Am I reading this correctly? I could be a passenger in my friend's Subaru, or even in an Uber, and they claim they have a right to my personal data? Surely this isn't legal, there's no way they could claim to have consent for this...
Am I reading this correctly? I could be a passenger in my friend's Subaru, or even in an Uber, and they claim they have a right to my personal data? Surely this isn't legal, there's no way they could claim to have consent for this...
"Why is it acceptable on any level for my car to become a spyware device on par with Facebook, when I paid an enormous sum to be its owner and controller for my own benefit, and not to become a residual profit stream for ${CAR_COMPANY}?".
What's a dossier like that with on the market when it includes location, Bluetooth IDs of all occupants and private conversations? $5/mo? $10$?
(not to excuse ISP data collection, but implying that a car is as critical for network access as an ISP is nonsense)
Signal for example, is also subject to US law. They can be compelled to reveal everything they have in a person. Which they happily do: they hand over a page with the date of account creation and the day it last connected. Which is all they have.
Don't collect information, and you don't have a problem.
Privacy is not about what someone _might_ do with your data, it’s what they _can_ do with your data.
It’s also that they have your data, which means it can be exposed to staff or the world as the result of a breach.
On the second point, sure, but so we have knowledge of what, how, and for how long, the carmakers are storing?
What they do with the data changes based on leadership (should we sell to 3rd party data brokers to increase our revenue or not?)
It’s also out of their hands once a subpoena for that data comes from law enforcement.
It's important to know what they do with that data today.
It's also important to know what they could do with that data tomorrow.
Even if a company provides assurances and pledges never to mishandle your data or use it for nefarious purposes, there remains a risk that your data could still end up in the wrong hands.
Note, this is not a justification, but an attempt to understand how we got to now in hopes that by seeing where we've been, we can collectively make better decisions about where we are headed.
Widespread breach of privacy is not a valid excuse for companies to continue violating privacy and even collecting potentially illegal surveillance, right? Phone taps and home searches without a warrant have been illegal for decades, and the fourth amendment to the constitution prohibits government search without probable cause in general. So what I expect is that the existing and established laws and goals carry forward in obvious and reasonable and unsurprising ways from the consumer’s point of view, without vested interests trying to pretend like digital devices’ ability to communicate are somehow radically different from any other type of communication. The only thing that’s changed is that recording and sharing and searching got much, much faster and easier. People who stand to benefit from that are arguing that because it got easier, it should be allowed, but from the privacy perspective it’s the opposite: because it got easier it means we need to actually enforce privacy, and put a stop to the contorted arguments that try to justify data collection without explicit consent.
This is slowly changing, but with 50 member states and aging union leadership, there is no GDPR equivalent yet for citizens of the US.
(And, CCPA protections are only offered to citizens of California, which demonstrates the corporate incentives to keep it fractured and at the state level nicely.)
The most effective way to get this changed would be to identify the cars used by every US senator, and then write them letters pointing out that their cars have granted a sometimes-foreign corporation permission to record every conversation they have, keep a file on who they meet, and document their sexual activities. This is standard espionage tactics, and as awareness of it should be spread in Washington DC in particular.
US corporations now demand you give up all rights that the law permits you to give up, and they do so by shrinkwrap licenses that are “take it or leave it”, while denying the ability to deactivate a reasonable and small subset of functionality if the buyer disagrees.
This is typically where regulation steps in, and does so quite successfully in the EU but not the US, to say that consumers may not contractually give up their right to privacy without express, plainly-sought consent — so, not just shrinkwrap licenses — and that refusal or revocation of that consent shall not deny someone access to functionality that can be reasonably delivered without it. The US has its work cut out for it to catch up here.
It sounds like it's no longer even an option to buy a car that doesn't come with a bunch of uplinks to the car company, maybe to the insurance company airplane-black-box-style, etc.
If the tech exists, it will be abused.
We—as in most people on this forum—can do much more than that. We can actually refuse to work for these companies, and to build such features. We can implore our colleagues to do the same, and inform our family and friends of these features, and suggest alternatives.
Yet many of us don't think twice about working for an adtech company, because of the prestige, compensation, or some other personal benefit.
For sure the Tesla recording while parked feature is illegal. I dont know why nothing is done about it. Probably just slow moving government. Especially now in Switzerland with the new privacy law. Private survalance of public grounds is illegal. Survalance of private property requires posting a clear sign of such including data retention, where data is stores and contact information.
