Canadians have a ‘right to be forgotten’ on Google, Federal Court rules
theglobeandmail.com
theglobeandmail.com
This permanent memory doesn't extend to yourself only, it covers OTHER PEOPLE who have the same name as you. You are with them, for better or worse.
I could see it being necessary for some people to have to literally change their name just so they wouldn't be the same search result as the other person.
I honestly can’t understand why.
People are complex and not their mistakes. Once you serve a punishment you should be free to live & not forever branded a criminal.
So we have to ask ourselves, is this a thing that is beneficial to normal people. Is their right to be forgotten and their privacy important? You know people will always abuse this system, but is it better existing than if it hadn't? You will __always__ be able to point to abusers with __any__ system, so the truth is pointing at abusers itself isn't an argument against something. It needs more context. If the system is only used by abusers, then this is a problem. But terrorists and pedos use encryption (the common fingers being pointed) but so do normal people and it is highly valuable to normal people and their daily lives. Idk if removing your identity from Google is as important as that, but we should make sure we include more context than saying "people abuse it." That's a statement that will always be true.
Most people used to live in small towns and die within 100 miles of where they were born. If you got convicted of something, everybody knew.
If you want to replicate the way it used to be then instead of trying to censor the world, just have the government give you a new ID and social security number when you change your name without publishing any record associating the new one with the old one.
NIST did a review in 2019 (published 2020) with datasets containing 12 million people. For searching a given photo against the database, solutions might, say, fail to pull anyone 3% of the time and pull the wrong person 0.5% of the time.
Thus, you get about 1 false positive for every ~190 true matches. It was also under pessimistic conditions: a big fraction of the searches were for individual not enrolled in the dataset.
https://github.com/usnistgov/frvt/blob/nist-pages/reports/1N...
edit: I see there are newer versions of the data since I bookmarked this, but I have not reviewed them. A glance shows they format the data differently.
Still, things have likely improved somewhat since then.
I thought that actually was the pairwise number for some algorithms in use. They're designed to produce a list of suspects to investigate, and then if you get a dozen hits against your surveillance camera photo from your database of a few thousand local mugshots, that's what you're after.
> NIST did a review in 2019 (published 2020) with datasets containing 12 million people. For searching a given photo against the database, solutions might, say, fail to pull anyone 3% of the time and pull the wrong person 0.5% of the time.
Doing the numbers this way implies that the error rate would be ~2800% higher if the database contained the entire population, even under these conditions.
> It was also under pessimistic conditions: a big fraction of the searches were for individual not enrolled in the dataset.
It was also under optimistic conditions: They had a database of profile photos taken under controlled conditions with an attendant present. This is obviously not available for most people. It's using the most sophisticated algorithms in existence under laboratory conditions rather than describing what happens in practice in most cases.
But even supposing that this is a problem, wouldn't it still be better to ban facial recognition databases than news reporting?
You can certainly accept a whole lot more false positives in exchange for a lower false negative rate depending upon application; that's what figure 1 shows.
> Doing the numbers this way implies that the error rate would be ~2800% higher if the database contained the entire population, even under these conditions.
Disagree. Error rates with 1 million people aren't anywhere near 1/12th; they're perhaps half. It's nowhere near a linear relationship.
Also, if you had everyone in the database, you wouldn't have lots of people presenting who aren't in the database, which is where most of the false matches presented.
> But even supposing that this is a problem, wouldn't it still be better to ban facial recognition databases than news reporting?
Don't take my disagreement on the magnitude of the threat of facial recognition as supporting something else.
Is this only because of the trade off between false positives and false negatives? To avoid raising the false positive rate excessively you could accept a higher false negative rate, but how much does one rate change if you hold the other constant?
> Also, if you had everyone in the database, you wouldn't have lots of people presenting who aren't in the database, which is where most of the false matches presented.
This is just a facet of measuring false positives like that: If you're not in the database, the algorithm may be confident that someone who isn't you, is you. If you get added, you may look slightly more like yourself than the other person does and you may end up at rank 1, and then it isn't calling this other person a false positive anymore even though it does consider them as looking enough like you to exceed the threshold for returning a match. But as long as the database isn't fully comprehensive, that means the false positive rate for someone who isn't in the database is going to get higher the more people who are in it, and then anyone would just claim that they aren't in the database.
As would be the case for someone who just changed their name.
