Mastercard Should Stop Selling Our Data
eff.org
eff.org
You are now the fat chicken, ready to be plucked: You just bought a hammer, now you need nails. From your social media trail sellers can also infer you are somewhat of a dimwit. Hurry, nails are in high demand in your area. But no worries, here is a great offer for you, valid for the next 0.3 hours.
I just can't understand how people have come to accept such erosion of their privacy, ultimately their very own economic interests and agency under the hands of manipulative operators and captured regulators.
What kind of collective inanity allows such social degeneration. Was it always like that? Is there any hope?
There will always be a battle between the wants and want nots.
I am no longer sure. One could always think that we hit a local minimum. But the comatose, practically non-existent debate suggests there are no reacting forces, the malaise runs deep.
Its puzzling and confusing because none of that phemomena seem pre-ordained. Its all self-inflicted through abysmally bad governance. Literally made up through behavior and choices.
'cept that education sector is struggling to even get financed in places. We even have people seriously thinking schools should finance themselves, because they are too short-sighted, to see the net benefit for a society, that a good education system brings with it. This in the face of ever more things to learn about the digital world. And I live in a country, where there isn't even an official school subject about interacting with this digital world.
It honestly makes crypto look desirable, and buildings designed with sensor blocking materials. You can't passively surveil a data-center. Why should my home, office or shopping mall be any different?
The powers-that-be never gave us a choice to opt-out. It's been a slow gradual decline.
We have to incentivize haggling over our own data. My unseen/unknown data is my asset and I will protect it's financial value.
We can't trust random joes to not sell out crypto exchanges and the like, so you have to build technology that functions as a manual crypto exchange - without a developer on it's back to pull the ripchord and destroy the technology whenever money shows up.
Manual software is key, as soon as it becomes "automated", some developer has to be roped into hand-holding it through tech changes. Crypto software that only exists because a man put it together and went hands-off, is Key.
Then you can build the normal philosophical/structural/relationship management ideas on top of that.
What they don't know is that they pay twice, once with their data and once with money. And the prices they pay now include the cost of the adtech too.
Back in the day, if the local leather tanner was polluting the town water supply... you'd just go tell him to stop, and if he didn't...
Nowadays the only people who have any idea what's actually going on are the ones who are profiting the most from it and have no incentive to shut it down.
-Pynchon, Gravity's Rainbow
If Mastercard used a private detective to follow you when shopping, and he wrote everything you bought and where you bought it into a notebook, which he later delivers to Mastercard, the average person would understand very quickly.
If you walk off and don't pick something up, they could then change the offer a little. It's no longer '2 for 1', it's now '3 for 2 with a free X'.
Disgusting.
> I just can't understand how people have come to accept such erosion of their privacy, ultimately their very own economic interests and agency under the hands of manipulative operators and captured regulators.
The frog born in boiling water doesn't realise it is hot, it's all he ever knew. The age bracket with the largest disposable income now doesn't know any different, it's how it always was.
> What kind of collective inanity allows such social degeneration. Was it always like that? Is there any hope?
No, technology made it far easier. It's now targeted and automated, it's as worse as it has ever been and continues to get worse. There is not a politician in any land willing to do anything about it - more product sold at higher prices means larger taxes. (And that's if the company doesn't lobby on top.)
If I were building this type of system I'd do away with electronic labels and just force people to scan a QR code with their cell phones, then use that data collected from their device to find out their income level, past purchase history, etc. then use that data to display their "price" (subject to change at any moment) right on their device along with ingredients, nutritional data, product information, ads, etc. Then I'd either generate a QR code on their device for them to scan at self-checkout, use Bluetooth to detect the device when they stood at the checkout counter, or use facial recognition. Either way, knowing what price the computer offered would be dead simple and the price of whatever is being purchased could (and probably would) change from the time you picked it off of the shelf and when it got scanned at the register. I'd be your responsibility to accept the prices or not when you pay.
The standard response from someone working in ad-tech: "But isn't it great that an advertisement informs you that you need nails too? Nothing would ever be built without the help from ad-tech!"
