US diplomat: If EU allows 'right to be forgotten' …it might spark TRADE WAR
theregister.co.uk
theregister.co.uk
I can't really hear this argument any more. Sure, any regulation will have bad side effects, but who are we? A planet full of people or a planet of companies that want to maximize profit on our back? The world will not end if we are allowed some more privacy for us.
I think my point is: "if we don't implement SOPA, we (the companies) are all gonna die!"
Don't know how to express it in general, but I hope I can make my view clear.
To continue your SOPA connection, "Google will go out of business if SOPA is enacted," isn't a good argument in and of itself. You're assuming that Google staying in business is a good thing.
Arguing against regulation of X because companies that have built a business around X being a certain way will go out of business necessitates that an explanation of why X continuing on in the same manner is in the interests of the general public.
As an example, stopping terrorism is generally seen as a good thing, yet opinions differ on whether the laws that purport to prevent terrorism are good, and the government has also used such laws (such as e wire tapping allowances) to justify non-counter terrorism ops.
I know this because pictures of long-dead relatives posted by family members are tagged.
This is a big deal and it has many concerned over how it can be implemented as well as enforced.
What they do have, that exceeds protection in the US, is the right for many EU citizens to request a copy of all of the information a company has on an individual, as well as, in many cases, the requirement that a company gain explicit permission before collecting or sharing personal information.
About this law: http://www.privireal.org/content/dp/poland.php
Article 12 of directive 95/46/EC [1] specifies:
Member States shall guarantee every data subject the right to obtain from the controller:
...
(b) as appropriate the rectification, erasure or blocking of data the processing of which does not comply with the provisions of this Directive, in particular because of the incomplete or inaccurate nature of the data;
(c) notification to third parties to whom the data have been disclosed of any rectification, erasure or blocking carried out in compliance with (b), unless this proves impossible or involves a disproportionate effort.
Article 17 of the proposed regulation [2], a.k.a. the "the right to be forgotten/erasure" strengthens existing erasure/data minimization laws. You are already required to erase data upon request under certain circumstances, and under the circumstances described in article 17 (1) and existing law, you should no longer be storing the data to begin with.
[1] http://eur-lex.europa.eu/LexUriServ/LexUriServ.do?uri=CELEX:...
[2] http://ec.europa.eu/justice/data-protection/document/review2...
Backup this salt separately from the rest of the data in an easier to access media.
When deletion of a full row is needed, you just need to delete the salt from the comparatively smaller and quicker salt backups, as well as the live row+salt.
Weirdly it is likely that the best way that the EU will draw together and get behind one set of federal organisations is by seeing itself as attacked by outsiders - hopefully not literally as in US.
And they forced Facebook to give us a copy of the information they have registered about us. How's that going in the US?
His point is, private data is big business and the US gov needs data to grind. We, the US won't let your liberal boundaries interfere with that.
Well, in Germany one has the "Grundrecht", the fundamental right to stay in charge of ones own data.
There are of course many problems in daily life and our data privacy laws sometimes hitting those practical limitations.
Nevertheless, enclosure movement was key in the rise of the US and it remains that way. Strong arming weaker forces out of their turfs and making profits. That is the american way, not ours.
This enclosure movement of private data means "web 2.0 the capitalistic way". We take your data, profiting and you are not. Here, have some booze and blankets.
I always thought enclosure was a British thing..
Thats how the wild west worked basicly. The natives haven't had the concept of property.
And we don't see our own private data as "our property" as well - which pages we use, which products we buy, which X we like, where we work, adresses and so on.
It isn't property, it is us and we should be able to decide what others do with those expressions. If companies earn money with it, we should profit from it as well. Don't you think.
Google profits from that and in exchange we can use their services. Often we do know that we are the product.
Having certain informations at certain online service deleted might just spawn new startups offering to do just that for your customers and your convenience.
Gaining the trust of customers is a good thing imho.
http://en.wikipedia.org/wiki/Enclosure
What happened in America was very ugly colonization, but arguably not the same thing.
People that are willing to fight a trade war (whatever that is supposed to mean) over this are so far removed in their worldview from my own that it's actually quite shocking.
