RadioShack Sold Consumer Data to Pay Off Its Debts
slate.com
slate.com
Consumer data should be one of those things which most companies consider something toxic but necessary so they handle it with care and use the least amount possible rather than collect as much as possible and worry about things later.
RadioShack may not have the reams of data an ISP has, but still need a precedent for future data handling and ownership resolution. It'd be great to see this kind of data devolve back to the consumer, i.e. destroyed, once its original user is no longer there to use it in support of ongoing business operations and should not be a mainline of business per se.
When I worked at Company X, one of our competitors was failing and offered us to buy them out. The most expensive part of the buyout was calculated basically by #users*<some price>. And really that's all we wanted, was their userbase, since we already had the product they wanted. We could absorb their users and immediately grow our business.
vs
Amazon buying Newegg and rerouting the Newegg website backend through its own network.
In the end, Amazon would end up with the consumers data, so to the consumer there is no difference. Are you saying that there is a difference? That's what I wanted clarification on, what that difference was.
In the example, Amazon can do whatever it wants with the data.
Data submitted to almost anyone online (maybe with the exception of large companies or companies specifically designed to not track data) should be considered public unfortunately.
I have seen some states recently put in place laws to protect this data from being made public or sold carelessly, but for the most part it is unregulated as far as I can tell.
TRUSTe was suppose to do something similar, but it's seal doesn't mean much anymore (not that it ever really did). http://en.wikipedia.org/wiki/TRUSTe
Medical records, children's data, and sensitive financial data is protected under US law. US-EU Safe Harbor has some consumer data protection rules.
http://en.wikipedia.org/wiki/Personally_identifiable_informa...
The fact that your data isn't protected can't be used as an argument that it shouldn't be. Just because something is legal doesn't make it right, either.
I'm not claiming privacy policies are legally binding, just that they can be an indicator of trustworthiness and integrity. That's what I really meant when I said "[Option #1] would breach customer expectations because they are outright lying."
The way I read mc32's "I think there's a difference" is moral difference, because I share the same sentiment as him or her ("I hope the FTC wins its case...") which would turn that moral difference into a legally binding one.
NewEgg selling customer data to Amazon, AND EBay, AND LinkedIn, AND Joe Schmoe's Tech Emporium. Each have their own data sharing policies.
vs.
NewEgg selling the entire business and assets to Amazon (and only Amazon). In this case, everything; hardware, product stock, servers, and data too.
You end up in a situation where you have a few huge companies that have shitty expensive products and huge amounts of money. If anyone ever does better, they use some of the money to acquire the customers. No one ends up with something better or more cost effective; the 800lb gorilla just pays a tax to remain the only choice, and that cost is easily passed right back to the customers.
Yet another case whereby a natural consequence of a free market is "bad" for the free market.
In reality it's only bad for the consumer, and certainly not the businesses.
I actually think the "free market" works pretty well at this, even if it's not perfect. Nothing is.
Think of it like software, your data is not the property of Facebook, but rather, they have a license to use it.
> For content that is covered by intellectual property rights, like photos and videos (IP content), you [...] grant us a non-exclusive, transferable, sub-licensable, royalty-free, worldwide license to use any IP content that you post on or in connection with Facebook (IP License).
No, "you" generally do not effectively retain the right to license your data collected by a third party out to other entities, because (as far as I know) there are no laws which require that third party to provide you with the data they've collected.
Examples here would be 23andMe vs. Fitbit.
23andMe is in the business of collecting data from you (in essence), then providing it to you and using it for their own purposes.
Fitbit is in the business of collecting data from you, then processing it and performing a number of black box calculations, then providing you summarized results. (Caveat: yes, I am aware that most activity trackers have API / export functionality. However, in all the instances I looked at that's limited and generally crap compared to the raw take the main party has access to)
There would be a difference if the license is non-transferable. Then Facebook wouldn't be able to give or sell that data to 3rd parties as part of a bankruptcy sale.
Edit: in the case of RadioShack's user data, I doubt that they got customers' agreement for a transferable license to the data.
I bet this had nothing to do with user data, but with user acquisition cost.
if company spends $10 on marketing and $15 on R&D per new user every quarter, then paying #users$10 when buying a dying competitor is a bargain.
How would you sell one company to another? There isn't much difference between a company being sold because it's being acquired and a company's assets being sold because it's bankrupt and needs to pay creditors.
This is a beautiful slogan. I think that it is far from something by which that businesses will ever abide, or laws will ever try to force them to abide, but I would love to live in a world in which it was true.
The issue here is whether RadioShack may sell the consumer data when its privacy policy said it would never do so.
