How messed up is it that random 3rd parties collect and assemble all this information to begin with, leaks aside? Sounds to me like all this data fell into unscrupulous hands way before any hackers may have found it on the public internet.
How messed up is it that random 3rd parties collect and assemble all this information to begin with, leaks aside? Sounds to me like all this data fell into unscrupulous hands way before any hackers may have found it on the public internet.
Or often, as in this case, collected it and stored it carelessly so someone else could get in and use or share it at will.
Edit: Added main company link providing this API [1]
[0] https://app.livestorm.co/api/v1/utils/email-enrichment/?emai...
This specific API seems pretty innocuous. They're not doing black magic, it's just aggregating data that people willingly put out there about themselves.
I'm sure I'm out there in many datasets with stolen (or just "shared") information.
That's has always been illegal in my country though (you can't even keep a record of people with pen and paper), and now with GDPR would of course be illegal with actual consequences if it contains data about EU citizens.
which, as an EU citizen, I can confirm it does
And if they try, any American court will be very leery of setting the precedent that Brussels can tell Americans what to do in any sense, particularly with respect to data stored on their servers.
I imagine the company using them will want to recover financial losses they incur after getting reamed by whatever european Data Protection Authority decides to go after them - especially if the culprits did promote themselves as being GDPR compliant.
The point of the EU's strong data protection rules is to have accountability - and it will fall on someone along the chain that caused the mess. Companies can't be allowed to completely disregard how they collect and store data and then go "Oops, haha sorry about that!" when the shit inevitably hits the fan, and just continue their business as usual.
enrich.email also does the same, though.
There’s also https://fullcontact.com.
In the end they all just search and scrape social media profiles and gravatar.
What is this URL: This is not a public API route, it is a proxy to a service called Clearbit to enrich professional emails with public company and person data from multiple public sources such as AngelList or LinkedIn (cf https://clearbit.com/enrichment and https://clearbit.com/our-data).
By using this route, you are using Clearbit with our credentials. Most importantly, we don’t store any data on our end when accessing this route. We don't own this data, it is stored on Clearbit servers.
Why are we using them: We entered in business with Clearbit to help our users get more insights on their webinar sign ups from public data sources.
Are they GDPR ready: Clearbit is GDPR compliant (cf https://clearbit.com/gdpr). You can claim your data here: https://claim.clearbit.com/claim.
We took all the steps necessary with Clearbit to ensure our process was GDPR compliant. However, this information makes us double guess it. Therefore, we are revaluating the compliancy of this specific process and in the meantime, we have deactivated this route.
Your GDPR compliance page is absolute crap. Ditto your Privacy policy. https://clearbit.com/privacy
For starters:
At what point does this site should that I have given consent for you to process my data? Who are the third parties that have given you my data?
20 years ago my first roommate worked for a company that did direct mail marketing, and they regularly engaged a "cleaning" firm that would scrub and update their mailing lists.
This company had a huge databases of information on people (name/work/address/DOB/income/etc) and they would send them data and they would clean it up.
Now they would not give them any new data, they could only update records they already owned.
Back then in Canada there were apparently only a small handful of well-known cleaners like this who traded on their reputation for accuracy and dataset completeness..