4 ms·
If some of the participants are located in the EU this is a GDPR violation.
by turtleman1338 4y ago
If some of the participants are located in the EU this is a GDPR violation.
- that_guy_iain 4y agoHow so?
- Etheryte 4y agoIf the bot transcribes anything GDPR considers personal data and then emails it out you're already in breach. Simply someone telling their phone number to another participant over the call would result in a violation.
- that_guy_iain 4y agoIt wouldn't be in breach. otherwise, you sending an email with someone's email/phone number via gmail in it would cause Google to breach it. That would be on the software user. If you use somewhere that to breach GDPR, the software provider is not liable for how the user uses it.
- handoflixue 4y agoIf the software is transcribing and sending emails without the user's awareness, much less permission... then the responsibility must rest with the software. Software isn't responsible for my deliberate decisions, but it is responsible for anything it does without consulting me.
- that_guy_iain 4y agoThat isn't going to fly is it? I didn't know this software did this when configured in this way isn't really something that moves the liability.
- sulam 4y agoHe specifically _didn't_ configure it in that way.
- that_guy_iain 4y agoHow many times has a user said they didn't configure something that way and when you checked they did and they were thinking about a different setting for something else? Realisitically, it's actually the most likely thing that happened. And he did have it configured to send out emails. So that part is true.
- pessimizer 4y agoIf they're lying or mistaken, let us discuss the lie or mistake, and even the possibility that there could have been a lie or mistake (based on something.) Just dismissing it based on a obvious counterfactual that you're declaring based on no evidence other than that you think users lie and developers don't make mistakes is a waste of time. If you have some kind of insight into the specific configuration of otter.ai, or evidence that this specific person has made a mistake (and that all of the other people that have also seen this behavior are also mistaken) that would be constructive. As it is, you're not even carrying water for a company, you're offering water to a company that didn't ask for it by denigrating the people around you.
- arcticfox 4y agoThank you for defending me; my HN has anti-distraction timer so I wasn't able to respond to them. Like I explained in the other comment, while mistaken configurations are frequently a user mistake, I was exceptionally careful in this instance because the same thing had just happened to my boss and I was wondering what the mistake she made was. Also, I was hoping for a quality investigation and response from otter.ai but I think anyone can compare the credibility of my account to their response in this thread to figure out who they believe.
- arcticfox 4y ago
- dspillett 4y agoIf you tell the software to do something that is a breach, or used it when you could reasonably be expected to know it would behave in such a way, then yes you are responsible. If, for custom software/configuration, you specify software to do something automatically that is a breach, then yes also. If the software does it without your instruction, especially if you explicitly opted out, that is in beach, then the service responsible for the software may be liable instead. How enforceable this is, is a different discussion…
- pbhjpbhj 4y agoIf you made a draft email with those details, then GMail sent that draft without your authority then they too would be in breach, albeit unwittingly. That seems like a reasonable analogy to what happened in the OP, assuming it was a bug and not some 'growth hacking' plan as others have speculated.
- deleted 4y ago[deleted]
- airstrike 4y agoIf any of the participants are in many US states including California, this is also likely illegal. https://www.romanolaw.com/2022/05/09/are-recorded-conversations-admissible-in-california/#:~:text=Unlike%20New%20York%20and%20New,law%20is%20a%20criminal%20misdemeanor.&text=Under%20federal%20law%2C%20only%20one,required%20when%20recording%20a%20conversation https://www.romanolaw.com/2022/05/09/are-recorded-conversati....
- JumpCrisscross 4y agoThere are also call-recording issues in all-party consent states [1]. The transcript not only shows recording, it could also be used as evidence that consent was never sought. [1] https://recordinglaw.com/party-two-party-consent-states/ https://recordinglaw.com/party-two-party-consent-states/