Formal GDPR complaint against Google’s internal data free-for-all
brave.com
brave.com
I hope they continue doing more cool stuff and measures like these don't end up limiting any future developments.
If anything I just wish I could more easily see what internal data all the advertising companies have on me. I'm sure they know more about me than I know about myself.
It's impossible to know everything that they've actually done with your data, so I don't see how you can maintain that they've been responsible with it.
I've started reading "privacy agreement" for Google's "do not track me" browser extension the other day and it just seemed grotesque.
a) The law states they cannot do this arbitrarily and most of us may not want them to do the 'free for rall'.
b) I doubt that the 'free for all' produces many benefits beyond targeted ads.
Seriously curious, what 'cool stuff' does Google do today that fundamentally relies on this 'free for all'?
Traffic information is probably one nice thing that requires the sharing of data. We could totally narrow the kinds of information shared, and on what basis, quite a lot with that one.
What else?
https://www.google.com/settings/ads
https://myactivity.google.com/myactivity
One arm of Google might be doing good things, but another arm might do bad things, like optimize engagement, ad clicking, manipulating buying behavior and stuff like that, or even worse.
I have worked in regulated markets for quite a long time. I can understand that many companies do not understand what it means to be compliant. For many years the tech industry has avoided many requirements that affect other engineering companies. Software is at the core of our society and cannot have a free pass any more. Now it's more important to be reliable than to move as fast as possible. I hope this is the end of the era of move fast and break things, software is now too critical for that.
One can dream.
Facebook, YouTube, etc spreading of missinformation is something that needs to be fixed for democracy to survive.
Apps like Uber that do not recognize its own employees and follow the strategy of running faster than laws are also a good example of something that is damaging our society.
Addictive loot boxes that prey on teenagers is another ugly one.
I will need more time to think to make a better list, but these are some of the ones I think need stronger regulation.
Re just the part about running faster than the laws: As best as I can tell, app based taxis exist solely because Uber ignored the laws - and good (in some cases) that they did as the laws were designed to protect the entrenched businesses that had no incentive to change regardless of how well they were working. Anecdotally, I've seen a huge increase in people taking Uber or Lyft to or from a happy hour when 10 years ago those same people would likely have decided to drive because calling a traditional Taxi was so much of a pain. Ignoring the laws is a weak criticism when sometimes that is the only way to achieve progress.
No comment on how they treat their employees - that is its own complicated issue that I won't comment on here.
https://en.wikipedia.org/wiki/Copyright_Term_Extension_Act#/...
It was a blow out, the average person like yourself is too politically uninformed to know what to do. The only way out would to get rid of DRM entirely and reform IP law so that we owned our machines and software, you can't have privacy if every piece of software is client-server oriented like PC games have become over the last 20 years.
The videogame industry has been stealing PC game software since the late 90's starting with them rebadging PC RPG's they had in development as mmo's to confuse a lay public, after the early successes of Ultima online, everquest and guild wars 1, that lead us to Valve dropping steam in 2004, a piece of corporate malware wrapped around games. From 2004 to 2009, was the game industry cleaning house as PC games they had in development were either rebadged mmo, or were given steamworks integration, this lead to EA and ubisoft to make Uplay and Origin, more malware, client-server oriented bs.
IF you don't own the software you have no rights to your machine and your software can now be disabled remotely.
Going from dedicated servers, complete software ownership in teh 90's to this locked down dystopian hellscape of steam, Epic game store, Ubisoft Uplay, Bethesda launcher, EA's origin, and Battle.net launcher for activision games.
I have to wonder what you are smoking to think regulation will work this time, when everytime IP law came up for reform it was expanded everytime to remove basic rights of the citizens.
Until then, it's just one competitor accusing another competitor of wrongdoing on their own web page.
Does it bother you that a commercial entity with "a dog in the fight" is asking you to take action on its behalf?
I'd like to understand what drives decisions around these parts.
> Please don't comment about the voting on comments. It never does any good, and it makes boring reading.
