Google sued for data-mining students' email
nakedsecurity.sophos.com
nakedsecurity.sophos.com
Just to display it on GMail, one of Google's servers has to read the mail. If they claim that Google has achieved sentience, the implications could be very far reaching...
I mean perhaps this lawsuit will clarify when algorithms will be considered sentient.
The situation with the NSA collecting and reading email is no different, specificly in terms of datamining the contents.
What exact part of "reading" is a privacy violation?
So assuming at least 1 million users, they are seeking:
1,000,000 users * $100 per user * 365 days per year * 2 years = ~ $73 billion in damages.
I'm not commenting on whether data-mining on Google's part was right or wrong, but why isn't there any limit to the amount that companies can be sued for?
It seems impractical for the people suing to sue for around 73 billion dollars when the product/service is essentially free.
In this case, presumably the individuals may have been signed up to Google Apps for Education without their direct consent (or, it was an unstated requirement of their courses to sign up).
Also note: companies have access to liability insurance to cover them for being sued out of existence. Google presumably have a budget for lawsuits.
Go to the Apps for Education page at Google, select "Customers", choose "K12" and it lists 10 primary and secondary education school systems as profiled "customer stories".
For example, "Saline Area Schools is a suburban/rural public school district of 5,450 students K-12 located in southeast Michigan, about 50 miles west of Detroit." ... "Encouraged by the success with faculty and staff, the Saline IT team will soon roll Google Apps out to their 3,200 students in grades 5-12."
https://docs.google.com/file/d/0B5AOHQcS-cAeODQ3MGVkNGEtNzJm...
Most are universities.
In fact, it's the site I suggested you visit. Next, use the pull-down under "all types" to see that the three targets are "K12", "Organization", and "University".
Because there is no limit on the damage that they could have done (regardless of the cost of the service). In many cases non-customers may be harmed (e.g. Deep Water Horizon) so there is no relevance of the cost of the service to the amount of potential damage that can be caused.
I'm not claiming that this claim is reasonable or that the amount of damage claimed here is remotely correct.
1) Restitution for the injured parties. Hard to measure in a case like this, but you can essentially think of this as the digital equivalent of conversion (i.e. using someone else's property for personal profit without permission). So the fair restitution might be whatever dollar figure the person would have been willing to have been paid to have that information data mined.
2) Deterrence of harmful behavior. The proper measure for this should be (dollar amount of profit from choosing the harmful course of action) / (probability of getting caught). I.e. if you do something harmful and profit $10 million, and have a 10% chance of getting caught, then assessing restitution and punitive damages of $100 million makes taking the harmful course of action economically irrational.
An arbitrary cap, or a cap based on the price of the product, is not relevant to either measure.
This. One victim is the private mailing list: There's always at least one sap who subscribes using google mail.
My personal hope is that suits like this will one day push them to discontinue gmail.
(my emphasis)
Well, in Norway I could report the company for storing personal data without a license to do so. Essentially any database (even list of phone numbers[1]) that contains personal data (name, contact information, any other information) is regulated. The laws have been somewhat modernized, so that it is assumed that it is ok for a school to give out (and keep) contact information to households/parents of a class -- or for a business to keep a database of customers, for example -- but you most certainly are not allowed to "just keep a lot of data on people because you can".
If you were to do it as a private person, you would most likely never get caught, of course -- but as a business you'd essentially be committing a crime -- and could face (rather steep) fines.
This is why Norway (along with a few other European countries) have taken a rather dim view of Facebook -- and note that with Facebook, users do consent in general (barring the shadow profiles, information uploaded by users regarding non-users etc).
Original HN post: https://news.ycombinator.com/item?id=7427368
Also, with Google's "Google Apps for Business", a user can use their own domain for their email. Sending someone an email doesn't inform the sender that they could be contributing to a Google profile.
There's nothing implied in sending an email beyond "I want you to read the contents". If there's more I want you to do, those wishes would be in the email itself.
30 years ago, if I wrote a paper letter to a company, I was not implying that I want them to build up a profile of me based on my stated info compared to the stated info of other people, where my letter came from, type of stationary, quality of my grammar, etc., then send me coupons that match the behavior they expect of people of my profile. I am implying that I want them to read my letter and take care of my request.
Meanwhile, no, you have no right to dictate how I contract out how I handle my mail by sending me a letter. You gave me that letter, and you'd have a difficult time making a case even if I then proceeded to make thousands of physical copies of it and distributed it at a street corner.
I guess what I'm saying is... what's your point?
edit:
You appear to be misreading your parent comment. The parallel situation they describe is precisely that the recipient engages a company to process their mail (read the description: "you hire some company to sort and collate your mail (and toss out your junk mail for you), and in exchange they slip in some coupons [for] people who get the kind of mail that you do". All of that applies to receiving mail, not sending it.)
And this is precisely what's happening with Google: if you send mail to my gmail address, I've engaged Google to process it on my behalf. You have no say in the matter, nor can you.
Yeah, but it essentially always happened. You know those warranty cards you get with new products? They have always been used to build marketing databases.
http://www.nytimes.com/2003/12/25/technology/do-you-really-n...