2. In general, this is not an erosion of privacy. Honestly? I really do not care what a company does with my transaction data. Why? Because I work in the field of data analytics, big data and I got a little idea of what happen: I'm just a small dot in a very huge picture. Sure, at some point in the very beginning of this process the company tracks my data. But this single data point is not of value. Only the aggregation of an massive amount of data point has a value. Saying "your data" is just framing the opinion into a direction "data collection hurts your privacy". Really no one cares about Mr A from B in C, born in 1900, having n kids and m wifes.
3. You may reply that my data is in danger, if a company is collecting it. That is right. And that's probably the main goal of legal stuff like the GDPR. Data breach can only happen to existing data. No data, no breach. Too easy. But if this is the argument, then you may stop using the internet or any other service.
So, to sum it up: Let's blame the companies for 1 (misleading) and 3 (no security)... but 2? Yeah well. I think it's fine to collect data. I mean... it's a human thing! Information advantage is an evolutional advantage and information comes from data.
It was a philosophical question. Why is it so hard to walk the talk.
"The Times 03/Jan/2009 Chancellor on brink of second bailout for banks"
Getting ride of the Visa/Mastercard duopoly would mean that all banks must connect to all other banks, which they do not want to do, believe me. That would be an administrative hell for them. Which is why they've been putting up with those two for so long. These are the google of banks. They are convenient.
The alternative would be some sort of joint venture between all the banks. The result would less fees for the banks but no benefits for the client as the bank would keep the margin and it would still be a privacy hell.
Another alternative is a public utility. But a lot of people will be as uncomfortable providing their payment data to the government.
What would be so strange about that?
That said, in a system replacing VISA/MasterCard (which I personally believe is a goal worth working toward), it seems like the easiest way would be to connect all the existing national clearing systems (many of these already have instant payments on their own - Fedwire in the US, STEP2 in the Eurozone, Zengin in Japan, etc etc) in a two-tier system.
This is what happens in India. UPI (unified payment interface) was launched by NPCI which is kind of a joint venture between the regulator and banks. In an abstract sense, the bank processing the payment does connect with every other bank via NPCI.
The underlying rails are an older infrastructure of IMPS[1] which is the interbank money transfer system.
I do not agree with the privacy hell part. When bank transfers happen, they anyway have to do the required checks with the other banks. Frankly, people in my circle never even cared if it could be a privacy issue for us.
On another note, there was always incentive to launch NPCI in india because 1/ The infra is relatively newer so it was easier to do (java I think) 2/ Almost all banks' software was built by Infosys/TCS etc. (in java) and that meant the ones integrating would be the same parties who practically used the same architecture 3/ Visa/Mastercard did not have that kind of penetration in 2010 so settlements were a real issue faced by every bank.
In US or European case, the issue seems bigger because the problem is half solved by Visa/Mastercard, so there is a bit of inertia to solve the same problem again.
[1]: https://www.npci.org.in/PDF/npci/upi/Product-Booklet.pdf
I think the EU's getting there with open banking directives like the PSD2:
"the provision of a standardised and reliable access interface to payment accounts (i.e. an application programming interface, API)" https://www.ecb.europa.eu/paym/intro/mip-online/2018/html/18...
I think we need more regulation and government oversight here - even in Europe, but especially in The Land of the Free.
Most in-store payment processing goes directly over those two companies still.
And of course with GDPR, there are actual restrictions on how Visa/Mastercard can monetise your transaction history, and with banking regulations, how much of a cut they can take.
India has UPI, China has WeChat Pay and AliPay, Russia has MIR, and forced Visa/MC out of business for domestic payments like five years ago. Adding insult to injury, all these systems do have instant online payments.
Oh, and Japan has JCB, heard African and Latin American countries have their own systems too. The "world" you're talking about is a small one.
Does this mean you're opting out of the anonymization, but not the collection of personal information?
The wording here could definitely be improved.
> Does Mastercard share transaction data?
> We do not share transaction data without consent or as otherwise legally permitted such as in the context of fraud prevention.
That's a yes or no question. Instead of answering it with a resounding YES they instead reply with some waffle about "legally permitted context".
They also miss out that they sell services that access that data. So an external party might not be able to see it directly but they can pay Mastercard to do the same customer monitoring for them.
> We will not deny, charge different prices for, or provide a different level of quality of goods or services if you choose to exercise these rights, except where the different price or level of quality of good or service is reasonably related to the value of the data that we receive from you. In some instances, we may not be able to provide you with the good or service that you request if you choose to exercise certain rights.
