Unfortunately, that doesn't go far enough. I don't use FB, but that doesn't mean it doesn't collect my data. It does because my husband and friends use FB, and I do not control the information they share about me with FB. Currently it has to be, "if you don't want any service collecting any of your data, don't use their service, and don't interact with other people or companies who use their service.". As an example of where your original statement fails, I don't want to be tracked in the mall by companies tracking my phone.
Take Facebook out of the equation and you still have friends showing your picture around, perhaps to people you don't want them to. In a Facebookless world, you would simply tell them to stop. My point is that it isn't Facebook's fault that your friends share too much about you.
That's a weirdly phrased question, since your biometric data is, by definition, part of "who you are".
I was under the assumption that it's only stored if your profile is linked with your face in a photo.
My comment has more do with the base concept of "don't want to be tracked, don't use their service" as a general concept for any service, rather than FB specific (which is why I gave a non-FB example). That said, I don't know if the rumors of "shadow profiles" are true or not. There is no technical reason why an image with two people in it (one of him which they already have) tagged with a comment of "Me and my wife on our honeymoon", couldn't be parsed given current NLP and face recognition capabilities.
Not sure you have any other option. Most of the time, you can't restrain what other people choose to do with images they've taken that contain your likeness, and you can't stop them from posting content that mentions their spouses. That person is willfully disclosing this data under the terms they've accepted. If the person is disclosing data about you that you don't want disclosed, that's an issue between you and that person, not that person and the entity who receives their willful, free, and unprompted disclosures.
Facebook can't know a priori that the user intends to disclose information on a person who doesn't want Facebook to know about them, and thus can't do anything about it until it's too late. Allowing people to delete other peoples' content because they don't want to be mentioned/included in it is an obvious non-starter (and Facebook already includes this to a reasonable extent with untagging features).
The privacy threat could be partially, not totally, mitigated by radically changing the way we approach online services, but I don't see how that could be pushed through. It wouldn't benefit any commercial entity, so no one with private motive would bankroll it to a height that could reasonably challenge FB, and it surely wouldn't be fair to use police/military force to dismantle Facebook et al and force users into a hypothetical somewhat-more-private decentralized, self-hosted, encrypted Facebook replacement, so we're basically stuck.
The reality is that this is the world we live in now. I don't think there's really a way to avoid it. Legal solutions that prevent vendors from referencing some data points may limit some effects here and there, but I think it's going to be difficult to craft something that really accomplishes anything big, and the tech and data is still going to be out there and used by some people regardless of the legal status.
I agree. Which is why when the original commenter stopped at "don't use their service", I pointed out that that action isn't enough. It's not good advice, because it doesn't actually work.
I think you underestimate the effectiveness of laws and punitive damages for breaking said laws. Seems to be working fairly well in reining in companies like AirBnB and Uber, its a matter of time before we rein in companies using data mining.
Without the CFAA, without improper application of trespass to chattels, without improper application of the Copyright Act to RAM copies of pages that exist for mere microseconds, and without considering exploitative browsewrap "agreements" legally binding, Facebook (and most other "walled gardens" that effectively downgrade the WWW into just another technical curiosity in content delivery instead of an independent, open, and free publishing platform) could relatively easily be harvested and reduced to something like the decentralized protocol described above, which would greatly enhance individual privacy and control moving forward. But I digress.
Uber and AirBnb have physical-world touchpoints that are easy to police using our existing police and justice infrastructure. You're driving a car with revoked registration or renting out a unit in an area not zoned for short-term rentals and/or without the proper licenses. These are straightforward violations that are trivially observable, relatively simple to prove beyond a reasonable doubt in a court of law and reasonably within a jury's comprehension and familiarity, and we can send a real guy with a gun to come and haul you off to jail if you break these rules.
All-digital conduct, like storing too much metadata, is much harder to detect, curb, and assign accountability for. And even if Facebook itself is stopped from making the correlations or compilations outlined by such a law, nothing can stop under-the-radar third-party scrapers or special-privilege actors like intelligence agencies from combining the data exposed to Facebook and ultimately achieving the same end: an uber-effective mass surveillance system capable of identifying anyone, anywhere (potentially even digitally) with nothing more than a semi-decent picture of their face.
I'm a little bit more optimistic than you. As noted in the article, there are important differences under the hood between FB in the US and The EU, and these were "pushed through" by courts, and cultural norms (e.g. not a violent/benevolent 'privacy junta' as you suggest).
I can imagine a world where the US gov banned sucking entire contact lists out of people's phones for commercial exploitation, for example. Everyone feels it's creepy, and there's zero user benefit. I don't see why this wouldn't be extremely popular, and straight forward to legislate.
This would remove the primary data collection means for FB's shadow profiles in one stroke.
What's the user benefit you have in mind?
But, assuming that FB's face recognition actually works, they can refrain from tracking people that don't have an account.
It cuts both ways.
Network effects cause monopolies. There should be regulation to undo the effects of this sort of monopoly to increase competition in this space. Namely by forced open api and data sharing, so you can take your data to another network if you want to.