Not sure what is so difficult to understand about this.
"Tesco is set to install hi-tech screens that scan customers' faces in petrol stations so that advertisements can be tailored to suit them, it has been reported.
The retailer will introduce the OptimEyes screen, developed by Lord Sugar's Amscreen, to all 450 of its UK petrol stations, in a five-year deal, according to The Grocer.
The screen, positioned at the till, scans the eyes of customers to determine age and gender, and then runs tailored advertisements."
https://www.theguardian.com/business/2013/nov/03/privacy-tes...
There's an asymmetry between what a company can do politically/legally given it's resources and what an individual can do. This is why countries generally have some kind of laws protecting consumers.
Security cameras recording footage and it not being used in 99.999% of the time when no crime occurs is fine. The tapes aren't kept forever. Just as having server logs to identify malicious actors i.e. hackers or scammers is fine. What's not fine is e.g. running facial recognition on the security camera footage, or figuring out who bought what (cough Amazon Go).
> Shouldn't it be Walmart's right to do what they want on their property, and my right to decide not to visit Walmart if I don't agree with that. Isn't the converse an infringement of Walmart's rights?
No. Property "rights" are secondary to human rights. Like, Walmart can't knowingly sell poison as food just because it's their property...
In your example, Walmart is free to record you on security cameras for security / theft purposes. However, they can't record what you're looking at and reuse that information for targeted advertising without consent - profling is simply not required to do business, so your right not to be profiled wins.
What law prevents them from doing this?
Why do you think you can control what I do with data you send to me? Don't send me data I'd you don't want me to have it.
Are you really interested in rehashing this conversation? You got plenty of answers last time¹, I doubt you'll get new ones
Legal protections, like the GDPR.
Don’t reflect light in my direction if you don’t want me having pictures of you!
It's hard if visitor numbers would directly translate into revenue or similar. The trouble you're running in then is discerning organic hits from clickfarming.
If all you care about is when, where what content is popular on your website, there's a pretty simple method: Tally 200 and 304 responses. 200 tells you how many visits you get. 304 tells you, how often people hit refresh, or re-visit your page within the expiration time of the URL that 304s.
Also there's little value in identifying individual visitors. Getting a coarse idea where visitors are located in the world might be nice (for a regional news outlet for example). So just slap some coarse grained. GeoIP on it.
I'm not sticking up for all the big data perverts, but what about an individuals right to speak freely and disclose information they have observed/recorded? The 'right to be forgotten' seems at odds with everyone else's right to remember and disclose occurances.
Go read GDPR article 17.3, it's easy to read. A few things for which the right to forgotten does not apply:
- exercising the right of freedom of expression and information
- for compliance with a legal obligation (e.g. keeping records for tax reporting)
- for public interest reasons related to health, science, historical research
Seriously, there is too much FUD about the GDPR.
The only bad thing that I've noticed about GDPR is that some niche sites that rely on ad revenue are getting fucked over by Google (if you turn off personalized tracking for your visitors you still need the consent to track, there is no difference) so their income might break down.
That's quite sad but on the other hand they're exploring alternative methods of income and I'm certain adtech will adapt.
This time it bites back tho.
Also, what pii is tracked (by default) by piwiki or ga or access logs? I certainly cannot think of anything.
Cookies and other artifacts in the request headers or query parameters that can identify a unique user.
How careful are you with tacking cookies to requests? Be mindful, and keep documentation.
https://eugdprcompliant.com/personal-data/
PII or not PII it is still covered by GDPR.