Study of Thousands of Dropbox Projects Reveals How Successful Teams Collaborate
hbr.org
hbr.org
Wait, Dropbox gave away non-anonymized data to a third party and they then anonymized it. Wow, what could go wrong? Just thinking of the endless possibilities of where all that data is now... Its deeply troubling how much unwarranted trust there is when it comes to handling of personal data.
Dropbox put Condoleezza Rice on their board, who supports warrentless wiretaps [1].
I deleted my account when they did that. Not so much because it would have any direct effect, but because it’s clear that we have differing views on how user data should be treated.
I surprised that people are shocked by them treating user data like this, it’s absolutely in character.
https://www.dropbox.com/terms#privacy
It certainly says the words:
"We may share information as discussed below, ... Others working for and with Dropbox."
> Dropbox gave us access to project-folder-related data, which Dropbox had aggregated and anonymized,
> we and Dropbox employees could view no personally identifiable information
> Editor’s note: We’ve clarified this article to say that Dropbox anonymized and aggregated the data before providing it for this analysis.
Truth be told I've also been dissatisfied with the price of the Plus and Pro subscriptions, relative to what they provide, with their support and their direction, so was looking for motivation to move.
This is just icing on the cake.
*not for long, perhaps
"Law & Order and the Public Interest. We may disclose your information to third parties if we determine that such disclosure is reasonably necessary to: (a) comply with any applicable law, regulation, legal process, or appropriate government request; (b) protect any person from death or serious bodily injury; (c) prevent fraud or abuse of Dropbox or our users; (d) protect Dropbox’s rights, property, safety, or interest; or (e) perform a task carried out in the public interest."
I would assume that this research fell under the "task carried out in the public interest" clause.
As in: a form asking the user if their information can be used in this way and giving them the possibility of opting out. Adding one more clause to the privacy policy doesn't count.
GDRP section 32
Consent should be given by a clear affirmative act establishing a freely given, specific, informed and unambiguous indication of the data subject's agreement to the processing of personal data relating to him or her, such as by a written statement, including by electronic means, or an oral statement. This could include ticking a box when visiting an internet website, choosing technical settings for information society services or another statement or conduct which clearly indicates in this context the data subject's acceptance of the proposed processing of his or her personal data. Silence, pre-ticked boxes or inactivity should not therefore constitute consent. Consent should cover all processing activities carried out for the same purpose or purposes. When the processing has multiple purposes, consent should be given for all of them. If the data subject's consent is to be given following a request by electronic means, the request must be clear, concise and not unnecessarily disruptive to the use of the service for which it is provided.
https://eur-lex.europa.eu/legal-content/EN/TXT/?qid=15323486...
Am I mis-understanding?
My guess is that they are using provision of service as the legal basis for processing, whilst relying upon the "public interest" clause in the ToS to justify the sub-processing by the third party.
There's some public interest exceptions, but from my knowledge it's not established that stuff like this would work under it.
It seems to me that an organisation the size of Dropbox would have a fairly watertight justification. However if the legal basis for processing is neither consent nor provision of service, then they must have done a pretty good job of obfuscating all PII (as the article says "...we and Dropbox employees could view no personally identifiable information.". If this is the case then this sharing of information may not even be in-scope of GDPR.
I'm not sure if the public interest exceptions would be a safe route to go down. The EU has made it clear that, like 'Legitimate Interest', the get-out-of-jail-free justification is going to be highly scrutinised.
EDIT: I have just seen that the article has been edited to say that the anonymisation and aggregation was carried out by Dropbox before being transferred to the third party, which kind of kills the discussion.
For the record: I'm not suggesting that what they did was ok, just trying to think about it from a GDPR perspective. Anonymising account information is great and all, but how can you be sure you've obfuscated all PII from information saved to file storage, unless you audit all that information - which in and of itself seems ropey from a data protection point of view.
It seems hardly necessary to share data with HBR so that Dropbox can offer file-sharing services...
Based on my reading here: https://ico.org.uk/for-organisations/guide-to-the-general-da... this does not apply.
However, to answer your question anyway - I don't believe you could justify the work as being in the public interest. I think it would be an extremely tenuous link and I think you'd be a fool to try and rely on something as flimsy as public interest if you're not a government body, or processing data on behalf of one.
