11 ms·
It's not your information in the sense of you having any ownership or control over it. It's just information about you. I got information about you by looking t
by 794CD01 9y ago
It's not your information in the sense of you having any ownership or control over it. It's just information about you. I got information about you by looking through your comment history. You cannot make me forget it. Lucky for you, I will anyway in a few minutes, since I am not in the business of selling that kind of information and thus don't really care.
- nostrademons 9y agoWhile what you say is factually true, does anyone else find it morally repugnant? The idea that information like your genetic code, behavioral data, photos of your likeliness, etc. might be owned by someone else strikes me as both slightly ridiculous and incredibly dehumanizing.
- zAy0LfpBZLC8mAC 9y agoWhich is precisely why this is handled completely differently in the EU. Essentially, data about you (personally identifiable information) is your data, people generally may not store or distribute it without explicit consent, and generally you may revoke consent at any time. There are exceptions and the details are complicated, of course, but the fundamental principle is much more sensible.
- sova 9y agoWow. This is great! US Privacy Laws would benefit to be at least this strong
- spookthesunset 9y agoIts good as a person, but it is a pain in the ass for companies. Things like the domain name used in an email address can be considered PII because if the domain name was your name, that is PII... IP addresses can, in many cases, also be considered PII. Once something is PII, you as a company have to treat that data different--you have to be able to provide that data to the person and you have to be able to delete it. Basically, the overall idea is good (data about you should be owned by you) but mapping that into actual nuts & bolts implementation details is a huge pain in the ass.
- zAy0LfpBZLC8mAC 9y ago> Things like the domain name used in an email address can be considered PII because if the domain name was your name, that is PII... That's ... just wrong. The email address itself, unless it happens to be a role address, is PII. Whether there is a person's name in there doesn't matter. > IP addresses can, in many cases, also be considered PII. Really, no, the address isn't PII, the information about someone's behaviour is. You may store IP addresses as much as you like. You just may not store it as a key that could be used to link information about someone to other information about them. > Basically, the overall idea is good (data about you should be owned by you) but mapping that into actual nuts & bolts implementation details is a huge pain in the ass. I wouldn't say it's always trivial, but it's not really that hard either. The only thing that is really hard is collecting data that you have no justification to collect. If you simply avoid collecting data, none of the other stuff affects you.
- Silhouette 9y agoThe only thing that is really hard is collecting data that you have no justification to collect. If you simply avoid collecting data, none of the other stuff affects you. Unfortunately, since our modern digital world works with data, that particular tautology is next to useless. With my small business hat on, I'm deeply concerned about the real world implications of the GDPR next year, even as with my privacy advocate hat on I'm happy that the kinds of big data-hoarding companies that cause most of the real problems are going to face more meaningful regulation.
- spiznnx 9y agoPII just stands for personally identifying information. If it identifies you, it is PII. Even if it isn't linked to any behavioral data explicitly, the fact that its in your DB means they are associated with you. Thus email and IP are PII.
- zAy0LfpBZLC8mAC 9y agoNo, if it is in your DB because it gets written to that DB as a result of them being associated with you, then that is PII, prescisely because that is information about them being associeted with you. If you use an RNG to generate IP addresses, that does not represent any information about any person, hence no PII, even if it is in fact the IP address of a person that is protected under the relevant regulation.
- Silhouette 9y agoThat seems to be somewhat overstating the current position under EU data protection laws, though some member states already go further, and with the introduction of the GDPR next year the situation across the EU will move closer to what you describe.
- zAy0LfpBZLC8mAC 9y agoYes, it's not all the unified across countries yet, but the basic principle still generally aplies, in contrast to the US model of "if you happen to have some information about someone else, good for you!", which then only has exceptions for medical information and stuff like that.
- chias 9y agoAre you suggesting that it would be better if an entity should "own" / be in control of all information about it? I'm not trying to straw-man your argument, but I can't find any other self-consistent scenario in which what you describe as morally repugnant, ridiculous and dehumanizing is "solved". Assuming that is what you meant, consider: Equifax's CEO owns all information about Equifax, looks at all this negative press recently and decides it should be scrubbed from the Internet / all publications / etc. If you meant it only to apply to people, lets play the Godwin's Law card and suggest that Hitler (or his descendants) wishes to scrub all information about the holocaust, etc. I think that scenario is far, far worse.
