Live data from Hacker News

Can I remove my personal data from GenAI training datasets?

knowingmachines.org

31–40 of 123 posts

Re: Can I remove my personal data from GenAI training datasets?

#31
post #12
post #9

Earlier quoted context omitted.

The complete lack of power or ownership of your work. Do you think anyone consented to have AI companies scrap GitHub etc?

Eh, you borrowed from society to create 'your work' and now you want to lock it up like you've created it wholly.

By that standard no copyrighted works have any protection, except clearly that isn’t the world we live in.

Re: Can I remove my personal data from GenAI training datasets?

#32

I don't get it, you put that information on the internet, you have no expectation to privacy. But now maybe you learned a lesson, and you won't publicly share things you don't want people to see?

I do have an expectation to privacy. It is possible to secure information if so desired.

Do you expect your online bank to secure your data? Your email provider? Your healthcare provider? So you do expect some privacy. I just expect some more. I believe that companies should not own my data just because they provide me with services off it. From that, consequences follow.

I have a better proposition: let's slap companies that don't respect privacy with fines until they too learn a lesson.

Re: Can I remove my personal data from GenAI training datasets?

#33

Earlier quoted context omitted.

The “right to be forgotten” is an explicit right in the EU, which I think applies here.

I'm not saying that this right is a bad thing, but the reality is that it's rarely enforceable. As soon as you put something on the internet, you have every "right" to expect that it's there forever. No amount of legislation can outweigh the technical reality.

The government has no problem getting rid of CSAM and terrorist material, for practical purposes. It's not a technical problem.

Re: Can I remove my personal data from GenAI training datasets?

#34
post #33

Earlier quoted context omitted.

I'm not saying that this right is a bad thing, but the reality is that it's rarely enforceable. As soon as you put something on the internet, you have every "right" to expect that it's there forever. No amount of legislation can outweigh the technical reality.

The government has no problem getting rid of CSAM and terrorist material, for practical purposes. It's not a technical problem.

They only get rid of those materials that they can seize. I doubt they will be able to seize a properly hosted onion domain. It's just that most of the actors aren't good enough with technology.

That's the reason you mostly see the pretty dumb guys getting caught. As long as you are smarter and more tech-savvy than 80% of the criminals, you are pretty much out of reach for the feds.

Re: Can I remove my personal data from GenAI training datasets?

#35
post #23
post #10

The article weasels out at the end by claiming that companies “may be unable to comply” with requirements to delete personal data. It’s easy to comply - if there’s no other choice then you delete the model and all backups and derivative data that was trained in flagrant violation of the law.

For most companies “deleting the model” is equivalent to dissolving the company so that is equivalent to not being able to comply. More realistically what they would need to do is exit the market of the country that has such stupid laws.

>For most companies “deleting the model” is equivalent to dissolving the company

I'm okay with that. It's sad that you're not. If you're willing to start a business on such shady foundations, there's a really good chance your business will continue to make shady decisions in the future. It's better to find and remove the cancer early

Re: Can I remove my personal data from GenAI training datasets?

#36
post #29

Earlier quoted context omitted.

They consented if the data was public. Opt-out scanning practices is a whole other beast. But unfortunately, unless you challenge the ToS in court, you consented the moment you didn't delete all of your data after the policy update. Is that fucked? Sure, and maybe we need regulation around that, but in the face of current legislation, consent was granted.

That’s factually incorrect. GitHub’s ToS don’t give them any rights to use your information in this way. Their argument is they don’t need any such permission, but they can profit from this data by selectively allowing large scale scrapping by 3rd parties thus breaking their TOS by selling your data.

GitHub's ToS expressly allows them to change the terms of their service at will, and they do indeed publish these changes, and your continued use of their website is considered consent.

Furthermore, as [0] states:

> We may use your information to provide, administer, analyze, manage, and operate our Service. For example, we use your information for the following purposes:

> ...Improve and develop our products and services including to develop new services or features, and conduct research...

[0] https://docs.github.com/en/site-policy/privacy-policies/gith...

Re: Can I remove my personal data from GenAI training datasets?

#37
post #23
post #10

The article weasels out at the end by claiming that companies “may be unable to comply” with requirements to delete personal data. It’s easy to comply - if there’s no other choice then you delete the model and all backups and derivative data that was trained in flagrant violation of the law.

For most companies “deleting the model” is equivalent to dissolving the company so that is equivalent to not being able to comply. More realistically what they would need to do is exit the market of the country that has such stupid laws.

[deleted]

Re: Can I remove my personal data from GenAI training datasets?

#38
post #4

Earlier quoted context omitted.

There are zero incentives for them to comply and zero ways a person can make them accountable. If your SSN can be leaked and nothing will happen why would they care about scrappable pictures? The only times they care are when it can cost them money. SD didn't care about visual artists but could not do the same for generative music since the rights are managed by deep pockets.

Frankly, and not directed personally, but that’s not really true. Government can make the incentive — and has. Legislation can put the teeth in societal goods like this even if financial incentives don’t. California has done exactly this with their right to be deleted law. https://www.foley.com/en/insights/publications/2023/10/calif... .

The two parties are the state and the data brokers. The individual has no way to do this on their own. But you're right, it doesn't have to be true. Maybe someone will have precedence and sue a company. Until then I am convinced it is true.

Re: Can I remove my personal data from GenAI training datasets?

#39

Earlier quoted context omitted.

The “right to be forgotten” is an explicit right in the EU, which I think applies here.

EU rights do not apply in the US.

The 'right to be forgotten' isn't a right.

Re: Can I remove my personal data from GenAI training datasets?

#40
post #33

Earlier quoted context omitted.

I'm not saying that this right is a bad thing, but the reality is that it's rarely enforceable. As soon as you put something on the internet, you have every "right" to expect that it's there forever. No amount of legislation can outweigh the technical reality.

The government has no problem getting rid of CSAM and terrorist material, for practical purposes. It's not a technical problem.

It is obviously a technical challenge. Image yourself trying to facing 3 pictures, one of CSAM, another of terrorist material and just some random photo of random guy eating ice scream: what steps would you do to determine if this last photo is "legal" or not?

YouTube have decades of attempt at determining if uploaded content violates copyright, normally through fingerprinting content submitted by right holders. YouTube still fails at catching all copyright infringement. That's why they are generally protected from prosecution while they demonstrate reasonable attempt that preventing their services from being misused.

Imagine ALL IMAGES IN THE WORLD being submitted for fingerprinting. How about malicious or erroneous submitions that taint datasets?

Also: right to be forgotten is a horrible misleading name. At most you have right to request data to be removed from datasets. And only if you have some legal basis that demonstrate that your data is in that dataset. It is not a right to be "forgotten". Imagine you yourself being told to "forget an image, sound, etc", how is this enforced? You may even ask for proof that you know the content you are being told to forget. How do you do this?

Post reply on HN