Once I get back that report will be requesting deletion.
That is, beyond rotation of card numbers whenever Apple Pay is used.
Knowing Apple has put an emphasis on customer privacy, and that Apple Card is run on Mastercard makes zero mention of it in either article kind of stand out to me.
It would be great to get clarification on what the scope is of Apple Card customer exposure to Mastercard’s commercialization of payment data.
I am in EU.
“For the past year, select Google advertisers have had access to a potent new tool to track whether the ads they ran online led to a sale at a physical store in the U.S. That insight came thanks in part to a stockpile of Mastercard transactions that Google paid for...”
“But most of the two billion Mastercard holders aren’t aware of this behind-the-scenes tracking. That’s because the companies never told the public about the arrangement. .... But the deal, which has not been previously reported, could raise broader privacy concerns about how much consumer data technology companies like Google quietly absorb.”
https://www.bloomberg.com/news/articles/2018-08-30/google-an...
I’ve opted out all the same, no mention was made that nothing would be done, or assurance that this might not be an issue for me.
[Edited for accidental Yoda grammar]
I agree. Just curious if I should be preferring a specific card company.
Best to opt-out of each that you use.
I would argue that data brokers are so prolific in the transactions processing space that we should assume the onus is flipped and assume all companies are doing it until they can prove they aren’t (which is a pretty difficult task).
I also realize that other countries/governments regulate this space differently, so I’m speaking specifically about the USA.
Curious to see if anyone has a good solution for that? (In the US.)
Potential flaws:
(1) They used to have a bit of overhead (1-5%). Not sure nowadays.
(2) None of that is ironclad anonymity. Don't be an outspoken gay ukrainian hacktivist journalist visiting russia or anything.
(3) Some organizations will only do business with you if they're able to slurp up more data than the initial transaction would suggest to a reasonable person. You can't use prepaid phones to sign up to many online accounts (notably Facebook for a long time) because the site owner can't slurp up your address and other info without certain postpaid plans, and you can't use any pseudo-anonymous card [0] to make transactions at a place that wants to buy your address and purchasing habits from the card issuer.
[0] Solutions like privacy.com might qualify here perhaps, in that you can actually anonymize your name/address/... and still use most of the sites trying to capitalize on that data, but fundamentally that just turns them into a middleman with the same data, and I expect they'll sell out eventually. Plus they have raw access to your bank account and other things you might not want to give out.
Presumably this is meaning prepaid phone numbers? Also assuming this is likely a US thing? Or I'm misreading it somehow.
Because otherwise, I've always bought my phone cash and buy my airtime and data prepaid (no contract) in both EU and Africa and have never come across a service that restricted my phone number for being prepaid.
At this point you can also 99% of the time pay cash and efforts to change this face significant political resistance as being discriminatory to the poor/unbanked. I think the argument “why don’t you just not use their products if you don’t like the deal” is a shockingly good argument… for now.
We can revisit this issue when society truly goes cashless, but for now, not the hill I’d die on. Mastercard will cry bloody MURDER before they let go of this gold mine. If anything I find the interchange fees and the virtual monopsony the credit card companies have to be more scandalous.
Sorry, I don't understand, perhaps because I am in the UK not US. My bank issues my Mastercard, so I don't have a direct relationship with them. How would they target me?
The answer to OP’s question, of course, is that Mastercard doesn’t make use of the information it has directly. It sells the information to interested parties like Google and other advertisers. This is the behavior EFF is objecting to.
Then, Google can show you super-relevant ads, that might encourage you to spend even more.
We've had the situation before when booking holidays that my wife sees higher prices for the same hotel on her laptop while sitting right next to me. Once she cleared cookies the price went down to match what I've been offered on a clean computer.
That was a few years ago so I would imagine IDing potential customers is done via browser finger printing now rather than cookies and so harder to protect against.
Really, who wants their bank or payment network to collude in higher prices?
We wanted to let you know we’re updating our Terms of Service and Privacy Policy (“Terms”), which applies to the products or services you use, like Shop and Shop Pay. We periodically update our Terms as our services evolve, and to address new laws and regulations. We’ve also made them easier to read.
