When I asked Tinder for my data, it sent me 800 pages of my deepest secrets
theguardian.com
theguardian.com
It's going to be interesting to see how Tinder tackles the 2018 EU General Data Protection Regulation in 2018 and how things will play out in courts and practice.
For example, are you allowed to store information that I have chosen to unlink? Will Tinder have an easy way to export the data without having to settle to long email conversations, as there is a right to data portability? If so, in what format will this data be presented?
I believe the company in question would also need a legal entity in the EU in order for the EU to prosecute them, as I don't think you can take (e.g.) an American company to an EU court. IANAL though.
No, but they can go after the original company who transfered the data. Remember, under EU law, companies don't own that personal data. It's not theirs to give away.
Without a US court case they'd be dependent on assets or an income stream in the EU to be able to force payment of any fines, though.
But I can't find anything about how they'd make it enforceable in other jurisdictions (as opposed to enforcing the judgements by e.g. fining EU subsidiaries and the like).
Article 50 does say the Commission should take "appropriate steps" to ensure international "cooperation mechanisms", and its clear under e.g article 44 onwards that carrying out a transfer to a jurisdiction where the data would be subject to inadequate controls would be a violation of the directive, so you may very well be right.
If the company wants to do business with a EU customers, they have _some_ surface area in the EU, which is enough.
> an income stream in the EU
If the company cares for EU customers, there's probably also _some_ way to make money on them. Unless EU customers will exclusively get Netflix USA ads in the future (which are 100% useless to them) on an otherwise 100% free service, there is a money stream to hook into.
e.g. if Facebook pulled out (unlikely), then someone can just make a new Facebook site (we already know what functionality to copy), and then suddenly Facebook has a competitor.
That said, that's usually only a problem with small companies. Very few large companies manage to avoid all financial exposure to the EU and still do business with EU residents, so it has relatively little practical impact.
Sure you can. EU Courts did it to Microsoft over (IIRC) internet explorer resulting in a brand new SKU. Microsoft tried the logic you used at which point the EU courts started levying 1.5m euro / day fines for noncompliance.
Turns out that if you want to do business in a jurisdiction badly enough, it creates their leverage to enforce their laws on you.
I don't quite get what logic you think I used that doesn't agree fully with what you said above would be.
At first I thought "how would they know that" but it's simple: establish "home" for each of a match pair and identify that both parties' devices are at one or the other "home" during certain hours after matching.
In that sense, it's more than just data, it's inference, and that's almost worse as a private company's data could end up libeling you if it leaks!
The GDPR isn't nearly as scary as people set it out to be, and it gives companies a huge amount of wiggle room.
Paragraphs 1 and 2 shall not apply to the extent that processing is necessary:
1) for exercising the right of freedom of expression and information;
2) for compliance with a legal obligation which requires processing by Union or Member State law to which the controller is subject or for the performance of a task carried out in the public interest or in the exercise of official authority vested in the controller;
3) for reasons of public interest in the area of public health in accordance with points (h) and (i) of Article 9(2) as well as Article 9(3);
4) for archiving purposes in the public interest, scientific or historical research purposes or statistical purposes in accordance with Article 89(1) in so far as the right referred to in paragraph 1 is likely to render impossible or seriously impair the achievement of the objectives of that processing; or
5) for the establishment, exercise or defence of legal claims.
The first example is effectively a carte blanche to argue nearly any request for refusal in court.
The second one allows member states to pretty much tell companies not to delete information, whilst this was set up with compliance in mind, the wording has likely been formatted to also fit other needs such as security and state monitoring.
The third one pretty much allows you to keep medical records and insurance information.
The forth one is similar to the first with celebrities, public figures and major events in mind (the Gawker clause).
The fifth one has been singled out by dating sites and other services such as ride sharing apps as the reason for them to keep data.
I am not a lawyer this isn't a legal advice, speak to a legal firm or an auditor for proper advice.
I have been working on a few GDPR compliance projects internally for the past year and I've had to speak with quite a few lawyers and they all pretty much said it's actually far better for most companies than the existing framework as long as they can automate data discovery and know where they data comes from and where does it go.
You can fight the right to erase the data of a user pretty easily, what you cannot cockup (Art. 15, 20 and 21 of the GDPR primarily) is the ability to disclose what data you have on them and what is it used for which is like I've previously stated the tricky part for most cases. And as far as I can see Tinder pretty aced the tricky part.
So the issue is not the right to delete data in the case where you no longer use Tinder. The issue is that Tinder is simply not allowed to keep your data. In fact they must on their own initiative actively ensure they dont store data they are not allowed to, that is, on their own initiative delete your data, if you revoke your consent.
Edit: oh, and the best part. If you withdraw your consent Tinder is responsible for instructing all other companies that they shared your data with (including sold to) to delete your data (and followup that they did).
I'm also not sure if how did Tinder get the data (and yes it's important), Data sharing, 3rd party clauses etc. are also covered by the GDPR.
