16 ms·
Data portability, the forgotten right of GDPR
- mxmilkiib 5y agoRemembering http://dataportability.org http://dataportability.org etc
- djdeutschebahn 5y agoMaybe these two are also relevant: https://github.com/google/data-transfer-project https://github.com/google/data-transfer-project https://datatransferproject.dev/ https://datatransferproject.dev/
- ot1138 5y agoDo you know what happened to them (and/or some of the other companies/projects/initiatives that launched with the same goals)?
- mxmilkiib 5y agoI've a messy collection of links (many of which I need to web.archive.org fix) on https://wiki.thingsandstuff.org/Open_social#DataPortability https://wiki.thingsandstuff.org/Open_social#DataPortability that you might be interested in. Basically, companies thought it more profitable to not put any effort into letting users escape their service (or keep chat federated, etc.) Various threads are still around though.
- ot1138 5y agoWow, this has been around for awhile. Pretty interesting take on this in the link to Brad Fitzpatrick's article from 2007. Your statement about companies being unmotivated to support anything like this rings true to me. It is exactly what I would expect. The question is, what might motivate them.
- mxmilkiib 5y agoProof that it works, that it can lead to customers migrating in. Or some kind of legislation. Main point is for it to work though. Personally, I'm waiting for some combo of SOLID, the Fediverse and Matrix. SOLID is like FOAF and XFN and *dav and etc on steroids, very JS orientated though and not the most friendly of UX.
- tester34 5y agowhere can I download my HN's data?
- notRobot 5y agoYou can't. There's also no easy way to request all profile data deletion, unfortunately. However, they do respond to privacy requests, see: https://news.ycombinator.com/item?id=26959559 https://news.ycombinator.com/item?id=26959559 https://news.ycombinator.com/item?id=26410165 https://news.ycombinator.com/item?id=26410165
- capableweb 5y agoHave you tried emailing hn@ycombinator.com and it got denied? Or what you mean there is no easy way to request the data deletion? AFAIK they don't scrub the comments but if you request it, your username will be replaced with [deleted] for all your comments.
- murphy1312 5y agothat is by no means an easy way. easy would be a button on the profile page for example.
- capableweb 5y agoAh well, I guess "easy" is relative. I'm sure if you send them one email, they'll confirm it with you once within a month and then delete the data. Compare that to Coinbase, which has forms, buttons and seems it's mostly an automated process instead of manual email, but I've tried getting Coinbase to delete my account + data for over 6 months now to no avail, multiple emails back and forward where they confirm the deletion, say it's in progress, I email back after a month and they ask me to confirm the deletion again. So even with a button, doesn't mean the process is easy, and there is also a lot more to consider than just how you initially the request.
- 5y ago
- capableweb 5y agoNot sure it got forgotten, I think members of https://datatransferproject.dev/ https://datatransferproject.dev/ didn't start actively moving until GDPR came into effect, and it seems they are doing _something_, although still it's very basic.
- jvalencia 5y agohttps://github.com/google/data-transfer-project https://github.com/google/data-transfer-project
- kijin 5y agoExporting your personal data is only half of the story. Importing is the other half. Suppose I exported all of my posts, photos, contacts, and a bunch of metadata from social network A. Perhaps I could view the contacts in Excel and browse the photos in my favorite gallery app. But unless I can upload it all to social network B and continue as if I've been using B all along, the data is not really "portable". It's just a backup, a frozen snapshot that can't be unpacked anywhere else. I'm not even sure if it makes any sense to import one's Twitter feed into Instagram or one's Facebook profile into Reddit. Edit: I'm not saying this is because of anti-competitive behavior on anyone's part. The services simply are so drastically different.
- BiteCode_dev 5y agoPutting a square into a round role does not make sense, but you may now be able to design a compatible square or round hole that one can move to.
- beckingz 5y agoOn the other hand every single app at one point would happily import your contacts no matter how they were formatted... The incompatibility is by design.
- DocTomoe 5y agoContact data is relatively uniform - you got names, addresses, phone numbers, maybe a few dates. Even with the handling of different addresses per contact, different systems already show divergent behaviour, even when they use the vcard standard. This becomes immeasurably more difficult with information from, let's say, Amazon: A competitor would not have the articles I've viewed, or the comments I have left under questions, or a compatible rating system. Even social networking sites ... how useful is it to import twitter exports of my tweets answering to someone if neither that someone nor the content I answered to is available in the target system? Sometimes, it is by design - in the majority of cases, it's just different people implementing different use-cases differently.
