Providing privacy rights is very much not a "nation accelerating efforts to control data", and shame on the NYT for muddling this.
Providing privacy rights is very much not a "nation accelerating efforts to control data", and shame on the NYT for muddling this.
China has famously been aggressive at controlling data. We all know this and no one thinks it’s about privacy. But the EU has been pushing to on-shore their citizens data. They have been pushing it for privacy AND pushing it as a national security issue. The EU has strong privacy laws, but they also have aggressive tech laws generally. Cambridge Analytica proved that privacy could be security and the whole drama around FB and the elections made nations weary of leaving the US laws to manage platforms.
Everyone wants more privacy - it’s the sugar to the anti-us tech pill. On-shoring data or requiring local companies own the data (and CX) will help local industries at the expense of Silicon Valley bottom lines. Oh and local companies can be controlled by local government, which makes censorship much easier, a convenient win for power grabbing governments.
TLDR Privacy is one of digital “think of the children” phrases that lets governments power grab.
Facebook, on the other hand, has sold some of my advertising data, and if I piss off Facebook I won’t be able to share memes on a website. There is hardly a comparison.
You can't just say that, you can't just talk shit about every single government that ever existed, like there was no differences between them. That there was no difference in intent. Like if you were on a desert island with nine other people, would you say that about the organization among the ten of you?
Further, I honestly prefer the contracts the governments of the countries in which I am a citizen to the contracts of practically or literally all businesses and institutions I've encountered.
If governments are muddling it, that makes it even more important for the NYT to un-muddle and call them out on it. And I absolutely agree some countries are using privacy as a dishonest argument.
Apologies for not being clearer here, it's the lack of distinction in the reporting that really riled me. Privacy requirements can — in theory — be met regardless of where the data is actually stored. It just needs to be a place that enables compliance with these requirements. Which just happens to frequently (and sadly) run afoul of "lawful intercept/access" laws.
And I really wish the NYT would have pointed that out.
How so?
Positive freedom is a right to do something. (e.g. free speech) Negative freedom is a right to be free of something (e.g. violence)
Actually, it just occurred to me that free speech could be categorized as both: positive freedom to engage in speech and negative freedom to be free of government-based silence of that speech. Interesting.
Edit: I guess this is saying the same thing as 'User23 with so many words; "privileges and immunities" are probably better terms to use.
My pet hypothesis is that the US perspective is prescriptive, because the ability of the state to enforce the rights has not been seriously compromised in a long time. The rest of the world is more familiar with the idea that the guy with a bigger gun may one day show up and take your rights away.
In practice in the U.S. we pretty much call things 'rights' any time we believe that people should have them by default.
I think there are two sides to this, as you yourself point out, but I also think the concern over data sovereignty is a valid one. Just imagine what would have happened if Russia had relied as heavy on Azure and AWS as the Danish public sector. Now I’m not suggesting that we in Denmark are going to elect a dictator and invade Sweden, but as far as national sovereignty goes, you sort of have to consider a world where we would do something that insane.
Then there is the issue of the wider internet moving from a fun playground for geeks to becoming as much a part of our daily lives as crossing the street. Most countries have laws prohibiting you from crossing the street in your birthday suit, even very liberal countries like Denmark don’t allow that. It would be admirable, but perhaps a bit naive, to think the internet would not be affected by legalisation as it’s importance and influence grew. I think the fact that remains as free as it is, is mainly because the current western leadership is quite old. I don’t expect the coming generations of politicians to be as lenient toward the advertising industry that the previous ones have been. What the EU has done and is doing so far is only the beginning, we will se far more legislation on our rights in the future and I wouldn’t expect major advertising companies like Google and Facebook to have much of a future unless they adapt quicker than they are currently doing.
With legislation, however, comes complexity and sometimes side effects as you point out. We have a filter to guard against piracy and property rights in Denmark. As so many other countries, and while it was original intended to block the pirate bay, child protection NGOs lobbied and eventually got sites containing child pornography included in the filter. I’m in no way advocating that this was wrong, but maybe it should have been two desperate filters as stealing Independence Day and Coyote Ugly is hardly the same crime as abusing children. Because what followed was that other NGOs and political interest groups added more and more things to the filter. Leaving it a mixed box of things, most of which should very likely be banned, but I think you sort of get my point in that nobody really knows what can or cannot be added to it because it quickly stopped being a “anti-pirate” or “anti-child-abuse” filter and became a “anything the political majority agrees is bad filter”. Or a very good example of exactly what happens when legislators get involved. There are side-effects, but I don’t think you should fault the NYT for also mixing up things in something that is really far more complex, than what I have outlined here.