- nostrademons 9y agoIt's possible to draw a distinction between corporations and people, Hobby-Lobby notwithstanding. You could argue, self-consistently, that people have a right to the information about them, while corporations (as a legal fiction) have no such right. In your example, Equifax's CEO would have no recourse to negative press about Equifax, but he would have recourse to negative information about himself, which he kinda does under existing libel & slander laws, though truth is an absolute defense for those. The EU operates under similar provisions, which as an ex-Googler and tech entrepreneur I find pretty annoying, but as a person find pretty encouraging. (There are issues even under this distinction that are problematic: if you commit a crime, does the public have a right to know? What if your crime puts them at risk? If you have a reputation for screwing your business partners over, should future business partners have a right to seek this out? But at the same time, there are huge negative externalities to not being able to control this information. If a company has false information on you - as happens pretty frequently - do they have a right to sell it to so many parties that correcting it becomes impossible?)
- c3534l 9y agoI can't imagine it'd be all that different from existing laws on using the "likeness" of a person in movies, TV, or advertising. All you'd have to do is extend that list to third-party financial institutions and on the non-public-facing side of advertising.
- dredmorbius 9y ago
- bllguo 9y agoHonestly, no. Because the flip side of that stance is that all information that has anything to do with me belongs solely to me. That just seems...naive? Unrealistic? I certainly don't find it morally repugnant or dehumanizing that someone can take a picture of me and keep it. And that's probably the mildest counterexample... IMO it's only a problem if I did not give away that information. Thing is, we give away a lot of data about ourselves.
- nostrademons 9y agoThere's an excluded-middle fallacy here somewhere. I don't really have a problem if I end up in the background of someone's family photo and then they stick it in an album or on a hard disk somewhere. I'd have a pretty big problem if someone snapped a photo of me in a public place and then sold it to a white supremacist magazine as "the face of minorities taking over this country". We'd have an even bigger problem if there was somebody out there who had hacked every security camera in the world and was collecting images to train facial recognition for a fleet of killer drones who would eliminate all his adversaries. These situations are not the same. Most people have no problem with the first. Most people would be pretty terrified of the last.
- aeorgnoieang 9y agoThere might be an excluded-middle fallacy here somewhere but you haven't provided any clues as to its location. But I think I get the gist of the thing you're pointing at, but surely you can understand why are other people would be wary of deciding what exactly is problematic in this regard via legislation, police, courts, etc., particularly as they exist today.
- kelnos 9y ago> IMO it's only a problem if I did not give away that information. Thing is, we give away a lot of data about ourselves. Sure, and why is it so ridiculous to expect that I might change my mind about certain types of information, when given to a corporation, and want them to delete that information? Why shouldn't I have the right to, say, tell a company with sensitive financial data about me to delete it and terminate my relationship with them? If I can't do that, then I'm at their mercy not to sell that data, be acquired and have the data used in new ways that I did not authorize by the new owner, or be compromised and have that data in the hands of parties that would misuse it. We're not talking about censoring obviously public information, here, or even allowing people to hide when they've done something newsworthy. We're talking about controlling the flow of, and access to, private, personally-identifying information.
- baddox 9y agoI don’t find all of that inherently morally repugnant. I own several photographs of other people, for instance. I think it’s clear that you’re really talking about the bad things that can happen when a large entity (probably a government or large corporation) gets a large amount of personal data. I don’t disagree that there are many bad things such an entity can do, but I certainly don’t therefore intuit that anyone possessing someone else’s personal information or likeness is inherently morally repugnant, ridiculous, or dehumanizing.
- astura 9y agoWell, like a lot of things, it's a balancing act. If we say "nobody is allowed to keep information about other people ever," that's clearly a huge reduction in freedom. Americans generally like freedom even if it brings some negative stuff with it. (Think The KKK - they would be flat out illegal in some countries but in America they are protected under the law) Some people may say it's morally repugnant to restrict private entities from writing down information they happen to know about other people. If I write in my diary "HN user nostrademons said XXX" should HN user nostrademons own that information just because my diary might be stolen? Right now how we balance it is companies are allowed to collect this information all they want and look at it themselves all they want. BUT it can only be accessed by a third party with your permission (you give a bank permission when you open an account, your landlord when they run a credit check, your insurance company when you get a quote, etc.) Creditors may send targeted offers to you based on your credit file, but you may opt out (or in) at any time. (you can do it here: https://www.optoutprescreen.com/ https://www.optoutprescreen.com/). You can access your own file for free yearly as well as whenever you were denied something as a result of what's on your file(s). You have the right to dispute the information in your file if it's inaccurate. Creditors are required to disclose to you certain information that they used to make their decisions. You have the right to freeze your reports so nobody can access them.
- closeparen 9y ago>does anyone else find it morally repugnant Yes, the idea that you are entitled to edit other people's memories is as repugnant as it gets.