> In the event of rejecting trackers, the user is constantly invited to make a new choice through a pop-up window, while the same does not apply if the user accepts trackers, in which case their choice is maintained for a longer period.
https://iapp.org/resources/article/cookie-guidance-from-gree...
That's not necessarily same context, but the main point still stands: By law, if you're invoking "consent" as the legal basis for collecting and processing data, consent must be freely given and as easy to withdraw as to provide. Provoking people to change their mind from "no" to "yes" but not the opposite is not considered to be freely-given.
That doesn’t make it wrong but you are definitely seeing a marketing push.
This is a little disingenuous to the point of almost gaslighting.
You need to 'click on a PDF' because it's 60 full pages of dense data in a spreadsheet.
It's 100% reasonable to provide a link to that data, it's exactly the right thing to do.
It's also fully reasonable to provide links to tweeting about specific issues, that's how information is shared in 2020.
Though on a level it's 'marketing' - the claims are that Google is in existential violation the law, this is not Walmart proclaiming they have 'lower prices and better service than Target'.
It 'won't work' for me because I hate twitter and don't use it, it 'won't work for you' because you use Mastodon, but that's fine, 'Twitter' is the ideal, broadly convenient choice.
Category: Accounting
Purported processing purpose: “purposes such as accounting...”
Other discoverable processing purposes: “…such as…” is vague language that may conflate or omit many distinct processing purposes.
Data collected: BLANK
Data shared externally: BLANK
Explanation and examples: For example, when you purchase apps from the Play Store or products from the Google Store. Purported legal basis: Unknown
Give me a break, the legal reason in the first column. To me obvious reason this is a 60 page PDF is because they hope people don't open it and discover that they are full of shit.
In GDPR terms, the "Legal Basis" is one of the following six values[1]:
Vital Interest
Public Benefit
Legal Obligation
Performance of Contract
Legitimate Interest
Consent
"Accounting" is not a Legal Basis.Several might apply, including Legal Obligation, Performance of Contract, Consent, or Legitimate Interest. Stating the Legal Basis for processing is one of the requirements under the Right to Transparency[2]. Among other things, the Legal Basis affects other rights the Data Subject has. E.g. the Right to Erasure is much stronger for data collected under Consent than Legal Obligation.
On the face of it, it looks to me that Brave has a point: Google is not complying with some (frankly, rather simple) transparency requirements.
[1] GDPR Article 6 Section 1: https://gdpr-info.eu/art-6-gdpr/. [2] GDGPR Article 13 Section 1(c): https://gdpr-info.eu/art-13-gdpr/
[1] https://policies.google.com/technologies/retention#purpose-f...)
Accounting for SEC filings or whatnot are legal obligations. But processing an individual payment is also probably part of Performance of Contract, and Google explicitly mentions fraud detection on that same page, which is usually Legitimate Interest. To say nothing of whether that financial data is compiled into a user profile or used to train a model in some way.
No, this is unreasonable, essentially false.
It's a very comprehensive recording of the specific issues relevant to all of the Google properties that they could find.
It's perfectly reasonable that there are 'empty columns', it's a table of data, not a 'communications document'. Data won't apply in many cases.
Far from being 'full of shit' - it's the complete opposite.
What the data demonstrates very specifically is that there are literally a thousand different places users are supposedly informed of their rights while being acquiesced, that it's all very opaque, that it's obviously not comprehensive for any person, and essentially hostile to reasonable user experience.
You don't know what gaslighting is.
They just want you to use their browser instead of Chrome's, and constant attacks on Google/Chrome is their primary marketing strategy (35 mentions of Brave on-page, Brave branding everywhere, giant "Download Brave" button at the end of the page, etc).
Google isn't the hand that feeds them because of chromium. It's the hand that feeds them because of Google's privacy track record. If they weren't so invasive, then there would be no reason for brave to exist.
Is it? Part of the point of open source is that you're not beholden to any individual contributor. They can't be cut out from existing code; I don't know if they try to roll in future code developments, but, if they do, then Google can't keep them out of those, either, without a license change.
