When a Company Is Put Up for Sale, in Many Cases, Your Personal Data Is, Too
nytimes.com
nytimes.com
Our subscribers (a little over 10k) trusted us enough to provide us their contact information (and mailing address for print delivery). Turning them over to 3rd party (even after due diligence) just didn't seem right.
Assume a kitten-loving company that will rather die than let your data be abused. They take VC funding, hit a bad turn, take more VC funding. Now the board is controlled by VCs. You're now trusting the VCs with your data and not the company itself.
Assume a second kitten-loving company that will rather die than let your data be abused, and is run by only two co-founders. You give them all your data. The two co-founders end up in a plane crash. Their company is transferred to... who knows really? Your data is now sold off in liquidation to.. who knows really?
But I would never assume the data is actually protected.
At least in theory, that's possible to avoid. If you accepted the data only under a specific set of terms, and ensured either that the original terms under which data was obtained are those that apply, or that specific privacy and usage terms were required to survive into any successor agreement, then in doing so you'd bind any future owner of the company by the same terms. You can't sell (or liquidate) something you don't have the rights to yourself.
Even if you had laws, I'm not sure they would help in this case.
Besides, even if you have perfectly written self-binding contracts, there's nothing stopping the next owner from being a scumbag and finding clever or illegal ways around the deal. eg, he could 'find' a million dollars on the pavement in the surprising position where he happened to 'lose' a hard drive with all the data. Exaggeration obviously, but if the data is in someones possession there are a lot of things that can be done with it without overtly breaching any agreement. Eg, he could start a new company himself that 'leverages' the data to provide all previous customers with 'incredible deals and benefits'.
But yes, even better protection would be never collecting data you don't need in the first place.
"Germans even have a word for it: Datensparsamkeit, the principle of only collecting the bare minimum of data necessary." (http://qz.com/390988/germans-are-paranoid-that-the-us-is-spy...)
Since the concept was established in 1983 by the constitutional court, there's probably a body of knowledge around that, just in the 'wrong' language and hence less known in the anglo-saxon culture.
http://eur-lex.europa.eu/legal-content/en/TXT/?uri=CELEX:319...
"Personal data shall be adequate, relevant and not excessive in relation to the purpose or purposes for which they are processed." [2]
Which the guidance[1] explains as "So you should identify the minimum amount of personal data you need to properly fulfil your purpose. You should hold that much information, but no more. This is part of the practice known as “data minimisation”."
[1] https://ico.org.uk/for-organisations/guide-to-data-protectio...
[2] http://www.legislation.gov.uk/ukpga/1998/29/schedule/1/part/...
And why isn't the user allowed to specify the amount of bits that google store about us?
There are 7 billion people on this planet. If I allow google to store at most 32 bits about me, then at least that data cannot uniquely identify me (roughly speaking).
No, I don't think companies should be aggregating all data without regard for consequences of breach, but nor do I believe that cutting data is the answer. Consumers, nee, people, need to learn that 'their' data is not so special snowflake, and that aggregate data is a fantastic tool for making their lives better.
https://en.wikipedia.org/wiki/Scientific_method
Sure you can. Who's going to stop you? The Data Privacy Police aren't going to come and break up the bankruptcy auction.
If anybody who understands this issue says anything other than "Stop giving people data that you don't want others to have" then I have to question their judgement. If you do decide that something is incredibly valuable then hand over the data; but make sure you consider the data 'sold'.
Now think about how they often contain your home address, birthday, spouces, photos etc...
If a company buys yours, does anyone expect them to buy everything expect for the information on their customers?
That gets nasty if a company is selling only the data, but the legalese that allows companies to sell data to whomever may be buying the company shouldn't come as a surprise.
Especially in times when most "tech savvy" people advice the use of cloud services for backups, syncing, sharing and communication, a sale of a company becomes a privacy nightmare for those who listened and tried out these services. There should be more people that spell out that it is not safe to upload your data to someone else's computer.
Would you upload a backup of your data to my computer? Of course not. Would you do it if I made an over-designed one page website and offered an iOS/Android app? There are a lot who do that every day. Once the deed is done, I shouldn't be allowed to do whatever the hell I want with your data. Selling or sharing data with third parties should be strictly opt-in, no matter the circumstances.
Imagine your Dropbox, Password manager or backups being sold to the highest bidder. A company which you previously trusted becomes greedy and sells you out. There's nothing you can do about it because "you should have read the small print 10 years ago, when you started using the service." It's not surprising that there are people who'd sell you out. What is surprising is that it is allowed.
According to studies cited in the last week on HN, yes. People underestimate the sociopathy of the corporate world. Or perhaps expect more European norms to apply.
> If a company buys yours, does anyone expect them to buy everything expect for the information on their customers?
Pretty much everyone in the western world that isn't the United States expects that because it's enforced by law. Although US companies are trying to get their proxies in the US government to have that stripped away as a "trade barrier".
Social media companies have a lot of data, yes, but most of it is pretty benign. The world should be far more concerned about the PII that gets transmitted around less tech-savvy smaller businesses and non-profits. Particularly for-profit education companies.
Education companies have gobs of very sensitive info like social security numbers, previous addresses, family relationships with full contact info, medical history etc and many of them are clueless when it comes to privacy and data security. Not only are they at high risk for data breaches but their lists can also get acquired and traded when the business changes hands.
It does always make me think twice before committing to using a startup's product, you never know who is going to fail and sell assets to the highest bidder, or who is going to get acquired by a big company whose ideals you don't like.
The problem is that oftentimes, the data is one of a company's most valuable assets, so you can't just make it off-limits since that would erase a lot of the value. I just wish there was a better legal framework to handle these kinds of situations.
http://www.statista.com/statistics/289505/social-networks-va...
also user generates revenue by themselves
http://www.technologyreview.com/article/424650/how-much-is-a...
edit: updated link to more recent stats
Was part of Startup with really fast growing user base, but small amount of sales. What some investors really suggested to do with our database - is to sell it!
So companies can sell personal data (and they do it) not only when put up for sale, but at any time.