Swedish data brokers claim journalists' legal protection to evade EU law
noyb.eu
noyb.eu
Moreover, this situation by extension could threaten the vital protection that (real) journalists must have, like protection against having to disclose their sources etc. That is, if the law is misused in this way, someone will surely get the bright idea that the law must be thrown out in its entirety.
Isn't that the core of the issue? Who decides what is journalism?
MrKoll is mentioned in the article but there are identical databases that originally were used to track the political opposition and are now partly accessible for selected "journalists", among others. Should those databases exist because they make their own rules on who is a journalist? What about a user posting a comment on Reddit or Flashback that used MrKoll for the information? Is that journalism, making MrKoll a journalistic database?
This legal battle might have a major impact on Swedish newspapers.
There are several issues at play here I think, but to take one: Who decides?
As long as journalists enjoy certain judicial privileges it is natural that the democratic state grants these certifications. This is not controversial in Nordic countries as it might be elsewhere.
Journalism has a well defined meaning in language. The concept has been interpreted extremely liberally up to now in Sweden. This can be carefully tightened without trespassing into undemocratic territory. The alternative - that anyone can register as a journalistic business without any certification will likely result in those privileges being removed. This is the real danger here.
Imagine being a criminal and now you want to find your victim's personal information and you directly call Skatteverket...
Less compelling than going to hitta.se from a public, open wifi network
This can also work to the victim's benefit: any information publicly accessible from these records is automatically unsuitable for identity theft and the likes. If e.g. a tax ID number is in these records (no idea if that's the case), some company asking for that number to establish authenticity/authorization won't have any ground to stand on if it gets called into question.
That said it's probably possible to make inferences, i.e. knowing what company someone works for might make it possible to guess security questions (e.g. "what was your first boss' name?")
Identity theft is still possible but requires much more intricate methods.
These companies have a copy of the database.
I remember reading that Guardian report when it was linked here on HN, at https://news.ycombinator.com/item?id=39334413.
As I complained then, it gave no evidence that gangs used data brokers to get this information, only writing "Experts say criminals are being greatly helped by a 248-year-old law, forming part of Sweden’s constitution."
Who are those experts? Where is the evidence that the bombers used a data broker to find their target, or that removing this information from the public would have changed anything?
And if those data brokers became owned by Chinese or Russian entities, would that change the answer?
You could then pay 10$ and get access to my legal history involving minor possession of drugs and DUI.
Now all my relatives know...
Yep this is pretty fucked, we also have our taxation calendar available for anyone to look up my declared income.
These systems and laws of openness worked great before the Internet, you'd have to call every court in the country to request access to my full legal history, and call the taxation office about my declared income. Now it's just 10$ away from anyone curious
Proper background checks for criminality are done by the police, who hands the paper to the person the check is done on, and can only be done for roles for which the police are allowed to do those checks for. Like banking and teachers.
The idea here is that the workings of the public authorities should be open to scrutiny. Hence, all documents (correspondence, working documents, the lot!) are public, except those that are explicitly made secret, and it takes national-security level issues to do that. The authorities are not even allowed to ask who’s asking.
The first problem is that even material on individuals, collected by the authorities, becomes public.
This generally went unnoticed for a couple of hundred years, as you still had to know which documents there were, go around and ask whichever authority held the documents, and probably pay at cost for copies. Now we have the Internet, which has led to the second problem. Several data brokers have started to request all data there is, and then index, repackage, and sell it on the Internet, drastically lowering the threshold to request all the juicy stuff on anyone. Now, that is obviously against the GDPR, but the law allows anyone to become a journalist, who play by different rules, by saying "I am a journalist!" and paying a token fee.
So, to summarize: Openness, intended to keep tabs on those in power, and which has historically been somewhat tamed by practical barriers has, those barriers torn down by the Internet, become uncomfortably open.
I don't mind these services and I think the recent development where they are blamed for enabling the violence is just a stupid distraction. The domestic terrorists we have would certainly still be a problem and would hardly stop their attacks if we got rid of our very useful public data laws.
The current politics are working hard on removing all the fundamental data laws of my country, beginning with making massive energy rebates confidential last spring.
One of those who got high private tax returns came out publicly and explained that his company was of the type "enskild firma" which means that it uses his person number, it's not a limited company. And apparently Skatteverket had treated all companies of that type as if they were private citizens. But of course most people just remember headlines, so if the headline had been "Look at person XX, that rich bastard got this much in tax returns!" you had probably remembered that but not the later explanation that it was his company that got tax returns.
Many mechanisms could have worked for this purpose. A fixed amount for instance. Or an upper limit on a tax cut. Remember, the idea was to keep a typical home warm.
Instead there was a tax cut with no upper limit. So the affluent heating outdoor pools in the middle of winter also got relief, not just home-owners on the brink of ruin trying to heat their old house. In the big scheme of things, probably not a big deal, but interventions by the state should appear (and be) as fair as possible, lest people will loose faith in the system.
https://www.regeringen.se/regeringens-politik/energikrisen/e...
Some employers and recruiting firms, to do background checks. I think they more or less funds the market.
In addition to that, police uses data brokers information regularly, and there's plenty of evidence of it. Example from the first google search page: [2]. Whether or not you consider them to be "just another gang" is dependent on your personal opinions and how corrupt your local police force is.