While we're at it I'd really appreciate if my bank data wouldn't be shipped off to the US. Pricacy terrorists at work over there.
According to the linked article, the person you're requesting to remove the data is also liable for any third parties that have it - and should take reasonable steps to ensure they remove it. Can you imagine the logistics of Twitter removing every reference to all tweets by xyz in a timely fashion? How about Google removing data from their search engine and making sure any number of aggregators etc also remove it? How can a company even know what's being done with public data? The law says personal data - there's certainly people sharing personal data publicly, making this effectively impossible to enforce.
The EU are right to be thinking about how to apply their privacy directive to the internet age - the current situation isn't working. However, they need to be a bit sensible here and realise that when data has been made public with a person's permission (eg Tweeted), it's that person's responsibility, not eg Twitter's.
EDIT: That's not even considering backups etc - we expect these services to work, so it's reasonable to expect and permit them to make backups. If I want to be forgotten with a reasonable degree of confidence, I'd need them to delete information about me from all their backups too. Maybe your average Wordpress blog doesn't have a nightly backup, but if it's picked up by a tech site/Reddit/HN, you can be sure they do - so I'd want it deleted from all of their backups too.
An unenforceable law that claims that people have more protection than is technically reasonably possible is not an improvement in my opinion - people should know what's happening with their data, and shifting whose lying/misleading from companies to Government is not an improvement.
The EU and the US squabble all the time about trade - it would be pretty surprising if they didn't!
e.g. Consider the long running argument over Boeing and Airbus.
Its typical weasel words from government officials who seem to find no method unreasonable if it lets them circumvent the intent of the Constitution. They love to forget it was a document which limited the government, not us.
There is inspector that is responsible for receiving complaints about companies that don't comply with this law, and he can issue warnings and fines to companies. It's working OK, I don't understand why USA would start trade war over sth like this.
I'm not sure what to do about my backups but hopefully common sense will prevail on that front.
I'm also curious about industries that need to retain all financial transaction records for a certain amount of time. They are going to have to be exempt from this as well.
"Dear European country X, would you kindly remove all my personal data from your databases" is probably not something they want.
Guess an opt out app for the tax database would be an all time bestseller though :P
I think it's just an empty threat. And I really hope EU doesn't cave in to their demands. They've done it plenty of times already, and I don't remember hearing much about "US caving to EU demands".
It would be nice if they had a full-time web designer or two on staff, though. Site's a bit horrible.
a) allow us to know who has obtained / stored individually identifiable information about us (presumably the storing party is opbliged to publically record who they have identifed and when where how - a cottage industry of letting us know will grow up)
b) allow us to block such recording - that is if we blacklist ourselves (right to be forgotten) then you cannot publish our details but must notify us at a contact point (ie email) and adhere to some wipe-orders.
c) this does not apply to warrented-supervised surveillance. But applies to governments et al.
This is not quite what the EU is proposing (there seems to be no "workability" to the proposals) but it is close.
In the end, technology has transformed a basic assumption about life - that we can only be identified by people within eyeshot. Now that has gone completely, and we need to rethink what we mean and expect from privacy.
As it has been said, secrecy is what other people don't know, privacy is what they politely ignore. We need to make sure companies are polite.
Talk about a blow to the First Amendment. Let's give it the benefit of the doubt and say that this law doesn't force news sites to remove old stories from the web that identify people.
According to the OP's interpretation, if someone uses Twitter to tweet something racist/sexist/utterly despicable and then deletes it after getting called out on it, that person could sue Twitter ten years later if I happened to reply and quote that Tweet? Or if I referenced it in a blog post? And Twitter would be expected to take any technical means necessary to silence me?
How is this law not the SOPA of information?
It wouldn't be hard to argue that that tweet serves the public interest by allowing the sunlight to shine on it in public.
Obviously this is a Register article so it's light on details, but it seems to me that this is targeted at organizations and you send them a message that says, "delete everything about me" ie a collection of data, not "delete this one thing about me" ie a member of data. How that is codified into law is unclear.
We aren't ideologically opposed, we have different pragmatic expectations.
I think you've misunderstood.
