Every corporation has to answer these questions but right now they have to do it with no real guidance from the government. This makes the data a ticking time bomb. It's not clear what can be done with it or even how much it's worth. It's not clear what best practices exist in terms of technologies and ethical guidelines.
That said nobody expects something like the GDPR too happen in America. Pretty much every other country will adopt similar laws though. If Americans are lucky they'll get some benefit from that.
Historically, these numbers have been $0.0+/-0. Executives aren't exactly bumbling around with hazardous materials.
https://www.schneier.com/blog/archives/2016/03/data_is_a_tox...
https://www.marketplace.org/2018/02/28/tech/sen-elizabeth-wa...
Equifax? Yahoo? Target? Heartland? TJX? eBay? JP Morgan Chase? Adult Friend Finder? Locationsmart and the cell phone carriers providing real time location information on all of their customers to third parties?
A CEO of a major corporation The Land of the Free™, wouldn't consider liability for negligent data handling very seriously given the government's seeming lack of interest in seriously prosecuting same. S/he'd probably even argue that investing more in security would lower profits and harm investors. And we can't have that.
What am I missing?
If I understand it correctly (IANAL), there are no penalties for getting hacked. Rather there are penalties for not having proper procedures for how to respond to a hack.
https://ico.org.uk/about-the-ico/news-and-events/news-and-bl...
> The data was taken from an underlying customer database that was part of TalkTalk’s acquisition of Tiscali’s UK operations in 2009. The data was accessed through an attack on three vulnerable webpages within the inherited infrastructure. TalkTalk failed to properly scan this infrastructure for possible threats and so was unaware the vulnerable pages existed or that they enabled access to a database that held customer information.
> TalkTalk was not aware that the installed version of the database software was outdated and no longer supported by the provider. The company said it did not know at the time that the software was affected by a bug – for which a fix was available. The bug allowed the attacker to bypass access restrictions. Had it been fixed, this would not have been possible.
Now that we have GDPR and the new data protection law ICO will be issuing fines under the new law.
This old case is an example of how the ICO regulate, and the things they'll take into account. GDPR wouldn't make much difference for this case.
I see this as similar to regulating pollution. Forbidding companies from cutting costs by polluting the air and the rivers allows for innovation and entrepreneurship in cleaner alternatives.
They also position themselves as a premium product and do not / cannot compete with google in terms of price. While apple products (and iOS specially) are very popular in the US, here in Brazil you almost never see them.
The EPA's exhaust regulations in the 1970s arguably birthed the catalytic converter industry.
If the regulation is costly enough or introduces sufficient compliance risk, the rise of an industry to help companies comply with it is almost inevitable.
If your startup to unseat Salesforce requires doing tricky or infelicitous shit with my personal data, I don't want you to be able to operate, full stop. Your business shouldn't exist, if its existence requires schlepping or selling my data in a bad way.
The rights to privacy that some new laws could give us is simply more important than that.
a.) You start a business in California and plan to do business that involves EU customers. If you plan on making actaul money you'll hire a lawyer for a reasonably small number of hours to incorporate, ensure you have trademarks covered, get your EULA in order, vet your corporate structure, etc. GDPR is just another thing to add to the hopper--it probably adds an hour or two to the whole process since legal procedures are pretty template driven. Most of the cost will be the lawyer briefing you on what to look out for. (Based on my admittedly quick reading of GDPR summaries.)
b.) There's already a net decreasing trend in startups in the US, but it predates the GDPR by many years. [0] If you are looking for culprits in the legal system you are far more likely to find them in US laws (or lack of them) than anything from Europe.
Taking the EU perspective, well, I've run a small tech business in France and GDPR seems like noise level compared to the other regulations you need to deal with there. (Hiring and firing being the biggest but there are others.)
[0] https://www.nytimes.com/2017/09/20/business/economy/startup-...
Edit: add source
Nobody cares.
Name one way your life was ever negatively impacted, in a concrete way and not just in your head, by companies using your data to create value in the form of targeted ads and such to keep websites free. I'm waiting.
Facebook famously did an emotion manipulation experiment on 500k randomly selected users.
There's a trial now alleging that Facebook used profile data to discriminate against older programmers in job postings: https://news.ycombinator.com/item?id=17178565
Many types of abuses are subtle and remain unknown for the victims.
