At least it didn't (hopefully?) start the driving by reloading the gun like Neuro did https://www.youtube.com/watch?v=LQ0VEDNR_jE
1,302 karma · joined October 8, 2016
Especially interested in systems scaling & IAM and also general interest in most of thing on backend side.
You can reach me via <username>@<username>.net
At least it didn't (hopefully?) start the driving by reloading the gun like Neuro did https://www.youtube.com/watch?v=LQ0VEDNR_jE
Civil liability is helpful because tax payers do care about $$$ (if judgements/settlements are starting to eat major part of budget the people will start to care on how to lower those costs) and victims are not limited by what prosecutors are ready to do. The QI is especially problematic because it has essentially become "did someone prosecute cops about this before" because that's effectively the only way to establish precedence that allows you to get across the QI-line in future for sufficiently similar conduct. And like you said, prosecutors are often unwilling to prosecute cops.
> Italian Supreme Court case law according to which defensive controls may be carried out where there is a well-founded suspicion of unlawful conduct, provided that an appropriate balance is struck between the employer’s interests and the employee’s dignity and privacy, and that the control concerns data acquired after the suspicion arose.
> ‘controller’ means the natural or legal person
There have been various cases where individuals have been determined to be separate controllers. For example there have been many cases where doctors/nurses/police looked into the employer's databases without having professional need and were determined to be separate controllers and were fined under GDPR.
* Who actually determines the essential means and purposes for each processing purpose (and is truly doing it). Fashion ID case is quite relevant here.
* If terms which grant Meta these rights and user a lot of obligations would fall under unfair terms or unfair commercial practices directives. If they do then those aspects of the terms are invalid. These could, for example, affect requirement that the user must get consent from data subject for Meta's processing operations.
And I believe in case of European users the contract is between Meta Ireland and user, Meta Ireland is the one who would be the one doing the exporting in that case.
Now if user actually did publish it on Meta's service for broader consumption then they might become controller for that & if initial purpose was that then the initial recording is unlikely to be exempted under household exemption.
> The first layer concerns the primary way in which the controller first engages with the data subject. At this stage, controllers may use a warning sign showing the relevant information. The displayed information may be provided in combination with an icon in order to give, in an easily visible, intelligible and clearly readable manner, a meaningful overview of the intended processing (Article 12 (7) GDPR). The format of the information should be adjusted to the individual location (WP89 par. 22).
> The information should be positioned in such a way that the data subject can easily recognize the circumstances of the surveillance before entering the monitored area (approximately at eye level). It is not necessary to reveal the position of the camera as long as there is no doubt as to which areas are subject to monitoring and the context of surveillance is clarified unambiguously
> The first layer information (warning sign) should generally convey the most important information, e.g. the details of the purposes of processing, the identity of controller and the existence of the rights of the data subject, together with information on the greatest impacts of the processing
While recording by these might not always implicate GDPR directly (as it might be exempted under household exemption or the broader allowances given for journalistic purposes), it does give good idea on how unambiguous it should be.
However that privacy policy raises also quite a few concerns. They say that "profile image URL" is based on contractual obligation which is quite weird, just why profile image is necessary to fulfill a contract? Additionally IP address and location are collected for "adapted pricing" and it's "legal and contractual obligation". I can somewhat understand that if it's used to calculate VAT, but "adapted pricing" sounds much wider thing. And even VAT calculation itself isn't really "adapted pricing", it's something that the company needs to handle. They are of course free to change the price based on that, but that price change goes more to legitimate interest rather than legal (or contractual) obligation.
They also claim that "Product analysis and improvement, marketing and attribution, incident management and in some of our logs" as well as "Analysis of products and navigation on the site and application" are also "legal and contractual obligation". I honestly want to hear what contract necessitates those or exactly what law requires them to do that.
1) what is the legal basis for storing it and if that's proper or not (e.g. legitimate interest requires balancing test)
2) if proper GDPR Article 13 notice was given and it covers that processing
3) if all Article 5 principals are being followed in regards to it (e.g. data minimization, retention period etc.)
4) if Microsoft had legal basis to transfer the data to police (they probably did, that's not high bar to clear)
If the the processing is subject to GDPR (e.g. if controller is in EU) then you do have recourse. You can complain to DPA or sue the company. The company is ultimately responsible for the decision to block you, at least in cases where you personally tried to access the site.
ePD is still active and national laws implement it. GDPR itself is not implemented by national laws as it's EU regulation rather than EU directive. Member States primarily repealed their DPD-based laws after GDPR and implemented various things that GDPR allows (like Article 23 restrictions). Some countries may have explicitly imported GDPR into their own law due to how their own legalization works. Like that's why UK DPA was originally pretty much just copy of GDPR.