This isn't something tne Tesla owner can sign in the ToS because the people in the footage are others. Tesla probably uses the excuse that you the operator are in violation not them but then again a Tesla owner has only limited control over this. I can legally buy a surveillance camera but it is my responsibility to use it legally.
But why do you think dashcams are illegal in the EU?
It's been ruled by multiple courts in the EU that dashcam recordings can be done legally because everyone is aware that they might be recorded in traffic at any time (e.g. by traffic cameras). That said, you have to comply with some restrictions. For example, you are probably not allowed to publish these recordings on Youtube. But they can definitely be used as legal evidence in court.
Secondly, I don't think Tesla's dashcam footage leaves the car in the EU (unless there is an accident, perhaps).
As far as I know, they don't even transmit or save any recording unless there is an accident or the user presses a button to save the footage into a USB drive inside the car.
In the accident scenario, it is quite clear that it's legal to keep this recording, because these can be used in court as legal evidence. As far as I know, there are many situations in which you are not allowed to film someone or something in the EU in general, but you are allowed to do so if you intend to use it as legal evidence, as that purpose trumps the other privacy concerns.
In the "user presses a button" scenario, it would be the user's responsibility to make sure that the recording is used legally. But again, if the user does not publish the recording and is only filming traffic, this is quite likely to be legal, especially if you only use it in reasonable scenarios (such as recording an accident in which you are not involved, or someone driving drunkenly).
It's not like anyone is going to be pressing the button every 10 minutes. And even if they were, it would be their responsibility to make sure it's legal to do so. It wouldn't be dashcams themselves that are illegal, but rather, what you do with them and the saved footage (if there's any).
Edit: I'm talking about the normal usage of the dashcams, not the Sentry mode functionality which has additional concerns (as you're not recording traffic, but rather people in the immediate surroundings of the car, when the car detects movement around it). As far as I know, courts have already decided that it's legal to have Sentry mode as well, but Tesla was required to warn users that they have to comply with data protection regulations when they use this functionality.
That said, I'm not sure what are the exact requirements for using Sentry mode legally.
Years ago, before smart phones became ubiquitous, I worked for a company that had a contract to provide kiosks containing travel planning software to bus and rail stations. As part of this, one of the jobs I had to do was create a method of recording information from an onboard camera in the case of the kiosk being vandalised.
How it worked is I made a rolling cache of the last 30 seconds of video; this was never saved unless an onboard "shock sensor" was activated. If the shock sensor was activated then I would save the last 30 seconds of video plus another minute or so. This could then be used as evidence by the police to help catch the vandals.
I have no insight into how the Sentry Mode functionality works, but it could very easily use a similar sensor to car alarms to only actually save the recorded video if there is some sort of "impact" on the car.
A state court in Landgericht ruled that everyone who is participating in traffic is aware of being seen and recorded [1], so apparently it's different from being near a parked Tesla in public in which you might be recorded without your knowledge.
There have been similar decisions by other courts, apparently.
However, the law is probably a bit tricky, in that it might be legal to use the recorded video as evidence in court (or perhaps insurance purposes?), but probably not for other purposes such as posting it on Youtube.
Last time I checked, in Spain (and probably other EU countries) similar reasoning applied for recording videos in public places, e.g. while you're walking on the street: I think you can record other people in public without their consent as part of your interactions with them, as long as you safeguard the recorded video and not publish it (and probably only for as long as it might be needed). You could use these recordings as evidence in court, but probably not for almost any other purpose.
You might, however, be prone to being punched in the face, as many people find that to be quite aggressive behavior. Police may even arrest you and confiscate your equipment as they're not all necessarily aware of all the intricacies of data protection laws.
[1] According to a reddit comment: https://old.reddit.com/r/teslamotors/comments/d2uzkd/sentry_...
If you watch news footage you will see street footage but as soon as a person is too close or start being the focus they will blur it out.
However there are exceptions, for example a large public gathering that is broadcast on television you can not expect privacy. For example the street parade.
I ended up in a CD album art booklet without my knowledge or consent but it was at the street parade at which you can't expect privacy if you are attending.