Whatever the result of this case, it won't apply where the privacy policy permits transfer in bankruptcy (as most now do).
Now, suppose the purchasing company isn't buying the entire business, but (say) half of it? What's changed? (This is roughly what is being proposed here)
There is no gray area here.
There are big privacy issues and little ones and this is definitely the latter. How revealing the Radio Shack's data is of people's behavior should be measured by the outcome of Radio Shack during the period in which it had exclusive access...and here the context is a bankruptcy proceeding.
In general I've started just saying "No". I mean, I went to get my eyes tested and three different people tried to get my email/mobile for their records. I'm not even that bothered about surveillance it's just i'm sick to death of twats phoning me at work to claim compensation/buy something/ give feedback.
I wasn't trying to be difficult or prove a point, I just really didn't want/feel comfortable with either of those things. As they did not impact the office's ability to perform their dentistry, it seemed perfectly reasonable for me to opt-out of them. The strangest part was, based on their confused reactions, it seems I may have been one of the first to deny one or both of those options.
For the consumer, it's a pain to have to manage several identities just to have a shred of privacy when using the internet.
For the company, they always want the most accurate data, so that it can be cross-referenced and properly analyzed (specific aged males like X product better than Y).
I assume that most customer data is accurate, at some companies I've done some verification of customer databases just to identify the "95% accurate" verses the "mostly inaccurate or unverifiable" data, so that it can be excluded in certain instances.
Me personally, I have a wide variety of methods of obscuring data and confusing LexisNexis type companies, I'm not sure how fruitful it is, but it would be foolish to not at least try.
Many places required a verifiable address, which can be difficult to obscure (UPS store works for many things).
If you see a random form online, don't enter your real info dummy. If you see a website offering to lookup someones information, don't give that site your information and credit-card info (I've seen it happen many times).
You also don't want to make it obvious that you are using false data. Using an alternative version of your name and slightly different numbers will do more to confuse data-correlation efforts.
Just for the record, US national security is a completely different issue and I do not support attempting to provide misleading data to those relevant organizations. I've always been on the fence about the data-privacy topic. Humans can do bad things, 7+ billion humans with increasing influence and power slightly worries me. If you order lots of a uncoated fertilizer and do not have a garden or any land, then yes, in my opinion it is acceptable to build a system that raises a red flag on that person to be subject to an unbiased and transparent investigation.
Perhaps I'm too cynical, but when the only recourse is through lawsuits that most can't afford, and even that has been taken away by biased arbitration, we are at a point where most keep their eyes down and hope they don't become a victim of the system.
If the answer is no, then how can trading such information ever be acceptable when you don't know who in what context that information will be used?
> The FTC is so displeased that Jessica Rich, its consumer protection director, has written to the bankruptcy court handling RadioShack’s case, asking that consumers' personal data be protected.
Ars Technica:
> The Federal Trade Commission (FTC) sent a letter to the bankruptcy court presiding over RadioShack's supervised asset sell-off suggesting a compromise that would allow RadioShack to sell its database of information from 117 million customers.
Previous coverage portrayed Apple as intervening to protect customers (although it seems to have more to do with enforcing their reseller agreement):
http://www.imore.com/apple-wades-radioshack-sale-protect-cus...
http://daringfireball.net/linked/2015/05/14/apple-radioshack...
http://arstechnica.com/tech-policy/2015/05/apple-asks-court-...
The stylist is often confused why there are 20 people with that phone number.
>Throughout North America, 1-XXX-555-1212 will connect to directory assistance for the specified XXX area code
I wasn't able to find a link between that number and TellMe/MS. They appear to have had the 1-800-555-TELL (8355) [1] number but no mention of the 1212 number.
Though a google for the number +"Microsoft" reveals they appear to use that number in a couple of their SQL server books [2]
[0] http://en.wikipedia.org/wiki/555_%28telephone_number%29#Real...
[1] http://en.wikipedia.org/wiki/Tellme_Networks
[2] https://books.google.com/books?id=8OxGcCJViU4C&pg=PA68&lpg=P...
Poor Jenny can't get a rewards card anywhere these days.
There is no way I'd not walk out the door and get my hair cut at one of the other 12 places within a 2 mile radius...
What of services for which that isn't possible?
I'm not sure if they still do, but it basically meant whoever was the poor person assigned to the takeout counter that day had to spend at least half their time dealing with people saying "Why do you need my phone number? I'm right here!"
I think they said it was to track customers' ordering patterns over time, which was interesting, but also kind of overkill (and probably misleading, since they wouldn't know when the same people sat down to eat in the restaurant or at the bar).
