8 ms·
No need to invent new jurisprudence - if the location data can be used to identify an individual, it is personal data under the GDPR and enjoys all the rights a
by jmickey 8y ago
No need to invent new jurisprudence - if the location data can be used to identify an individual, it is personal data under the GDPR and enjoys all the rights and protections enabled by the regulation.
- schaefer 8y agosome of us are in the USA, (including article's author). The privacy realities we face are drastically different than in the EU.
- crankylinuxuser 8y agoThat's fine for you Europeans under GDPR. (Sure, there's careouts for weird exceptions.) That doesn't do diddly for us US citizens living in the US. Our data policy is "we will sell your data, too bad so sad".
- jlarocco 8y agoIt is kind of our own fault, though. Judging by the sentiment on HN when GDPR was coming into effect, if something like it came up for a vote in the US, a lot of HN users and other tech people would vote against it. There was no shortage of angry geeks posting articles about their service turning away EU users rather than complying with GDPR.
- thisisweirdok 8y agoI would hope that those people would at this point realize that the upset about the GDPR was completely overblown?
- rock_hard 8y agoThis is a double edged sword...in the EU it doesn't matter because they didn't have a internet economy to begin with but here in the US a lot is at stake. So if you want better privacy laws in the US then they have to be much more clever than GDPR to not destroy the economy and global competitiveness! BTW: Personally I think it is possible to do better than GDPR here in the US.
- wahern 8y agoAs a percentage of GDP the so-called "digital economy" isn't much less in the EU than in the U.S. See, e.g., https://www.imf.org/~/media/Files/Publications/PP/2018/022818MeasuringDigitalEconomy.ashx https://www.imf.org/~/media/Files/Publications/PP/2018/02281... Excluding the U.K. and Ireland (tax haven) the difference between the EU and U.S. is greater, but (eyeballing) only on the order of 30-50%--e.g. ~4% vs ~6%. What's more surprising is how small the share of GDP is the digital economy in the U.S. That said, "digital economy" may be a poor proxy for understanding the impact of privacy regulations. It's a superset of tech industries, including much more than those parts which broker private information and to that extent would overestimate the impact. OTOH, I presume "digital economy" excludes large parts of non-tech industries (i.e. traditional sales and marketing companies, TV and newspaper ads, etc) and thus underestimates the potential impact.
- rock_hard 8y agoI guess it depends on your definition of digital economy...I was referring to companies of the size and influence like Apple, Amazon, Google, Facebook, Microsoft, Oracle, Airbnb, Tesla, SpaceX, etc
- Tsubasachan 8y agoIf you work in tech or marketing your salary comes from eroding privacy. There is a lot of money at stake here and people don't vote against their interests. Europeans aren't inherently better: if Facebook and Google were companies founded in Germany or France who knows if GDPR would exist.
- jlarocco 8y agoI don't know if I'd say that. "Tech" is a really big field, and most areas don't have anything to do with eroding privacy. Unfortunately, many areas that would have been "safe" years ago, like games and standalone applications, are moving in the direction of violating privacy by phoning home and sending "telemetry" data, but there's still a lot of areas that are good.
- crankylinuxuser 8y agoI'm a sysad for a small company. We have an on-prem solution and a social media app. We don't sell our data. We don't trade it. And we adhere to a fedramp medium (in spirit), even though the social media site wasn't checked for that. Users have control over their profile, and we admins cant even read it (unless we read raw DB, and we dont). And deletion requests entail in zeroing out all user's data. The next day, zeroed data is then purged completely. Seriously, companies can do this right. And I work for one that absolutely does this right.
- irrational 8y agoI work in tech, but my and my companies work definitely doesn't involve eroding anyone's privacy.
- icebraining 8y agoEuropeans aren't inherently better: if Facebook and Google were companies founded in Germany or France who knows if GDPR would exist. The Data Protection Directive, which the GDPR merely extends and updates, is older than Google and almost as old as the web itself, and was an attempt to unify even older national laws regarding personal data. It's not a reaction to having "lost" the privacy-eroding race.
- dylan604 8y agoWere these people that actively work on projects that depend on this data for their business to remain viable?
- jgalt212 8y agoI don't think it's enough or sufficient to make "bad" actions against the law. It's better and more comprehensive to make it difficult to take "bad" actions and "easy" to take good ones. People break the law all the time, and if you're high enough up the food chain Eric Holder will leave you be.
- kokokokoko 8y agoIn the US it is actually a big deal because data is not a "creative work" so it is not covered by copyright protection. Because of this, black market re-sellers can operate with relative impunity. Most data brokers have a TOS that prohibits the re-selling of their data, but there isn't any copyright protection. For example, if a company has location data, the only way for them to be held liable is for a particular company to prove they obtained that data directly from them. Once the data has reached a minimum of two parties, everyone now has plausible deniability. If this data was under copyright, the original copyright owner would always have a claim and it would be each parties responsibility to prove they had a right to hold and distribute it. The lack of a copyright style concept of original owner allows data to flow freely even if that transfer is violating a specific TOS.