Burden of proof lies on the one making the claim.
>Facebook famously did an emotion manipulation experiment on 500k randomly selected users.
I don't really find that abusive or ethically troubling.
>There's a trial now alleging that Facebook used profile data to discriminate against older programmers in job postings:
Maybe this age discrimination, which was already illegal on its own, wouldn't have been possible to commit if the data didn't exist in the first place. That doesn't mean it's the tool's fault or that the tool should be illegal.
I didn’t make a claim, you did, then flipped it around and made one for me. ;)
We can go back and forth about the best way to deal with this, but it's crazy to think that this systemic gobbling up of personal data doesn't have real consequences.
But I can't think of any internet regulation that's ever harmed me. Which ones are you talking about?
Edit: I can think of a small number of regulations (much less than one per year) that cause problems, but they still don't meet the personal concrete harm threshold you've proposed.
Yeah, I'm onboard (like I said, I think the intent of the law is good) -- but regulatory compliance is expensive and in general creating a SaaS business is not. Compliance is more than just doing the right thing, BTW, it's creating processes, audits, attorneys, etc to prove that you're doing the right thing. One of SFDC's risks is that today a competitor could probably arrive and eat up their business by emulating their business model and undercutting their costs. They're very well placed to establish or enhance their existing regulatory compliance team(s).
This tends to not be maximally congruent with reality.
https://gdpr-info.eu/art-83-gdpr/
"Infringements of the following provisions shall, in accordance with paragraph 2, be subject to administrative fines up to 10 000 000 EUR, or in the case of an undertaking, up to 2 % of the total worldwide annual turnover of the preceding financial year, whichever is higher:"
So then why not just set it to a percent of revenue? If you're just going to slap a small company with minimal turnover with €1k fines anyway, then why the need for the "up to €10M" amount?
Depending on how quickly regulators can act, and how they would determine the date of precedence for 'the preceeding financial year', it's just about conceivable that a company might have >1 year of warning to do some financial trickery to minimise their fines.
Having a range(0..max($turnover_amount, $fixed_amount)) reduces the scope for that sort of trickery.
This is exactly the opposite of what GDPR says. If I am Satan himself and I do terrible things with the data of millions of people the maximum possible fine available is €20m or 4% of turnover, whichever is higher.
There is no lower bound. When a penalty is applied they're likely to be about €1000. But often penalties won't be applied, the regulator will ask the company to come back into compliance and give advice on how to do so.
> of €10M in penalties with no respect to how much data the company holds is what makes this taxing for startups.
...and GDPR is full of caveats about how much data is held, and how it's held, and how the company responds after a leak.
https://gdpr-info.eu/art-83-gdpr/
> When deciding whether to impose an administrative fine and deciding on the amount of the administrative fine in each individual case due regard shall be given to the following:
> the nature, gravity and duration of the infringement taking into account the nature scope or purpose of the processing concerned as well as the number of data subjects affected and the level of damage suffered by them;
> the intentional or negligent character of the infringement;
> any action taken by the controller or processor to mitigate the damage suffered by data subjects;
> the degree of responsibility of the controller or processor taking into account technical and organisational measures implemented by them pursuant to Articles 25 and 32;
> any relevant previous infringements by the controller or processor;
> the degree of cooperation with the supervisory authority, in order to remedy the infringement and mitigate the possible adverse effects of the infringement;
> the categories of personal data affected by the infringement;
> the manner in which the infringement became known to the supervisory authority, in particular whether, and if so to what extent, the controller or processor notified the infringement;
> where measures referred to in Article 58(2) have previously been ordered against the controller or processor concerned with regard to the same subject-matter, compliance with those measures;
> adherence to approved codes of conduct pursuant to Article 40 or approved certification mechanisms pursuant to Article 42; and
> any other aggravating or mitigating factor applicable to the circumstances of the case, such as financial benefits gained, or losses avoided, directly or indirectly, from the infringement.
You could literally say that about any property right ever. For instance: common law creates magical rights where none exist. You don't own your toothbrush. Matter is matter.
The law can create rights. That's how most rights are created.
You have to consciously decide to take me toothbrush, and it deprives me of it. But just seeing me walk by puts "my data" into your mind, and arguably doesn't harm me.