Another trick is to use a 1 in the first nxx, so npa-1xx-xxxx. Downside is that some basic US telephone checks/regex might fail it.
It felt very odd in 2001 to try and sell electricians that would come in the store at opening to buy 10-11 fuses if they wanted a cell phone, and bother people just getting batteries for their first and last name so they could 'return their item'. We got dinged for each person who refused us. So there is potentially a LOT of data this company is getting.
Radio Shack was definitely in the vanguard of data collection.
Anyway, this is a warning to all of us. No matter what promises that honest startup gives you, the minute they are sold (and most sell in the end) the new owners are free to do whatever they like with your 'private' information. In fact it will be hawked in the marketplace like a chicken.
Is that really the case in the US? In Germany, I don’t see why simply transferring ownership of the data should not also transfer ownership of the agreements bound to that data. If I agree to let company X use my data for purpose A under terms T and company Y buys company X, in my view company Y would still be bound to stick to terms T and purpose A. Otherwise any leaked/stolen and subsequently published personal data could be used by anyone for anything…
We reserve the right to revise, amend, or modify this Agreement and any other policies and agreements at any time and in any manner. We may modify this Agreement by placing a notice of such modification on our website, and User's continued use of the Service following notice of such modification shall be deemed to be User's acceptance of any such modification. User agrees to check this on-line area regularly to determine whether this Agreement has been modified. If User does not agree to any modification of this Agreement, User must immediately stop using the Service.
However IANAL so I might be wrong here.
The default setting of anything like this should opt you out and seek re-confirmation.
volcanic erupts
This sounds like something an aggressive lawyer could have some fun with.
Changing contracts needs explicitly expressed consent here.
Notice that in this case, the FTC is attempting to use the court's approval of the sale of Radio Shack's assets in order to force restrictions on the use of the personal data. That's because they couldn't use virtually non-existent personal data protection laws.
From
http://comingsoon.radioshack.com/privacy-policy/privacy.html
"If we decide to change our Privacy Policy, we will post those changes to this privacy statement, the homepage, and other places we deem appropriate so our users are always aware of what information we collect, how we use it, and under what circumstances, if any, we disclose it. If however, we are going to use users' personally identifiable information in a manner different from that stated at the time of collection we will notify users by posting a notice on our web site for 30 days."
It appears they've done none of this; then again it amounts to accomplishing nothing other than a PR show, so not much has been lost.
Their policy doesn't seem to have considered in its design, "what if we go bankrupt fire everyone and someone else buys us".
I wonder how far back the records go. Could they give me a copy of my Dad's purchase receipt from 1980 for our TRS-80 model III? For 16K of 4116 dram for about $300 or whatever it was back in '81 or '82? On the other hand, given the decline of the company in recent years, if they only have records going back 5 years I probably don't even show up in them.
And for all the wailing and nashing of teeth I can go down to Acxiom and get far more data about people than radio shack has.
And this is why privacy is dead: so long as there is a financial incentive to having this data, it will be bought and sold like any other commodity.
This was a new email account I was trying out made for when I got asked what my email account is by retailers, and I swear that the spam started once I gave the address to them.
http://gizmodo.com/apple-sues-to-prevent-radioshack-selling-...
If anything, I would liken Apple to a jealous and abusive boyfriend - they'll beat and abuse their customers with sometimes arbitrary controls over what they can do with their hardware, but God help you if you try to do the same to their customers. Whether you're a third-party developer, an accessory manufacturer, or anyone with a relationship with those customers, Apple will come down on you HARD if they think that you're harming their platform or exploiting their customers. From that point of view, Apple's action here - trying to interfere with RS' sale of Apple customers' personal data - is typical of Apple.
But is the original privacy policy equivalent to a license (that we consumers grant Radio Shack)? If it isn't, maybe this will be a chance to set a precedent for this to be the case.
Typically, when you license your data to a company you accept that they can sell that data as part of the sale of the business, in the event of administration or liquidation, and a variety of other situations in which you don't want to have to ask the permission of your N million users to go ahead with a merger or other essential business activity.
Further to this, we've also seen client service agencies who are processors of data seizing user data as an asset if a client goes into administration and leaves their service providers as unsecured creditors (i.e. "you're up the creek, we'll pay you £0.000001 for every £ we owe, your £80,000 is now £0.80"), as they also have a responsibility to mitigate their own losses, and again, contracts usually allow for the seizing of assets in the case of default.
So, long story short, this is not even slightly abnormal, and something consumers should consider before providing their data to anyone.
Why are there not consumer protection laws in place to prevent this? In my opinion, in order to sell customer data you should have to go to court and have a judge look over the data to determine what can be sold.