- greglindahl 8y agoYou're trying to use the wrong kind of law for the problem at hand.
- coldtea 8y ago>In the US it is actually a big deal because data is not a "creative work" so it is not covered by copyright protection. It doesn't need (and shouldn't be) "copyrighted". It's enough that the law classifies it as private info, and protects it from any third party without an immediate consent.
- kokokokoko 8y agoAs someone who has worked with a couple data aggregation startups, I find it surprising I am unaware of the laws that classify it as private info(or even the legal definition of what "private info" is). With that said, I am certainly not a lawyer and was never directly involved. Which particular laws are you referring to? Edit: I should mention I am aware of laws preventing the collection of certain types of data. But unaware of laws about possession of that data.
- coldtea 8y ago
- zorga 8y agoThe GDPR doesn't apply to most of the world, it's awful legislation anyway. It's not your data, it's my data about you, I own it, it's in my databases, and if you don't want me to have it, you shouldn't have given it to me freely to begin with.
- nothrabannosir 8y agoI'm afraid you accidentally posted your canned response about the GDPR next to an article that directly refutes it. The opening paragraph of the article: > Nervously, I gave a bounty hunter a phone number. He had offered to geolocate a phone for me, using a shady, overlooked service intended not for the cops, but for private individuals and businesses. Armed with just the number and a few hundred dollars, he said he could find the current location of most phones in the United States. Do you own a phone?
- zorga 8y agoAnd? That doesn't refute anything I said. And no it wasn't a canned response.
- rypskar 8y ago> It's not your data, it's my data about you, I own it, it's in my databases And there you have the main difference between European and US laws and mindset. Because it is my data, you are only allowed to store it in your database as long as I say you can, and you can only use it for what I have agree on. Since it is my data you cannot give or sell it to anyone else
- zorga 8y agoNo, it isn't; the product of my labor belongs to me. Whether it's photographs of public spaces or data logged in public spaces, the data I put in the labor to collect belongs to me. If I write a book about you, it belongs to me, it doesn't matter that it contains data about you: you don't own everything that happens to be about you.
- DoctorOetker 8y agorelevant clip: https://www.youtube.com/watch?v=GOkFHTGgao8&t=68m36s https://www.youtube.com/watch?v=GOkFHTGgao8&t=68m36s on a more serious note, even if such data is not resold commercially, and even if more detailled surveillance by a real human analyst only occurs when automated red flags are raised, and the system was designed to only allow the analyst access to the detailed data if enough or the right combination of red flags are raised there is a remaining problem: if your job consists of interpreting all day long the details surrounding red flags concerning an individual case by case, and an individual piques your interest (legitimately or not) and if your access to detailed surveillance on this individual expires when the red flags expire (in order to keep the analyst workforce focussed on their job, not their pet theories), then it becomes trivial for the analyst to "tag" an individuall of choice (out of curiousity, fascination) or a previous target (to prolong detailed surveillance): just arrange for an automated red flag concerning this individual to go off! you don't need to guess what types of automated red flags exist since you are constantly handling cases of individuals, and the red flags that were triggered! (Oct 15) A few months back, my sister visited me in the city I live, and at one point she asked if I could use a prepaid sim card that was soon to get expired (16 days later or valid till including Oct 31), I said I don't really need it, but if she couldn't think of anyone else I would probably use it to call some of my more remote friends (I usually text). She remarked it was stupid that she had forgotten to bring the card. I remember asking why she bought it if she didn't use it?? But she said something along the lines of "I'm not really sure", I had the impression she didn't buy it, but in turn somebody had given her the card... I also said it's OK if she gave it to someone else. At that point I assumed that was what would happen, and simply forgot about her mentioning the SIM card. Here in Belgium, the mail is delivered "D+1", so pretty quickly.. (Oct 24) Nine days after my sister visited me, I am staring out my living room out on the street, and I see the postman going through the street and crossing to enter the apartment building I am in. After a while I notice him at the end of the street, so he already passed. I go down to check the mail, and there's a notification card, telling me about a letter with insufficient postage, that I wasn't home, and that I can go to the post office if I wish to pay and receive it nonetheless... Here the weight for a single post stamp is 50 grams. So thats quite a letter. I had forgotten about the SIM card and started fantasizing about a (long) loveletter from N (a girl from the past). Obviouly I go to the post office, I say I want to pay for the postage, and I ask who the letter was from. The employee looks at me as if I don't understand the postage system and says: "If it had a return adress, it would have gone straight back to the sender. So the envellope did not state a sender, in which case the recipient can elect to pay for sufficient postage." I suddenly had a flashback to elementary