For example I use onion2k@myemailprovider.com to send emails to alice@gmail.com, bob@gmail.com and charlie@gmail.com. Google now have a profile for onion2k@myemailprovider.com with a graph that includes nodes for alice@, bob@ and charlie@ and edges for the relationships between the four people, and links to anything we've discussed. If david@gmail.com then sends an email to onion2k@myemailprovider.com Google know that david@ has a second order link to alice@, bob@ and charlie@ despite the fact that they have never communicated or informed Google of this relationship, because Google have a profile based on onion2k@myemailprovider.com - an address that Google might not have a justifiable reason to be building a profile on.
Whether or not you believe that is a reasonable use of data is up to you. Some people think it's not.
But does Google profiles it?
I'm not sure at all that it is clear what the nature of that link is. I have no insight into the gmail's email relationship modeling but I suspect that it doesn't automatically build a relationship between david@gmail.com and other people that onion2k contacted. For one thing, it would be impractical to do this across all possible relationships -- there would be polynomial growth of the adjacency matrix with no information gain to justify it. Ask yourself, what does it mean that david contacted onion2k and onion2k, at some point in time, contacted alice, bob, and charlie? Unless you already know something nontrivial about these people, you assume they are independent.
I guess my point is that data analysis can be very costly; it is reason that humans have a hard time dealing with meaningful relationships spanning more than about 150 people[1]. Even a company with Google's resources would be overwhelmed if it had to store and take into account a large number of mostly (I mean, vastly mostly) meaningless relationships. At the least, it takes away resources from the relationship graphs that do matter and which are actionable, such as the graphs of spammers.
Except that people who are on regular GMail will probably use e-mail forwarding provided by their domain registrar. Especially since the free Google Apps for domains is gone.
I can forward all of them to a virtual personal assistant in Mumbai and have them deal with it all, just sending me a daily summary and maybe writing some auto-responses for me, and there'd be no need for me to disclose that fact to every person that writes me an email.
You can do the same thing with physical mail as well...there are services that can receive your mail, scan it, and send me stuff that seems relevant. No need for people to be able to figure out that you're doing that.
The fact is that I can contract that sort of thing out however I like. It's my mail once I receive it. I think it should be required for students to be protected when they have to use an email system when attending a school, so go ahead and get a firm statement from google on that, but the main part of this class action, the people sending email to people with gmail addresses, are barking up the wrong tree.
This is all about moving from offline to online.
In the ancient days pre-email it was a non-trivial task to read every single letter being sent in a country, categorize them all and then profile people based on them.
And the countries that did that weren't somewhere you wanted to live.
In the modern age it's a "feature" that companies provide because "if you're not paying for it, you're the product".
Not that I think it's necessarily bad, but boundaries have to be set for this new age and this law suit is simply part of that process. Just look at it from a different perspective.
(And note that spam filters & image preloading are problems that only need to be solved because of the same new trivial cost of automated malicious actions)
It's more like if the person you are sending to hires an assistant to sort and organize their mail for them (which people actually do.) You then go and sue the assistant.
Many people sign NDA's. If you have an assistant read mails covered by the NDA, then the party who sent the mail can sue.
and so on and so on.
I'm not sure how common it is, and it's probably less so now with email, but I'd guess a lot of important people do have their assistants screen their confidential mail. For example, I know politicians often have people help with their mail.
A new cleaning company called CleanU create an app where people can easy order office cleaning by a single press of a button. In the ToS/service/liability contract on page 43, it says in legalize: "any document found by our assistants might be used to improve service and decrease costs".
This might sound as a great way to start a legit industry espionage service, but alas, it would be illegal under several laws. First, a judge would ask if there had been a merging of minds, and thus declare the contract void since no buyer could possible have agreed to such terms. Second, as a product (sale), one could ask if "theft" could reasonable be expected when one purchase cleaning. Since it can't, the contract can be made void in that way. Thirdly, if the intent is to hide an otherwise illegal activity under the assumption that people do not read EULA, that would qualify criminal charges under Mens rea, thus fraud.
In all, reading peoples mail because you managed to get people to click a box during registration is a deal on a very unstable legal ground. Law suits like this will explore exactly how unstable it is.
Cleaning services are also reasonably expected to clean desks. They might even temporary hold confidential documents in their hands while doing so. However, once they start reading the document and interpret them, a line has been crossed which no legal fine print can fix.
It's not that there's an assistant, it's that there's just one assistant reading everyone's mail, they can take all the tit bits to make a story and they've got a perfect memory.
This is one of the many differences between the new and old worlds, the sheer scope of the damage they could reap.
Also the cusomised ad advertising is an option you can opt out of, so once again I'm not understanding the issue here beyond grabbing some headlines for mistakes that were avoidable on many levels.
As far as I understood from previous coverage and reading the privacy policy, the point is that e-mails are mined even if ads are turned of for the domain. The resulting profiles are then used for showing contextual advertisements in services that are not in Google Apps (e.g. Google search and Google+). Google's lawyers have also admitted that this is true. IANAL, but reading the privacy policy and the ToS for Business accounts, it seems to be the same there.
Of course, you can completely opt out of interest-based ads, both on Google services as on Google ads across the web. But I assume that profiles are still built, if not used.
A related problem is that persons sending e-mail to a GMail address (which could be hidden behind a non-gmail domain) never consented to the ToS and their e-mails are profiled. To which Google's reaction was: "all users of email must necessarily expect that their emails will be subject to automated processing." [1] IMO there is a difference between scanning e-mail for spam and viruses, and using the content to build a profile of the sender or receiver.
[1] http://www.theguardian.com/technology/2013/aug/14/google-gma...
Take into account that process the email is not the same that profiling that user