- 5y ago
- beyondcompute 5y agoAbsolutely! I remember asking to export my data from one of the services and the support pretty much ignored me (they replied in general but “forgot” to mention anything related to that question).
- varispeed 5y agoCompanies think that the data that is portable is your email address, profile picture, address, IP addresses - but other things like posts, comments are not. It is actually not well defined in GDPR and if portability means transferring your profile (e.g. username, email and some details about you only), then GDPR is pretty much useless in that regard.
- account42 5y ago> Companies think Which ones have you tried exporting your data from?
- grishka 5y agoI wanted to get my data out of ask.fm because I answered quite a lot of questions there back when it was fun. The GDPR export option was nowhere to be found. Opened a support ticket, they asked me for a EU ID... Well, yeah, I don't have one, I'm not a EU resident, I wanted to piggyback on the laws of countries that actually care about their people. But it just struck me that they hate their users this much. Even Facebook didn't go this low. On an absolutely unrelated note, I reverse engineered ask.fm's client API back when I was actually using it.
- wizzwizz4 5y agoUnder GDPR I think they're not allowed to require an EU ID. So just say “I'm not required to give you my personal data for this”.
- johndough 5y agoDo you have a source for this? In my experience, many large companies ask for ID. I am not quite sure which is correct since, on the one hand, they should verify that a request comes from the legitimate account holder, but on the other hand, they should practice data minimization.
- nicbou 5y agoThere are still some issues with it (incomplete data, manually triggered data exports), but it's a notable improvement nonetheless. It's particularly valuable when it lets you export instant messaging conversations and shared photo albums. It means that companies cannot hold your data hostage to keep you on their platform. I use GDPR exports for a personal data thing I'm building [0][1]. It simply wouldn't work without GDPR, because public APIs are increasingly rare. Most of your personal data is locked and GDPR data exports are usually the only way to access it on your own terms. [0] Intro: https://nicolasbouliane.com/projects/timeline https://nicolasbouliane.com/projects/timeline [1] Code: https://github.com/nicbou/timeline https://github.com/nicbou/timeline
- varispeed 5y agoThe problem is that the what actually has to be made portable is not well defined in GDPR. It basically says that it means any data by which the user can be identified by. When I requested a data export from some companies their legal team argued, that they cannot send me my projects in a structured format nor they won't allow import of project files from another service, because this is not a personal data (or rather not a PII). So this is actually another area where GDPR is all bark but no bite. I could only request my personal data, that is my name, address, email and IP addresses...
- pmlnr 5y ago> The problem is that the what actually has to be made portable is not well defined in GDPR Wait, is there anything well defined in GDPR? EDIT: k, so for the downvoters: I mean it. GDPR is muddy at best. Think IP addresses: in most cases, they are _not_ PII, especially when it's a dynamic IP from an ISP, yet nearly everything insists on hiding IPs or converting them into geo information.
- TeMPOraL 5y ago> Think IP addresses: in most cases, they are _not_ PII, especially when it's a dynamic IP from an ISP In other words: they can be PII, and you can't easily determine which of them aren't - the way they're being assigned is out of your control. (Even in cases people think IPs aren't PII, they become so when combined with other datasets - dynamic IPs can be quite stable.) > Wait, is there anything well defined in GDPR? In terms of singling out particular technologies? No. In terms of defining principles and criteria? Very much yes. If GDPR went the other way, it would be trivial to work around by subtly changing the technologies or data involved.
- dariosalvi78 5y agoWhat the law doesn't specify is if data associated to personal data should be included or not. It's kind of paradoxical because I may have a table in the DB with the details about the user, like name and email, and another table about, say, sexual preferences (usually considered quite sensitive). I could argue that the sexual preferences table is not personal of viewed alone, but of course it is very personal when linked through an ID. I think that, as long as the ID is there, and that data is therefore linkable, that data IS personal. IANAL, but that company's reply is bullshit and could be easily brought to court.
- maxdo 5y agosounds like data communism, who's going to support that?