I am skeptical of this being the case with Google's idea of "open source"; does anyone other than Google actually have any material say in any of its projects? Or is it like Apple's open source: code dumps with no path to upstream?
But another important part is that the code is there, relatively freely (depending on license), for others to use as they will.
In the sense that the parent meant his comment, this is the critical component of open source that matters. To put it in classic terms: don't bite the hand that feeds you.
- this complaint is lodged by an upstart privacy-based browser which directly competes with a Google product (Chrome) so they are not objective players here
- reading through the PDF linked in the blog post, it seems there is no "canary in the coal mine". It is a spreadsheet with a lot of empty cells and red backgrounds. The post and the facade of the spreadsheet scream "look at this, something's wrong" but the content doesn't match that at all. The impression is that they have found Google to be doing something wrong but the reality is that they want regulators to check and see if Google is doing something wrong. Is there presumed innocence in this circumstance (really asking here because I don't know)?
As with most things, the truth often lies in the middle. It seems to me at least that this is both a click-baity blog post and complaint meant to drum up media and press for Brave as much as it is a spotlight on Google's data practices. Both are bad.
I agree on this, but if there's a company trying to make a name for itself by attacking privacy violators, and if the benefits of that accrue even to people who aren't customers of the company, then I don't overly begrudge the company a little (or, let's be honest, a lot of) breathless self-generated PR in the process.
Google's speech model, for example, was bootstrapped on the audio collected from GOOG-411. Is the GDPR intended to prevent things like that? Then it's "intended" to hinder development of practical speech models the likes of which hadn't been seen from decades of research that lacked access to hundreds of hours of input from users asking real questions in real environments.
Me personally, I'd been waiting for the breakthrough that Google hit upon to get reliable voice recognition for a couple of decades.
Nobody has a right to know whether the highway is congested because your car may have been one of the counted datapoints?
That seems like a very arbitrary distinction, and I'm not sure how one arrives there. There are a lot of for-profit companies that build business around data analysis of things that most people could count (given time and inclination to do so) but do not, be it cars on the road or the average price of gasoline state-by-state. Is that a moral red-flag?
I think a blurring of the difference between "things that the government can do" and "things that a private company can do" is a very unfortunate (and also very deliberate) development in modern society.
To me, the distinction is far from arbitrary; it is fundamental. Democratic governments are elected, and at least nominally accountable to the people over whom they exercise their reserved rights; for-profit companies are generally accountable only to their shareholders, not to those over whom they exercise these privileges—and technically to governments, although governments seem unwilling to exercise much of that right of restraint.
(This is a response to your point about the distinction being arbitrary, not to your question about private companies analyzing data. If a dataset of which I am a part is used without identifying me as part of it, or after obtaining my consent to be included in it, then my qualms about it go away. If, however, the company gathering this information, while counting the traffic flow of which I am a part, decides to sell information about where they've noticed I like to shop to advertisers, then, yes, that's a moral red flag for me.)
What happens when the government chooses to lie about the numbers? What if it's doing so because the public has signaled it wants to be lied to (which happens from time to time)?
This is simply not true.
Google can absolutely obtain data from users in a manner that's transparent and clear for specific purposes.
They have 40K highly paid Engineers and $100B sitting in the bank. They have ample resources with which they can draw meaningful data necessary - but they'd rather not, if they can just use your data for whatever they want.
This is not really a problem. Quite the contrary, it's unusual for a neutral party to be the one lodging a complaint. The important thing is that whomever processes the complaint is a neutral/objective party.
I also maintain my general skepticism that Google's business model is illegal under the GDPR. If the regulators had intended to make Google illegal, I'd think they would have said that.
They would not have a "Purported Legal Basis: Unknown" column with a scary red background in their spreadsheet.
Delta and Southwest, say.
The amount of data Google collects about users is quite simply of unimaginable scale. Who sees this information at Google? Are they able to identify an individual and browse or analyse their online activity (which for millions of people will include some of their most personal and private details)?
Who has access to this data should be stated clearly in Google's Privacy Policy [1]. Instead we have this vague and generic paragraph:
"We restrict access to personal information to Google employees, contractors, and agents who need that information in order to process it. Anyone with this access is subject to strict contractual confidentiality obligations and may be disciplined or terminated if they fail to meet these obligations."