[1] https://www.securityweek.com/access-brokers-and-ransomware-s...
The Guardian article was about a bombing of the relative of a gang leader, which also killed a woman living nearby. The implication was that public name->address lookup played an important role in that bombing, so should be curtailed in order to prevent similar future events.
My complaint is the article presented no evidence supporting that implication.
This linked-to page uses the Guardian article to support their position, but I don't think the Guardian article has any substance.
FWIW, Sweden is one of the countries which requires you to register your address with the government. The Swedish police already have the name->address information and don't need a data broker for it.
In the first one, you have someone registered at your house despite not living there. Getting notified about it doesn't solve it though. You still have to report it as a crime and then they will investigate before fixing it. Due to all the bombings, they implemented a speed track a few years ago when gang members are involved (so they don't blow up your house during the process) but I still believe it takes months to solve.
In your case, you have physical squatters. Then you need to take it to court and prove that they shouldn't have access to your house. It takes many months to sort out and they can claim that they have an agreement with you. This was major news in Sweden about 5-8 years ago when waves of EU beggars were making camps on people's land that cost a ton of money to clean up afterwards.
The article is very confused about this. There are two separate issues:
1. the principle of free information ("freedom of information" in the US is super weak compared do Swedens much older laws)
2. Doing stuff with this data on a large scale and in bulk. This is where data brokers come in. This is also not needed for the gangs.
I mean, this Swedish openness is nice (and I wish some parts, like salaries not being secret, were adopted elsewhere too), but your address being publicly available is an anachronism, like the phone books that used to contain everyone's phone number, and will eventually have to go.
The Guardian piece says "reports at the time said it could have been a neighbour related to a gang member."
That's the location of the relative of their opponents. And "could have" indicates uncertainty. Has the investigation since then determined why the bombing took place, and if a data broker or public data was at all relevant?
The Guardian piece only conjectures, yet noyb seems to think it's a solid foundation. This makes me distrust noyb's ability to support their position - making a mountain out of a molehill.
For that matter, how did the bombers know that gang leader had a relative, and that relative's name? Is one's family tree information also public in Sweden, or did the bombers know it from some other means? Like, did the gang members grow up together before joining different gangs, so knew each others' extended family?
In that case, public access to the data would be irrelevant.
Based on these two facts, all the bomber planning the attack needs is a phone number to find out the address. If the victim is using a burner phone (which, by the way, have become illegal in Sweden since 2023, now all "kontantkort" or anonymous simcards can't be anonymous, they have to be registered to someone's name, and you can only do that with a valid ID), they can otherwise target one of their family members.
> Where is the evidence that the bombers used a data broker to find their target
The writing is on the wall. This is a free service. Why wouldn't they?
> removing this information from the public would have changed anything?
The problem is that these companies (like MrKoll there are others) are abusing the media license they have been granted, not only violating rights that have been well established in the EU (which Sweden is a part of) but also they are making an already vulnerable population even more vulnerable.
Grandmas and Granpas are being targeted by scammers with all sorts of schemes, and where do they get phone numbers and also a quick profile of the target? via these websites.
So yeah, removing this information from the public would change something, perhaps not necessarily to the gang wars, but for sure for the safety of the public in general (gang family members would be harder to find).
> The writing is on the wall. This is a free service. Why wouldn't they?
Did they use information at the library to learn how to build the bombs? That's a free service. Why wouldn't they?
Let's shut the libraries down too. Only people with enough money to buy books, and to pay for street informants, should be able to bomb other people. It'll cost you, what, $100 to have someone trail someone else home? There's no way a bomber could afford that.
Now with my tongue out of my cheek - if the bombers knew who to target because some of the gang members grew up on the same neighborhood so knew where the relatives lived, then making this information private wouldn't change a thing.
A site dedicated to strong privacy laws should use strong arguments to support its claims, not a mischaracterized third-hand (a Guardian writer describing Swedish news reports about police and neighbor statements) news report that may actually have nothing to do with the topic.
Wouldn't letting the government decide who qualifies as media go against the idea of free press?
Just get rid of that nonsense. No more problems.
This is probably the "license" they're mentioning.
What you're asking for will not be easy to enact. In a monarchy, the concept of "natural rights" remains somewhat culturally foreign.
How do you figure? The monarch is just a symbolical position. It carries no political power.
What the license in question does is that it makes the publisher potentially liable for publishing stuff that shouldn't be published rather than the journalist for writing it. That license is not the problem.
Profiting off a secret password is not intrinsically illegal.
The journalists David Leigh and Luke Harding famously made the WikiLeaks password "SplinterItIntoAThousandPiecesAndScatterItIntoTheWinds" public when they included it in a book. https://en.wikipedia.org/wiki/WikiLeaks:_Inside_Julian_Assan...
They didn't get special permission to sell that manuscript to the publisher.
Besides, all of my passwords contain secret information concerning Swedish defense installations, making them illegal for you to publish. /wink
Tell me again how knowing 18 year old Sven Svensson earning $10k a year at a part time job and renting in flat B69 is oh so essential for an open society again.
The question is rather whether pieces of information which is public from authorities (Some which are common in many countries such as court records, others which are more unique to Sweden such as addresses) should be legal to index and make searchable, at third parties. This is where the GDPR is an issue.
And I agree strongly with noyb here. I can't see how any of these companies have any journalistic goals.