Upcoming EU data law will make Europe tricky for Facebook
theregister.co.uk
theregister.co.uk
I hope that this language portends a paradigm shift where users are no longer kept in the dark concerning the inferences made by analyzing and correlating data that they, and others, submit. By incorporating language that protects users from unauthorized "use" of their data, I hope that this Directive will encourage industry self-regulation to the extent that unforeseeable inferences become a relic of the Internet's "wild west" days.
By unforeseeable inferences, I'm specifically referring to situations where a company like Amazon might tacitly suggest to your girlfriend to open a wedding gift registry. Its algorithm might to do this based on information gleaned from chat transcripts it licensed from Facebook. While certain laws might protect the actual transcripts from being transmitted to Amazon, nothing to my knowledge prevents Facebook from unforeseeably inferring that you intend to get married, based on complex natural language processing algorithms that it most certainly already employs. The EU's proposed Directive would, I hope, protect people from just that.
[1]: http://europa.eu/rapid/pressReleasesAction.do?reference=MEMO...
Perhaps a better situation to illustrate the point is where a girlfriend is talking with her friends that she's hoping her boyfriend will propose to her soon. That boyfriend, based on the information in the chat logs, might begin seeing advertisements for engagement rings. Those are the types of inferences that I consider unforeseeable.
I'm all for that, but where does it leave community collaborated work when one author wishes to delete their contribution totally?
i.e. wikipedia
One way around this might be to disassociate contributions form the public, to anonymise those contributions. But then... how do you stop spammers and trolls?
If a person has made a contribution under a perpetual licence, then that licence should trump. But if that were the case then everyone would just sidestep this law such that all user contributions were under a for-commercial, shared-forever licence.
Does the law win? Yes.
How would it apply to collaborative works in which data contributed is clearly identified as coming from an author who wants to delete their data? Unknown.
On the other hand, use your real name, and you get the privacy protections.
Besides if you contribute to Wikipedia you have to agree to a license which would obviously trump any privacy measures.
The data protection laws in Europe are enforcement laws and provide detailed instruction on the enforcement of the treaties that make up the "European Convention for the Protection of Human Rights and Fundamental Freedoms"... basically what is referred to as just "Human Rights".
As governments and companies in Europe keep finding, no laws trump that EU treaty.
A wikipedia licence won't cut it.
Further the 1995 data protection laws already stated that any data which could identify the person is covered. That definitely includes meta data, hence my comment about needing to disassociate the data to anonymise it. A person can request any identifying information be deleted, including pseudonyms as it's conceivable that a pseudonym used on multiple services is identifying.
Which leaves anonymous contributions to a project... then how can you continue to enforce anti-spam/troll policies when most of the existing methods rely on spotting the spammers/trolls based on signals from IP, user-agent, emails, usage... if you can identify a spammer, then you can identify a person (given access to enough data), and therefore it's identifying.
These new proposals strengthen the existing laws, which are actually already pretty good. I'm basically saying that there is an edge case here, and it could lead to problems. The law being black and white needs exceptions clarified in writing and not left to assumption.
EU law will be enforced even if the company is based in a third country and has its data centres outside the EU, the statement reaffirmed.
I'm reading this as suggesting they'll set up a firewall to block non-EU websites that don't adhere to EU data protection law. That would be a cure worse than the disease.
(But yes, the Register's tabloid-speak grates.)
Quick summary:-
- The existing laws date back to 1995 - They need updating - Recommendations are going to be made before Jan 2012 - EU law is needed because data travels so easily across borders - Companies wishing to deliver services to Europeans should obey EU law, or be prevented from supplying those services
-- Customers must be in charge of their data -- Customers must give explicit consent before their data is used
For those that are unaware the "EU Cookie Law" requires explicit user consent before setting a cookie that can be used for tracking[1]. That's a pretty high bar for sites that just want to use something like Google Analytics. Now if you consider extending out the intent of that law to all data collected from EU citizens it will make doing business in Europe via the internet much more cumbersome for those that want to do any sort of marketing.
Personally, I like the idea that the EU is forcing companies to be transparent about what information they are collecting and what purpose they are collecting for, but publicly listed policies, such as a privacy policy or terms of use, should be enough. To force users to have to read a legal statement and check a box to agree to start doing business makes that step much more difficult and I'm betting that is exactly where they are heading.
http://www.privsecblog.com/2011/07/articles/main-topics/mark...
The cookie directive specifically excludes those client-side persistence mechanisms ("cookie-like") that are necessary to deliver the pro-offered service.
If the cookie isn't necessary for that core service (e.g. a third party tracking tool), then it requires an informed consent. Hiding it in legal wording in that case is not an option, it needs to be clear and understandable.
Note too, that the ICO cookie rule isn't limited to cookies, it covers all client-side persistence mechanisms that can be used in third party tracking and behavioural aggregation tools.
Those that are concerned that the data they deleted isn't really deleted?
Or those that learn that they can't get their data back which they just now accidentally deleted?
I'm a techie. I'm part of the first group. But daily I have to deal with the second group. Telling them that, no, you deleted the data, so now it's gone, would break their heart.
And. No. I can't have backups of that data because having a backup would be the same as not really deleting it. Think of retroactively altering the backups of the days where the data still existed shudder.
This is pure theory anyways as there is a huge difficulty in reliably deleting data once it's replicated all over different machines.
By the way: I wonder how this request for immediate deletion flies with the more and more strict data retention laws that the EU is issuing. You know: Either you store the data for the state (and thus don't delete it), or you delete it, at which point it's gone.
I think if normal people would really know that Facebook keeps their data even after they deleted it, they would get pretty freaked out about it, too.
So long as Facebook offers two options and makes it really clear - [this is our normal 'hide your profile'][This will really delete everything. No, really, are you sure?]
However, I would suggest penalising people genuinely concerned about their privacy and completely leaving out the option of permanent deletion, only because some people aren't responsible enough to to be trusted with that decision, is not really acceptable.
It's just one of those issues you have to think about before building something - trying to avoid storing sensitive material wherever possible. This goes against modern trends where the retention of as much data as possible is favoured.
I think the problem we see here, is a lot of start-ups and individuals are starting to think about it too far down the line. Whereas big, established companies have been dealing with this for decades, with departments dedicated to compliance - a bit like how everyone is building websites for accessibility to comply with disability laws.
> And. No. I can't have backups of that data because having
> a backup would be the same as not really deleting it.
> Think of retroactively altering the backups of the days
> where the data still existed shudder.
I think this is very interesting technical problem. Can anyone shed some light on
currently available solutions and approaches?This isn't true. If a company keeps data on you, then you may request a copy of that data. It's illegal, under existing EU data law for them to store data (regardless if the 'delete flag' is set) and not tell you.
Facebook does and has given users copies of the 'deleted data' when people have made requests under this law. In fact learning that, on Facebook, "when you press delete, it doesn't really delete it", was a big deal and potentially in breech of Data Protection law. (cf. http://www.guardian.co.uk/technology/2011/oct/20/facebook-fi... )
And, like many others, they told me they couldn't handle my request on time, it may contain intellectual property, whatever- I haven't received my data. Unless they've really found a legit loophole by calling my data their IP, they are violating existing EU law right now.
Maybe if it gets enough publicity... but even then I have low hopes.