The changes will take effect on November 6, 2023. Here are some highlights:
Terms of Service
• Broadened the description of the services and features we offer to you and how these services work • Addressed new compliance requirements around Shopify’s role as a platform Privacy Policy
• Explained how we use your data for advertising, and provided information about your consumer rights • Integrated the Privacy for Customers policy, improving transparency about how we process personal information when you interact with a merchant • Updated language to better reflect how our products work, such as Shop • Re-structured parts to add detail about the information Shopify collects and why, how we use it, and how we may share it.
---
Now I "need" to figure out how to delete that account/request erasure of all my personal data. Just did that with "23andme" yesterday and it was pretty straightforward, but still I have to kick my past self for being naive enough to sign up for this crap in the first place.
It used to be that buying something remotely was mailing or calling Sears-Roebuck. You give them money, they ship you a thing. Reasonably discretely.
Vito Corleone knew how to make an offer you can't refuse. Tech has done the same, in very finely measured increments.
The wording only says they can’t share or sell transactions for those two reasons but I’d imagine analytics may be a valid reason?
At least here in Europe MasterCard and visa are the only options. Amex and Discovery are really unusable here.
Besides selling our data this also means we get American morals pushed on us, eg they won't provide payments for some websites they don't like.
But how do you break up such a duopoly?
Not exactly easy but it’s not impossible. An app based system could probably do it and force ApplePay and GooglePay to use it in those areas. They will if it’s in place.
Also, some businesses, such as car rental companies, won't provide services to debit card holders.
Also, it's a free [edit: zero-interest, not free] loan (if you pay credit card bills in full); you get some small marginal revenue from the money you keep for up to a month.
And that's why we're in this mess to begin with. Credit card transactions are reported to credit bureaus (from a quick web search, it looks like debit card transactions aren't) and this normalizes the idea that your financial data should be shared freely amongst finance companies.
There's really no such thing as a free lunch, or a free loan. When someone offers you one, it's good to understand how you're going to be paying for it.
A cash transaction is between 2 parties. A debit card transaction is between 5: consumer, consumer's bank, merchant, merchant's bank, payment network/card provider.
You also get fraud protection.
It’s not free, but you’re not necessarily paying for it. The main concern is that some people are definitely paying for it disproportionally more than others.
If there was no credit reporting, the lender would still need to loan just as much. They would base their decisions on other factors (down payment, wages, employ stability, assets, ...) rather than the extremely invasive credit rating.
In America, yes. Not really a thing in Europe, at least not in any places I’ve been to.
In the US, the rental agreements let them keep charging you the daily rental fee until the amount collected exceeds the value of the car.
Your issuer is only liable for the few hundreds of dollars that the rental car company has authorized; beyond that, it's still their (or their insurance's) loss.
The only practical difference is that you're not out that money on your checking account for a few days, which can indeed be inconvenient – but arguably that's not really the rental car agency's problem?
The issuer can also sell that debt (daily rental up to car value) to a debt collector.
It’s probably to avoid lending the car to higher risk demographics.
It’s a test.
The rental car company basically loses fewer cars overall and thus has lower insurance premiums, and thus can offer cars cheaper than other rental companies that do not require a credit card (if any even still exist?) that have higher premiums to pay.
Which unfortunately creates all kinds of false-positives, like making it very hard for tourists from countries where credit cards are not commonly used to rent a car…
That said, you’d think they’ve considered exceptions based on your passport?
I think most debit cards, at least in the US, can also be authorized on the credit rails, and can therefore be used to rent cars. It's always worked for me.
Of course if you do that anywhere else, you have to restart the flow.
This almost ruined our vacation. I didn't have a drivers license and my SO didn't have a credit card. I've never had any issues renting cars here in Norway, both with credit and debit card, despite not being the driver.
But not in the US, no no! Credit card had to be on the same name as the drivers license.
And so we stood there, just having exited the plane, our two week vacation turning to dust in our minds as a car was most definitely needed.
After some desperate attempts by us at finding a solution, the manager came by, having noticed the commotion. After some thinking she asked where we stayed. We had rented a place through Airbnb, which turned out to be the solution. Using the zip code from that place, she could register the debit card, and we finally got a rental.
[1] https://www.statista.com/statistics/968220/credit-card-owner...
https://en.wikipedia.org/wiki/Access_(credit_card)
They spent all that money on advertising, I still remember it, but for what?
This and Harding and Hobbs
So European cards worked but the owners ie banks wanted global ones.
