5 ms·
Is there legal precedent for "sharing" when the only entity you're providing the data to is your owner? Presumably if I bought WhatsApp, I would legally be all
by mikeokner 9y ago
Is there legal precedent for "sharing" when the only entity you're providing the data to is your owner? Presumably if I bought WhatsApp, I would legally be allowed to query some database for someone's phone number if I so chose because I now own the database.
- teekert 9y agoThis piece is a nice argument for what FB/WA did wrong: https://www.engadget.com/2016/08/27/privacy-groups-call-foul-on-whatsapp-sharing-data-with-facebook/ https://www.engadget.com/2016/08/27/privacy-groups-call-foul...
- Brakenshire 9y agoYou do have to get specific permission to use data for a specific purpose under the GDPR. For instance, there are approved forms to ask customers for permission to add them to a mailing list. In that case, whether or not the company has the data stored somewhere is immaterial if it does not have the correct permission to use it for mailing.
- soziawa 9y agoYou could but you'd have to tell the users in the terms of service. If you tell them that you won't query the database and then go on and decide to do so anyways you'd get sued. With WhatsApp having a quasi monopoly on messaging it's difficult for the to change the terms of service without giving their opponents the argument that the change was forced.
- mikeokner 9y agoSure, that makes sense to me. But this seems more like "the company said it wouldn't allow anyone else to query the database" before I bought it. Now that I'm owner, do I still count as "anyone else?" I'd argue not. Edit: that's from a US perspective. Sounds like France (& the EU) put additional restrictions on how personal data may be used even after it's voluntarily provided.
- shakna 9y ago> on how personal data may be used even after it's voluntarily provided. That feels wrong. The personal data was provided under a contract. Now, you can pretend you're Vader and change your deal, but people can still attack you for changing the contract to terms they have not agreed on. And so far in court, long lengthy legalese Terms & Conditions haven't always held up to scrutiny, and nor has any contract that states "we can change these terms at any time". [0] Just buying the database doesn't let you do anything with it - you just bought the responsibility of fulfilling the contract. [0] One example: https://law.justia.com/cases/federal/appellate-courts/ca2/11-1311/11-1311-2012-09-07.html https://law.justia.com/cases/federal/appellate-courts/ca2/11...
- freeflight 9y ago> And so far in court, long lengthy legalese Terms & Conditions haven't always held up to scrutiny, and nor has any contract that states "we can change these terms at any time". [0] Especially not in the EU, many ToS that are completely legal in the US wouldn't see the light of the day in the EU due to consumer protection rights.
- freeflight 9y ago> how personal data may be used even after it's voluntarily provided It was voluntarily provided under the requirement that said data will not be shared with third parties for commercial purposes. Once that restriction does not apply anymore, as the data ends up being shared with third parties for commercial purposes, neither does your right to use that "voluntarily provided data". Imho private information should be handled like a license; Sure I can allow you to use it, but if you break against the rules we agreed on I reserve the right to revoke your license to use my personal information because at the end of the day it's still MY information.
- geofft 9y ago> Sure, that makes sense to me. But this seems more like "the company said it wouldn't allow anyone else to query the database" before I bought it. Now that I'm owner, do I still count as "anyone else?" I'd argue not. I don't think the change of ownership matters. If I say that I won't allow anyone else to query the database, that statement isn't about restricting others from wandering into my offices and pulling up a Python prompt. What I'm really saying is that I commit to not querying the data with the purpose of sending it to others. Maybe that means I commit to not building something to query it for them; maybe it means I commit to not running a mysqld that accepts connections from them; maybe it means I commit to not doing a database dump and sending it, but in all cases, I'm the one not doing a thing. So, the fact that you "own" the data doesn't mean you have the right to use it how you want - because if you could in fact use it how you want, you could send it to anyone you want. And if you transfer it, e.g., by selling your company, you don't transfer rights that you never had.