This is a data protection act concerned with the right to delete information you have given an entity. It's for going to facebook and saying 'delete all the information I gave you, I no longer want you to have it and make sure you tell all the people you sold it to to delete it too'. It's nothing to do with freedom of the press, etc.
From the OP: Under the draft Regulation individuals would enjoy a qualified 'right to be forgotten'. That right would enable them to force organisations to delete personal data stored about them "without delay". Organisations that have made the data public would be liable for the data published by third parties and would be required to "take all reasonable steps, including technical measures" to inform those groups to delete the information.
Your Facebook example is a good one, as it has defined data as including the content submitted by the user. You are correct that FB, the organization in this case, would be required to delete the data. But then the proposed law goes further, mandating that third parties need to delete the data. That is what my comment was referring to. Who do you think "third parties" mean? From usual interpretation, it means every and anyone besides the user and organization, hence, anyone who retweets or reposts or refers to the data made public by the organization
It says in the quote personal data. Nothing to do with public information or information in the public interest.
Clearly, most users consider the content they've posted themselves as being personal data...when you delete your FB account, you expect that posted content to be deleted.
So if an ex-lover decides to screenshot some material that I only shared with my close friends and republishes it to Tumblr to embarrass me...does this law cover that? Sure, that seems like a clear cut case to most of us...and there are libel and harassment laws that cover this.
Now what if I make my affiliation with the KKK known on FB (such as Liking them and listing it under my job history). I renounce the organization and delete my FB account a month later later, but before then, someone has decided to post a screenshot of that ugly tidbit on their blog because while I was working as a cashier at Acme burger, they feel that I discriminated against them and so this KKK datapoint is proof.
Ten years later, does the public have a right to know that info, even if I spent the rest of the decade doing what I can to fight the KKK's efforts. Don't I have a right to be forgotten by search engines of my brief dalliance with the KKK?
Again, there are defamation laws that I can try to leverage (in the US, I would be considered a non public figure with stronger libel protections)...with this EU law, I now have e ability to bring a lawsuit against Facebook for not doing enough, in my opinion, to stop the dissemination of information after I deleted my account.
Now if your rebuttal is "well, it is a technical impossibility for FB to stop others from disseminating that information" Well, is it really? Or did FB just shirk their duties to save an extra buck? That's for the courts to decide...and as you well know, technical implementation is not always a deciding factor in the ruling.
I've used two extreme cases (most people hate the KKK so much that I assume they don't care if the person in the second scenario has their data shared)...but you can imagine all the other cases to fill the spectrum. You seem to take it for a given that the courts all agree what is in the public interest and what free speech is...but the reality is that such debates and lawsuits still go on today
Now I know no one sympathizes with the companies here...but given the litigious possibilities this law opens up, how do you think that might stifle initiatives that theoretically could fall afoul of this law? This is why I think it is akin to SOPA, which ostensibly protected the rights of content producers, but would've opened up new ways for certain companies to restrict and sue Google.
The controller shall carry out the erasure without delay, except to the extent that the retention of the personal data is necessary:
(a) for exercising the right of freedom of expression in accordance with Article 80;
[1] http://ec.europa.eu/justice/data-protection/document/review2...
This right is particularly relevant, when the data subject has given their consent as a child, when not being fully aware of the risks involved by the processing, and later wants to remove such personal data especially on the Internet. However, the further retention of the data should be allowed where it is necessary for historical, statistical and scientific research purposes, for reasons of public interest in the area of public health, for exercising the right of freedom of expression, when required by law or where there is a reason to restrict the processing of the data instead of erasing them.
So these are the competing interests that I was alluding to. This: when not being fully aware of the risks involved by the processing, and later wants to remove such personal data especially on the Internet -- covers everyone who has ever posted something on the Internet and regretted it.
And this: for reasons of public interest in the area of public health, for exercising the right of freedom of expression -- is not at all a settled definition...freedom of expression lawsuits happen quite frequently. And speaking from the U.S. perspective, the EU's laws on free speech or quite different than the ones in the U.S.
Same thing happening again as in the 1920s, but now it’s the Middle East. Same cause, different players. Lets not repeat old mistakes.