Most user data is of minimal economic value, until you leak it, and then suddenly there are millions of euros of fines headed your way.
Better to not hold the data in the first place.
Most user data is of minimal economic value, until you leak it, and then suddenly there are millions of euros of fines headed your way.
Better to not hold the data in the first place.
They're collecting more than ever.
There was a fair amount of scrambling to get GDPR/CCPA compliant, but even that was done largely with a prevailing "ah, this is a defensible thing to store, make sure you can annonymize it or scrub it if needed" vs "stop storing this."
Starting with the ones that are most popular in the US, "Big Tech" usually includes:
- Google - Gmail and Maps contain massive amount of PII, Photos contains all sorts of other sensitive stuff, and they have not treated those aspects of those products like radioactive waste
- Meta - Facebook has a real names required policy even. Not a lot more needs to be said there, I think.
- Amazon - Nothing I've seen about trying to move away from how they need your name/address/payment info and all. If anything, more and more geographic targeting and such.
- Microsoft - Now you need to tie your local Windows install to their cloud services, not moving away from collecting user info. Also moving towards subscriptions which means PII and payment info.
- Apple - cloud accounts + email + payments + subscriptions all here too. Getting into banking-type services, that's leaning into PII...
- Netflix - more and more PII (IP tracking and geolocation combined with things like email and name) to fight account sharing...
Which ones were running away from it, exactly?
I'm not sure about that. As I see it, there is no business case for treating PII carefully: security costs money while leaking PII costs nothing and has no repercussions.
Storing all that information is cheap nowadays. Any state agency may be happy to get more information about The People.