Germany: Data retention to be abolished
tutanota.com
tutanota.com
[0] https://en.wikipedia.org/wiki/Electronic_Communications_Priv...
It's actually super weird, because US culture has a strong component of distrust of government. But the government is pretty good at making people fear crime, terrorism, etc., which allows them to get the people to "trust" them with mass surveillance and other privacy invasions.
That is such a horrible idea, I go on vacations longer than that. My Dropbox should be deleted if I don't log in for 4 months?
"Sorry, you can't log into this NCAA bracket website because you haven't used it since last year."
"Why would I use it more than once a year?"
That's the bigger injustice, tbqh.
I completely agree.
I will take this even further: that company should break a data retention law in order to hold ambiguously abandoned data that might be important to that user.
Further: that company should safeguard that data and protect it from unlwaful intercept or surveillance just like the data of any other paying customer.
Finally: no additional costs should be accrued beyond the original terms for this safekeeping of data.
Please do not abuse this.
You seem to just not believe in morals I guess? ;P
Like, yes: the law says you can do something... but I am claiming it isn't moral to do that. You can assert your terms of service let you, but I am claiming that it wasn't moral of you to put that in your terms of service in the first place. (And to the extent to which the law requires you do the opposite, that is us arguing over what the law should say, given that the entire point of this thread is about a changing law.)
And like, the user of course should expect you to do the things you claim you will do, but I also think it is fair for users to expect you to claim you will do moral things in the first place. If you are going to pull stunts like deleting data users entrusted to you, hopefully your service is sufficiently optional and unimportant that they can just not use your service without losing out on anything at all in life.
I see you work in medicine. Your field collects data on people all the time and then hoards it from them. You take X-rays and then just put them in some filing cabinet. To get a copy of MY X-ray I have to argue with people about it and then I usually get some low-quality shit copy. Meanwhile, you purge your records and delete MY data because I somehow have the gall to not need your specific service for some number of years until I get old and suddenly wish I could get my X-ray and you destroyed it :/.
You should frankly be REQUIRED to give people their data to take with and not take it yourself, a step you can't be trusted to not put it in your terms of service that you get to both hoard it and delete it on a whim. If you must insist on holding it yourself, you should be required to have a trust set up that you make regular deposits into to ensure that the data you are holding will survive at least as long as all of your patients.
That's what I will claim is "moral", and to the extent to which either laws or the terms of service of your organization fails to match then the lawmakers, lawyers, or entrepreneurs are being horrible people. If you believe in a religion that has a place similar to hell, maybe that's where all of the people who push for, allow, or take part in stuff like this will end up :/.
You have this backwards.
They do not have such legal responsibility - and you are correct that their legal responsibilities are defined by laws, T&C, etc.
However it is for them, not you, to define their moral responsibility.
I believe that if you run (something like a safe deposit box) you have a moral responsibility to (make human decisions about burning the contents).
Also, have had similar experiences, and would be livid is someone deleted my data after only a few months.
I'd rather see my family photos leaked to hackers than see them purged from existence forever because I forgot to log in enough.
I found this sentence interesting, as it contained positive and normative statements that I disagree with, with a non-sequitor between them. You say that you have no contract with them, even though you agreed to some sort of 'user agreement'. Then you say that you forgot about it, and that makes your faulty memory their problem. They have to make sure your data is secure for you because you... just don't bother to pay any attention to where you're leaving it? Should they also be responsible for checking your password against known breaches, to make sure it's not compromised? Where does this end?
> and that makes your faulty memory their problem
It is not only memory that is flawed in humans. Hence the protective measures I'm proposing.
> against known breaches
What about the unknown ones? How do you protect your user's account when under GDPR Dropbox is the controller of the data? By sending mails ocassionally to update the password, to adopt 2FA, by locking account due to suspicious activity or to purge it in the end if no further action is taken. It ends with the deletion of the user.
As a bonus, I get the “bragging rights” of having nearly the oldest possible steam account (it can now vote).