I suppose I was taking a stab at understanding what their thinking was to see if anyone else could provide me with something which I had not considered.
"The principles of data protection should therefore not apply to anonymous information, namely information which does not relate to an identified or identifiable natural person or to personal data rendered anonymous in such a manner that the data subject is not or no longer identifiable. This Regulation does not therefore concern the processing of such anonymous information, including for statistical or research purposes." [1]
But seriously, as an example, I know people that share sensitive personal information with their accountants at tax time using Dropbox. Would suck for any of that to be made available to any third parties.
Then imagine you have a second folder with 117 subfolders with another pattern like above.
Now imagine that the first folder structure matches a torrent of embarrassing pornography and the second appears to be a superset of a project published to GitHub under your name (i.e. with some directories being gitignored)
I've stored non anoynmized data on Dropbox as part of my own research. IRB gave me permission to keep that data and my consent form explained it to participants. We were all working under the assumption this type of sharing by Dropbox was impossible. My school's IRB does not allow the use of Google drive for nonanonymized data storage based on just this type of concern.
If you don't want your information accessed--run your own servers, people. That's your only option.
This seems like heaven for industrial espionage purposes. Just because there's some anonymisation doesn't mean that the metadata is useless. I sincerely hope they get GDPR'd over this.
"which we [...] anonymized" doesn't sound like there was any anonymisation.
Plenty of universities work (often in collaboration with national laboratories and/or with corporations) on work that's far more important and critical than many "real for-profit businesses".
From there, you could potentially identify other tools those people are using or embarrassing folder structures (e.g., deep folder tree structures people used to use to primitively conceal porn and other secret files, or signature folder structures for embarrassing repositories like erotica archives, collections of extremist literature, or piracy tools).
Hopefully they'll release more info and some sample files (like for themselves).
For the past two years I've using a free open-source encryption app called Cryptomator (https://cryptomator.org/) for my Dropbox folder without problems. The only caveat is the mobile apps aren't free.
Another Dropbox encryption app is BoxCryptor, but I quit using them when they went subscription-only.
However they decided they needed a consistent revenue stream so they renamed their software "Boxcryptor Classic", stopped updating it, and now users have to pay $48/year to get features previously available as a one-time fee. This was about 2 years ago, by now they've probably scrubbed all references to the "Classic" version on their website.
To be fair the subscription version does have new group/admin features for multiple users or businesses.
This is just a simplified explanation. The actual deduplication is done in smaller blocks.
If you want client side encryption with Dropbox, you have to add a layer before the Dropbox client sees your files on your system, using Cryptomator or Boxcryptor or encrypted volumes with Veracrypt, etc.
Or you could switch to other online backup/sync services that claim to have client side encryption, like SpiderOak and a few others.
"How successful teams collaborate"... wait, I meant "the average number of users who update the same directories in Dropbox from institutions that tend to have influential research.
Sound insights. Make sure you're collaborating with no more than 2.3 people or else you'll have to move your research projects over to Yale.
Yeah, that caught my eye too especially the missing RMS so we could see whether the difference between 2.3 and 3 is significant.
I agree that senior researchers probably bring valuable experience and insight to research projects, but I don’t think you can validly arrive at that conclusion from the number of times they open a doc in Dropbox.
- Dropbox denies giving researchers non-anonymized user data
https://www.zdnet.com/article/dropbox-denies-giving-research...
Regardless of whether or not the GDPR applies to these people, it's a useful tool to illustrate why this kind of data is still wrong to share (especially without any kind of consent!).
Doesn’t require any 3rd party addons.
I really can’t believe they shared this data. Universities do work for businesses all the time. Imagine a folder of research subjects organized by geo/age/sex then full patient name or SSN, under a folder called HIV survey or something. I mean really?
Analysis where the majority of the projects have less than 3 people tells you nothing on how to collaborate.
Wow, can't HBR afford a proofreader?
Is there some way to address this when it does happen? Or is it just a matter of the right people being involved?
In the latter case, I think that means you adjust process to be lighter. In tbe former, there is no procedural fix, only hiring fixes.
Also, there's more to true collaboration than sharing files.