- dariosalvi78 5y agoAll those that operate with the EU
- jokethrowaway 5y ago*EURSS
- robin_reala 5y agoThe best use of GDPR for data portability that I’ve ever seen was right here on HN: https://news.ycombinator.com/item?id=24764371 https://news.ycombinator.com/item?id=24764371 Long story short, Confiks takes Spotify to task for removing the API that SongKick used to retrieve playlist data; a short time and several factual emails later they restore API access.
- okamiueru 5y agoIt's great that it made Spotify activate a useful API they had little good reason to terminate. However, that "victory" always left me thinking a lot of people missed the point, including the person who challenged Spotify, as well as Spotify employee who responded to those emails, who confirmed they had little good reason to disable/remove the API. To summarize, Spotify can of course terminate any API they so wish, and there is absolutely nothing in GDPR that compels them to keep it up. As long as they of course still follow the requirements by GDPR. As annoying as a workaround would be for Confiks, emailing the data within those 30 days to SongShift is acceptable and in compliance. There is nothing in GDPR that says "data transfer options once enabled cannot be removed and/or changed". Quoting the clause "the data subject shall have the right to have the personal data transmitted directly from one controller to another, where technically feasible.", always seemed off with what is being demanded, because, they would be complying with that requirement by compiling and archive of the data, a big dump, and send it to SongShift. "I demand that you re-enable the API", on the other hand has no basis whatsoever in GDPR. The quote follows with "... or allow for some other method to allow me to exercise my rights under the GDPR", which is exactly right. Spotify re-enabled the API because they chose to, not because they had to. To clarify: I think it was great that Confiks convinced Spotify to re-enable the API. But, the arguments presented were not particularly convincing, and I took this as a case of Spotify doing the right thing, rather than a "David vs Goliath".
- wizzwizz4 5y ago> Spotify re-enabled the API because they chose to, not because they had to. Spotify re-enabled the API because: • they already had the API, so they couldn't claim it was an undue development burden to re-enable it; • it was cheaper than setting up another system based on manually emailing large chunks of the database; and • it was good press.
- maxdo 5y agoI'll re-phrase. Imagine I'm a startup. If government force me to to delete some data, it makes my life easier, no data - no privacy issues. if someone tells me , I want to port my data to competitor, because my UI better then theirs, but they still prefer competitor, why should I care about this requests, why should i spent a single second of my engineers time to implement that?
- dbetteridge 5y agoBecause the data isn't yours, it belongs to the customer. That is the opinion that GDPR encodes into law
- deleted 5y ago[deleted]
- pmlnr 5y agoErm... because you need to follow laws. Your company would file tax records, right? And follow fire and building regulations in the office, correct? So why would it not follow GDPR?
- deleted 5y ago[deleted]
- toomuchtodo 5y agoIsn’t engineering time cheaper than legal counsel time when your customers file complaints with the government against your org for not adhering to the law?
- MattGaiser 5y agoIs any legal counsel time actually being spent on this? It seems like all the disability legislation. In theory it applies to websites. In practice, few give it a 2nd thought. I have yet to hear of a company significantly harmed by failing to consider accessibility.
- sam_lowry_ 5y ago
- LeonM 5y agoThough an important part of privacy, I think this data portability is really useless, for both consumers and businesses. 1. There is no format defined in which the data must be given 2. There is no feasible way of defining such format anyway 3. Thanks to 1 and 2, there is no feasible way of importing this data into another service. AFAIK, a consumer has the right of requesting the export in any chosen format, but it says nowhere in the GDPR that the data controller must supply this for free [0]. As a business you are allowed to charge a fee to cover the cost of exporting the data, as long as this fee is considered 'reasonable'. [0] Note: IANAL, a befriended paralegal told me this.
- ocdtrekkie 5y agoIf the right exists, tools can be built to exploit it. For example, one could write a tool that ingests Google Takeout data to convert it for other platforms, because the data output exists in a... somewhat... usable form. Presumably, someone wanting to build a service that encourages people to migrate from Google services could build an import tool to their platform with it.
- simpss 5y agodata needs to be provided in a machine readable format. From there, a specific parser/converter needs to be built by the competing service for imports.
- Danski0 5y agoForgotten? It's a basic GDPR article (article 20) that every somewhat serious EU company know. Link bait by a company making their profit of GDPR confusion.
- jbverschoor 5y agoWhat about data-portability of in-game assets?