I can see simple things happening though that work towards this; for my pet project I just coded a feature that hashes email addresses of inactive (3 months without any interaction) and using another differently salted hash of their email address (which we then no longer have after this) to encrypt their data. They can still login, which restores their account and data without them noticing, but they will never receive email and possible breaches hurt less.
This is the sort of experience that you want. In case you don't want to click through, this is someone with over 1700 hours in an MMO who lost all their progress and items because they took a break and missed the GDPR-related opt-in to get their account transferred.
I'm super happy I don't have to worry about storage for my large Steam collection.
Or not purposefully obscured.
Those most be some fancy barber shops that you need online accounts for.
Very reasonable and totally with the GDPR rules as well, as long as they purge the data after a certain time.
If a data aggregator can create a timeline of an individuals life, watching personality traits, social graphs, income, travel, routine, biometrics and health, stress and recreation, political affiliation, brand and taste preferences, savings, debt, credit, and social media influence traces, local, regional, and national cultural influences, and so on... that email archive is gold.
You can then create predictive models that let you target products, politics, music, media, and so on. It's not about spying on individuals, it's about manipulating populations. It's about rent extraction and wealth consolidation using tools of influence that negate consent. It augments abuses by law enforcement, corrupting the principles by which democratic governments are supposed to operate by hiding tyranny behind EULAs and TOS and private sector proxies.
Imagine a gpt-3 type model, except that instead of predicting text, it's designed to predict behaviors and psychological effects. That gives you a tool that's got a Darren Brown level of manipulation potential that you can scale. It's never going to be 100% accurate at the individual level, but you can target huge collections of individuals to modulate their lives through advertising and media sequencing.
An example: here in the UK the limit on taking legal action on most civil issues is 6 years. This means it is perfectly reasonable to have a 6 year retention policy and indeed that's what most companies do.
I didn't spend much time to think about it so I might be totally wrong but anonymizing IP addresses is probably not easy unless we give up aggregation. I think that anything that uniquely maps IP addresses also becomes personal data, e.g. cookies.
[1] https://www.whitecase.com/publications/alert/court-confirms-...
Germans are quite pissed about their privacy, and for good reason. I also like that they are taking matters into their hands.
The Vorratsdatenspeicherung counteracted that principle, if it falls away storing this data gets really complicated.
Edit: For example, you can't assume people will work on weekends. So if an issue occurs on a weekend and someone needs to look at it, then the log need to at least last throughout the weekend.
Edit: clarified "forever"
https://en.wikipedia.org/wiki/General_Data_Protection_Regula...
Yes, just the german name :)
> Why wouldnt ISPs bake personal agreement into the TOS like every other cookie clickthru?
Personal agreement baked into a TOS is illegal. It has to be declinable and the service be offered regardless. Those cookie clickthroughs are getting those publishers sued now, see https://www.huntonprivacyblog.com/2019/10/03/cjeu-reaches-de... for an example.
> better to get permission in case unintended retention occurs or business needs change.
Which exactly is why this is not allowed. You can't just collect data just in case. Or you can of course, until you get caught and fined.
Middle-Left coalitions are actually a pretty good idea.
And real estate prices. Don't forget the insane real estate market.
The alternative is worse. Fire is hot. Water is wet.
In fact, for heating, this is already happening pretty much everywhere in Europe where households otherwise wouldn't be able to pay those bills.
And yes, social media providers have to get their act together if they want to do business in Europe.
Did I say it it would? Pretty sure I was talking about smallpox, as a general example how mandatory vaccinations helped in the past.
Also, COVID and SARS are two different diseases, caused by different Coronaviridae.
Vaccination makes COVID less likely to spread through the population, and can prevent a severe course of the illness.
So how is it relevant to this conversation, which isn't about smallpox and where mandatory vaccination won't help?
SARS-CoV-1 and SARS-CoV-2 are both SARS, it's not a coincidence they're named such. The media simply called the first one 'SARS' when there wasn't a second one yet. Then they labeled the new one "coronavirus". You can see even the people reporting on this are confused.
