The internet exists as an information resource that people need to be able to sift through themselves, not something that governments or other self selected groups decide to arbitrarily censor for whatever selfish reasons they have.
I invented the web. Here are three things we need to change to save it
211–220 of 255 posts
Re: I invented the web. Here are three things we need to change to save it
#212Surprised that no one mentioned the new EU data protection directive, which goes a long way to fix the first issue mentioned in the article, the loss of control over our personal data (only for users in Europe though). I studied it in detail as I work in data analysis and consult companies on this, and I honestly think it is one of the best laws produced by the EU so far: It gives users a multitude of rights such as…
Re: I invented the web. Here are three things we need to change to save it
#213Earlier quoted context omitted.
I think you're dead wrong about this. Desktop developers have been thinking for decades all the web needs is a more-desktop-like environment. The general conclusion of web developers is that they like html, CSS and JavaScript and want them to improve, not disappear. Many people see them as the evolution of GUI development, not anything to be removed.
Only web developers that have never actually written desktop apps think that in my experience. The prevalence of hacks, frameworks and layers that try to make the web stack marginally less terrible suggest that no, they don't like html, css and javascript - they deal with them because they have no other choice and it's all they've ever known. Just take SASS as an example. Why does it exist?
Re: I invented the web. Here are three things we need to change to save it
#214Surprised that no one mentioned the new EU data protection directive, which goes a long way to fix the first issue mentioned in the article, the loss of control over our personal data (only for users in Europe though). I studied it in detail as I work in data analysis and consult companies on this, and I honestly think it is one of the best laws produced by the EU so far: It gives users a multitude of rights such as…
2) How specific is "for which purposes?" I can't imagine companies would ever go collect explicit opt-ins for every new SELECT statement in their codebases. It seems like the only thing to do is list the broadest possible set of purposes upfront.
3) How do you decide whose data it is? For example, HN comments can't be deleted because they're considered the internet's data, not yours.
What if I sync my contacts containing your phone number, or a photo of us together? If you demand the deletion of "your data" then do my contacts and photos disappear?
What if you make a scene at some establishment, or default on a loan? Can you demand that their record of "let's not do business with this person again" go away?
Re: I invented the web. Here are three things we need to change to save it
#215Earlier quoted context omitted.
Is this just an opinion, or do you have any data on this?
Opinion. I mean we tell kids to be wary of strangers, but we can't assign a policeman to every stranger. Easier to teach people that they can be deceived or that bad things can happen, than to prevent any deception or bad thing from ever occurring.
Continuing this analogy - it actually turns out in practice that child abusers are almost never strangers, but someone known to the child, such as a teacher.
Re: I invented the web. Here are three things we need to change to save it
#216Surprised that no one mentioned the new EU data protection directive, which goes a long way to fix the first issue mentioned in the article, the loss of control over our personal data (only for users in Europe though). I studied it in detail as I work in data analysis and consult companies on this, and I honestly think it is one of the best laws produced by the EU so far: It gives users a multitude of rights such as…
If my business runs servers out of Canada that Europeans use, what are the enforcement mechanisms for this law?
Re: I invented the web. Here are three things we need to change to save it
#217Earlier quoted context omitted.
Woah, didn't know it went this far. If anything, this would be great for facebook (which has been anything but transparent when it comes to what they do with your data when your account is deleted). Google already has some relatively transparent controls on what data they have on you, and allow you to wipe all or parts of it.
Max Schrems, an Austrian lawyer, sued Facebook Ireland over this and got them to release all his data. He also keeps a website where he explains how to get yours: http://europe-v-facebook.org/EN/Get_your_Data_/get_your_data...
Facebook emailed back stating:
"There isn't a Facebook account associated with the email address from which you are writing. This might be because you don't have a Facebook account or because you already deleted your account. In either of these cases, we do not hold any of your personal data."
I didn't ask for data attached to an email address, I asked for any personal data they had collected on _me_ and their answer was evasive and non-responsive. I didn't pursue it any further but I know they are bullshitting me, and I had to move on to other things.
Re: I invented the web. Here are three things we need to change to save it
#218Earlier quoted context omitted.
If my business runs servers out of Canada that Europeans use, what are the enforcement mechanisms for this law?
European businesses will be punished with the sane terms as well if they use a service which is non eu compliant. So they can only use compliant services.
Does it flow through to subsidiaries or EU citizen owned foreign enterprises? Because it seems like this could lead to a regulatory race to the bottom.
