When the top folks in the US government are personally affected. Until then, "congressional hearings" and presidential ambivalence is the most action we'll get out of them. Most people don't really understand what the significance of these events are.
Remember, we only got the Video Privacy Protection Act after someone published Bork's rental history during his supreme court nomination[0]. I had to say that public shaming works, but, public shaming works.
[0]https://en.wikipedia.org/wiki/Video_Privacy_Protection_Act
The OPM breach covered a lot of powerful senior people.
https://krebsonsecurity.com/2014/03/who-built-the-id-theft-s...
It will only change when consumers demand it to change or outright refuse to give their personal information away. I think everyone should adopt pseudonyms for everything and to be constantly changing their pseudonyms regularly.
In some cases you're not knowingly giving them your data either.
So I refused and made it clear I would walk away. The sales guy went though the whole ‘it’s not a problem, I’ve bought cars from here and haven’t got spammed’. In the end he had to get a manager and it turned out that the option could be removed from the contract, three menus down in the system.
Sounds like no one had ever asked before. I imagine GDPR will have changed this to opt-in.
I scratched that, and other lines, out of my rental agreement when I rented my New York apartment. The landlord agreed.
I don't believe it'll be feasible to purchase just one person's purchase data [easily], but if you knew who you wanted to get to, it should be possible to narrow the targeting to get to them
[1] http://www.oracle.com/us/solutions/cloud/data-directory-2810... [ctrl+F + mastercard]
but i guess it might be different for different acquirers.
the purpose of loyalty cards is that the messages are usually acquired or processed on non-bank systems so they can go into much greater detail and include individual sale item details
With the advent of the chip and pin cards in the USA, it seems logical that just about everyone upgraded to equipment that does support it; which might explain why you are only seeing this in the past year.
(quizzical look)
Are you aware of their MPerks program? Tied to your phone number and an email address, electronic receipts, tracking of your savings, online/in-app clipping of coupons auto-applied at checkout time, automatic "rewards" of $2-3 for every $150 you spend.
The only part of a traditional loyalty card program it doesn't have is making their sale prices apply only with card, but it definitely gives you measurable (and measured) discounts both passively through those "rewards" and actively via the in-app coupons.
Data are facts, money is a repository of value. With a bank, you are the customer. With marketing, you are the product.
Data about you is not (necessarily) data you own.
I'm not saying it's right, but any reasonable discussion has to take this legal landscape into account.
There is no rising fascism in America, if people really knew anything about the Wiemar Republic, Republican Spain, or March on Rome they would know that the left always loses when it tried to be humane and gain power. The only time the left gains power is when 'tankies' are the ones leading the resistance.
But, remember the left chooses the hard road, not because they can but because it is moral.
Regardless, Trump is absolutely a fascist. It seems a bit futile to disagree.
Edit: On a more practical note, it's always baffled me how normalised it is. People who defend fascists in the US media are still respected and hired. They might be prominent political figures. Somehow calling attention to someone who is fascist is confused by anyone doing something as simple as saying "liberals are evil!", as if the two party system there has anything to do with racial supremacy. As an outsider, you look at it and think "This is the country that helped liberate Europe from the Nazis. How are they not ashamed?". Maybe I think the first step is allowing shame to enter into things when you think about your nation, instead of a quasi-religious patriotism.
With corporate interests.
And of course we can’t make honest claims to democracy until then either.
If the congress is unable or doesnt want to draft a bill to stop predators from milking money off of your data, then that money probably ends up in their pocket some way. Or at least some of it.
Please dont quit your job for the sake of your security - food, shelter, etc. Move these assholes out with next election. Vote in young people that are probably as angry about this shit as you are, in hope they won’t sell out their soul.
You should reach out to a venture called Equifax. They are providing customer alerts for data breaches and a premiere data protection service.
Your imagination is working against you here. The obvious and well-known reason that congress is ineffective is they work for the private sector, who is the disease; not the cure.
Here you go, first result in Google:
https://morningconsult.com/2018/01/16/months-after-data-brea...
> Average person saw Equifax commercial on “hey be smart we will keep your info safe with alerts” and thought “wow this company cares about my data” when its precisely opposite.
The result you cite is a general consumer favorability rating for Equifax, which is different than this particular claim. People who didn't hear anything about Equifax and Congress are included in the general consumer poll. I'm not trying to nitpick, I'm just pointing at a lack of data for this particular claim.
And yet, when GDPR tries to address the issue, HN is full of "blocking the damned EU users completely" and "stop stifling honest companies".
I mean, I'm a "tin hat" privacy nut in the USA, but that doesn't mean that I'm a fan of 100% of the GDPR. It has plusses and minuses. It'd be nice to have a conversation about them.