- gpm 5y agoYou want a csv saying what "this account has this item" flags are set for your account in the database? Ya, you can probably get that, for all the good it will do you.
- 5560675260 5y agoTheoretically you could ask for your account data in a game and for it to be sent to developers of another game. But there are very few if any incentives for receiving party to honour your purchases somewhere else. And even if they would chose to do this - they will not be able to provide you same assets (unless we are talking about some unity store bought models).
- selfhoster11 5y agoLet's solve this with NFTs! Partly joking, but partly serious. Maybe we could use something like this.
- dundarious 5y ago2 of the 6 ways portability is broken are duplicates of each other.
- brutuscat 5y agoZKP all the way https://www.aepd.es/en/prensa-y-comunicacion/blog/encryption-privacy-iv-zero-knowledge-proofs https://www.aepd.es/en/prensa-y-comunicacion/blog/encryption...
- slver 5y agoFacebook's data worth $1294 per user per year is probably BS. It'd mean Facebook generating 3.5 TRILLION in PROFIT every year.
- loeg 5y agoThe website currently says, "up to $1294." The phrase suggests that at least one user is worth that much and the rest are worth less. One might imagine that that user is clicking on a ton of ads every year (and buying the products).
- mehdim 5y agoauthor here. We divided the number of revenues and the marketcapitalization per regional revenues US user : $1294 market cap in average, EU user : $494 market cap in average, Asia $109, Rest of the world $80 It is explained in more detail in the report
- bombcar 5y agoMaybe they took Facebook's market cap (about a trillion) and divided by yearly active users or something.
- jFriedensreich 5y agoit took me fighting 6 months with viacom support to get my song plays for last.fm . spotify improved from 2 weeks to 2 days but its still ridiculous to call something true data portability that is not automatic and not instant. a lot of companies tried giving me semi obfuscated pdfs or html without classes or classes that were random strings, we need to improve the law to enforce instant availability and an industry standard format like json or xml. also this needs to be completely automatable without having to do it myself.
- capableweb 5y ago> it took me fighting 6 months with viacom support to get my song plays for last.fm Sue them. It should be faster than 30 days according to GDPR. > a lot of companies tried giving me semi obfuscated pdfs or html without classes or classes that were random strings Giving you obfuscated data is also against GDPR as the data needs to be clearly machine-readable. Again, sue them as you now have two points against them.
- ot1138 5y agoSue them under what law or jurisdiction?
- jeroenhd 5y agoThe GDPR does not give you any way to sue them directly. You can report the company to your country's DPA, which should look into the issue and might take it with the offending party in a court of law. That is assuming that the parent is actually an EU citizen or a foreign citizen living in the EU; if they aren't, the GDPR doesn't apply to them. I see a lot of (mostly non-EU) commenters thinking that the GDPR is grounds for any individual to sue any company for practically anything because privacy is hard, (which is probably why everyone was so hyped to hate on the GDPR) but that's just not how it works. As much as I value data portability, I'd much rather see a DPA sue the hell out of the companies that make those ridiculous, illegal cookie walls and popovers filled with dark patterns instead.
- mihaic 5y agoOverall, I think GDPR is a positive force that protects consumers. It does have one major downside though, and that's that it treats entities of all sizes in the same way. Placing the same regulatory burdens on start-ups as on big tech is a drag on innovation, and it's frustrating that there is no minimal cap on users before GDPR comes into effect, given how the EU has constant exception for artisanal food and goods manufacturers. Lawyers and third parties want to get a piece of the pie, so they'll present themselves as indispensable. It's almost as if this is the EU version of TurboTax.
- dheera 5y agoI think a much stronger solution would be to require all browsers to disable cookies by default, and let the user opt into websites that you need to sign into. In its current state GDPR has effectively just littered the website with popups that don't let you disable "functional" cookies in the popup. Functional my ass. The pages work fine without them. I disable all cookies except on a short list of sites I need to log in. Unfortunate side effect is the goddamn GDPR popups keep popping up on all those news sites.
- chrizel 5y agoYes, I don't understand why this is not handled on the browser level. Back then in the 90s browsers asked the user for every web page that wanted to store a cookie. The situation we have now is not much worse. But now every web page (at least in the EU) makes some kind of ugly popover and many of them try to convince you to accept all tracking with some kind of dark patterns of UI design. I don't understand why we won't stop all this nonsense and build this stuff into web browsers as opt-in or opt-out (let the user decide) and therefore ensure that the UI is always the same without any dark patterns.