Clearly, when a phone network sells my location data to the highest bidder, I'm harmed. But they do need to know my location to provide me service.
In general, I think we want services to collect no more data than necessary, discard it as soon as possible, protect what they must store, and disclose it to others as rarely as possible. But all of those things are murkier than "don't take my toothbrush."
Obviously, we as a society have decided that property rights are more advantageous than not, and we're deciding the same thing about information rights. There's not anything inherent to either one that precludes us from regulating it.
> We hold these truths to be self-evident, that all men are created equal, that they are endowed by their Creator with certain unalienable Rights, that among these are Life, Liberty and the pursuit of Happiness. — That to secure these rights, Governments are instituted among Men...
But I understand that "rights" such as copyright are somewhat arbitrarily bestowed.
My point was that a right to one's possessions is more obvious and definable than a right to one's data. My hands are mine. My toothbrush is mine because I made it with my hands or bought it with money I earned with my hands. Etc.
It's much more nebulous to say that I own information about myself. If you see me, is your knowledge of what I look like "mine"? What about if you write down what I look like? What if you take a picture? What if you write down a detailed account of all my movements and sell it? At some point it starts to seem wrong, but it's fuzzy.
You may say these are both arbitrary. I don't think all rights are arbitrary, and to the extent that things are fuzzy, I think rights to physical possessions are less so.
But again, I'm in favor of privacy regulation. It's just less obvious what it should protect and how.
Data isn't that clear-cut. Your knowing my name and address doesn't take that knowledge from me. It's not obvious that you know it, nor how to make you "give back" that knowledge. So it's less clear what my ownership of that data would mean.
Unlike possessions, there's some fuzzy continuum from "clearly it's fine for someone to look at me when I walk past and know what I look like" to "clearly it's not fine for someone to track my every move and sell that knowledge for profit without my consent."
Then when I thought about it I decided that essentially all “ownership” rights are like this. Intellectual property and physical property laws are artificial. There is no basic right, they are all rights created where “none exist”.
They can be useful though, and part of how we decide what kind of society we want to create. Seems like Europe has decided that privacy and control of data personal data is something they want.
But also:
> Seems like Europe has decided that privacy and control of data personal data is something they want.
The problem here is that governments allow people to claim rights without bearing the cost of that claim (or at least hiding the cost).
It is not difficult to avoid storing data you don't need.
You don't need a user phone number? Easy, don't ask for it.
Of course you argument is that it is difficult to change existing systems to follow this principle. Except that your starting position was that this regulation was about stifling competition, which is thus in direct contradition with this argument.
Existing systems were built on the assumption that "misappropriating" PII was a lucrative thing to do. This led to abuse from the industry.
Access logs for one thing are pretty unreasonable to force people to avoid storing.
>Existing systems were built on the assumption that "misappropriating" PII was a lucrative thing to do. This led to abuse from the industry.
Can you point out a specific example of somebody suffering actual damages from this "abuse?"
I think it is certainly possible to find cases of identity theft resulting from PII that were leaked in security breaches, made easier by overreaching data collection.
Store them for a limited time, it's not hard.
Sometimes it's important to update regulations, despite the inertia of existing implementations.
As the first offense only seems to result in a warning, they have a chance to figure things out. Then is asking their webdev to schedule a cron job to delete logs really such a burden?
“This Regulation does not apply to the processing of personal data: (...) by a natural person in the course of a purely personal or household activity;"
So, it really only applies to companies, or if you’re processing a large amount of user data for a hobby project.
That being the case, it doesn’t feel like the bar to being able to respect the law is so very high. But I’d be interested in counter examples.
Why do you think this is required by GDPR?
Here's the actual bit of law. Note how many exceptions there are. https://gdpr-info.eu/art-17-gdpr/
It's not surprising you fear it so much if you think it forces you to do all the stuff you've said. What is surprising is that almost everything you've said isn't in GDPR or has been exagerated beyond recognition.
European countries draw a slightly different line than the US does (for instance including hate speech in the list of banned speech), but it's a difference in degree, not in kind.
