 border border-amber-700/30 rounded p-3 text-[11px] text-amber-300 font-mono mt-2\">\n<strong>What the record shows:</strong> Valve retains device-level and account-correlation records — its counsel's letter of 1 October 2025 describes them (see Appendix A, Evidence Memorandum — Source 1).\n                                In ticket HT-2YBP-F7JP-D4VB the same class of records was requested by the data subject and the ticket was closed with a referral to a self-service page that the data subject reported did not contain them.\n                                Whether that refusal is lawful is a question for the supervisory authority; the effect is that the person the data concerns does not get it.\n                            </div>\n</div>\n</div>\n<div class=\"lg:col-span-7 space-y-4\">\n<div class=\"bg-gray-950 border border-gray-800 rounded-2xl p-6 space-y-4\">\n<div class=\"flex items-center gap-3 border-b border-gray-800 pb-3\">\n<span class=\"w-2.5 h-2.5 rounded-full bg-red-500\"></span>\n<span class=\"text-xs font-mono text-gray-300 uppercase tracking-widest font-bold\">The exchange — four messages, three days</span>\n</div>\n<p class=\"text-xs text-gray-400 leading-relaxed\">\n                                Two Steam Support agents replied under first names shown on the ticket: \"Logen\" on 17 September and \"Kal\" on 19 September. Both referred the requester to the Account Data page. Nothing on the ticket shows whether the request reached Valve's Privacy Team or Data Protection Officer, and the dossier does not assert who the agents are, what their roles are, or how the ticket was routed.\n                            </p>\n<div class=\"grid grid-cols-1 md:grid-cols-3 gap-3\">\n<div class=\"bg-gray-900 rounded-lg p-3 text-center\">\n<div class=\"text-2xl font-black text-red-400 font-mono\">16 SEP</div>\n<div class=\"text-xs text-gray-400 mt-1\">Art. 15 request filed with four named data categories</div>\n</div>\n<div class=\"bg-gray-900 rounded-lg p-3 text-center\">\n<div class=\"text-2xl font-black text-amber-400 font-mono\">17–18 SEP</div>\n<div class=\"text-xs text-gray-400 mt-1\">Referral to Account Data; requester asks for DPO escalation</div>\n</div>\n<div class=\"bg-gray-900 rounded-lg p-3 text-center\">\n<div class=\"text-2xl font-black text-cyan-400 font-mono\">19 SEP</div>\n<div class=\"text-xs text-gray-400 mt-1\">Ticket closed with the same referral; no data, no stated basis</div>\n</div>\n</div>\n</div>\n<div class=\"bg-gray-950 border border-gray-800 rounded-2xl p-6 space-y-3\">\n<span class=\"text-xs font-mono text-blue-400 uppercase tracking-widest font-bold\">What Article 15 GDPR explicitly entitles the subject to</span>\n<div class=\"space-y-2 text-xs font-mono text-gray-300\">\n<div class=\"flex gap-3 items-start\">\n<span class=\"text-blue-400 shrink-0\">Art.15(1)(a)</span>\n<span>Processing purposes — why Valve holds the data</span>\n</div>\n<div class=\"flex gap-3 items-start\">\n<span class=\"text-blue-400 shrink-0\">Art.15(1)(b)</span>\n<span>Categories of data — what Valve holds</span>\n</div>\n<div class=\"flex gap-3 items-start\">\n<span class=\"text-blue-400 shrink-0\">Art.15(1)(c)</span>\n<span>Recipients or categories of recipients — <strong class=\"text-white\">who received the data (e.g., API key holder)</strong></span>\n</div>\n<div class=\"flex gap-3 items-start\">\n<span class=\"text-blue-400 shrink-0\">Art.15(1)(d)</span>\n<span>Retention period or criteria for determining it</span>\n</div>\n<div class=\"flex gap-3 items-start\">\n<span class=\"text-blue-400 shrink-0\">Art.15(3)</span>\n<span>A copy of the personal data undergoing processing — i.e., the API-key log itself</span>\n</div>\n<div class=\"flex gap-3 items-start bg-red-950/30 border border-red-800/30 rounded p-2 mt-2\">\n<span class=\"text-red-400 shrink-0 font-bold\">ART.12(3)</span>\n<span class=\"text-red-300\">Response required within <strong>one month</strong> of receipt; an extension must be communicated within that month. The period had not expired at publication. <strong>Art. 12(4):</strong> if the controller does not act, it must state why and inform the subject of the complaint routes.</span>\n</div>\n</div>\n</div>\n<div class=\"bg-gray-950 border border-emerald-700/30 rounded-2xl p-5 space-y-3\">\n<span class=\"text-xs font-mono text-emerald-400 uppercase tracking-widest font-bold\">Regulatory complaint pathway — for any user</span>\n<p class=\"text-xs text-gray-400\">\n                                Any user who submitted an Article 15 GDPR request to Valve and received no compliant response (or a template refusal without data) may file a complaint\n                                with the supervisory authority in their EU/EEA member state.