Unless they add themselves to the database under their new name, in which case the opposite happens: The database has Bernie Madoff with your mugshot from 2009, you change your name and go to the Department of Privacy to have your picture taken as Altria Academi, and your recent picture looks more like you do now than your old mugshot so Altria Academi comes up as rank 1 and Bernie Madoff comes up as rank 2 and you've got yourself a false negative.
Google has been trying to argue that the Privacy Commissioner needs to consider charter implications of PIPEDA applying (and allowing right to be forgotten), while the Commissioner and the courts have been stating that they will first rule on if google search engine results are in scope of PIPEDA before considering if delisting would unduly limit Charter rights.
Finally, as I understand it, PIPEDA effectively grants the Privacy Commissioner investigatory powers, and that enforcement and remedies are supposed to be enforced by courts (ie, another lawsuit). That said, the Privacy Commissioner has published a draft position on online reputation that says it does believe that delisting/deindexing can sometimes be an appropriate remedy, so the obvious follow up steps would be the Privacy Comissioner/original complaint proceeding.
In other words, even if Google fails to win an appeal on this set of rulings, there will almost certainly be another round of court cases on if delisting ("right to be forgotten") is actually Charter compliant.
I'm not particularly comfortable with the obvious extensions of this. What if I'm a local businessperson doing unpopular things? What if I'm running for office? Where does it start and stop?
"The case began with a complaint to the federal Privacy Commissioner in 2017 from a man whose name and details are kept confidential in the ruling. The man said outdated and inaccurate information about him in newspaper articles found on the internet was leading to great personal harm, including physical assault, employment discrimination, severe social stigma and persistent fear. He wanted the information to be delisted – made unsearchable, unless someone knew the website urls featuring his name."
Even worse to leave that punishment to a private company.
So if the victim of the crime published an essay about what happened, are they allowed to tell their own story and have it listed in Google?
What if it’s a story about conduct that could be criminal but for which you were never charged?
This case could go either way https://arstechnica.com/tech-policy/2023/09/scotus-to-review...
My SIL, divorced with a young daughter, started dating a man. My wife (her sister) googled him and discovered he was a convicted child molester.
What if I was hiring an accountant? Should I be able to google him and find out he had been convicted of embezzlement?
Who decides what’s inaccurate or outdated? I think the subject of a negative article may often feel it’s inaccurate even if it’s generally correct.
Addressing your point, if the newspaper article is inaccurate, why not have the article removed or corrected? Instead, it is the opposite. The man says the articles can stay up. Canadian defamation law is pretty clear. If the article is false, he can sue to have it removed. I'm tending to believe delisting from Google is the man's plan because he can't get the articles removed.
https://en.wikipedia.org/wiki/Canadian_defamation_law
FTA: "The man said outdated and inaccurate information about him in newspaper articles found on the internet was leading to great personal harm, including physical assault, employment discrimination, severe social stigma and persistent fear." and "He wanted the information to be delisted – made unsearchable, unless someone knew the website urls featuring his name."
But you hear about people having to explain drug possession charges, or even robbery charges from their past when they were a different person. We pretend like we actually want the judicial system to at least sometimes “fix” people but we make it next to impossible to do that. We assign a “price” to pay back to society, and the whole point is that price is supposed to be concrete and understandable.
The line is hard to draw between crimes where “society agrees you’ve ruined your life” (child molestation) and “society wants you to get better”. (drug possession, I hope?)
Maybe I’m more so vouching for “public awareness” to be a part of the sentencing procedure? (Allowing crimes without that punishment minimum to be forgotten on public platforms like Google.)
We already have laws/precedence that make the distinction between degrees of homicide for example. So the fuzzy line problem is already kind of solved in that sense? We’ve being doing that sort of difficult sorting for other punishments for many centuries. We just assume that EVERY crime is worth remembering at the moment.
It's a little careless to equate arrest with conviction.
I mean “tried and convicted”.
Adding mob justice to the formal legal system doesn't make it better.
> Removed from newspaper archives too?
No, but most people don't look in the archives so that doesn't matter.
I don't, they can be offline, just as they were prior to the internet.
If you meant anything else: I wouldn't distinguish between any search engines, large or small… but I'm also not a lawyer or a lawmaker, so I have a paper-thin awareness of the consequences of my suggestion that even ChatGPT can probably poke holes in if only it weren't so sycophantic.
https://gdpr.eu/right-to-be-forgotten/
Not sure what the Canadian basis is, but in general these laws recognize that it’s a tradeoff where the public has some interest in most information, and the individual may have an interest in it being forgotten. Criminal records would be a clear grey area where one could make the case for a public interest particularly in the short term, which is less strong over time. But inaccurate reporting is clearly much less eligible for the public interest.