Azhar Ahmed, a British Muslim, was charged with treason, and ordered to pay a fine and complete community service because of a Facebook post he made wishing "All soldiers should DIE & go to HELL"
Herve Eon was convicted in France for insulting former French President Nicolas Sarkozy by holding a sign that said “get lost, jerk”
And, despite your narrow definition, I posit that all of these are thought crimes in the common parlance, and even to your narrow definition, the first example showcases the assumption that being pro-Palestine is automatically anti-semitic, whether or not it actually is.
https://www.judiciary.gov.uk/wp-content/uploads/JCO/Document...
Seriously, if you don’t know what something means, don’t use the the damned phrase.
“For insulting” “For wearing” are not thought crimes. A handy rule to detect a thought crime is this: unless someone was jailed just for thinking it wasn’t a thought crime.
Please, actually read 1984.
You seem to be under some mistaken impression that you can say whatever you want whenever you want in the United States. You can't. There are many categories of speech that are banned in the US as well: if I think to myself "Tom Smith is a liar and a drunkard and he's cheating on his wife", that's perfectly fine, but if I communicate that to a large group of people in order to stain his reputation, that's illegal.
See the difference? In neither the US nor the EU is thinking things illegal, but in both countries, expressing stuff can possibly be illegal. It's true that the US and the EU has slightly different categories of banned speech, but that's a difference in degree, not in kind. but neither region has anything close to "thoughtcrime". You have a poor understanding of these issues if you think that is the case.
Comparing this to libel/slander is just absurd. It’s not a slightly different category, it’s such a massive difference that Europe has essentially outlawed aspects of political speech, which is the most important aspect of freedom of speech to begin with.
Here's my question: under your definition, how could "thoughtcrime" possibly be detected, let alone punished?
This is one of the central themes of 1984, that Ingsoc ("the Party") tries to control not just the speech and actions of their subjects, but their very thoughts. Literally: in 1984, having thoughts that goes against the party is illegal. That is why it's called "thoughtcrime", because it's the thought itself, even if it goes totally unexpressed in any way. Such crimes are punished by the "Thought police", who quite literally police thoughts. When a dangerous thought presents itself, you're supposed to use "crimestop", a technique for ridding yourself of that thought. Here's a quote from 1984:
> The mind should develop a blind spot whenever a dangerous thought presented itself. The process should be automatic, instinctive. Crimestop, they called it in Newspeak.
Oh, and yes: Newspeak! The language developed by the party with restricted vocabularies and grammar so that some thoughts will be literally unthinkable.
I took that quote from the wikipedia page on "thoughtcrime", which helpfully begins like this:
> A thoughtcrime is an Orwellian neologism used to describe an illegal thought. The term was popularized in the dystopian novel Nineteen Eighty-Four by George Orwell, first published in 1949, wherein thoughtcrime is the criminal act of holding unspoken beliefs or doubts that oppose or question Ingsoc, the ruling party. In the book, the government attempts to control not only the speech and actions, but also the thoughts of its subjects.
Feel free to look in any other dictionary or reference work, they will all say the same thing, some variation on "a thought that is illegal". I could go on with many more examples of how 1984 talks about thoughts (you should google "doublethink"! or maybe just read the book), but you get my point.
Your reaction, "how could 'thoughtcrime' possibly be detected, let alone punished?" is what the book is about. Every reader of 1984 reacts that way in the beginning, and the book is an exploration about what that very concept means, and what the implications are.
Look, the argument you are making is something like "European hate speech laws are an unacceptable abridgment of free speech and democratic rights". Which is a fine argument to make: I personally don't think so, but reasonable people can disagree on it and discuss it. What it is not is "thoughtcrime". It's just not what the term means.
I am not making any argument about European hate speech laws whatsoever. My issue is solely with the pedantic definition of the word "thoughtcrime" that is at odds with how it's actually used.
There is also a trend, even in the US, towards keeping some prisoners behind bars for thinking certain thoughts. Sex offenders in many US states can be held long after their sentences based on mental health determinations, determinations that turn on their response to questions: their thoughts. Whereas expression of thoughts can be clearly illegal (ie hate speech) simple consumption, reading, of such thoughts can land the reader in jail too. Governments aren't yet crawling into people's heads, but they are certainly willing to criminalize the communication of illegal thought.
Thought crime = the thought itself is a crime, i.e. simply having the thought. Expression is a totally separate thing, and using “thought crime” this way is just announcing that you didn’t actually read 1984.
