4 ms·
Unless I'm very wrong about the technical implementation, the data that the bank has is just the store where I shopped (merchant, card terminal) and the amount.
by ACS_Solver 7y ago
Unless I'm very wrong about the technical implementation, the data that the bank has is just the store where I shopped (merchant, card terminal) and the amount. They do not have data on what I bought, as in the data that's on the store's receipt. The store, on the other hand, only has the card number and not my name. This is where I see the need for legal protections. The store should not be allowed to keep that receipt info (item breakdown) for more than X days. They should not be allowed to transmit it at all. The bank should likewise not be allowed to engage in any data mining or forward that information anywhere.
As for the broader privacy implication, that is something I would hope a national cryptocurrency addresses. While cash is anonymous, anonymity is not a property exclusive to cash. From my point of view, everything sucks about cash except anonymity - so, by a software analogy, it makes more sense to port anonymity to cashless systems than to maintain a legacy cash system.
- distances 7y ago> Unless I'm very wrong about the technical implementation, the data that the bank has is just the store where I shopped (merchant, card terminal) and the amount. They do not have data on what I bought, as in the data that's on the store's receipt. You're partly correct, partly wrong -- as far as I know the payment provider doesn't have/store this data but can request it from merchants. Merchants have to opt in, but by now I assume all the large ones are in, at least. These APIs can be used to get purchase details such as item names, quantities, and tax rates. See e.g. https://developer.visa.com/capabilities/visa-cardholder-purchase-inquiry https://developer.visa.com/capabilities/visa-cardholder-purc...
- ACS_Solver 7y agoSome of the language there indicates that's primarily with the US in mind, which it probably is indeed. I think Sweden's different. I've read the data usage policy of my local grocery store chains (those are quite detailed thanks to GDPR), and they indicate that no such data is shared unless I'm in a loyalty program. Joining their loyalty program counts as consent for a lot of data manipulation, but as long as I'm just purchasing goods, they're not allowed to collect or store any personally identifiable information. Also worth noting that bank privacy is protected by law, and it's a criminal offense for the bank to violate that by, for instance, telling a marketing company where I shop. While not perfect, I'm fairly comfortable with this level of legal protection for my data.
- distances 7y agoI know for a fact that these APIs (in general, not necessarily this exact VISA API) are starting to be used in Europe's privacy champion, Germany. I do believe that they can be only used for customer service enhancements (such as electronic receipt service or expense tracking), and are not freely available for third parties. I'm not an expert on the surrounding legislation though so that's just my assumption. Just pointing out that links to this data do exist, even if it has strong legal protections/opt-in barriers.
- elhudy 7y agoConsumption data (at least in the US) is tracked by two major vendors: Nielsen and IRI. They have all PoS data as it relates to you, and sell that data for $. The store, distributors, and cpg companies themselves all might buy this data. Usually they sell it aggregated for reporting purposes but that's not to say they can't break it down to get to your granularity.