Does the GDPR can improve privacy? yes, but it really isn't the sledge hammer that people think it is.
This is a very big subject to big to cover over this channel to be frank.
Also (from B&B): "Individuals can require data to be ‘erased’ when there is a problem with the underlying legality of the processing or where they withdraw consent."
This is also a bit vague but it looks like withdrawing consent does not invoke deletion explicitly, it might simply change the lawfulness of processing which might require you to delete data if it's you only use consent as the basis of your LP.
However explicit consent is also not the only way to do "lawful processing" there are other ways to keep and get data.
Tinder can claim lawful processing after a retraction of consent with other allowances under Article 6:
1) processing is necessary in order to protect the vital interests of the data subject or of another natural person;
2) processing is necessary for the purposes of the legitimate interests pursued by the controller or by a third party, except where such interests are overridden by the interests or fundamental rights and freedoms of the data subject which require protection of personal data, in particular where the data subject is a child.
The 2nd one is pretty straight forward this is in essence a third party clause loophole, and the first one can be used by Tinder or the likes specifically in such cases where they would need to give data to the authorities in the such cases as sexual assault or harassment.
There is also a difference with what the GDPR defines as "further processing", which what happens when you want to use information for other purposes than what consent was given for, there has to be a link but this is again vague enough to be on a case by case basis.
"Further processing for archiving purposes in the public interest, scientific or historical research purposes or statistical purposes should be considered to be compatible lawful processing operations."
Bird & Bird has a lot of free information on GDPR and it's real world implications for companies google them :)
Completely agree that there are other basis for legality, but most of the seem to favor either the registered person or other laws. And that was sort of my thought when saying Tinder would have to delete if you withdraw consent: I would think consent would be the only grounds for processing data for a company like Tinder. Wrt 1 and 2 of article 6 you mention. I'd have though Tinder wouldnt be able to claim anything since for 1) the interest of the subject would the to delete it and 2) "Tinder making money on your data" cannot be considered a legitimate interest. And when it comes to Tinder havning to store due things like in the case of sexual assault they would still have to consider the priciples of limitation on what they use the data for (eg. cannot sell your sexual prefernces to adverticers if the only legal grounds is some law requirinh them to store data for a very scific cause), right? And then there is the whole notification to the subject thats going to be a major pain aswell.
Anyway, not a lawyer, and all the special cases you point out is probably valid. But thats why the only really interesting thing is to see the first cases and judgements on this so we can get some indication of interpretation. And ofcourse seeing EU will actually execute the high fines - if not then all this wont have any effect anyway
1. The AI was kind of hacky. Updates were done by polling rather than push. There were a lot of unused fields - for example, "remaining likes" would hang at 100 until the likes were used up, then it would go straight to 0.
2. They tracked absolutely every action you took and sent it to a different server from the API requests. Opening settings, opening your own profile, opening someone else's profile - it was all logged. They knew exactly what you were doing in the app and for how long.
It wouldn't surprise me nowadays if this is standard practice but it was eye-opening to see it happening firsthand.
You can still use MiTM HTTP proxies pretty easily. If they don't pin certificates it is trivial. If they do pin certificates you have to understand how they are doing it and break that. Often trivial to easy, but requires an app-specific approach.
We haven't met an Android or iOS app using HTTPS that we could not MiTM yet. Usually without a lot of effort. Some times with a small to moderate amount of effort (a couple hours to a day of poking the app/code/certs).
Are there always-connected apps that don't do things like this? It's always seemed like an obvious source of usage research data that the product team isn't going to want you to forego.
A lot of apps are A/B tested for new features, I would assume this is where the results come from.
- Data collection is about learning things about your users - Logging is about learning what your users were doing when Something Went Wrong.
Obviously, there's a _ton_ of overlap here, in that a lot of (all of?) the info one uses collects for one purpose could be used for the other. As a developer of the UI, however, my main concern is not about learning more about our users (our UX people already do that), but rather about understanding what happened, or which features are actually being used (so that we can know if they are safe to prune).
If a company is hitting an external API with every interaction, I'm guessing it's for gathering data on user behavior. The question then is whether or not it's anonymous.
Note, most sites that do analytics don't really care about who you are, individually, as a person, just how can they categorize you and your activities so they can generalize it and find ways to "improve the user experience" (read: improve how many users spend mucho dinero on our services).
And it's gotten to the point that they're never satisfied and want as much data as they can get away with so they can analyze it from a billion angles and tell the developers to change everything about the app every other week in the chase for better numbers.
The guy's name is Emil Kirkegaard and the paper and data is still available. I skimmed the paper and have no idea why he was labled a "white supremacist", or by whom. ("some commentators", really? Is this journalism?)
[EDIT]
paper: https://openpsych.net/files/papers/Kirkegaard_2016g.pdf
dataset: https://www.reddit.com/r/datasets/comments/4jj53i/here_is_a_...