Governments aren't crawling into people's heads just yet, but they are certainly willing to criminalize the communication of thought.
No shit. Communication has been subject to government intervention and overreach since th dawn of recorded history. The 1st Ammendment in the US was created for a reason.
That action put the trial at risk of collapsing.
He was caught, and given a suspended prison sentence for contempt of court. That judgement is available here: https://www.judiciary.gov.uk/publications/committal-for-cont...
Here's the judges words:
> The sentence, therefore, that I pass upon you, taking into account all of those matters that have been placed before me and your admissions entered via Mr. Kovalevsky, is one of three months' imprisonment which will be suspended for a period of 18 months. That will be suspended. There will be no conditions that need to be attached to that suspended sentence, but you should be under no illusions that if you commit any further offence of any kind, and that would include, I would have thought a further contempt of court by similar actions, then that sentence of three months would be activated, and that would be on top of anything else that you were given by any other court.
> In short, Mr. Yaxley-Lennon, turn up at another court, refer to people as "Muslim paedophiles, Muslim rapists" and so on and so forth while trials are ongoing and before there has been a finding by a jury that that is what they are, and you will find yourself inside. Do you understand? Thank you very much.
What did he do after beign given this very clear instruction to not interfere with criminal trials? He did exactly the same thing again, and so his suspended sentence was activated, on top of the new sentence.
Note that he only highlights trials of child sexual abuse involving muslims. He kept very quiet when a senior EDL member was similarly prosecuted.
Here's a decent write up: https://thesecretbarrister.com/2018/05/25/what-has-happened-...
Interfering with ongoing trials and making threats of violence is as far from hought crime as you can get.
[1] There's been an element of "this would never happen in the US", so here's a video of someone being tased because they try to take a camera into court. https://youtu.be/A7U5eJN3hLI?t=2m0s
You’re right that Robinson was in the wrong on this one and that he did commit a crime; I wouldn’t have used him as an example had he not been brought up specifically.
Even in the U.S., there are people actively lobbying to use the government, usually state governments, to restrict the BDS movement. In my opinion there’s been a lot of media attention around silencing right wing speech in order to get the left to comply in undermining the underlying legal principles. But at the same time, quieter work is being done to restrict left wing speech as well. This has already been put in place in Europe and there seems to be bipartisan support for it in the U.S.
He's not being silenced because he's right wing. He's being silenced because he's jeopardising trials and threatening witnesses.
This seems like a strange stance. Clearly some data is not just data and must be protected, for example Top Secret information. From a broad consumer perspective, we have FERPA and HIPAA, which place restrictions on educational and health information.
Have you considered the wild west of no data restrictions was the anomaly, not the other way around? Or, are you of the mind that HIPAA and FERPA should be scrapped?
If they try to circumvent the protections you put in place, that's different. Same thing with data.
And this completely ignores the difference in scale between a single person looking through a single window and the aggregate data of millions upon millions of human beings.
Here's a helpful tip: in our society, the responsibility is on the criminal for doing bad things, not on the individual for not going to enough lengths to stop the criminal.
That's like claiming the 1st Amendment in the US is just a "magic right."
[0] https://en.wikipedia.org/wiki/Treaty_establishing_a_Constitu... [1] https://en.wikipedia.org/wiki/Charter_of_Fundamental_Rights_...
You're making the wrong argument. You're saying "this is not a right that can logically exist", which is nonsensical. Of course it can. What you should be arguing is "this right is far too burdensome on society and should not have been passed". I personally disagree with that, but it's at least a valid argument.
Larger businesses (250 employees or more) may need a privacy policy though.
For example the law itself says: The processing of personal data strictly necessary for the purposes of preventing fraud also constitutes a legitimate interest of the data controller concerned.
The UK's IPO for one example definitely doesn't agree with your assessment of the GDPR and it is their job to help companies adhere to it.
There are many instances where abuses had real-world consequences, you just need to have the will to find them.
- What data is being collected about you
- What they're doing to keep that data reasonably secured
- Who to contact should have you detect some security issue
- How to request that the company stop using your data
.....and we've reinvented the GDPR.
That's pretty much how laws work.
What are your credit card numbers? :)
Same too for credit ratings. The right to view and alter them comes from various other common law rule (ie slander) but the credit rating itself belongs to the corporation that generates it.