As an initiative against mass surveillance, entering all your personnal information on a website isn't the smartest thing.
As an initiative against mass surveillance, entering all your personnal information on a website isn't the smartest thing.
[1] The direct link to this ECI: https://europa.eu/citizens-initiative/initiatives/details/20...
It still does: see, e.g., the "No Profit on Pandemic EU" initiative [1]. Not sure why this one does the signature collection on its own domain, it sounds suboptimal.
It's usual to ask for addresses, at least in the UK, and if the petition is aimed at being submitted according to a legal process there may be requirements that signatories be residents or constituents.
Sure faking addresses is not much more difficult than faking names but then I suppose there's also a trade-off with complexity and cost and they also ask for ID data.
The only impact is for real people, that will have to disclose additional private information.
weird
with the difference that the bank is relatively trusted entity backed by shitton of formality
meanwhile crypto exchanges seems to be more shady orgs with 30 yo CEOs
This originates from what was at the time the least controversial part of the Patriot Act. If you want to be able to exchange cryptocurrencies to a Visa/Mastercard, the service needs your ID, regardless of where you're from.
If you select Netherlands they’re at least informed enough to not ask for the Dutch equivalent, the BSN. It would be against the law for them to ask, process or store it.
If you try the form for different countries, in a lot of cases they don’t ask for that particular identifier, because they legally can’t, and ask for address information instead. That’s still a little creepy, but a whole lot less.
>>"By itself it doesn’t help in that context since residents get one too."
At least in my country that's not true. The resident but not citizen number is different.
- Select the country, get redirected to the sovereign identity auth platform
- There you can log in/provide the details in the sovereign run platform.
- The sovereign run platform validates and sends out a unique anyonymized hash for the user which the platform can store to keep count.
This can be used for other validation purposes as well which are not limited to just petitions and the data returned by the platform can be scoped to the requester sort of like Oauth.
To make it even better for privacy, you can introduce the concept of an application identifier which will be unique for petition/form etc. The hash will be unique with the application identifier scope, so outside platforms can't correlate individual identity through multiple petitions.
Any idea why they would treat Poland differently? Austria, Belgium, Bulgaria all also seems to ask for a document number and not an address.
Where I'm from you never submit your national ID number (13 digit number given to each citizen once, never changes), but you do submit the "number" of your national ID (9 numbers and letters, changes when you move places or every 10 years, whichever comes first) when signing any petition.
Depending of your country they ask for different data. For instance, for Finland they ask the physical address but for Belgium only the national ID number. I suppose that there is not such number in Finland or it's illegal to ask for it.
There is a link in the form to the relevant regulation. So, the website looks legit. Of course, that doesn't mean that it's legit but my gut feeling it's that they are.
Some key facts:
- "ECI signatories: your full first and last names, country of residence and date of signature. Depending on the signatory’s nationality, we will also collect a combination of the following data: residence (street, number, postal code, city, country), date of birth, national identity document type and national identity document number." This seems to indicate that the data requested is dependant on the country you live in. So blaming the organization is a bit unfair.
- "Your data will be stored by the group of organisers for a maximum retention period of one month after the submission of the initiative to the European Commission or 21 months after the beginning of the collection period, whichever is the earlier. It might be retained beyond these time limits in the case of administrative or legal proceedings, for a maximum of one month after the date of conclusion of these proceedings." They will remove your data whatever happens.
I've signed the petition and handed over my the equivalent of PESEL. I did that because I understand that if we want to enact change we have to be more than a signature on an online form, we have to be a living breathing person and not just another email-address in a database. They can sweep gme_diamondhands_6969@whatever.com under the rug rather easily but along with data that proves that I'm a citizen that becomes much harder to do.