\n                                Valve's EU establishment is Valve GmbH in Hamburg, so the lead supervisory authority for cross-border complaints is the <strong class=\"text-white\">Hamburgische Beauftragte für Datenschutz und Informationsfreiheit (HmbBfDI)</strong>. (Valve's Article 27 representative is also located in Hamburg; a representative's address does not by itself determine the competent authority.) A complaint may also be filed with the authority of the complainant's own member state under Article 77.\n                            </p>\n<div class=\"flex flex-wrap gap-2 text-[11px] font-mono\">\n<a class=\"bg-emerald-900/40 border border-emerald-700/40 text-emerald-300 px-3 py-1.5 rounded hover:bg-emerald-900/60 transition-colors\" href=\"https://datenschutz.hamburg.de/beschwerde\" rel=\"noopener noreferrer\" target=\"_blank\">\n                                    HmbBfDI complaint form ↗\n                                </a>\n<a class=\"bg-gray-900 border border-gray-700 text-gray-300 px-3 py-1.5 rounded hover:border-gray-500 transition-colors\" href=\"https://eur-lex.europa.eu/eli/reg/2016/679/oj/eng\" rel=\"noopener noreferrer\" target=\"_blank\">\n                                    GDPR text (Art. 12, 15, 77) ↗\n                                </a> <a class=\"archived-link\" href=\"https://web.archive.org/web/20260920024236/https://eur-lex.europa.eu/eli/reg/2016/679/oj/eng\" rel=\"noopener noreferrer\" target=\"_blank\">archived 2026-09-20 ↗</a>\n<a class=\"bg-gray-900 border border-gray-700 text-gray-300 px-3 py-1.5 rounded hover:border-gray-500 transition-colors\" href=\"https://edpb.europa.eu\" rel=\"noopener noreferrer\" target=\"_blank\">\n                                    EDPB guidelines ↗\n                                </a>\n</div>\n<p class=\"text-xs text-gray-400 font-mono\">\n                                Ticket reference for any complaint: <strong class=\"text-amber-400\">HT-2YBP-F7JP-D4VB</strong> — preserved in this dossier as a documented instance.\n                            </p>\n</div>\n</div>\n</div>\n<div class=\"evidence-conclusion\">\n<div>\n<span class=\"case-kicker\">One documented instance</span>\n<h3>The records exist; the data subject did not receive them.</h3>\n<p>\n                            Valve's counsel described device-level correlation records in a letter of 1 October 2025. On 19 September 2026 an Article 15 request for the same class of records was closed with a referral to a self-service page the requester reported did not contain them, without a stated legal basis.\n                            Ticket HT-2YBP-F7JP-D4VB is one documented instance; whether it reflects a wider practice is a question for the supervisory authority, which can ask Valve for its handling records.\n                        </p>\n</div>\n<div class=\"case-legal-note\">\n<span class=\"case-kicker\">GDPR Articles 12, 15, 77 / Supervisory authority</span>\n<p>\n                            A complaint under Articles 12 and 15 can be lodged directly with the relevant supervisory authority without cost (Article 77).\n                            The authority may impose corrective measures including orders to comply with the access request, and fines under Article 83(5)(b) for infringements of data-subject rights.\n                            Preserving the original ticket reference and any Valve response (or its absence) strengthens a complaint.\n                        </p>\n<a class=\"case-text-link\" href=\"#dsar-playbook\">See the DSAR template →</a>\n</div>\n</div>\n</div>\n</section>"
  },
  "original_content_sha256": "fa6319ee9d4f0391481c70248e0cbd46f6dd8021a47e6975146982e68ca221cb",
  "author_pseudonym": "Agent Viola",
  "schema": "phishdestroy.macro-fact.v1",
  "language": "en",
  "aggregator": "PhishDestroy",
  "exports": {
    "pdf": "/steam_dossier/exports/agent-protocol/files/en/steam_dossier_section_18_agent_viola.pdf",
    "json": "/steam_dossier/exports/agent-protocol/files/en/steam_dossier_section_18_agent_viola.json",
    "signature": "/steam_dossier/exports/agent-protocol/files/en/steam_dossier_section_18_agent_viola.json.asc"
  },
  "integrity": {
    "signed_object": "steam_dossier_section_18_agent_viola.json",
    "signature_file": "steam_dossier_section_18_agent_viola.json.asc",
    "signing_key_fingerprint": "129FC7F39C40C69D2EF3C329BFCF9E8DD295EE01",
    "scope": "Exact JSON bytes, including macro-fact author and corresponding PDF SHA-256. PhishDestroy is the integrity signer; original evidence attribution is unchanged."
  },
  "pdf": {
    "filename": "steam_dossier_section_18_agent_viola.pdf",
    "sha256": "949d07f6cee83fd7579cdc6a1879791489a67ef453ebad127dc418e15a163533",
    "pages": 6
  }
}