But given the network effect, Visa and Mastercard have a lot of power over both issuing and acquiring banks. Issuers have at least a choice out of these two; acquirers just have to accept whatever their customer puts on the counter at payment time (or lose ~50% of their card-paying customers).
In other words, participation is (relatively) easy; getting some amount of control, let alone autonomy, is almost impossible – again due to the network effect.
The European banks just sold their stakes in the late 90s to the US parents, because they supposedly didn't see a future in that business model...
The system we use in Switzerland (Twint) has everything you'd need for barely any fee and real privacy laws, for everything else and over border transactions there is SEPA. There is simply no need for anything else than that.
Nobody is looking to use Google pay or apple pay when we already have a perfectly fine system with way lower fees.
Those apps are easy to make and don't have to get any special system access to NFC hardware.
Small merchants can just use their existing phones or get iPads, although the payments are now also integrated into merchant systems and the standard card readers in shops now also have a camera to scan QR codes.
Start buying things with cash again.
I can name you at least 50 shops that dont take credit card but at least 2 different payment methods.
It's a pretty clever scheme by the card companies where the have raised the price for people not using their services.
Never heard of that. What are some examples?
In Europe, more aggressive adoption of SEPA instant payments.
TLDR utility priced payment rails provided by a central bank or other neutral clearinghouse, instead of a for profit corporation trying to maximize its skim off of nation state or some fraction of global commerce volume.
https://news.ycombinator.com/item?id=36801491
https://techcrunch.com/2023/10/11/mastercard-india-upi-econo...
https://www.ecb.europa.eu/paym/intro/news/html/ecb.mipnews23...
https://www.ecb.europa.eu/pub/pdf/other/ecb.eurosystemretail...
We are discussing OnlyFans and WikiLeaks, the only reason you can't pay them is because credit card bosses said so.
HSBC is a premium service, cant afford it untill you are a boss of a drug cartel
For your local purchases with trusted entities, you can still use cash.
It also goes the other way. Go and try to purchase something from any business on credit when you don't have the money right now. They will always say no, even if you've been shopping there for decades. Visa and MasterCard always say yes.
People love to rail against the CC companies, but if you actually clear your mind and think about it, their payment systems are incredible.
https://www.axios.com/2023/07/22/fednow-instant-payments-cre...
> Interchange fees — the swipe fees paid by merchants when customers pay by credit card — reached $100 billion in 2022, per Matt Schulz of Lending Tree. That's more than $800 per household.
> In a world where goods cost the same regardless of how they're paid for, it's entirely rational for consumers to pay with credit cards and then collect their kickbacks.
> There's no particular reason why this kind of financial intermediation should be a $100 billion industry, rife with inefficiencies.
> "The shift to instant payments is inevitable," writes TD Cowen analyst Jaret Seiberg in a research note, "though it will take time."
(work at a fintech payments-adjacent, thoughts and opinions are my own)
You mention BNPL, but those systems AFAIK are much worse for the merchants, with very high fees. I'm not sure I understood the insurance per purchase part, but if the vendor is going to scam you, he for sure is going to scam you on the insurance as well. Who sells this insurance and how?
> There's no particular reason why this kind of financial intermediation should be a $100 billion industry, rife with inefficiencies.
What are the inefficiencies really? As a customer, paying by card deducts the money from my bank account instantly. As a merchant, card sales are paid into my bank account the next day.
> You can extend credit instantly to someone with a deposit account like you would with a credit card (with the "overdraft" being the issued credit, lots of ways to skin the UX around this).
I apologize, but I didn't understand this part. How will the merchant instantly open an account for a customer? How would this be as fast, secure and convenient as swiping a card?
My solution for property taxes has been to just set billpay every year to send them a check at the expected intervals.
Precisely why credit cards are a hidden parasite on overall economic activity. They incentivize customers to use to get rewards and then take a ~4% cut of the payment from the merchant. So that's why merchants charge you extra fee they need to make up that 4% cost somewhere and it's either fees or raising prices even though you might not realize it.
I've run a SaaS in the past. About 10% of all US customers were cc fraud, by far the worst rate by country in my data.
I've lost about ~7 dollars on any transaction that went through and then got refunded. I never had any fraud issues with any other payment method.
For me accepting credit card was a pain and costly, but you are telling me for customers this is painless?