I think phrasing it as a right is perhaps sets the wrong framing, as it’s quite conditional. (Certainly seems to trigger many Americans.)
It’s common enough though. Here’s an old pointer article https://www.poynter.org/reporting-editing/2010/5-ways-news-o... and there are tons of companies offering to help you get articles removed from Google.
Edit: I think honesty and HN spirit compels me to steelman against my own argument as well. An argument can be made that there was a time when it was possible for someone willing to take some serious risk, cost, and effort to start anew from even a really bad past. Step back a century or two or earlier, and identities and persistent records could be pretty scattered. Somebody who did something pretty bad (but maybe not truly notorious) and served any time but was determined to reform could leave it all behind and travel a thousand miles away with a new name and build a new life (or die trying). The space for that has undoubtedly shrunken in some respects, and looks like it may continue to do so. I can accept that there can be reasonable differences of opinion on that.
But against that is what it means to force it to happen. What such powerful legal tools will do when, with total inevitability, they are most effectively wielded by the most powerful as such tools always are. The people who already face the least accountability in many ways also tend to be the ones most able to make use of anything that may give them even a colorable case against critics and detractors. Some people truly reform, but of course some do not. And of course there are the principles involved. Is this something to use force over, because make no mistake, that's what it means to make something a right backed by law. That's what the very nature of "law" is, it's formalized opinions backed by power. The push for this new "right" feels different and dangerous to me then mere basic privacy, or worries about government (or even megacorp) surveillance.
>the former has a singular lifetime and there can only one instance - zero copies.
That's curious, I could have sworn humans had developed ways to share their memories with each other through things like "words" or "pictures"? Things proven to allow someone to share their memories with millions and pass them down such that we still know them even thousands of years later. So you're "only" talking about censoring/destroying conversation, phone calls, letters, messages, newspapers, paintings and such?
There is no shock phrasing here, despite you wanting to deflect. To forget is to lose memories. A right to have others forget necessarily implies actively forcing them to destroy their own memories. That's what it means, stripped of the misdirection. It's evil. I'm not sold that "do it on a computer" always is a magic wand that means now it's fine to use government force with it.
"Destroying a person's data" and "destroying Google's copies of that data" are two different things.
It's quite possible that Aunt Sally could keep her conversations, poems, paintings, macaroni pictures, or what have you, without allowing Google to index those things or make its own copies.
Why? How many people may they share copies with before it's no longer allowed in your opinion? What is your basis for calculating that?
>It's quite possible that Aunt Sally could keep her conversations, poems, paintings, macaroni pictures, or what have you, without allowing Google to index those things or make its own copies.
Of course she can choose not to allow Google to index those things or make its own copies, but why should she be forced not to? Or Google forced not to? What about her circle of friends, and how big can that circle be? What if she runs her own little blog, wiki, forum, newsgroup, or the like? What about if it's a newspaper, can they index it or make copies? A single journalist? Researcher? What does "newspaper", "journalist", or "researcher" even mean as a matter of law? Are only certain elites allowed now? And on and on.
You shouldn't argue for a big new expansion of government force restricting information over and above defamation law without really being able to think all this through IMO. Details really matter. Imagine the absolute worst populist wannabe dictators at not merely national scale but at the local small town scale that doesn't get much attention but has real power to affect people's lives. What are they going to do with this? Does it matter if they'd lose a 6-figure lawsuit in the end if no one they would go after can afford to fight it? That's not a theoretical threat. Anti-SLAPP laws help a lot by making things much cheaper thanks to a fairly straight forward (under defamation law) low pass filter. A judge can determine pretty easily if there is a colorable case or not. As the linked article says, "right to be forgotten" is complex and case-by-case, ie, expensive. And we know that "expensive lawsuit" means "bullies will use this for illegitimate ends", so we should be very cautious about opening up mass applicable complex new forms of action without really thinking it through.
Zero. Google is allowed to share zero copies.
That's the whole point, right?
> but why should she be forced not to?
She isn't "forced not to". Google is forced not to.
I'm not sure why you can't see the difference here.
> What about her circle of friends, and how big can that circle be?
Google isn't "her circle of friends".
> What if she runs her own little blog, wiki, forum, newsgroup, or the like?
Google isn't allowed to index it. And?