Either way, this is a very grey area, as if you tie up corporate affairs with every single one of your customers, it would make your business unsaleable, and make liquidation impossible, so while consumer protection is desirable, there also have to be measures that allow businesses to operate without the explicit consent of each and every one of their customers for any action.
What's the difference in Facebook acquiring WhatsApp's customer database via purchasing the entire company and it being sold numerous times during a hypothetical WhatsApp liquidation sale? None really, and whatever WhatsApp's (and all other companies) Privacy Policy said about protecting user data is somewhat meaningless.
Increasingly the value in a business is the customer base, and therefore their data - this will only continue as the service economy grows and brand continues to be king.
It's good to know that data is somewhat protected after bankruptcy if a company's privacy policy is in favor of it.
Here is another good article on that particular subject: https://www.turnaround.org/Publications/Articles.aspx?object...
Is there any indication that what you bought there, along with your contact info was sold? Or just your contact info?
If I had fewer scruples I'd actually use the data for criminal acts, but I simply amuse myself by seeing how far I can get with callers.
Oh come on, I was drinking coffee when I read that :(
Merriam-Webster defines evil[1] as:
: morally bad
: causing harm or injury to someone
: marked by bad luck or bad events
Google defines evil[2] as: profoundly immoral and malevolent.
Surely Google isn't profoundly immoral and when they happen to be I'm sure they can add a few hyperbolic adjectives to their definition.[1] http://www.merriam-webster.com/dictionary/evil [2] http://google.com/search?hl=en&q=evil
(This is distinct from "selling / buying the company" which usually means assuming all obligations).
For a class of contractual obligation to be "special" in the context of bankruptcy you typically need some kind of legislative protection (some states have rules about "outstanding payroll gets paid first", student loans are nondischargable, etc). Or some kind of bankruptcy cour ruling that liquidating the assets in this way would be somehow inefficient or against the public interest, which looks like how the FTC is approaching it. But in a circumstance where a huge portion of the business's assets were "private information", I could see a bankruptcy court ruling the other way - this doesn't necessarily establish binding precedent.
As a wise man once said, if you have something that you don’t want anyone to know, maybe you shouldn’t be doing it in the first place.
But there are also dangerous scenarios that don't involve government at all, and that we don't talk enough about.
I'll use Facebook as my example. To make the argument stronger, let's assume that everyone currently at Facebook is committed to user privacy and doing their utmost to protect the data they've collected.
What happens if Facebook goes out of business, like so many of the social networks that came before it? Or if Facebook gets acquired by a credit agency? How about if it gets acquired by Rupert Murdoch, or taken private by a hedge fund?
What happens to all that data?
If Best Buy had swooped in and bought Radio Shack, maintaining it as an ongoing concern I don't think anyone would have objected to them getting the data and honoring Radio Shack's original agreement. That is, they are not a third party, they are the successor to the party of the first part, viz Radio Shack.
Also had a private equity group come in and bought Radio Shack and taken them private, few would have objected to the now private Radio Shack under new management, maintaining the data and the agreements they held.
But by dragging Radio Shack through bankruptcy, they begin to lose the appearance of a successor organization, and begin to look more like a third party.
The first principle is "Australian Privacy Principle 1 — open and transparent management of personal information", and it states that every organisation must publish a privacy policy and it must state "the purposes for which the entity collects, holds, uses and discloses personal information".
That's legally binding. If the company violates it, there are massive fines and the Privacy Commisdioner can investigate.
The investigation for stalking, not so much.
They went into administration, and the administrators came in and wanted to see if they had anything of value.
Data is of value, so they sold it to a rival company. Not a lot you can do about it really, apart from not store the data in the first place.
In this context, "your data" is 100% of the time used to indicate data you've provided to someone else about you. Have you ever seen an article saying "Facebook to target ads based on their photos" or "Google using their data to make money"?
When someone says "company X is using your data", there's a common understanding in play. We all know what they mean. They mean "data they've collected about you". If you want to call everyone names because, taken literally, it's incorrect, then go ahead, but you're beating a dead horse here. And I'm not actually accusing you of pummeling the carcass of an equine. I'm saying you're spending your energy on a pointless task, but doing so in a way that relies on you understanding that the meaning of a sentence isn't strictly determined by the meaning and order of the individual words in it.
Some people don't have a problem with that, though I think they should.
You might be outraged however to discover that your state DMV will happily sell your license/cartag data to corporations.
If you have a privacy policy and you violate it, the FTC comes after you. No policy? No harassment from FTC.
Aside that fact, it's not like they really matter. Right?