It would be detrimental to the cause, which is to collect everyone's ID.
It would be detrimental to the cause, which is to collect everyone's ID.
Most user data is of minimal economic value, until you leak it, and then suddenly there are millions of euros of fines headed your way.
Better to not hold the data in the first place.
They're collecting more than ever.
There was a fair amount of scrambling to get GDPR/CCPA compliant, but even that was done largely with a prevailing "ah, this is a defensible thing to store, make sure you can annonymize it or scrub it if needed" vs "stop storing this."
Starting with the ones that are most popular in the US, "Big Tech" usually includes:
- Google - Gmail and Maps contain massive amount of PII, Photos contains all sorts of other sensitive stuff, and they have not treated those aspects of those products like radioactive waste
- Meta - Facebook has a real names required policy even. Not a lot more needs to be said there, I think.
- Amazon - Nothing I've seen about trying to move away from how they need your name/address/payment info and all. If anything, more and more geographic targeting and such.
- Microsoft - Now you need to tie your local Windows install to their cloud services, not moving away from collecting user info. Also moving towards subscriptions which means PII and payment info.
- Apple - cloud accounts + email + payments + subscriptions all here too. Getting into banking-type services, that's leaning into PII...
- Netflix - more and more PII (IP tracking and geolocation combined with things like email and name) to fight account sharing...
Which ones were running away from it, exactly?
I'm not sure about that. As I see it, there is no business case for treating PII carefully: security costs money while leaking PII costs nothing and has no repercussions.
Storing all that information is cheap nowadays. Any state agency may be happy to get more information about The People.
Seeing as how these companies get hacked all the time, (https://krebsonsecurity.com/2026/09/fbi-probes-service-selli...) , I don't think it's unreasonable to resist this.
Furthermore, I think many folks have reservations about requiring an ID checkpoint to utilize a computer. Obviously it's not that bad yet, but I don't think it's hyperbolic to state that the landscape is certainly trending in that direction, and it's absolutely not unreasonable to point out that governments and institutions to have a material interest in setting up access controls on who can and can't use the internet (read: participate in society).
Which is why the people trying to do it always pull out the misdirect about ZK proofs. Those don't fix anything because a system that actually preserved privacy wouldn't be able to prove that the user is over 18, only that someone is over 18, not necessarily them. And that in turn means you're setting up a rug pull. You roll out a system which is indistinguishable from the perspective of ordinary people from the one that screws them, and then that system can't actually exclude minors so what follows is calls to change it to stop protecting privacy, at which point the people trying to collect everyone's ID will be arguing that you already have to show ID.
It also presumes you would even get a privacy-preserving implementation to begin with, which a pretty credulous assumption given how these things usually go.
Exactly. Which in turn requires you to have some way of tying those accounts to that ID, which was supposed to be the thing to be prevented.