I'll repeat that this is a company that holds the private and personal online behaviour of millions of people, and yet the only detail they reveal about who sees that data internally and which user details are exposed is the purposefully vague and unspecific paragraph above.
The fact that the "tech community" has never chosen to challenge Google on their internal usage of people data shows how little developers care about privacy (as this thread amply demonstrates).
The benefits of the surveillance capitalism business model are seeing business values being recalculated as business owners recognise the value of exploiting vast amounts of data collected in the pursuit of a purpose other than for which it was collected. Microsoft for example has been heading in this direction over the last few years through their acquisition of Lynda/LinkedIn, Github and Glint. I expect other SaaS businesses to increasingly exploit this opportunity.
Personally I support the efforts of Brave in this case and there are other potential targets that I think are vulnerable to a similar complaint. It will be interesting to follow the Irish Data Protection Commission's progress on this.
1) it fails, and the GDPR has some precedent to constrain its application in the future
2) it succeeds, and Google actually pulls out of the European markets completely. Internal responsible data-sharing and data-aggregation is extremely core to Google's entire business model (it is the "special sauce" that drives the entire application suite, from search to speech), and if the GDPR is incompatible with that business model, Google is incompatible with Europe.
Google tends to be a long-term-thinking-oriented company, and requiring them to silo internal data (under the rules of a third-party oversight, not their own rules) strikes at their ability to do R&D. They know that in the long-term, the survival of a technical company is hinged on what they deliver in the future, not what they're delivering now.
It's super implausible that Google will pull out of Europe (the EU at least), because they are forced to implement the laws.
It's as likely as them pulling out of the US because they are forced to refuse to deal with countries under US sanctions.
... and China.
And the refusal of the ability to deal with countries under US sanctions doesn't strike at the core of Google's R&D techniques and resources.
If the restrictions prove unreasonable in practice, it's a question that I'm sure those companies will revisit.
Is that still true? The number of products they've launched and abandoned, sometimes in the same market (like messaging), seems to indicate they're more an in-the-moment company to me.
As long as Google doesn't have to pay their lawyers more than what they are earning in the EU, Google will happily continue doing business in the EU. And if I had to guess, lawyers make up 0% of their costs in Europe and anywhere else, when rounding to the next integer.
I see suggestions of various companies leaving the EU far more often these days than suggestions to leave China. It seems people on HN consider GDPR a more serious danger to justice than, say, "reeducation" camps for unliked minorities. Go figure..
I also suspect that Project Dragonfly (Google's re-entry into China) might've been partially to blunt the effect of a European exit - Europe hasn't really liked Google since about 2010, and the regulatory climate keeps getting worse for them, so at some point it'll become not worth it for them to continue. They already pulled Google News out of several European countries when regulations made it too much trouble to continue offering the service, and then reinstated it when the regulations were rescinded because local publishers realized how much traffic they'd lose if Google News no longer featured their articles.
California is trickier because many key employees work at their Mountain View, San Francisco, and Santa Monica offices. I suspect that that's changing - they've been expanding rapidly in offices in other locations, perhaps as insurance against this (and the rising cost of living in California), and there's probably less of a concept of a "key employee" now that the main services are written, not really innovating, and mostly in maintenance mode.
* google appears to make all of our data available to most of its developers
* we complain that brave wants to boost its reputation
wtf, seriously, wtf?
I mean, granted, brave sucks and wants to have an easy buy-in to some folks, but still: what's hiding behind this is huge.
If I were google I'd buy brave for this kind of burying.
Einstein was right :)
Just one small thing to consider: if even one person of google was a federal agent (of an offending country). Fill the missing parts of the sentence.
And yes, as much as I despise the EU in its current form, that's the intention of GDPR: to prevent spilling personal data into a pool of people with potentially malignant actors, and, if this happens, to be responsible to full disclosure.
@dantheman: I guess you still won't be considered to be hired by google for this post.