19 ms·
Surely fingerprinting is PII? It allows for mosaic identification.
by ElvisTrout 6y ago
Surely fingerprinting is PII? It allows for mosaic identification.
- ttt0 6y agoI don't know, are fonts installed on your system PII? Because it can be used for fingerprinting. But I don't know the precise definition, so maybe you're right.
- ska 6y agoPerhaps a reasonable line to draw would be that if the content of the information is enough to fingerprint, the it is PII (regardless if broken into many messages) and the individual data doesn't matter.
- ttt0 6y agoIf we talk purely about "reasonable", I don't think it's even possible to draw any line, besides something obvious like unique user identifiers. It's hard to predict what data can be used for fingerprinting until someone actually does it, just like it's hard to predict what bugs are actually possible to exploit. I could never predict some of those things being used for that and yet here we are. So it can be a cat-and-mouse type of situation. And some of that information is probably legit useful for purposes other than tracking.
- tremon 6y agoIntent matters. If you use the fonts list to identify persons, it's PII.
- lmkg 6y agoFingerprinting doesn't reveal an individual's name or passport number, so it's not PII. That's why PII is not a very useful concept in general, and why claims about privacy safeguards that over-focus on PII should be met with some skepticism. The laws are catching up this in regard. GDPR uses "personal data" and CCPA uses "personal information," both of which more generally refer to data that identifies an individual.
- ttt0 6y agoAt the same time let's not forget it's Google we're talking about. They are even parsing your emails to extract all the data from your transactions. They already have all your personal information, they just need to keep track of you when you're using other websites.