Even laws have this problem. There are so many cookie bars on websites that users just click through them anyways.
Every time a company wants to sell on your data, they have to email you and ask permission. Not responding to that message isn't consent.
Find a loophole in that.
Enforcement.
This would honestly still be a huge improvement imo, as even forcing data brokers to anonymize or aggregate the data, even if it is ultimately not actually providing privacy, is still a recognition of the problem over the current system in most states.
Your law as written would only cover company A doing the sale of data to B, but not the downstream intermediaries.
Alternatively, company A doesn't sell the raw data, and instead sells reports and anonymized data that can easily be joined with other datasets. As this is not a sale of "user data", but an aggregated, anonymous insight.
The data industry is full of scum - nothing less than scorched earth in advertisers and brokers is sufficient at this point.
Aggregation isn’t the real problem. Honestly it’s the crosstabs that are killing privacy. Remove the correlations, and no one gets hurt.
The problem is people are stupid and uninformed about giving consent. You're the one trying to loophole around that.
If you actually want to regulate this the way you describe, you have to do it by removing peoples' right to give certain consents. For example, nobody may give consent for more than 6 months for the use or transfer of their data.
This is a big deal! You're removing a free mode of contracting. But if you think about it, we do it all the time. That it has a higher burden of proceeding around new technologies is a large reason why American (where we are careful about rulemaking) and Chinese (no rule of law) tech companies are ascendant. But at a certain point, the usual rulemaking frameworks may need to be applied.
Not really. People have a limited amount of time to deal with issues and aren't trained legally. This doesn't make them stupid. Their inability to suss out all possible downsides of a set of EULAs across various products for a service they're looking for isn't stupidity; it's just an inherently complex space that requires a lot of time and specialist knowledge.
This is one of the main ideas behind consumer law; certain contracts are inherently slanted towards those who draft the contract, therefore we remove some of their freedom to abuse consumers by placing limits on the clauses we're willing to enforce.
That lack of willingness to place restraints on these types of freedom has less to do with the inherent difficulty of restraining freedom of contract and has more to do with the fact that the harm is distributed diffusely amongst a massive swath of consumers, vs felt acutely by specific data aggregators so one side advocates far more for their position - even if that position is antisocial in nature.
> "Their inability to suss out all possible downsides of a set of EULAs..."
This is the part I quibble with, however. This assumes folks even read legal-speak. Privacy laws have undermined this by forcing more text and more "I see, I agree, go away" links/checkboxes/buttons in front of people. The problem isn't the EULAs, the problem is that no sane person can (or should) keep up with it.
Yes, sometimes people can be surprising. My wife has an awesome t-shirt from MailChimp from a not-so-hidden "if you read this, you get a free shirt!" clause she found in their legal stuff. But relative to the amount of cheap "consent" given, this is a huge outlier.
That said, I also have to give kudos to some of the lawyers I've worked with in the GDPR/CCPA/etc era. At least at the point of purchase, there was no better corporate consumer advocate of "boil it down to two or three crystal clear sentences and link to the details, which must cut to the chase" to be found.
They obviously don't, but you're missing a key idea; why aren't they?
You can't benefit from reading without expert knowledge, and the cost is a massive time-sink. Even lawyers, with experience reviewing these types of documents, take a substantial amount of time to get through them and note them up.
If EULAs said: "In exchange for this free Solitaire App, we're going to reserve the right to inform your insurance company about which doctors you visit and the government about which abortion providers your phone keeps going to" you'd obviously read it because you can understand what's going on and you'd understand the exchange in a reasonable time-frame.
This situation doesn't exist because people are stupid. People are smart, which is why they aren't wasting their time trying to go to law school each time they need software.
I don't know the answer to this, but it would probably be a crisis of some sort, like cambridge analytica.
It's sort of amazing how far out of hand things have gotten, with phones, cars, televisions, and more collecting data and matching it with your "dossier(s) in the cloud"
If I want google to sell my data in exchange for keeping Youtube free, that’s 100% my prerogative
But I don't want any of my data collected or shared!
The laws you are hoping for won't allow that - if they existed, at best they would only allow those companies to whom you have consented. Ie the mega-corporations. Local shops would be the ones without the data. Which would be pretty much exactly the opposite way I would choose to share my data, if I were forced to by law.
I agree such laws are necessary, but I'm not sure they're the best of the various solutions. Technical measures might be more robust, such as fine-grain permissions in mobile operating systems. I'd rather it not be possible to collect my data in the first place, than trust that some developer (in whichever jurisdiction) isn't breaking the law.
An advantage of the web is that hostile code is more easily tamed than in native apps, but in itself this observation doesn't do the user much good. Apps are pushed in part because of their superior capabilities for user-hostile functionality.
Similarly, Free and Open Source software is rarely this user-hostile, as few people have the nerve to publish their user-hostile code for all to see. Again though there's a sort of collective-action problem: if only the abstemious few like Stallman insist on not using proprietary software, things don't improve.
ie. the political will to make any such changes just may not exist beyond pure lip service to minority who actually know and care.
I've considered what the options would be for something like "privacy-as-a-service", but I get the feeling that such an industry would be more likely to be regulated to death than the one it's in reaction to.
Ironically, "privacy-as-a-service" already exists to protect the financial records of those with big enough financial records to be able to afford said privacy protection service. One law for me, another for thee.