Other processing (like after value is read) can happen under GDPR if the data is personal data.
> strictly necessary in order for the provider of an information society service explicitly requested by the subscriber or user to provide the service.
One very ignored qualifier here is "information society service". This is defined in Directive 2015/1535 and one of the requirements is that the service is "normally provided for remuneration". That is usually understood to mean that the service needs to be tied to provider's economic activity. This effectively excludes, for example, public authorities websites which are for their own public duties. It does however include e.g. ad supported websites.
And yes, I'm aware that many national implementations actually miss that qualifier. That can save the non-commercial private sector websites, but public authorities do not benefit from Member States failing to transpose Directive correctly.
You could, for example, require that user answers very specific questions regarding 10 randomly selected partners and how exactly they can use the data ("is partner x allowed to build very detailed profile of you and target you with political adverts that are designed to manipulate you?").
It's hard to say directly from the article if there is any GDPR breach. If everything was part of the installer and it doesn't actually submit anything (including downloading the ad) to LG then it's harder to argue that there is GDPR violation, but knowing the SOP of these kinds of software that is unlikely.
If the software did indeed send personal data to LG then there are at least following question: How was Article 13 notice delivered to user? Article says that this was installed quietly. Did Microsoft deliver Article 13 compliant notice to user at some point? They probably did deliver their own notice (though it's open question if it's compliant), but not LG's. However since Microsoft is the one that installed the software and they exercise control over the standards which must be met, it's possible that they would end up being joint controller at least for some processing.
I should add that Article 13 requires that the notice is given "at the time when personal data are obtained". The only exception is when "data subject already has the information" and possible Article 23 restrictions, but those are unlikely to apply.
If someone wants to make a complaint they should first make Article 15 request to LG. Copy of personal data is useful, but 15(1) information is the primary goal. Additionally ask for information on how and when did LG provide you the Article 13 notice if they did indeed process your personal data.
After that if they cannot show that they provided Article 13 notice when they received your personal data submit a complaint to your local DPA. You can additionally flag other violations as well if they are applicable (e.g. not naming recipients as part of Article 15 response, not giving actual retention time or meaningful information how that is determined, invalid legal basis etc.). You should also flag in the complaint that Microsoft is likely joint controller for some of the processing given that they are the ones who approved the automatic install of the software which violated GDPR.
Or do you mean the feedback stuff? Their KB article at least seems to contradict that.
https://help.openai.com/en/articles/5722486-how-your-data-is...
> Even if you have opted out of training, you can still choose to provide feedback to us about your interactions with our products (for instance, by selecting thumbs up or thumbs down on a model response). If you choose to provide feedback, the entire conversation associated with that feedback may be used to train our models.
https://privacy.claude.com/en/articles/7996885-how-do-you-us...
> If you explicitly report materials to us (e.g.via our thumbs up/down feedback mechanisms), or by otherwise explicitly opting in to training, then we may use those materials to train our models.
Now what I would expect AI companies to do is to take things which were submitted as feedback and pretty much adding to training:
"Do more of this: <copy of the whole response which was flagged as good in feedback>"
"Do less of this: <copy of the whole response which was flagged as bad in feedback>"
It's paraphrased, but the point is that they will most likely use it more-or-less as-is and thus whatever is in there will be part of the model's training set rather than someone picking up the parts from response that are important and only including them (which happens with traditional feedback).
https://sushiconfidential.com/wp-content/uploads/2024/07/sc_... "3.5% Living Wage Surcharge added to each bill which allows us to provide the service you have always enjoyed!"
https://www.pacificcatch.com/menu/ "NorCal - A 3% surcharge (5% in San Francisco) will be added to all Guest checks to help offset the rising cost of wages and benefits. This is not gratuity."
In theory someone could directly sue some company which engages on this via Article 79, but this can be expensive and depending on jurisdiction the plaintiff can end up with personal liability on defendant's legal costs if court ends up finding that this is actually legal (e.g. Finland has "loser pays" rule in civil suits).
Additionally this does also touch ePD and in some countries there might be different agency which handles ePD complaints compared to GDPR, like in Finland Data Protection Ombudsman handles GDPR, but Transport and Communications Agency (Traficom) handles ePD. If there is something that touches both the Ombudsman usually lets Traficom take care of ePD aspects before they give any GDPR ruling. Both of these can take years.
> This shall not prevent any technical storage or access for the sole purpose of carrying out or facilitating the transmission of a communication over an electronic communications network, or as strictly necessary in order to provide an information society service explicitly requested by the subscriber or user.
This is the reason why these are usually separated to "strictly necessary" and "functional" cookies. Functional cookies are things which enhance the functionality, but are not strictly necessary. These would generally include things like persistent cookie for language choice rather than just session one.