> I'm not sure why you can't see the difference here.
Indeed. This is a poor analogy, but it seems kind of like the difference between
1. Aunt Becky is allowed to keep a diary with lies about you
2. Aunt Becky is allowed to show those lies about you to Susan
3. Aunt Becky is allowed to take out a newspaper add sharing those lies about you, in every newspaper in the world, for the rest of time
There's a gap between 1 and 2 where you can make an argument. There's a HUGE gap between 2 and 3.
Definitely. With 1 or 2, the lies aren't in a searchable database accessible to (e.g.) potential employers, or any rando stalker with an internet connection. That's a very important difference.
>Google isn't allowed to index it.
I assume you mean Google can't index the forbidden names on her blog. Or is her entire blog now unfindable because she included a forbidden name? How does Google know if the name, of which multiple named people may exist, is the forbidden one? What of the rights of samed named people to be found?
Note that they already have a well-established takedown mechanism for copyright violations.
I don't know what is worse - that, for example, a Norweigen neo-Nazi mass murderer who will only serve 20 years in prison could erase the stories about them and that event ever occuring, or that someone who did something really dumb in college could usurp and override everyone else's right to free speech.
The right to be forgotten rests on the premise that someone can be "reformed" and that their right to erase the past outweighs the rights of everyone else. The basic premise is someone did something really bad or embarrassing and they are too lazy to change their name (I have friends who have done that, due to an embarrassing newspaper article appearing Google.)
I think we are headed toward a bifurcated interest. The reason that countries outside of the US have been able to compel American tech companies to do their bidding, to date, is because these companies are monopolies that generate massive amounts of cashflow doing things which are not impacted by that law (right to be forgotten does almost 0 to Google's income.)
How is this going to work with LLM models? Keyword censorship can be inserted at the input and output levels, but you can make the LLM bypass that. These models will not be re-trained on demand. The open models can not be recalled. I suspect a lot of countries are about to be excluded from the next wave of innovation.
This is different from what the article (and ruling) are talking about. This is not about going in people's memory and deleting them, neurolizer style. It's not even talking to get the page down. It's talking about stopping to smear that person's name by advertising the publication.
> There is no parallel in history
Yes there is. If someone smears your name on billboards you're allowed to sue. Yesterday I read a story of a comedian who was getting YouTube videos about his plagiarism taken down. If you are publish stuff about a corporation that is bad for them, you might be sued to take it down. Plenty of examples.
Sure, but you're not going to get anywhere with your suit unless it's defamation. "Smearing" your name with something you actually did is (and or should be) protected speech. The article does not describe the confidential plaintiff winning a defamation lawsuit and forcing the material to be taken down from its source. And there would need to be no new "right to be forgotten" for that, that's just bog standard century old defamation law. All search engines and regular sites for that matter, anything that hosts 3rd party generated content, has (and is required to have by law) contacts and processes in place for taking down actual illegal material. The entire debate around this new thing is getting stuff you merely don't like but is entirely true hidden away.
>Yesterday I read a story of a comedian who was getting YouTube videos about his plagiarism taken down
Which sounds like horrible to me and exactly the problem! If he plagiarized, why should he be able to get those videos taken down?
Not in the US it can't, truth is an absolute defense against defamation. And while sure, absolutely lots of countries don't respect free speech or support robust criticism very well, but I think those that don't are wrong. Hence why I included "(and or should be)", the ones that don't still should IMO.
Countries that infringe on the First Amendment rights of Americans are properly termed "enemies". Countries that are currently under the US nuclear umbrella should understand the cost of that protection.
I'd be very happy if this were about correcting facts: about forcing the takedown of inaccurate content from websites. Google would then update its index to reflect the improved accuracy.
Fix the problem, not hide it.
Thus you have to make the indexer stop indexing you.
If big publishers are doing this often on well known topics, it stands to reason that the much larger number of little publishers are also doing it with at least similar frequency for less well known topics.
Hence the ruling here.
Only in the sense that they index what other sites say, which might or might not be factual or honest.
It's impossible not to. Even merely putting one specific search result above another because it's "more relevant" is the very act of curation, because you are inherently defining "relevance."
Sure Dave, please wash your hands for a valid finger print and move in close so I can scan your retina. Closer Dave...
I'm wary of the "right to be forgotten". In this particular case, the complainant (allegedly) had false information posted about them that was detrimental. This can certainly happen. But why aren't the outlets who posted that false information on the hook?