- capableweb 5y ago> I don't understand why we won't stop all this nonsense and build this stuff into web browsers as opt-in or opt-out (let the user decide) and therefore ensure that the UI is always the same without any dark patterns. Because GDPR covers the everything, not just the web. If we had protections in the browsers, smartphone apps would still be affected. Instead, we fix it on a regulation level and no matter if it's web, apps or quantum-apps, we'll be covered.
- somethingAlex 5y agoWhat are consumers intuitively expecting compliance with this law to look like? Data from one service may be in an entirely different schema than the service you want to import it too - let alone format. Service A may summarize your data and throw away the granular stuff, but service B runs on the granular data. Are consumers going to implement ETL pipelines to achieve portability? Are they expecting to hook up streaming mechanisms for enormous swathes of data? Just as an example, if I wanted to get a list of every song I liked on Spotify and import it into Apple Music, how would that even work? The songId of Spotify is undoubtedly different than the one Apple uses. Are Apple and Spotify supposed to agree on a common file format? I agree with the intent of the law but I'm not surprised most services do not offer an automated way to take out data. It's a rare case, often a heavy workload, and there's really no way to guarantee the data you receive is actually portable.
- dsr_ 5y agoThere are incentives for, say, Mastodon to be able to ingest your tweeting history, or for Linked-In to eat your Facebook social graph. There's no incentive other than the law for Twitter or Facebook to make that data exportable.
- deleted 5y ago[deleted]
- StopHammoTime 5y agoThat’s why laws exist. There’s generally no incentive to not kill someone except going to jail.
- deleted 5y ago[deleted]
- brokenmachine 5y ago>There’s generally no incentive to not kill someone except going to jail. I'd let some of you survive.
- 5y ago
- mehdim 5y agoCo-author here of the research. The most simple and effective and rapid solution would be to impose API neutrality. As explained in the report, it would just obliges API providers to give back the same API access to users than they give to their partners. For instance, why I get less data from Facebook if I ask my personal data, than if I create an app and ask maximum app permission (all OAuth scopes)? API neutrality already works. For instance, Open banking in UK and PSD2 in Europe apply API neutrality. Any 3rd party can access to a bank API if they are granted by the user to do so. After 2 years, for instance, up to 20% of the UK online banking population beneficiated from it as "Banking data Portability via APIS" . 20% is huge. If FAMGAs and all other big companies data was accessible via "neutral APIs" to users, data portability would be "a thing" Also, the fact that you don't know what to do with you data dump in JSON is a blocker. With APIs, integrations by 3rd parties are simpler and more user oriented. Last point, with API neutrality, no need of maximizing "interoperablity" (even is is always useful and makes things simpler, we have seen that with DataTransferProject it does not work really as companies don't work with the same data model) Developers will do the matching work between the original app and the destination app, no worries, when incentive is here, middleware glue will come. The problem these days is that the source of data is useless, has no value, so no incentive. You can look at this study with GDPR Facebook data value for developers https://www.law.nyu.edu/centers/engelberg/pubs/2019-11-06-Data-Portability-And-Platform-Competition https://www.law.nyu.edu/centers/engelberg/pubs/2019-11-06-Da... The main question is : Why a Facebook GDPR Data dump/takeout has no value for developers where Facebook API has value for millions of applications developers and businesses? With API neutrality it will have maximum value for users (as it has already value for partners) and minimizing fatigue to implement portability (an API is lot more developer friendly than a JSON dump that you receive in 30 days via email and that the user need to upload somewhere)
- Xavdidtheshadow 5y agoFor what it's worth Facebook and Instagram (also owned by FB, but is fairly separate product-wise) have pretty good export tools. You make a request in the web UI and a short time later, can download a zip with a bunch of JSON files. I was pleasantly surprised by how much they included.
- fossislife 5y agoUnder GDPR, they have to include everything (they admit) they have about you, isn't that right?
- Xavdidtheshadow 5y agoI think, but I'm not sure how accessible it has to be. I was mostly commenting on how approachable the data format was. Formatted json with descriptive keys. I have no idea what the law requires about the data format, so they could be doing the absolute minimum.
- anticensor 5y agoUnsurprisingly enough, they only include what you entered yourself, but not derived data about you.