- deleted 9y ago[deleted]
- seszett 9y ago> I now own the database. You might own the database, but you will never own the personal data that is stored in it. And in France (and in the near future the whole EU with GDPR) this personal data has a specific set of allowed uses (explicit or implicit when the user provided the data) attached to it, that you cannot change without asking the owner of the data (the user). So you own the database, but you cannot use the personal data inside for purposes that were not allowed by the user when they provided it.
- mikeokner 9y agoSeems like in that case it should be Facebook being reprimanded if they do something with the data that violates the original terms of use. "Sharing" is a bit misleading because as soon as Facebook acquired WhatsApp, they became the legal owners of the user database and data insofar as anyone can "own" user data. WhatsApp is Facebook.
- cbcoutinho 9y agoBut I think that's the point, WhatsApp doesn't own the data, and that carries over to Facebook. From what I gather, what they own is the database schema and whatever business logic is specific to WA/FB, and they 'lease' the data from users to populate their databases.
- eicnix 9y agoIn the EU you would need the explicit permission of the user to share their data with the new parent company. Which isn't a huge issue since most users will accept any data privacy declaration.
- beberlei 9y agoPer European Privacy Law, you only own the data for the specific use-cases that you asked it for in your terms of use / privacy policy. I agreed to that when signing up. If you change that in the future, you have to ask for my consent again. If I deny, then you cannot use my data for your new use-case.
- cmurf 9y agoIs the revision opt in (express permission required, by default you do not agree)? Or is it opt out (by default you agree, unless you expressly refuse)? In the U.S. terms of service are usually the latter. You'll get a notification of revised terms, and you can refuse. But as a consequence every company I'm aware of will then terminate service. Examples include insurance, banks, and (perhaps infamously) iTunes which had more revisions than the average number of needles on a pine tree. Yes you can send them a note saying you do not agree to their new terms, and they'll send you a note your account is closed.
- JorgeGT 9y agoFrom EU Regulation 2016/679: (http://eur-lex.europa.eu/legal-content/EN/TXT/PDF/?uri=CELEX:32016R0679&from=EN http://eur-lex.europa.eu/legal-content/EN/TXT/PDF/?uri=CELEX...) (32) Consent should be given by a clear affirmative act establishing a freely given, specific, informed and unambiguous indication of the data subject's agreement to the processing of personal data relating to him or her, such as by a written statement, including by electronic means, or an oral statement. This could include ticking a box when visiting an internet website, choosing technical settings for information society services or another statement or conduct which clearly indicates in this context the data subject's acceptance of the proposed processing of his or her personal data. Silence, pre-ticked boxes or inactivity should not therefore constitute consent. Consent should cover all processing activities carried out for the same purpose or purposes. When the processing has multiple purposes, consent should be given for all of them. If the data subject's consent is to be given following a request by electronic means, the request must be clear, concise and not unnecessarily disruptive to the use of the service for which it is provided. (42) Where processing is based on the data subject's consent, the controller should be able to demonstrate that the data subject has given consent to the processing operation.
- vkou 9y ago> Presumably if I bought WhatsApp, I would legally be allowed to query some database for someone's phone number if I so chose because I now own the database. It's not your data. It's your users' data. So no, you may own the database, but you do not own the data.
- briandear 9y agoI don't understand how users own their own data. That doesn't make any sense. Where does that idea come from?
- fatwa 9y agoCommon sense?
- PeterisP 9y agoThe legal concept is that despite having the data in your physical possession and control, you're not allowed to do whatever you want with it, and you have to ask the user's permission for many specific use cases. This means that for a colloquial understanding of "owning data", you don't own it (since you can't do what you want) but they do (since they can limit the uses to what they want).
- vkou 9y agoThe same way that my bank does not own the contents of my savings account... Even if it is allowed to use that money (in highly limited and regulated ways) to, say, issue loans. You don't own your users' data. Your users do. You may be allowed to use it in highly limited and regulated ways.
- kaybe 9y agoPhotography laws are similar. I cannot just see you on the street, shove a camera in your face and take your portrait and then proceed to do whatever I want with the image. The resulting image is property of both the photographer and the subject. (Exceptions for people in the background of landscape/architecture etc and 'people of public interest' such as politicians.)