The new DPD is very strict, but there are two parts of the directive that a particularly interesting:
- The Data Portability concept: A company covered by the DPD is required to deliver to the user all data the company has on the user, in a standardised format. That means Facebook now has to hand out all your data (information, pics, likes, posts,...) for you to use freely - also in other services. I think this in effect means you own your data. I'm excited to see the effect of this one.
- The right to be forgotten: A company is required to delete all data they have on a user, if the user requests. Actually, if the user invokes this right, the company is not allowed make public, <b>store or process</b> any data related to the user.
From what I hear in discussions between american colleagues, american companies have no clue whats about to hit them. I know there is a mild panic here in Denmark, and the DPD is the most talked about subject in IT at the moment - and we've always been rather anal with the privacy stuff (e.g. cookie-law).
Edit: Oh, I forgot the fun part; this gets a lot of attention due to the sizes of the fines companies get for not adhering to the directive. Fines are up to EUR 20.000.000 or 4% of the company's global annual revenue, whichever is higher. Facebook made USD27.638.000.000 in 2016, so thats a fine of USD1.105.520.000 for not playing nice.
[1]: http://ec.europa.eu/justice/data-protection/reform/index_en....
I think the practices of online tracking joined up with offline tracking, as Google is now doing is going to be forbidden unless you consent.
https://www.washingtonpost.com/news/the-switch/wp/2017/05/23...
This was exactly my point a while back. That the default option should be to get explicit permission for each piece of data you collect AND infer, even if the inference is being done in situ as the code executes (otherwise it will become another out clause). Of course, the geeks who get all delirious by seeing a mountain of data to analyze would not want that kind of friction in the process.
I wonder what would happen if someone would spend the time to completely dissect and reverse engineer exactly how lookalike profiles are being generated. My guess is that it will expose data collection practices which will confirm our worst fears.
Then there is the secret negotiation of TAFTA where the US wants to siphon data without providing privacy and Germany refuses to let TAFTA go on until there are adequate privacy measures.
So yeah, this battle has been an ongoing one for years now.
Technically each and every advertising agency that creates a profile on you, gives you a cookie and stores your IP address is in violation of the law. (IP addresses count as PII, Personally Identifiable Information).
I don't see the legal hammer coming down on the advertising industry (of which Facebook and Google are the major players) any time soon if ever.
One way hashed (that can't be rainbow tabled) are not however PII afaik however, so it's quite easy to turn an IP address into a "net location ID" or something similar that can't be tracked back to a physical IP for analytics.
No need for rainbow tables, the search space is small enough to brute force.
Given a GPU farm however I'm sure it might be feasible. However at that point surely you just add a salt?
If you add a salt, then that "net location ID" becomes of very limited use. You won't be able to grep through the logs for request from specific IP, you won't be able to tell how many distinct IPs are accessing your services, etc etc. The only use I can see is keeping it in the session to check if IP address had changed, as a security measure.
How would that work? You'd have to use the same salt for every IP (which completely negates any benefit of the salt), otherwise how do you know that bcrypt(salt_1, IP_1), which you stored in your database yesterday, refers to the same IP as bcrypt(salt_2, IP_1) that you stored a month ago?
Recently Facebook got fined 110 millions by France for lying to antitrust regulators during the vetting of the whatsapp deal, a few days before it got fined the maximum of 150k euros for repeated infringement to local privacy laws (maximum has since been raised to a percentage of the worlwide revenue) and a few days later it got a 3 millions fine in Italy for a similar privacy offense.
I'm not sure shadow profiles are covered by the legal obligation as facebook never acknowledged the existence of those for they are illegal in the EU.
More about the difficulties and process to get your data from facebook here: http://europe-v-facebook.org/EN/Get_your_Data_/get_your_data...