Having worked on those products (and in some cases, written the terms), I'd say so.
That is just one example which was made public and was done intentionally. There's potentially plenty more cases where it's either done but concealed (because of how many factors go into ad targeting it's often impossible to categorically prove/disprove which data was used to target an ad) or done by accident from earlier code that just assumed all data is fine to use for ads (or that the new product which shouldn't share its data for advertising purposes was accidentally storing data in the same place as other products who do share data for advertising purposes).
Why should we trust companies that have a business incentive to break their promises? If Google's biggest revenue stream is ads and that requires personal data then I wouldn't trust any of their promises not to use some personal data unless I can 100% audit all the code myself and prove that it's indeed that code that is running in production.
Because the prevailing voices our country have spent the past half-century telling us that government is Bad, and business (and greed) is Good, and enough of us have bought into the idea that we've systematically dismantled enough of the systems that keep corporate greed from running amok and ruining people's lives that they now effectively run large chunks of government (eg, see ALEC).
Because too much of our society—especially in the tech sector, and more especially in the parts of it that are overrepresented on HackerNews—has come to worship wealth and the wealthy, and to believe that they should be allowed huge amounts of latitude to do what they want with their wealth.
If I had to choose a stage of my life to become part of the public records, I'd definitely pick my childhood over my adulthood.
1) School is a mandatory part of life for every child, therefore increased scrutiny and high standards are warranted. As an adult, you are free to go if you ever disagreed with your employer on ethical grounds. But if children were forced to participate in a dubious (in terms of privacy) online service, they really have no choice other than to accept it (going to another school in the same area is hardly a realistic option).
2) In general, it is understood that children might not be able to grasp all consequences of their decisions. Even if children had a choice whether to accept their school's mandatory online services, I don't think they can really give consent considering they might not understand the ramifications of their personal data ending up in the wrong hands.
Reading your question again, I don't think children need a higher standard of privacy than adults - rather, I think the point is that regardless of the standard of privacy, children can only give limited consent.
that doesn't sound sensible unless you are assuming at adulthood you would be out of public records, in which case sounds great! because your adulthood will hopefully be a lot longer than your childhood. On the other hand I don't think an advanced society would work with that model.
Secondly - why do children need a higher standard?
People at different changes of their life are not necessarily the same people, a man at 50 might not be very much like who he was at 20. Unfortunately our society does not do much to support such a concept. It does however support the very rudimentary concept that things you did as a child should not follow you as an adult - when you have different legal responsibilities and possibilities of action. So that is something that probably shouldn't be taken away.
Furthermore as a child is not fully developed in reasoning it is probably nice that things the child does is not part of their permanent record.
It’s presented as a contract mutually agreed between you and the service provider - you get the service; the provider gets the data. A legal contract.
But, in all systems of law that I’m aware of, you can’t make enforceable contracts with children.
This exists as a way of protecting children from making disadvantageous agreements that they don’t yet have competence to understand.
So, the service provider can’t use any contract as justification for handling personal data of children.
This leaves the service provider without legal justification and then calls their ethics into question.
In most (all, I think) US, contracts with children are generally legally valid, but voidable by the child. This means the child (or the child’s guardian) mau cancel the contract before performing any obligation. It does not mean that once completed, the exchange can be retrowctively invalidated, though.
I'm going to assume without being a lawyer, that sending out school data is a violation of Federal law.
> E.g. for protected government data, you have to run in amazon's govcloud.
Not really. Many .gov workloads are fine in commercial cloud. It depends on your compliance requirements. Sometimes there are downsides too - some services aren’t available. At one point, Azure Gov required separate credentials.
https://aws.amazon.com/service-terms/
The GDPR DPA does a good job of encompassing the entire extent of their data use:
> AWS will not access or use, or disclose to any third party, any Customer Data, except, in each case, as necessary to maintain or provide the Services, or as necessary to comply with the law or a valid and binding order of a governmental body (such as a subpoena or court order)...