6 ms·
"Some 800 pages came back containing information such as my Facebook “likes”, my photos from Instagram (even after I deleted the associated account)" It's goin
by thestephen 9y ago
"Some 800 pages came back containing information such as my Facebook “likes”, my photos from Instagram (even after I deleted the associated account)"
It's going to be interesting to see how Tinder tackles the 2018 EU General Data Protection Regulation in 2018 and how things will play out in courts and practice.
For example, are you allowed to store information that I have chosen to unlink? Will Tinder have an easy way to export the data without having to settle to long email conversations, as there is a right to data portability? If so, in what format will this data be presented?
- Legogris 9y agoDamn, the right to data portability had completely passed by me. This has the potential of being way more of a headache for existing services than the right to be forgotten. It's great, though - I can't wait to see when this gets tested in court.
- slamdance 9y agoI think worst case (best case?) scenario is that they will 'copy' the data they're not supposed to keep off to another country, maybe anonymize it but otherwise the data will still be there. Its too important - even in anonymized form. Its capable of helping sociologists, medical researchers, advertisers, etc... They don't need to know that "James. T. McLovin' of 123 Happy Lane, went on 15 dates and slept with 3 women, prefers brunettes", but knowing that a "John Doe, M, 27, income of $50k, likes rugby, etc..." is good information to have.
- nicktelford 9y agoThe country the data resides in is irrelevant. If the data is about an EU citizen, that's all that matters. I believe the company in question would also need a legal entity in the EU in order for the EU to prosecute them, as I don't think you can take (e.g.) an American company to an EU court. IANAL though.
- slamdance 9y agoeh. Maybe. If they copy the data to a 3rd party in America (i.e. sell the data a marketing company, for "research" purposes), then the EU can't really go after the marketing company. I'm not saying it's right. I don't see why they couldn't anonymize the data (morally or ethically). But, I don't own a marketing company.
- vidarh 9y agoIf a company based in the EU is transferring the data to a 3rd party in America without appropriate safeguards to ensure said data is treated in a way that complies with EU law, then the transfer itself is unlawful, and the EU can go after the company for that.
- stordoff 9y agoThey don't need to. By selling the data on without ensuring the requirements continue to be met, the original company can be taken to court.
- kuschku 9y agoActually, the EU wrote into the GDPR that they can do exactly that. Any company with data on EU citizen is liable, no matter where they got it from.
- rmc 9y ago> If they copy the data to a 3rd party in America (i.e. sell the data a marketing company, for "research" purposes), then the EU can't really go after the marketing company. No, but they can go after the original company who transfered the data. Remember, under EU law, companies don't own that personal data. It's not theirs to give away.
- vidarh 9y agoYou can take an American company to an EU court assuming the EU court has jurisdiction, and laws can specify that its jurisdiction should extend to actions taken outside the geographical area (I don't know if that is the case here). Without a US court case they'd be dependent on assets or an income stream in the EU to be able to force payment of any fines, though.
- beager 9y ago> and slept with 3 women At first I thought "how would they know that" but it's simple: establish "home" for each of a match pair and identify that both parties' devices are at one or the other "home" during certain hours after matching. In that sense, it's more than just data, it's inference, and that's almost worse as a private company's data could end up libeling you if it leaks!
- dogma1138 9y agoConsidering that they've managed to gather all of the author's data in a short time they would fare pretty darn well, for most companies that is the hard part. The GDPR isn't nearly as scary as people set it out to be, and it gives companies a huge amount of wiggle room.
- ATsch 9y agoCould you give some examples of this wiggle room?
- dogma1138 9y agoThe GDPR replaces the right to be forgotten with the right to erasure. But article 17 also gives the following grounds for refusal: Paragraphs 1 and 2 shall not apply to the extent that processing is necessary: 1) for exercising the right of freedom of expression and information; 2) for compliance with a legal obligation which requires processing by Union or Member State law to which the controller is subject or for the performance of a task carried out in the public interest or in the exercise of official authority vested in the controller; 3) for reasons of public interest in the area of public health in accordance with points (h) and (i) of Article 9(2) as well as Article 9(3); 4) for archiving purposes in the public interest, scientific or historical research purposes or statistical purposes in accordance with Article 89(1) in so far as the right referred to in paragraph 1 is likely to render impossible or seriously impair the achievement of the objectives of that processing; or 5) for the establishment, exercise or defence of legal claims. The first example is effectively a carte blanche to argue nearly any request for refusal in court. The second one allows member states to pretty much tell companies not to delete information, whilst this was set up with compliance in mind, the wording has likely been formatted to also fit other needs such as security and state monitoring. The third one pretty much allows you to keep medical records and insurance information. The forth one is similar to the first with celebrities, public figures and major events in mind (the Gawker clause). The fifth one has been singled out by dating sites and other services such as ride sharing apps as the reason for them to keep data. I am not a lawyer this isn't a legal advice, speak to a legal firm or an auditor for proper advice. I have been working on a few GDPR compliance projects internally for the past year and I've had to speak with quite a few lawyers and they all pretty much said it's actually far better for most companies than the existing framework as long as they can automate data discovery and know where they data comes from and where does it go. You can fight the right to erase the data of a user pretty easily, what you cannot cockup (Art. 15, 20 and 21 of the GDPR primarily) is the ability to disclose what data you have on them and what is it used for which is like I've previously stated the tricky part for most cases. And as far as I can see Tinder pretty aced the tricky part.