Absolute liability for data losses. Exactis lost 360 million peoples' data. They should be able to (a) form a class and (b) extract money damages from Exactis without having to prove specific harm, which is difficult to do with data loss.
A good model is Illinois' Biometric Information Privacy Act [1]. Broaden the the definition from "biometric identifier" to a longer--but still specific--list. If you want to get fancy, create a regulator who can add things to the list after a public hearing. (The specificity avoids GDPR's "what's personal data?" mess. The public input mitigates the risk of unintended consequences and corruption.)
[1] http://www.ilga.gov/legislation/ilcs/ilcs3.asp?ActID=3004
Well they do. Our government takes money through fines and taxes and uses it to build infrastructure and provide services.
> which would make sense with personal data being leaked.
My preference would be that personal data not be leaked at all. Ideally the warnings and fines kick in long before that happens.
> A fine also misses companies who are "doing what the law says" but still have some horrible flaw anyways.
What example are you thinking of?
The GDPR is quite broad and open to interpretation by both sides.
> If you are _genuinely_ responsible for the data, meaning if something happens to it you are liable for it, then you often take more care of it above and beyond, than for simply complying with rules.
That's what the GDPR does.
Requiring people to lawyer up to make the company responsible is far weaker.
Using fines to fund public services creates perverse incentives though, especially where the fines go directly to the agency that brings the case.
> Well they do. Our government takes money through fines and taxes and uses it to build infrastructure and provide services.
That's only true if you consider the public at large to be equivalent to any individual member of the public, or if you believe only the government is "injured" by a data breach.
If I stole all your money and repaid it in fines to the government instead of directly to you, would you consider the matter settled?
Nonsense.
> If I stole all your money and repaid it in fines to the government instead of directly to you, would you consider the matter settled?
I mean, that's typically how it works.
People get robbed by people who don't have the ability to directly restore what they've taken, so the state takes them into custody and makes them a productive member of society.
Would I consider the matter settled? Gee, I've seen some really stupid arguments on the Internet that have made me wish I could punch someone over TCP/IP, but while I'm wishing I'm not going to wish for that either.
Can you please detail why paying a fine to the government is the same thing as paying a fine to the people injured by a crime?
Me too! But not at any cost. This discussion involves thinking about scope (both in who and what is regulated), penalties (both in frequency and magnitude) and pre-emptive enforcement, if any. The trade-offs are far-reaching. A conservative approach is prudent. (It's also politically resilient.)
> GDPR is quite broad and open to interpretation by both sides
That's a sin and a virtue.
> Requiring people to lawyer up to make the company responsible is far weaker
This, too, is a sin and a virtue. The sin is it may allow bad deeds to go unpunished. But presently, everything is going unpunished. The virtue is in its prudence. It's unlikely to cause systemic harm, and we can observe its case law to more-precisely draft the next wave of rules.
And what is this "any cost" rubbish?
Replace EU by "the data/privacy regulator of the country in question"
Reporting requirements. If you find out you're breached, you have to notify everyone involved--plus their states' attorneys general--within N days. If you find out you're breached and fail to notify at least one attorney general, that becomes a criminal liability for those who knew but didn't act.
I was working with Albany on a law in this form (notice only) after the Equifax breach. It was tabled due to lack of Equifax-related outreach from voters.
I suspect this is because the very people who would be the most vocal about this issue are also the most politically cynical, and would never think to reach out to their representatives. That's a damn shame, if true.
Of course, "responsible" and "data aggregation company" rarely belong in the same sentence...
For example, Europe was first on texting on the mobile network while the US (single country) took years to come to a standard.
I think it will be the same with regards to GDPR. You (US) will discuss this for years and come up with a different law.
But after going several answers deep you still haven't listed any specific complaints and instead complain that nobody discuss them. This really make no sense.
So, feel free to explain what specific things you dislike, why, and how else you would have done it, and then people would be able to discuss them with you and exchange opinion.
Saying "it's not possible to talk about x" when you don't even try to really isn't the way.
The work sucked, but I was more than happy to help our customers get their data from us.
No one lost your data, they still have it, but someone else made a copy.
That emphasis is twofold: 1) they can do it again, because 2) they didn't lose anything.
The corollaries being that their incentives aren't aligned with the people whose data is leaked, the company don't need to spend on avoiding leaks because they're not harmed beyond a little (bad) PR.
The pedantism is unhelpful.
You can't stop data loss until you can guarantee platform security. You can't do that until you prevent developers from creating bugs and security flaws in the first place. You can only do that unless you have either perfect tools to catch all the issues or a perfect testing regime.
It's basically an unsolvable problem.
If the problem is inevitable on some level, then why isn't insurance to cover that eventuality required?