Just a brief look on the titles of the Kirkegaard's other publications seems to confirm that he appears to have a deep interest in immigration, genetics, crime and IQ. One of his independent papers even mention cranial volume, which sounds vaguely familiar: https://en.wikipedia.org/wiki/Scientific_racism#Craniometry_...
One can of course draw rather more obvious negative inferences about the quality of his research from everything from the paper's laughable description of the sampling methodology to its entire premise that correlation between responses semi-arbitrarily assumed to represent intelligence demonstrates validity of that set of responses as a measure of cognitive ability.
Assuming a reasonable portion of these are refugees(or from third world countries), wouldn’t that be a fair link to make? Malnutrition has a clearly established link to lower IQs, hence migrants having a lowe IQ(iirc, Nordic countries have the Flynn effect strongest, so this link might hold true even for immigrants from developed nations).
I suppose we should differentiaye between illegal and legal immigrants. I'd venture to guess that, on average self selection for intelligence manifests in the form of legal immigration, while the so called "tenaceous" immigrants tend to ignore legal borders.
Before anyone accuses me of white supremacy or privilege or such nonsense, my parents were first generation legal immigrants.
How is that inconsistent with White supremacy or privilege? Because of geographic distribution of races, immigration demand, and per-country allocation of visa quotas, white people often have an advantage in legal immigration and the legal immigration is structured around preference classes which are themselves institutionalized privilege and also correlate with various more general privileges of birth, inheritance, and circumstance.
Ironically enough, his attempt at focusing on the objective led to you solely responding with accusations about how 'being white etc etc etc'.
Take arguments at face value; they can only be fully dispelled after reasoned, objective consideration.
Also: I will say that your point is a really interesting one re: racial privilege, but it's not relevant to the validity of his immigration stance.
http://www.givewell.org/charities/IGN
And there are also all the other things that public hearth programs do for those of us lucky enough to grow up in wealthy countries which most people don't appreciate nearly enough.
No.
Among other errors, you seem to be assuming that immigrants from third-world countries are a representative sample of the population of the country.
Unfortunately, people will take this as another example of how "racists are stupid," but they dont realize that the only people who are willing to touch what communities like HN have made taboo are those with nothing to lose, or those who have already been "outed" as the racists they'll be accused of being.
Research into gender and racial differences does not need to be as sloppy as this Kierkegaard guy, and I can't deny that he unfortunately has an agenda, and that he's created a breeding ground for confirmation bias and cherry picking.
Point is, though, taboo is antithetical to science. And when we dont treat it as such, and cordon off certain topics as "not socially acceptable questions," then we end up with shit like Kierkegaard.
I don't feel silly anymore. :)
(btw: my name is not zoltaan ;) )
In my estimation, this is a good first step, but privacy has to be a feature of the system, not just a heavy shield you carry through it.
"There is significant discrepancy between a user's stated dating preference and his/her actual online dating behavior." For how much discrepancy, read the paper.
Data Available In-App · Username · Email Address (current) · Phone Number (current) · Birthday · Name · Snapcode/Profile Picture · Snap Privacy Settings · Stories Privacy Settings · Friends (Contacts) · Blocked Friends · Snapcash Transactions
Data Available for Download Account History and Information Snap Count Local, Live, and Crowd-Sourced Content History and Information Purchase History Snapchat Support History Content and App Engagement History Demographic Profile
I wouldn't be surprised if it was auto-generated from keywords that the author can assign to their article.
Update: I have forgotten to unselect Google Photos and GMail, that's what takes most of the space.
My own biggest issue with data retention is not that these companies collect all this data (they need to for their business models to work) but that they keep all of it, forever, regardless of whether it could possibly still be relevant to any business purpose (such as chat conversions from a decade ago).
Can't they just keep (at most) the metadata?
Data retention
We keep your information only as long as we need it for legitimate business purposes and as permitted by applicable legal requirements. If you close your account, we will retain certain data for analytical purposes and recordkeeping integrity, as well as to prevent fraud, enforce our Terms of Use, take actions we deem necessary to protect the integrity of our Service or our users, or take other actions otherwise permitted by law.
[1] https://en.wikipedia.org/wiki/Ashley_Madison_data_breach
To be fair, this article is a vulgarization of what "tech-savvy" internet user already know.
There was a time when attaching your real identity online was considered a major safety risk. That time hasn't past.
She matched with a new guy every two days basically, and he mentioned she only sent 1700 messages since she started. That's almost two average messages per match before getting bored and moving on.
With that much abundance of choice, I guess you could say life is nice and easy for the author.
Which is better, getting 1,000 matches in a day, when 999 of them are people who just swiped right no matter what, or who are downright rude, aggressive or poor communicators?
Or getting 2 meaningful matches in a day from people who actually want to meet you and might be a good fit for a relationship or friendship?
The first is just a bunch of noise with no signal. The second is preferable.
And plus, I'm a guy and I would easily get 3 or 4 matches a day when I was on Tinder. It's not like men are completely ignored on it. I'm hardly a supermodel, but nice pictures and a well-written profile can go a long way on online dating. Plus living in a high-population city.