Probably I didn't make this very clear, but in the specific scenario I mentioned, it is legal to record a specific person without their consent but only if:
1. You are interacting with that person, and
2. You don't publish the recording (without the person's consent).
And I think there are other restrictions as well, although I don't remember exactly, e.g. you might be required to delete the recording if it's no longer needed and/or you might only be allowed to record it if you intend to use it as legal evidence and/or you might be required to take reasonable steps to protect the recording (i.e. not allow other people to access it). But again, I'm not sure about these latter restrictions.
Also, there is a distinction between recording someone (or some place) and just keeping the recording vs publishing the recording. The latter has more restrictions than the former, obviously.
Although I have no clue how live streaming fits into all of this, as you're not (necessarily) saving the recording? So I'm not sure how the GDPR laws come into the live streaming scenario, if at all.
If Mozilla really wanted to be helpful they could suggest legal terms to cover the manufacturer for features people want, such as crash reporting or locating stolen vehicles - except I suspect that Mozilla would feel obligated to issue a scathing review of Mozilla's suggested privacy policy were they to do so.
If contrarians really wanted to be helpful, they'd not downplay risks inherent in the utter lack of basic privacy legislation in the US and pretend this is all fine and normal. But instead they shill for car manufacturers, pretend adtech is harmless and try to portray anyone who has a problem with these things as weirdos.
Don't you think Mozilla's message would be much stronger if their privacy guide had an example of what the legal agreement should look like? I didn't see anything like this, maybe I missed it. Clearly manufacturers have gone overboard in some cases, but I don't believe it's that easy to make you guys happy.
There are lawyers in the audience here, how about post some legal contract that protects manufacturers from a passenger pressing the OnStar button while the driver is in the gas station bathroom and being liable for anything resulting from that, and every other possible liability from OnStar. I'll take my -4 and your lack of constructive counterargument as the answer I know it is.
People carry phones in their pockets equipped with mics and running operating systems that have secret source code. If you think the mic can never turn on without you knowing you are in for a big surprise.
It's in a totally different class.
Whether you believe them or not, it's a completely different situation from reserving the right to record everything and sell the recordings to whoever they want.
Looking at the MySubaru app, it looks like I can cancel any subscription. There is also this opt-out setting to “Send Vehicle Location at Ignition-Off”:
Vehicle Location
If you choose to opt out of this service, MySubaru will not collect your vehicle location when you turn your ignition off. You will still be able to locate your vehicle by sending a remote command through the MySubaru app.It's worse than that. The way the law works is that you'll only have standing to sue if you're harmed in some way. But since your data is slurped into a big black box, and then passed around and used by 3rd parties, the connection back to the original ingress point is tenuous at best. Some of those 3rd parties, arguably the most harmful, will themselves be law enforcement, and in the US they have qualified immunity, section 720, and a vast array of a) excuses to snoop and b) immunity from consequence. So, it's worse than illegal because you'll never have standing to sue them and find out.
Of course, the solution is to not buy their products or, if you do, substantially modify them to remove all owner-hostile features after-market. Indeed, I predict a healthy secondary car (and phone!) market where trusted 3rd parties "sanitize" the product to protect the owner.
I mean, yes, the terms are insane, but I'd also never agree to a silly monthly subscription Internet/entertainment/whatever thing from a car company. I'd never even pay for Sirius.
How do you know that? There's a 5G modem.
Ditto (eventually) for several other spy agencies around the world.
Given Apple's and Google's emphasis on security, I'm doubtful the same is happening for phones... but with targeted use of zero-days (assuming the right ones exist) it's at least possible in theory.
Or, you know, your telco provider, who then bundles and sells such data in aggregation to third party services. They've been caught doing it with location services over and over; it wouldn't take much for them to include audio recordings, as long as they have their terms & conditions sorted out
Your real time location data (and everything else) from phone apps is sold on a semi-open marketplace to bill collectors, marketers, spies and PI's.
I am assuming it doesn't go that far and is referring more towards eye/hair/skin color...maybe just a CYA in case they "accidentally" collect info that could be identifying on a level not allowed (discrimination/privacy laws?).
For example:
https://www.smithsonianmag.com/science-nature/scientists-pul...
Presumably this includes GPS data, so they know if you frequent Starbucks or McDonald's. And sell your data appropriately.
Are you sure there aren't local data privacy rules elsewhere that this also violates? GDPR itself basically just unified the existing privacy laws across ~EU member states.
How is this data tracking any different from what google, twitter, or Facebook use? If it’s legal for tech companies to collect user data, why would it be illegal for car companies?