Any politician that attempts to regulate this can be thwarted by just shadowbanning any content that mentions them on social media - and he'd effectively disappear for a large chunk of people.
That's not law, that's a service!
Make a law where if you ever sell a minor’s data, regardless of whether that minor lied about their age or agreed to a contract (wouldn’t be binding!), then you face steep fines. If you’re found buying data belonging to a minor, also steep fines. If you buy and then de-anonymize data belonging to a minor, really steep fines. To collect and hold data that may belong to a minor, you need to justify it (like GDPR).
Obviously this doesn’t scale for aggregators, advertisers, basically SV, which is the point.
A restaurant is responsible if they sell booze to a minor. A store is responsible if they sell cigarettes to a minor. Serving a minor that lies about their age does not get you off the hook!
Problem solved. User data is toxic. You won’t want to hold onto it for any other reason than a legitimate use.
Steep fines are barely a speed bump to either a profitable business or a scammer. They take years to actually get implemented, don't survive bankruptcy and get reduced in court.
Jail time. Mandatory. Zero room for judges and juries to go easy on the perps.
Even this does not stop white-collar crime, but it maybe slows just a little bit of it.
Are you going to buy shares in a company who’s entire worth is derived by it’s user data when it turns out that a significant but unknown amount of that user data is actually a very expensive liability?
There’s always going to be someone searching for loopholes, like anything, so keep it unambiguous and straightforward.
... but I feel like it isn't the ideal solution. I don't think we should make the perfect the enemy of the good, but what I'd really like to see is that people own their data about them.
I should be able to figure out what vendors have data about me. I should be allowed to be forgotten. There should be severe liability if they don't forget me.
I should be able to contract away my data, but in return for a real benefit, and that shouldn't extend to sale / redistribution.
I don't buy anonymization. De-anonimization is too easy, too good, and progressing too quickly.
- GDPR-like legislation to try to prevent the inappropriate collection of this information.
- Ban the sale of or trafficking in illegally collected personal information. Apply serious monetary penalties to anyone who sells such information improperly. Additionally, anyone who sells such information and subsequently learns that it was improperly collected or was GDPR-deleted must tell their buyers, who must then delete it.
- Buyers are liable if sellers are found to have violated the rules and don’t pay. They are also liable if they fail to honor delete requests. Buyers who consider this liability unacceptable may attempt to purchase or require insurance.
In the US isn’t the sale of illegally acquired data already illegal under 18 U.S. Code § 2315?
I wonder if any existing stalking laws would cover existing data collection practices. Most people are upset when they learn there are records of their location down to a meter or so wherever they go that are sold to anyone who wants it. Does that meet the bar of “emotional distress”?
I'm just thinking out loud, but maybe send my own phone a bunch of fake GPS signals, say, within my own house? Or maybe, somehow 'trade signals' with someone else in a way that collecting the data is useless? Or store my phone in. Faraday cage when I'm not specifically using it? Im sure other people who know the specifics better than I do will flesh it out better that I have, but maybe this will get the ball rolling...
I was thinking the other day of setting up a bunch of VMs with some browser automation with the goal of aimlessly browsing popular sites with the plugin enabled in the background in order to have most ad providers blacklist my IP for ad fraud and thus not trust any data coming from me.
The problem is that it's the internet... the law works for honest websites and companies but not for anyone else.
GDPR is not really about selling personal data but about using it; a big part of its effect is on buyers of data since GDPR effectively (there are all kinds of nuances) means that it's not legally possible for legitimate company to simply buy personal data for arbitrary purposes, since the data subject obviously did not opt-in to that particular purpose by that company when the data was collected.
That's not possible to opt in to under the GDPR, FAFAIK. People can consent to the purpose for which their data will be used, and any such purpose must be enumerated explicitly. "Selling the data" is not a processing purpose, and it would still be illegal even if the person consented (it does not meet the bar for informed consent).
Under the GDPR, the only legal way for personal data to be transferred between companies would be for the "buyer" (processor) to use the data original data from the "seller" (controller) on behalf of the controller. The data, as consented to be collected, remains the liability of the controller for its entire lifetime.
I wholeheartedly admit, some of our data providers are shady, and there's no way I would go work for them. I don't like the way they mislead people.
That said, the data we get is anonymous. Sure, if I know enough about you, and you're in one of my panels, it's feasible that I might be able to figure out which panelist you are. I know there's been some kerfuffle there with less than upstanding "private investigators" and bounty hunters in the past. But, the data we deal with is far too expensive for those sorts.
We find valuable consumer behavior insights the data at regional levels. That creates information that's valuable not only on Wall St, but to retailers and brands, who are desperate for anything to help them understand market share and loyalty.
I dunno. It's a weird world. It's also a very commoditized world. Just having access to the data is no longer the main value add - you have to provide the meaning of it as well.
I know our location provider did some things proactively - like they would not geofence hospitals, for example, but "home" is likely very visible.
That's a dataset I didn't work on as much, so maybe I'm not being sensitive enough to the "this should be illegal" argument. I guess on reflection misleading you for the collection should be illegal, though how to do that isn't obvious.
What I've worked on the most is people's credit card transaction histories, and that's quite a bit more naturally anonymous, though again, if you know enough about a person they would be discoverable.