For smaller entities it's a PITA to have to manage a separate additinal contract, and it costs a lot more for the merchant, when virtually nobody only owns an Amex.
If you're in europe there are probably other payment means that don't rely on Visa/Mastercard thay will be much more welcome.
Funny thing to me was the store credit cards that are processed internallu without hitting the network (e.g. Carrefour cards, AlbertHein as well I think ?)
It’s almost as if a business needs to decide if it’s mass market or high end. I would only buy certain classes of goods with my AmEx due to how confident I am that Amex customer service has my back.
For example, the Amex platinum card will reimburse you for items the merchant won’t accept as a return. I recently bought an electric screwdriver that sucked, but wasn’t able to make a decision until I’d used it for longer than the merchant return window. I paid with amex and just got it refunded.
As a consumer that has real value.
Of course, that value is entirely funded out of your own pocket.
Instead of paying with your Amex for overpriced goods, you could put a bit of money to the side for every normal purchase, and use that pot to 'refund' your electric screwdriver yourself.
The Amex makes me confident I have recourse. Is your point that I would spend less if I didn’t have that confidence? I suppose so, but I’d actually rather prefer having that confident experience rather than feeling insecure or like I got ripped off.
That’s real value, and I don’t mind if it means I buy an extra tool here and there. Especially if I can get some extra refunds.
Cheaping out on processing fees or putting friction on the payment part will be a signal that you don't understand your customer and will potentially be nickel and diming the experience all the way down, which is clearly not the image you're trying to convey.
In other countries like Romania the taxi drivers just laugh in your face when you try to pay with an amex. I hate that thing but our stupid HR VP from the US forced it on all of us. Probably gets some nice kickbacks in return.
I completely agree on the cost part for AMEX, but how do you mean it's a PITA to accept those cards? It's usually as simple as enabling an option with your card payment service, not very complicated at all.
Growing up, my parents had a Discover card (among others) and everywhere we went, I remember them asking if they took Discover because so many places didn't. It wasn't until years later when I saw the joke about this on Futurama that I realized this wasn't a unique experience:
> Fry: Do you take Mastercard? > Employee: Mastercard has been out of business for 100 years. > Fry: Okay, do you take Visa? > Employee: Visa has been out of business for 200 years. > Fry: Hmm, do you take Discover? > Employee: Sorry, no, we don't take Discover.
[1]: https://en.wikipedia.org/wiki/Payment_Card_Industry_Data_Sec... [2]: https://www.pcisecuritystandards.org/
They did start the first payment card that wasn’t linked to a specific company (i.e. the American Airlines card).
Store accounts/cards have indeed been around significantly longer.
The distinction between a credit and a charge card is not that relevant in that context, in my view: For both, you spend an issuer’s money at unaffiliated merchants and pay the issuer back later.
Does anyone know when this changed? I don't think I've just been lucky this entire time.
Edit: When traveling overseas, I've always just used VISA though, but that's just because I have a card without foreign transaction fees with them.
Amex charges significantly more than the others, to the point that multiple businesses I frequent offer a sliding scale - par for cash/check, +2-5% for Visa/Mastercard/Discover, +5%+ for Amex.
This is just one more input to an optimization problem for me, but for merchants makes a significant difference: my mechanic says he saves thousands of dollars a month by turning Amex customers into Mastercard customers, and Mastercard customers into cash customers.
Costco was unique because they used to only take Amex credit cards and then Citi/Visa won that business.
https://www.ecb.europa.eu/paym/intro/news/html/ecb.mipnews23...
Here [1], it says:
> strong potential for "wero" to emerge as the leading wallet for the digital euro central bank digital currency (CBDC)
Great, but I am not sure about its potential to safeguard our privacy. One can hope maybe they wont sell our data to commercial entities.
[0]: https://www.epicompany.eu/european-payments-initiative-selec...
[1]: https://payments1connectingthedots.substack.com/p/new-kid-on...
You create a publicly-funded option.
https://finance.ec.europa.eu/digital-finance/digital-euro_en
Depends on the country!
Amex is accepted in many places in Germany these days (though you definitely still need to carry another card, so it can't be your only card).
And Discover and Diners Club are actually the same network, so in the European countries that have strong Diners Club acceptance, you can usually also get by with Discover. (No idea about how good the exchange rates are, though; those of Diners Club in the other direction are atrocious.)