To use an application from one of these providers, you explicitly have to agree to their terms and services: a contract between you and the company is established. How is that equivalent to taking an uber?
The Services may be made available or accessed in connection with third party services and content (including advertising) that Uber does not control.
https://www.uber.com/legal/en/document/?country=hong-kong&la...
What’s different here is that car manufacturers are claiming that, say, sitting in that Uber gives them the right to record your audio and sell it to advertisers. That’s illegal in many places such as the EU or states with two-party consent laws, and it’s unlikely that courts would accept it elsewhere without some kind of informed consent.
you accepted the tos, you've been informed, that's not unlawful if you gave your consent and the data is kept in the EU.
Moreover, the article is claiming that the manufacturer can "maybe even sell" the recordings but the official statement is that they are only collecting the data, not selling it (it would be stupid to claim otherwise).
The blog post specifically use the sentence and maybe even sell, because it is not stated anywhere.
> and it’s unlikely that courts would accept it elsewhere without some kind of informed consent.
meanwhile the advertisers already used your data, and there's nothing you could do about it.
Except not using Uber (that's why I never used one, even though cabs in my Country and especially in my city, are a big "mafia style" mob)
Are you seriously saying that everyone who gets in an Uber signs a form the driver gives them saying that the car manufacturer might resell all of their data?
No, I am saying that Uber can collect that data itself through the app.
I was replying to "To use an application from one of these providers, you explicitly have to agree to their terms and services: a contract between you and the company is established. How is that equivalent to taking an uber?"
It is equivalent because to use Uber you have to accept their license agreement.
Nobody ever explicitly said "resell" because it would be stupid.
It's allegedly proposed by the blog post, but it's not officially stated anywhere.
BTW as written in the part of the Uber TOS I've quoted, they explicitly says that the service can be provided by third parties "outside of their control" and you accept their terms of services by accepting the service provided on the Uber platform.
So yeah, you could be accepting to have your conversation recorder by the driver (or by an autonomous vehicle which is considered a third party provider) or your orders being linked to your persona by the restaurant.
Third-Party Services and Content.
While many Third-Party Services are available in the Uber App, certain Third-Party Services or content are only accessible by exiting the Uber App (“Out-of-App Experiences”). Once you click on a link to access Out-of-App Experiences, you will be subject to the terms and conditions and privacy policy of that website, destination, or Out-of-App Experience provider, which are different from Uber’s
Don't use Uber, it's all I'm saying,
But you are right that this is illegal, because just sitting in a car is not a “specific, informed and unambiguous indication of the data subject's wishes”, which mandatory for consent (GDPR article 4(11)). Neither it is “transparent” (GDPR article 6(1)a).
You can write anything you want, but no that doesn’t make it a valid contract.
Seems very similar to me.
- collected by FB
- without even the pretense of consent
- sold to the highest bidder
I don’t think FB is arguing they have consent for shadow profiles. Where Subaru’s argument would presumably extend to secretly uploading and selling conversations that took place in a car they no longer own.
An unsuspecting person (Alice) ends up with a shadow FB profile because someone (Bob) who actually created an account (therefore having an opportunity to read terms of service) decided to take a photo of Alice and send it to Facebook.
An unsuspecting person (Alice) ends up with Subaru having an audio recording of what they said because someone (Bob) who actually bought the car (therefore having an opportunity to read terms of service) decided to invite Alice into the car.
In both cases, the company receiving Alice's information would likely say that Alice should take issue with Bob's behavior, not the company's behavior, if they don't like the situation.
Whether it’s legal or not is menaingless given the power imbalance.
you might upset the status quo.
worse, you might succeed, proving all the naysayers to be both negative and wrong.
1. Certain rights cannot be easily waived depending where you live — this requires "informed consent". Informed consent means you laid out what you are collecting and for which purposes clearly and in easy language — and that I consented to that.
2. Implying consent through action ala "by entering these doorsteps you have signed away your firstborn child" doesn't work.
3. At least under the GDPR not consenting shall not lead to a worse service.
If I enter the car of some guy and his cars manual (available only as pdf download) says on page 234 that he automatically consents to this by using the car, the manufacturer did neither gain his, nor my informed consent.
This is illegal under the GDPR — a law that doesn't only apply to cookie banners and the internet, but to any form of data collection.
(In the EU of course)