Re: I invented the web. Here are three things we need to change to save it
#219Earlier quoted context omitted.
You also have the right to demand the deletion of your personal data and to revoke the right of a company to process it, as well as to demand correction of inaccurate data. This is probably the biggest change. Previously, at least in Europe, the emphasis has typically been on allowing people to know what data was being collected and to require correction of inaccuracies, but much less on whether it was actually allow…
Yes it surely creates some work for companies, but on the other hand what good would it be if you could just keep personal data around just because it happens to be on a backup tape? Companies simply have to implement suitable backup schedules, which will ensure that the data gets deleted within an acceptable time period (e.g. two weeks), which is doable without actively erasing any specific data (instead of simply e…
Arranging proper backups at all is not something to take for granted when you're dealing with small businesses that have many other things to do, but obviously they're important for safeguarding the provision of products and services to all customers and it's important that any backups that are made are handled with proper regard to both security and integrity.
Requiring businesses to separate every tiny item of data that might ever be legally required from every tiny item of data that is collected and used with consent for reasonable purposes, just in case some customer one day decides to retrospectively withdraw their consent for some or all of that data, could easily become absurdly disproportionate. I hope it would go without saying that incentivizing businesses not to keep backups of all important data because of the compliance overheads is insane.
However, without such fine-grained separation, two weeks might be far too short a period to keep backups. To use my own businesses as an example here, we have accounting and reporting obligations that potentially require several years of data. The reporting information is typically derived once a year during reporting season, from straightforward records kept in the main databases and/or spreadsheets. However, we would probably have to completely restructure those records and denormalize all kinds of things in order to delete everything we don't strictly need for some legal purpose, which would be a huge amount of work.
That's just the structure of the original data. Then you have to consider things like deduplication in online backup services, where it's practically impossible to guarantee the complete destruction of all instances of certain data without destroying all backups that ever involved that data and starting over.
If this is the situation for small businesses that typically only collect a small amount of personal data in the first place and for obvious and necessary purposes, I shudder to think of the implications for organisations that actually process personal data as part of their main purpose rather than incidentally. I'm not sure it's reasonable to assume, in general, that it would even be possible to totally separate legally required data from everything else in such organisations, and there would surely be a lot of grey areas.
Now, please don't misunderstand me. I'm all for reasonable regulation to protect individuals from exploitation. I'm a privacy and civil liberties advocate, and I run my own businesses the way I hope others would run theirs, even if sometimes that means not doing things that would probably make us more money because they also make us feel uncomfortable. But there has to be a sensible balance, and the EU does not have a good track record of balancing its business regulations sensibly. (See also: EU VAT, cookie law, various provisions in the last round of consumer protection rules, etc.)
Re: I invented the web. Here are three things we need to change to save it
#220Surprised that no one mentioned the new EU data protection directive, which goes a long way to fix the first issue mentioned in the article, the loss of control over our personal data (only for users in Europe though). I studied it in detail as I work in data analysis and consult companies on this, and I honestly think it is one of the best laws produced by the EU so far: It gives users a multitude of rights such as…
1) How does this interact with backups? It would seem impossible to build a safe backup system that can comply with "delete all this user's data" faster than the expiration of the backup retention period. Recovering from backup could potentially reintroduce data about someone who requested deletion. 2) How specific is "for which purposes?" I can't imagine companies would ever go collect explicit opt-ins for every new…
This is one of the most tricky areas in deciding what is reasonable. Obviously there are advantages to being able to share personal data about other people for your own benefit. On the other hand, every time you do that, you are potentially giving someone personal data without the subject of that data's consent.
I don't think we fully understand the implications of modern technologies in this area yet. However, I suspect we'll be learning some lessons the hard way over the next few years, as the correlation and processing of that data starts to catch up with the volume of data that's been collected.
It's also possible that some of the people giving up that data about other people, or more likely the businesses that encourage individuals to do so, are going to come under a lot of scrutiny even in terms of compliance with existing law and regulations. For example, if you install a social network's app on your phone, and that app uploads your contact list complete with names and phone numbers to their database, then both you and the social network have obviously just compromised the privacy of everyone on your contacts list. That much is black and white, but if the social network concerned then uses that data for any purpose other than providing whatever services you are explicitly requesting in terms of the contact list you already had, then from a data protection point of view it becomes a lot more just black. I'm a little surprised that data protection regulators, particularly in Europe, have taken such a hands-off approach to this issue for as long as they have already.