I know you can't use it everywhere, and for everything, but -- for the sake of privacy, use cash when and where you can. The cashless economy is a surveillance economy, and if you care about privacy (for others, if not for yourself) then you should use cash whenever possible.
Would the EFF feel any differently if the data were pseudo-anonymous and open to everyone?
You can go to SteamDB.info and learn a lot about millions of people based on what games they buy. It's a psuedo-anonymous per-user purchase history. Here's mine: https://steamdb.info/calculator/76561197975362423/?cc=us . You can look up basically anyone on Steam, and even do advanced math on all of it. It's been going on for at least a decade.
Have there been consequences or harms? I mean maybe in some isolated case I can imagine it. But there's also lots of value in the data being open.
Selling/sharing depersonalized data is hard to find fault with.
My point is that the EFF spends no time investigating this in a serious way at all. We live the reality I'm describing with Steam, which is millions of people, it's been going on for a long time, it's conceivable that even broader categories of transaction data may be prisoner-dilemma-style valuable to share. I just wish the EFF would engage with that 1 iota. Otherwise they are just another opinion in a sea of brand-and-celebrity posters.
It should just be illegal to use customer data unless they explicitly agree.
It's not even about harm. It's about having a right to privacy.
And this is not some computer games we're talking about. It's our whole lives.
And customers already explicitly agree. They just don't read the terms when they sign up or value having a credit card more than that level of privacy.
But perhaps go further?
> It should just be illegal to use customer data unless they explicitly agree.
Should you be able to use customers data for any purpose whatsoever except in the delivery of goods and services that define your business?
There are edge cases, of course. But it is not edge cases that matter.
Giving permission is problematic. How do you know if you have genuine permission?
Her in New Zealand I think (IANAL) that if the other side of a major contract (like a house purchase) does not get independent legal advice then it is very difficult to enforce the contract in any way other that buy/sell.
Other conditions, idiosyncratic ones, cannot be enforced.
can't you opt out by making your profile private?
I think having data visibly public and open to everyone is a lot better than having it seemingly private and quietly selling it.
> Have there been consequences or harms? I mean maybe in some isolated case I can imagine it.
There have definitely been people getting outed against their will because they didn't realise their play history was visible. I'd be amazed if there wasn't at least one case where someone has been attacked as a result.
See the Bloomberg reporting from 2018: https://archive.vn/SLmFw
Also, the Dutch iDEAL system might form in important building block of a European home-grown payment solution, that hopefully will give the Visa/MC duopoly some actual competition: https://en.wikipedia.org/wiki/European_Payments_Initiative
But we also know why a European home grown payments system is not happening. The incumbent banks hate it and have enough power to block such solutions.
- Maestro, V PAY, Debit Mastercard en VISA Debit issued in Europe: €0.047-€0.06 per transaction
- iDEAL: €0.35
- Mastercard en VISA creditcards issued in Europe: 1.70%
- Mastercard en VISA creditcards and debitcards issued outside of Europe: 2.50%
https://www.ing.nl/zakelijk/betalen/tarieven/betalingen-binn...
For a €100 payment, we're looking at €0.06 debitcard transaction vs €1.70-€2.50 creditcard. If I were a Dutch retailer outside of areas/sectors with a lot of foreign/tourist business I probably wouldn't bother with credit cards either, as probably 99%+ of the Dutch have Maestro, VPAY or cash.
If you had to pay the fees as a customer, free market forces would do its job.
So if the fees on non-Dutch European and Dutch cards are the same, what explains this? Xenophobia? That is what my colleagues in Holland say.
Retailers just choose from the options from their bank, which are the debit card I already listed (Maestro, VPay, MasterCard Debit or VISA debit), and optionally VISA and MasterCard credit cards (which are separate from their debit cards). Retailers do not have the option of accepting Dutch Maestro/VPay but excluding Maestro/VPay issued elsewhere in Europe. They do have the option to exclude credit cards altogether, and many do for the reason of € 0.06 transaction cost vs 1.7% and that around 100% of Dutch account holders have one of (Maestro, VPay, MasterCard Debit or VISA debit). Xenophobia has nothing to do with it, any more than retailers in your countries might not accept Bancontact, giropay or UnionPay cards.