The only safe thing is for the records to never exist in the first place.
AP: Across US, police officers abuse confidential databases
https://apnews.com/general-news-699236946e3140659fff8a2362e1...
This was one of the motivations for passage of the Driver's Privacy Protection Act of 1994. Nowadays, officers need a legitimate reason to run a plate - unless the patrol car is fitted with automatic cameras[1] that look up every plate of every car they drive past.
> The Virginia state police used license plate readers to track people’s attendance at political events; > The New York Police Department used license plate readers to keep track of who visited certain places of worship, and how often;
> Despite all this surveillance, ALPR technology has been repeatedly shown to be unreliable; like other police technologies, ALPRs can and do make mistakes.[2]
Generally, court decisions have held that you have zero expectation of privacy when you are in public spaces. Current license plate standards[3] aim for plates that are not cluttered and are easily read by the human eyeball, despite being wrapped with license plate frames (which usually make the state hard/impossible to read which is the most common failure mode for ANLR[4]). If the reflectivity material (traditionally called "ScotchLite"[5]) is worn out (or defaced), most states require the plate to be replaced.
Notes:
0 - https://en.wikipedia.org/wiki/Driver%27s_Privacy_Protection_... Prior to passage, a slang term for running/looking up the plate/registration of a car with a pretty woman driver was "running a date".
1 - https://sls.eff.org/technologies/automated-license-plate-rea...
2 - https://www.aclum.org/publications/what-you-need-know-about-...
3 - https://www.aamva.org/getmedia/646bcc8a-219b-47d8-b5cd-72624...
4 - https://www.aamva.org/getmedia/0063bf88-cb44-4ab9-90b6-200c8...
5 - https://www.3m.com/3M/en_US/scotchlite-reflective-material-u...
Disclaimers:
I used to work for my state's motor vehicle department and had database/developer access to driving licenses and motor vehicle registration records.
I graduated from a police academy when I was a youngster.*
The only way is through - everybody should get into the practice of stalking and gossiping about each other in a Molochian environment, where the people who do not do so suffer from the losing side of an information asymmetry.
Expect AI, especially post-Mythos, to just enable this at even further scale. Consumer grade wireless networking gear as a whole is a very wide attack surface and is basically never updated.
Note that PIs are effectively illegal under GDPR by default. They would generally need to provide Article 13 notice, i.e. you would become aware of them unless they were just asking around without actually following you. Member states can make them legal though (via Article 23) and likely in many cases they have done so.
EU is more complicated, but Article 14.5.b allows withholding notice if it would impair/defeat the purpose of processing. The PI must however apply "safeguards", whatever it could mean.
This becomes extremely relevant when you read it in the light of the C-422/24 decision. In that personal data collected via body worn cameras was determined to be "directly obtained". Paragraph 41 from the judgement:
> If it were accepted that Article 14 of the GDPR applies where personal data are collected by means of a body camera, the data subject would not receive any information at the time of collection, even though he or she is the source of those data, which would allow the controller not to provide information to that data subject immediately. Therefore, such an interpretation would carry the risk of the collection of personal data escaping the knowledge of the data subject and giving rise to hidden surveillance practices. Such a consequence would be incompatible with the objective, referred to in the preceding paragraph, of ensuring a high level of protection of the fundamental rights and freedoms of natural persons.
Given this it's very unlikely that PI observing (especially if they record) could be considered to be Article 14 instead of Article 13 type of collection as it's exactly "hidden surveillance practice" that the Court warned about.
Member states do have a right to restrict the Article 13 disclosure obligations via Article 23 restriction, but that requires specific law in the member state & the law itself must fulfill the obligations that Article 23 requires. Article 23(2) essentially forbids leaving everything up to the controller.
And as far as PI in the US goes, actions between stalking and PI "for self" tend to be so similar that I wouldn't necessarily recommend anyone to try it.
Pretty sure that would be considered stalking and is broadly illegal in the US, PIs being an exception.
The core ill is aggregated data, because that's what allows the mass in surveillance, data mining, etc.
The collection actions are almost immaterial. Without persistence they must be re-performed for each request, which naturally provides a throughput bottleneck and makes "for everyone" untenable.
If we agree the aggregated data at rest is the problem, then addressing it would look like this:
1. Classify all data holders at scale into a regulated group
2. Apply initial regulations
- To respond to queries for copies of personal data held
- To update data or be liable in court for failing to do so
- To validate counterparties apply basic security due diligence before transferring data (or the transferer also faces liability)
- To maintain a *full* chain of custody of data (from originator through every intermediate party to holder) so that leaks / misuse can be traced
- To file yearly update on the types, amount of data, and counterparties it was transferred to with the federal government that are made public
The initial impediment to regulatory action is Google, Meta, Equifax, etc. saying "This problem is too complex and you don't understand it."It's not. But the first step is classifying and documenting the problem.
It is not realistic to say that no person is allowed to keep track of another person; watch where they go, when, with who, etc.
It should not be acceptable for a company to gather information on "everyone"; where they have been going, when, with who, how often, etc. And it should not be acceptable for them to sell that information (to government agencies OR private citizens).
It's a matter of scale.
- Making the first one illegal/impossible would be difficult/costly; and not doing so has a limited impact (to society, not to the single person affected).
- Making the second one illegal is much easier, and it's much easier to shut down a large company doing it than it is 1,000 individual stalkers. The impact of making it illegal is much wider and better for society as a whole.
We don't want anyone being stalked. But in a cost/benefit analysis, we can do something about one of them but not the other.
Consent should be _voluntary_, not mandatory.
When I installed the SoundCloud app and it told me by continuing I agree to them sharing my data with their 954 partners.[1]
1. I’m not even joining. When I mostly recently installed the SoundCloud app - for the first time on a new device, that’s what’s it said: 954 partners. How can anyone reasonably understand what it is their agreeing to in that scenario.
Which is why "we don't serve patrons without shoes and pants" policy is unconstitutional, yeah.
If you don't want to agree to a business's demands — you're welcome to not deal with them and look for an alternative. All the alternatives have the same (or even worse) demands? Unless you can prove collusion, that's just how the invisible hand of the market worked its magic out. Go petition you congressman to violate laissez-faire even more than it already is, I guess.
The shirt and shoes example is a great example in fact that illustrates the point. You don’t have unlimited freedom to not wear shoes, just like a business does not have unlimited freedom to impose whatever terms it likes, just because it put it in its ToS.
Okay, I am gonna be 100% serious here: you absolutely should have such a freedom. Just as loitering or jaywalking being a crime is inherently totalitarian, what the hell.
You do have the right to go barefoot in your own home. And in true public spaces.
But, a property owner can require shoes. Do I care if somebody is barefoot in the local grocer? No, not really. But, the proprietor might because they want to limit their liability (should something fall on your foot, a cart run it over, or a loose tack/nail somehow land in an aisle, etc).
Microsoft (or Apple).
Any web host, payment processor, etc that's contracted to do work for your local government (I suppose you could try driving to the government office and pay by check, but then you need to give consent to Ford or Chevy).
Short of living like a hermit, there's no practical way to avoid all ridiculous T&C.
Government is the bogeyman we are afraid of, but ad tech is doing the actual heavy lifting.
The precogs over at flock say you drive too close to the criminals though, and you know what that means. Stay loyal, stay safe citizens.
Even if we somehow, perhaps via magic genie-wish, made the government totally disinterested... these systems would still enable dystopian levels of private surveillance and manipulation.