I think data sovereignty, privacy and censorship in general are interesting subjects that I hope established media will take more of an interesting so that we can have a proper public discourse about it that involves non-techies and non-technocrats.
I'd like to add/clarify/point out that there's two very different kinds of law/policy nations can go for here:
1. passing requirements that anyone processing data needs to meet some set of guarantees, e.g. privacy (including against state actors, e.g. CIA/NSA), cyberbullying handling, or copyright enforcement. This also includes (the absence of) safe harbor agreements.
2. passing requirements that data processing happen in a particular place, regardless of intent (could be in the belief that place X provides better privacy guarantees, could be because place X can censor/control data)
The latter doesn't solve anything from the citizen's perspective, even if that's the intention. But it does address the issue of "invading Sweden".
I personally consider the former much more important, but the latter is sometimes necessary too. But they need to be clearly identified in discussion. They are not interchangeable and sometimes issues better addressed by one are used to try to argue the other.
If it chooses to move that data elsewhere, that is its choice, and also liability if moving that data runs afoul of regulations in the original country. The foreign country itself doesn't really matter, the entity is doing business in the original country, and would be held liable there by its users/business partners according to local laws.
>The foreign country itself doesn't really matter
Of course it matters. Every country has legal differences on the definition of privacy and associated liabilities (if there any at all). In addition, it's unlikely that one country can establish jurisdiction over data in a foreign country without violating national sovereignty. Arguing that doing business establishes a legal nexus with someone of a particular citizenship opens up a massive can of worms about whose law applies where.
Data is generated in the location where a human user interacts with the system, whether that be with a fully local system, some random website with a server in who-knows-where, or just configuring a domain for e-mail.
(Yes, AI actions are a separate can of worms.)
> > The foreign country itself doesn't really matter
> Of course it matters.
It doesn't for suing for rights, that's the point of generation-based legal authority. The legal transaction is taking place in the user's location, and by offering services there, you are agreeing to the local legal framework.
> Arguing that doing business establishes a legal nexus with someone of a particular citizenship opens up a massive can of worms about whose law applies where.
This is already the case, except with location and not citizenship. Safe harbor agreements just used to make this much less of an issue until they disappeared. You really can't expect to do business somewhere without adhering to the local legal framework.
I'm not sure why anyone with "national security" concerns ever trusted American (or anyone else's) tech platforms to begin with. Everyone spies on everyone, and many current alliances are not even 50 years old---a blink of the eye in historical perspective. Even if some other nations have "better" privacy laws than the US, those are only laws. They can be changed rather quickly if the political winds start blowing differently.
I honestly had to look this up since I did not believe you that Denmark would take until 2016 to realise that keeping public sector data in a foreign country was a bad idea. I mean what, Bush and Snowden didn't convince Denmark that the United States was not a safe place for data? All danish public data getting a nice look over by the NSA didn't alarm anybody?
Is business continuity more of a concern amongst the Danish than privacy? The only novel thing I can recall Trump doing is effectively barring Huawei from using things like Google Play Services. Or is Trump simply enough of an asshole that the higher ups got riled up about him? It's so strange to me to think a country would only be concerned about this after Trumps election, to me data sovereignty seems like something one should have been concerned about around the late 90s or early 00's.
This entire article just baffles me as if data sovereignty is some bizarre development instead of something you should have been thinking of from the start. Does the government of one country store its personnel files in the warehouses of another country? Seems kind of insanely naive to me.
So you are sort of right, that our leadership trade away privacy. Similar to how they secretly allowed America to house Nuclear weapons at the Thule base doing the Cold War, and, how we typically participate in American lead wars in some form or another, as well as a range of other things.
You call it naive, but it’s quite frankly the reality of being a tiny western country. In a sense you can think of many European countries as you would vassal states to the Roman Empire. It’s obviously more complicated than that, and the comparison is a little daft, but in essence you dance when America tells you to Dance. What happened with Trump wasn’t America electing emperor Nero or Caligula, and then sort of doing business as usual, it was a sign that America might not keep on trucking.