It shows that mandatory vaccination works in fighting infectious diseases. Whether that results in the eradication of the disease, or getting it under control to a degree that we no longer have to have lockdowns, and/or masks in public transports, is irrelevant.
Source: https://www.spiegel.de/netzwelt/netzpolitik/bundesrat-stoppt...
It's not as visible for outsiders, because nations with corruption issues usually also have police and office workers essentially doing shakedowns to do their jobs, and that's not really a thing in Germany.
What is quiet widespread is politicians and office worker enriching themselves either directly from budgets theyre responsible for or by doing things for corporations which pay them handsomely.
Take our Kanzler for example. He was involved in stealing over 50 million €. (CumEx) Not only didn't he get punished, now he's also in the highest position of the German government. And I wish it was an extreme example, but it's really not.
The health minister is responsible for the current health care crisis, which he kicked off over 10 years ago. Thanks to him clinics prefer to amputate diabetes patients over treatment, because it pays more.
Each of the ministers has done similar things such as getting an extra 150k€ salary from the coal industry etc.
Of course, the existence of a mechanism to enable this is itself a thing which can be exploited by the exact same criminals I’m most concerned about with data retained by private businesses, so it’s not much of an improvement even though the attack surface is probably smaller.
[0] and indeed this is why I was already looking to leave the UK even before Brexit; the Investigatory Powers Act gives the Welsh Ambulance Service access to anyone’s “internet connection records” without a warrant.
Private corporations at least do it for money. Governments do it for power. I think it’s a hard case to make that that’s a better reason than to do it for money.
But… money is one kind of power, so I don’t think it’s “better”.
Given what happened in living memory to a previous government in (East) Germany that abused surveillance power, I both accept the concern, and yet also don’t expect it to actually apply here, at least not until about 2040 when the last people who remember experiencing the receiving end of it retire.
Also large enough corporations tend to do things for power reasons rather than money, as once you are a billionaire your money is mostly just a means to exert power so trading money for power is what you do. And at that size they start to intermingle with governments, making the acts of the company hard to separate from acts of the government.
A small democracy can still be an illiberal democracy, and a large democracy can still be a liberal democracy. However the size of the democracy nor the probable liberalness of a democracy should serve as a grant for arbitrary power wielded on behalf of anyone, even “the people”.
For example, take the surveillance and excess force against protestors during the summer of 2020 in the US (various judges and courts have agreed that some of the most high-profile police actions were illegal.)
How would they go on about infecting a PC?
Crazy that the app stores play along.
I could easily imagine a system that leaves case by case decisions completely to law enforcement practitioners, but constrains them with paper trail requirements (accountability, I do agree with that part) and, most importantly but unfortunately kind of irreconcilable with the legal mindset, an artificial quota that forces them to actually think about the case. I believe that a system like that might in the end lead to less frivolous eavesdropping than one where everything is fair game as soon as they get someone authorized to sign off a form. "I got it signed off" goes a long way when it comes to questions of moral licencing: suddenly it becomes someone else's job to feel bad about it if maybe someone should.
And what about situations where the surveillance doesn't even result in a trial? If a suspicion is made up to gain e.g. intelligence over some personal opponent (or personal opponent of someone the eavesdropper swaps favors with) evidence disadmittance couldn't even be an issue at all. But the party requesting the warrant would find it comparatively easy to appease their conscience with "nothing I wrote in the warrant request was a lie". I believe that most people doing bad things don't really like to acknowledge that to themselves, and that many who might actually talk themselves into requesting a questionable warrant would rather not risk running out of "wiretap wildcards" they might later need for doing their actual job. Of course a system trying to cause self-regulation with a quota could still be designed in dysfunctional ways (e.g. if there were "leftover wildcards" at the end of a quarter, those would be powerful fuel for abuse), but with a bit of care those pitfalls should be avoidable.