4 ms·
However, Facebook maintains that users prefer seeing ads that are linked to their interests and lifestyles. Also, the company reminds us that private informatio
by law 15y ago
However, Facebook maintains that users prefer seeing ads that are linked to their interests and lifestyles. Also, the company reminds us that private information stays private, even when data is used to sell ads, because information is collected in aggregate and is anonymized.
This troubles me, because information being collected and 'anonymized' is somewhat of a misnomer. I think many would contest any assertion that data capable of disassembly into its constituent parts (assuming each constituent part to be a unique combination of variables represented in the aggregate) comports with anonymity. I'm generally not one to praise governmental regulatory agencies for their technological prowess, but the U.S. Department of Health & Human Services really "got it" with HIPAA's de-identification standard.
HHS understands the importance of aggregating healthcare data and conducting statistical research, and does not let HIPAA preclude this from occurring. Instead, HIPAA outlines a "safe harbor" approach that limits a covered entity's criminal/civil liability in the event of a breach if and only if the covered entity removes 18 identifiers and has no actual knowledge that the remaining information could identify the individual. These identifiers include names, dates, geolocational codes covering populations less than 20,000, etc. Alternatively, covered entities may opt to use a 'statistical' approach by hiring a qualified statistician (or other scientific expert) who can use acceptable analytic techniques to conclude that the risk of identifying the person from the disclosed information is very, very small.[1]
A safe harbor approach to large-scale data privacy would be absolutely wonderful. Using statistics to prove the anonymity of data being collected/used by Facebook is nonsensical, since by default, we've given them a non-exclusive, transferable, sub-licensable, royalty-free, worldwide license to 'use' anything we submit to them. Contracts of adhesion, in my opinion, are more of the problem since there's no good way to 'make change' for the information that you submit. For example, someone very active on Facebook might arguably be 'worth more' to the company than someone who isn't, but both receive the same product.
EDIT: A safe harbor approach to large-scale data privacy isn't even unknown. See COPPA[2], for example.
[1] http://ecfr.gpoaccess.gov/cgi/t/text/text-idx?c=ecfr&rgn=div8&view=text&node=45:1.0.1.3.77.5.27.9&idno=45 http://ecfr.gpoaccess.gov/cgi/t/text/text-idx?c=ecfr&rgn... 45 CFR 164.514(b)(1)--(2).
[2] http://en.wikipedia.org/wiki/Childrens_Online_Privacy_Protection_Act http://en.wikipedia.org/wiki/Childrens_Online_Privacy_Protec...
- Silhouette 15y ago> Contracts of adhesion, in my opinion, are more of the problem In the Internet/data mining era, contracts of adhesion are an incredibly overpowered legal tool. Suddenly things you used to do in person, with reasonable expectations and no practical way for commercial entities to override those expections, have been replaced by doing everything in software and on-line, with EULAs and click-through agreements that contain numerous obviously abusive terms that are not necessary for the performance of the basic agreement, would be unexpected by the individual agreeing to the standard form contract, but are never known (until it's too late) because no-one actually reads the full details of every form agreement they "agree" to. It is well past time that consumer protection laws were updated to dramatically rebalance the legal weight of form contracts containing potentially unexpected or misunderstood terms against what would seem necessary and reasonable to the person entering into such an agreement. It is also well past time that privacy laws were updated to reflect the Internet/database/data-mining age. You can't just assume that some minor action that might not in itself have been considered an invasion of privacy in more innocent times is still harmless at a time when technology can turn a collection of such actions into a searchable life story.