There is a balance between people having a permanent mark against them for doing something stupid and the public having a right to know when, say, someone actually commits a crime.
There are PR firms that specialize in "reputation repair" where wealthy people will pay a bunch of money to have anything disparaging about them removed from the Internet or just buried. This can take the form of takedowns but can be way more isidious eg buying a local newspaper to simply bury a story.
Government: "Apparently you've forgotten exercising your right to be forgotten. Fret not! We have remembered on your behalf. Some day you'll thank us. We're waiting."
As a tangential side note, why shouldn't people have the right to be killed? Assisted suicide is legal in many countries for people who are e.g. battling a painful disease with no hope for a cure or improvement with modern medicine.
There is a vast number of situations where someone might want to be forgotten because someone else has done / is doing something wrong towards them.
I recognize the potential problems, but there are absolutely good and just reasons for this in the main.
Does that mean if there's unflattering information about you on the internet (eg. disorderly conduct video), you can get that scrubbed by by posting some "demonstrably false information" about yourself (eg. that you're a child predator and war criminal), thereby causing your whole identity to be delisted?
Barring that? I think erring on the side of the vastly more numerous set of decent people who may be affected by parrot farms is probably wise. (And I can't speak to Canadian jurisprudence, but it's often the case that courts make a broader decision in the American system and constrain it down over time.)
Okay but the hypothetical above doesn't include any court proceedings or any other government records. It's just a video of the person doing something illegal. It doesn't even have to be limited to videos/photos, it could also be verbal accusations (eg. of sexual harassment).
>Barring that? I think erring on the side of the vastly more numerous set of decent people who may be affected by parrot farms is probably wise.
I don't get it, are there websites out there dedicated to posting false information about random people?
Yes. And also prurient and invasive things that may be true (which is why we have laws against things like revenge porn, which Google also removes from its SERPs in some jurisdictions.
We already have defamation law for that, have had it for literally centuries. If you can prove in court that something is defamation, you can then get court orders around it, including having it taken down from the actual source sites as well as search engines. There is no new "right to be forgotten" law needed for that that that's not what the push has been about, it's about people complaining about stuff that they say is "outdated" or "harmful" but not actually defamatory, you'll notice they don't actually go after any of the places that host the content even when it's in their own jurisdiction. It's the truth, just an unpleasant truth they don't like showing up.
The extent to which government force should be used to wipe someone's slate cleaner is certainly debatable. Arguments can be made that at one point even a nasty criminal who wanted to turn over a new leaf could travel to a frontier or the like where nobody would know them or find out about them and start anew, and that was a good thing (vs criminals who did that and just did more crimes). And that maybe that should be something society backs. And then there are arguments against it.
But that's a very different debate then if the information is simply false.
Allowing someone to delist information via the single most important bottleneck, the search engine, is a very reasonable solution.
Google decides what someone will see when they Google your name, they might decide that the articles where you were accused of CP have much more priority then the single article 1 month later where you were found not guilty.
I don't see your logic at all. The premise is something which the person is seeking, and your examples are things the subject would not want (to be killed or sold into slavery). I understand the rest of what you're saying, though.
The same goes, of course, for any drunken party pictures and the likes, which should have no bearing on your life decades later.
Rather than gaslighting the world, shouldn't you just prevent the problem? That is, just ban posting that sort of information before a conviction.
A society that does not make arrest information public is one where it is very easy for someone to "disappear." That's the whole point.
There aren't enough details to go on in the story, but I'm going to make an assumption that this person was charged with a crime, stories were written about the charges, but when the charges were dropped or he was acquitted there was no followup story written and no update made to the original story.
Journalism in Canada is dying. Most of the newspapers in Canada are owned by one company and newsrooms have been consolidated and shrunk. I used to read my city's two major newspapers - they'd report a different subset of what was happening, and where they reported on the same thing the stories and takes would be different. Both were biased, but biased in different directions, so I felt that I was getting a semi-balanced view by reading both. Now both papers are owned by the same company, have the same reporters, same editors, report on the same things, and run identical stories. There's no balanced view and not enough reporters to follow up on every little thing that gets reported.
Ideally searching for this person's name would show the newest stories first ("person acquitted of crime", "charges dropped", etc), but if those stories never get written they will never show up in a search engine. And very few people will dig into CanLII to find the outcome, if it even makes it far enough to get into CanLII.
I don't know what the solution is. Maybe the media shouldn't name names until someone is convicted? But that would likely have unintended consequences.