[1]: https://www.quantcast.com/privacy/data-subject-rights/ [2]: https://www.quantcast.com/privacy/
This is probably a dark pattern disguised as a mistake.
They will almost certainly satisfy your request (even if you don't truly live in California or the EU) because there are significant regulatory repercussions for not responding to legitimate requests. Or at least that's how it works at the big company I work for.
I can't speak to Atlassian specifically, but at sufficiently large companies, privacy@ emails tend to get routed directly to internal compliance teams, which may be operating under/within the legal org or just using a playbook legal has previously signed off on.
Legal@ has a good chance of being monitored by someone else. Worst case they route it back to the appropriate team and you continue getting stonewalled. Best case, the new set of eyeballs on the conversation has a very different view of the legal risk of your stonewalling experience, and you get what you want.
I haven't tried the above for compliance requests (as I'm not in a jurisdiction covered by GDPR or CCPA), but general BigCo experience has taught me just how variable responses from legal can be depending on which particular lawyer covers it[1]. Every lawyer evaluates risk in their own way, based on their experience, understanding, and conservative (or not) predilections. Simply having your correspondence seen by a different set of (legal) eyes could be enough to get a more satisfactory outcome for you.
[1] Or in this case, if the legal team sees it at all. Which may not be the case for privacy/compliance requests, if they've been delegated to a purpose-specific team that's operating off of a playbook.
Her answer was that she provided her cookie ID to Quantcast and then asked for any data associated with that ID. She also promised me to include that information in the article to prevent confusion, but she never did.
Ironically, Quantcast only knew her real identity after the request.
To Quantcast she was just a cookie with some events that ultimately indicated she might like x and has shown interest in buying y.
Sorry if I'm being a daft punk.
[0] https://www.privicy.com [1] https://www.privicy.com/legal/privacy-policy
Please consider referring to it as spying over theft and PII about you, as opposed to your PII?
Part of the server logs may be about you but are not yours per say.
Better to assume all PII and PI even if not identifying, belongs to the user. GDPR is explicit on some of this and not on others. Shared information, or that deemed necessary, won’t be deleted on request for say Uber/Lyft. There is a financial transaction and a driver etc, they won’t delete. They could sever the link to your profile though. Facebook offers something like this, but don’t do it. You will never be able to authenticate yourself again, and they will keep building the “anonymous” profile. It’s complicated for users out there...
I agree from a liability standpoint, from a company's perspective. From a user perspective, better to assume all information that can be captured will be, it will eventually be available to all humanity and it doesn't belong to you.
'server logs' fails to account for how that data is used which should explicitly defined. Failures to do so is misappropriation. A good litigation firm couls retire by challenging reckless companies on these grounds.
I guess this is where our opinions differ. In order for them to be absent the right to collect it you must force them to forget. That's where it doesn't seem like your information, after all they need to erase it. I'm all for legislation to regulate it's use.
Not sarcasm, we issue GDPR requests from an app on device, and you can request data (back to your device and not through us unless stated). Deletion requests are done as well. Data brokers, as a group, are obviously very anti-consumer, and getting them to comply in CA has been a huge headache (most simply do not). Prop 24 should help, so it’s going to be a long burn for consumers to take control. CCPA made hiring an agent (like us) explicit, but almost no one accepts that at the moment.
Alright, that's good, because I would really love for there to be a service that would streamline the way I request data from service providers or request the deletion of data connected to my account, as well as the account itself.
However, your site says:
>> We import and analyze all of your data across your online accounts and give you an audit and a plan of action.
Doesn't that mean that apart from all the, possibly bad, actors out there that have gotten their hands on my activities _you_ are now also in possession of PII connected to me? How does that improve things for me?
And yeah, we don't want to become a honeypot for what is the largest profile on you -- the combination of all the others.
It's enough to email from the address thats associated with the account. Generally speaking.
Requests for information should only be fulfilled with a notarized identification verification. The potential for security breaches here is massive.
Under GDPR (Europe), if you send a request, the company must honor it unless they have reason to doubt your identity, in which case they must ask for follow-up. Under CCPA (California), they are only obligated to honor "verified" requests. There's a range of what counts as verifying, from just being able to log in to your account on the low end, up to providing 3 pieces of matching data on the high end.
The company is obligated to tell you what data they have. They are not obligated to go out of their way to make connections, though, so you're better served by providing as many identifiers as possible (like account numbers).
What do you think they'll do with a cookie id associated to a few events?
Source: I worked on these products at Quantcast.
Many people (especially on HN) think that this kind of data collection is unethical. How do you feel about that and did you like working on it?
I did enjoy my time at Quantcast. The dataset is used for more than targeting advertising. For example, Quantcast's offers a free analytics product that uses the same dataset.
I am conflicted, and my view on data collection more broadly is more nuanced than what's in this comment. For this kind of data collection specifically: On one hand, it's how the entire publishing industry has built their revenue model. And I like news, sports, content, etc. On the other hand, it's creepy for a 3rd-party service that I've never heard of or interacted with being able to infer traits about me based on my browsing patterns, and then sell targeted advertising to yet another company I've never interacted with. I use an adblocker specifically for this reason, despite running an analytics startup.
I've only done this for deletion of data by the way.