7 ms·
That broad definition opens itself to so much… Even raw movie rating data was famously partially de-anonymized. I’m not sure that I could imagine a detailed da
by bertil 3y ago
That broad definition opens itself to so much… Even raw movie rating data was famously partially de-anonymized.
I’m not sure that I could imagine a detailed database with personal activity at a reasonable scale that couldn’t be de-anonymized, at least partly, if one assumes that people use related services and that one has access to them via public social media, mostly.
- Emails: of course;
- social media: easy;
- search queries: LOL;
- transport: through commute;
- any cultural good: you can connect to contemporary commentary;
- fashion shopping: pretty much trivial with OOTD posts;
- medial record: not everyone, but most major diagnostics could be matched to social media for many people;
- https blobs via VNP: most people would connect to the same four sites again and again, but exact timestamps and public statements on social media;
- grocery shopping: harder, but doable as you’d have neighborhood from the store address and a lot of surface…
Is the letter of that law against pseudonymous databases?
- genewitch 3y agoIs it funny that it is so broad? People don't want their information leaked! Why is this so hard to understand? It makes your job harder? Tough shit. It makes law enforcement tougher to do? Ohhhh nooo, they might have to work for a living instead of pushing buttons. Stop trying to defend companies that do this in service of capital. It is heinous. Some, if not most of us, want to be left alone and not have our addresses and medical history and YouTube stats available for the whole world. There is no such thing as an anonymous dataset. It has been proven again, and again.
- bertil 3y agoNo need to be snarky or insulting: I was trying to ask for a sincere assessment of that law. > do this in service of capital Sir, this is ycombinator.com If the intent is that no database with an individual-level breakdown falls under GDPR IID protections, I presume that far more processes and declarations would have to be applied to circumstances where there never was an intent or a credible option to de-anonymize them. This is not how it is enforced, understood, or applied today. The large companies that you criticize so readily would have an issue automating the paperwork or building hashing solutions that divert the problem, but their privacy-respecting competitors would fall under a lot more paperwork and legal risk than they could handle. Thankfully, there are solutions: a lot of people are now handling internal data processes with the same open-source tool, dbt. That platform could help change standards if they knew current patterns do not respect the letter of the law. But their lawyers seem to think otherwise.