school, and these once-deeply-studied facts long ignored immediately sprang alive. "Of course!" I said... I ask when I will receive it, and he says it depends if I want to go pick it up today at the main post depot, or if I wish to receive it by mail, and in that case in just a few days. I tell him they can send it by mail. From then on, the first thing I do upon awaking, is run down to get "N's loveletter". However no letter marked with "insufficient postage" stamp arrives. (Nov 1) The SIM card expires. I distinctly remember one day noticing it had already been exactly 2 weeks and I still didn't get the letter. That same day (Nov 7) I read in the papers that the national postage system starts a strike, and mail already underway will be on tine, but new mail may get delayed. The strike is still ongoing about 2 days later, when I finally receive the letter marked with the "insufficient postage" stamp. Immediate dissapointment: it's not from N but from my sister, and it's the SIM card. Immediately more inconsistencies pop up: 1) my sister did of course as always state her name and return address on the letter 2) the whole envellope, greeting card, unopend prepaid SIM card weigh less than 20 grams, let alone 50 grams! So I fire up my abductive reasoning skills. Of the hundreds of letters I receive: What is the probability or how often do I receive a letter that is insufficiently stamped? it was my very first such letter! Moreover what is the probability that a letter is incorrectly marked with "insufficient postage"? Moreover what is the probability that a letter with return address is sent on to the recipient if it has "insufficient postage" ? Those co-incident probabilities are very low indeed. And it is also the first letter I receive that contains a prepaid SIM card. Bingo! obviously authorities do not want people mailing unused prepaid SIM cards! That may re-anonymize any over-the-counter de-anonymization, like paying with card! Probably criminals (perhaps also investigative journalists) create demand for clean SIM cards, where the cleanliness to the buyer is illustrated by the prepaid SIM card package still being unopened... So the motive to detect and intercept SIM cards in mail exists. Now I obviously get curious, how did they detect this in the benign case of my sister sending me her almost expiring SIM card? The actual SIM card is to be broken out of the larger card, which states the PIN and PUK code... This larger card has the same dimensions as credit/smart cards... They both contain a chip under the contacts... Some credit cards contain RFID for contactless payments... So I postulate abductively that the larger card with PIN and PUK code contains an RFID coil, and when breaking out the SIM card, it's connection to the coil is broken! Are these RFID tags visible with off the shelf commercial RFID readers? or are their also "secret" tags that the readers refuse to identify by design? If so, and someone finds a way to detect this secret class of RFID tags, then we may find more of these in unexpected places/locations... I will see my sister back in a few weeks, and she will obviously ask if I made use of the SIM card. Now I hate lying, and I also hate dissappointing people when something is not really my fault, since the unjustified inssuficient postage delay caused the card to expire. Then I will ask if she actually bought the card herself, was given the card, or if she somehow found the card, for example mysteriously in her mail box... Everybody has their own SIM card, nobody really needs an extra one, and my sister is not very sociable, she wouldn't know who to give a surplus card about to expire. So if an analyst wanted to tag me (or her), it is entirely predictable she would ask her younger brother if he perhaps could use it! And that she would send it by mail (since we live in different cities). Any future analyst will come to believe this red flag in the record is genuine, and not a placed one! It is entirely conceivable that there are some very unlucky people with a boatload of flags on their record, which convince the new analyst that this individual needs more tracking even if the last flag expires... so they place a new flag! and after this analyst's second term of observing the individual, he gives up, ... until next time a new analyst observes the person's record, is amazed with the richly filled flags in the past, and perhaps does the same.... Now apart from being overzealous and having pet theories, what other motivation could the analyst have to bypass the agency focus mechanism by placing tags? What about pure boredom? The first time you investigate a bunch of neo-nazi scum you are all excited, and the first time you investigate some angry muslim lowlife, you are similarily excited... but after a few weeks/months/years you realize there is nothing exciting, just the endless stream of boring as hell hitler greetings, and the boring as hell angry muslim's communicating things like "the infidel whore!" etc... It's like working at the zoo, when you are small it seems awesome, and the public part of the zoo is nice, but when you actually work there, the non-public part of the zoo is just grim walls, and shovelling different kinds of excrement. Of course the analyst / zoo employee tries to make quick work of the shoveling part, so he can spend some time checking out the lizards or whatever kind of people really fascinate him in an entertaining way!!
- closeparen 8y agoThe subject’s location is necessary for the performance of the bond. As long as it’s clearly disclosed, there should be no problem signing over those rights as part of the contract. If there is, the bondsman can just make you wear a tracking anklet.