Earlier quoted context omitted.
> I don't understand how trading one ISP for another (Cloudflare?) is an improvement long-run. The system itself needs to be resilient, not just depend on the kindness of the upstream gods. Mozilla and Cloudflare negotiated a special privacy policy for Firefox DoH requests [1] that limits what Cloudflare can do with the data – in particular, most information must be deleted after 24 hours. There is no technical measu…
Oh, they promised not to be evil, did they? That link isn't very reassuring. Who are parties to the contract? Who can enforce it? What does it cost to breach?
That's the main mechanism for enforcement, but there are a few additional ways it could theoretically be enforced:
- The FTC and state attorneys general can sue companies for violations of their own privacy policies, as "unfair and deceptive acts and practices". For example, they sued Cambridge Analytica recently. [1]
- The California attorney general in particular would also be able to sue under the California Consumer Privacy Act once it goes into force.
- As for ways for individual consumer to sue... well, it's more difficult, but possible. For instance, a class action suit against Facebook on a grab bag of claims, also related to Cambridge Analytica, recently survived a motion to dismiss. Among other things, the judge held that users could sue for breach of contract if Facebook violated its privacy policy. [2]
[1] https://www.ftc.gov/news-events/media-resources/protecting-c...
[2] https://www.cand.uscourts.gov/filelibrary/3755/Order-re-Moti...