Could I:
1. Create a subsidiary (Company C)
2. Share info 'internally' with company C
3. Sell Company C to Company B
Could I:
1. Create a subsidiary (Company C)
2. Share info 'internally' with company C
3. Sell Company C to Company B
Just word it "not share with unrelated third parties" and it reads like "no sharing" but of course any party you're selling too is related by contract.
No-one reads the terms really, well I'd guess <<1%?
Probably what's needed is a general framework from law about not sharing without explicit consent banning the company; and that personal data expires in a company transfer/sale without consent (but perhaps a lower bar there).
It is pretty baffling to see how often programmers talk about law like it's an algorithm. Even the DAO didn't work out that way, and that was explicitly intended to turn contracts and law into algorithms. If that didn't resist social pressure to redress harms, why would we expect actual humans to do so?
(And frankly, thank god the law doesn't work like that. I don't want to live in a world where legal loopholes open up as often as software vulnerabilities.)
The FTC is fairly broadly empowered to stop deceptive practices, and most of the standards there are about what reasonable users would expect.
So you may be able to work around a contract implicit or explicit, but in practice it's unlikely you would get away with it.
Plus if you said this to a judge they'd laugh at you. They are not (and should not be) judging automatons.
The reality is that if you're considering selling the golden goose of all your user data then you might as well just sell the business outright and be in 100% compliance without the expense of the proposed convolutions or risk of FTC ire.
With not a damn thing your users can do short of trying to delete their accounts.
Depending on how they are worded, either the share, and/oor the sale, and/or neither will break the policy
5. Laugh all the way to the bank.