Live data from Hacker News

We caught companies making it harder to delete your personal data online

themarkup.org

31–40 of 76 posts

Re: We caught companies making it harder to delete your personal data online

#31

Earlier quoted context omitted.

Yes, I am happy I can export my data with google but boy it is annoying to do.

Those pricks throttled the download to 30 kbps. When I tried to download with aria, after a few failed attempts (not straight forward ofc) I got a message saying I can only download it 6 times, and that I should send a new request. This is evil.

Yes, I am sure this is a mustache-twirling power move by Google, and not a bug in your obscure 20-year-old HTTP utility.

Re: We caught companies making it harder to delete your personal data online

#32
post #30
post #15

Earlier quoted context omitted.

Some companies somehow blatantly get away with not allowing any export at all. For example, Amazon eero, the overpriced WiFi router that doesn't even work (without phoning back home and having an app installed on your phone). They had an outage like a year ago, and during said outage, all your existing ad blocking stopped working, too, even if you never rebooted during the outage, and even though said blocking is sup…

> Does anyone know how exactly does Amazon get away with not providing data export for their eero product? I checked eero.com. It seems info about the product other than “it’s a secure WiFi router that doesn’t require users to manage it” is in the videos, if it is on that site at all, but I couldn’t get the videos to play, so I may be wrong, but why would a WiFi router have personal data on the device? It will have t…

I’m guessing Amazon could have info on their side about your eero. Without knowing more about the router’s cloud functionality it’s hard to say what exactly they would have.

Re: We caught companies making it harder to delete your personal data online

#33

Has anyone used deleteme or a similar service? What was your experience, and do you feel it was worth it? It feels like such a cat and mouse game, that should be easy to automate, that said, I'm not sure it'll be effective.

I have used Incogni for a few years now, I was a little worried after the first year things wouldn't be worth the price, but I'm noticing that there are data brokers who will happily remove you but not put you on a block-list, meaning that they will happily ingest your information again if it comes to them, and another request from Incogni will be needed to remove it again.

I'm on the fence about whether that's real value delivered from Incogni, but I do think overall it's working to limit some of the spread of my data.

Re: We caught companies making it harder to delete your personal data online

#34
> Telesign, a company that advertises fraud-prevention services for businesses, offers a simple form for “Data Deletion” and “Opt Out / Do Not Sell”. But that form is hidden from search engines and other automated systems, and isn’t linked on its homepage. > > Instead, consumers must search about 7,000 words into a privacy policy filled with legalese to find a link to the page.

In fact, while they do have a robots.txt [1], their form [2] isn't actually listed there. Instead, the page itself has a meta tag:

    
The reason is probably something mundane like this being easiest to do via the Wordpress UI, but putting on my conspiratorial hat, they just want to make it even hard to find out that they did this.

(Disclosure: I work on Mozilla Monitor, where we try to help people send these data deletion requests.)

[1] https://www.telesign.com/robots.txt

[2] https://www.telesign.com/privacy-requests

Re: We caught companies making it harder to delete your personal data online

#35

Does deleting your data even matter if it's already been sold to a data broker?

If you are a California resident you can request a deletion via the state's new DROP platform which is launching next year. That will send the deletion request to every registered data broker in the state who will then have 45 days to comply. Part of that compliance is sending deletion notifications to everyone downstream that they have shared or sold your data to in the past. The penalty for not responding to a DROP request is going to be $200 a day, per request.

Starting in 2028 CA registered data brokers will have to undergo audits to ensure that they have been complying with deletion requests to the fullest extent of the law. Now, maybe only 20% of actual data brokers are registered in California like they are supposed to be, but it's a start.

Shameless plug: I'm building a platform to help the data brokers actually delete the data they are supposed to, provide full auditing and accounting for that process, and automate privacy request handling: forgetmenaut.com

Re: We caught companies making it harder to delete your personal data online

#36
post #30
post #15

Earlier quoted context omitted.

Some companies somehow blatantly get away with not allowing any export at all. For example, Amazon eero, the overpriced WiFi router that doesn't even work (without phoning back home and having an app installed on your phone). They had an outage like a year ago, and during said outage, all your existing ad blocking stopped working, too, even if you never rebooted during the outage, and even though said blocking is sup…

> Does anyone know how exactly does Amazon get away with not providing data export for their eero product? I checked eero.com. It seems info about the product other than “it’s a secure WiFi router that doesn’t require users to manage it” is in the videos, if it is on that site at all, but I couldn’t get the videos to play, so I may be wrong, but why would a WiFi router have personal data on the device? It will have t…

It collects WiFi Radio Analytics (2.4GHz / 5GHz-Low / 5GHz-High frequency utilisation), Activity History (data usage by device, as well as "scan" and ad blocks by device).

For ad blocking and network control, it also has "Block & Allow Sites" with the blacklisted and whitelisted domain names, which you may have to use to block ads and also unblock some domains that stop working as a result of bogus entries in the ad block.

All of this information is stored in the cloud, but I found no way to export it in any way. I've actually contacted eero, asking for the export, and they've basically admitted that it's not supported.

Re: We caught companies making it harder to delete your personal data online

#37

And as important: making it impossible or very hard and annoying to export and own your data.

We didn't set out to hide our GDPR requests, we put them behind our Support/Legal button. But we got sued anyway, and we lost.

Now we have to have the "delete my data" and "request my data" as part of our main settings list. Result: flooded with requests. People are clicking the buttons just because they are there. For me it's not a big deal, I automate all the requests. But, I still feel like this went too far.

Re: We caught companies making it harder to delete your personal data online

#40

And as important: making it impossible or very hard and annoying to export and own your data.

We didn't set out to hide our GDPR requests, we put them behind our Support/Legal button. But we got sued anyway, and we lost. Now we have to have the "delete my data" and "request my data" as part of our main settings list. Result: flooded with requests. People are clicking the buttons just because they are there. For me it's not a big deal, I automate all the requests. But, I still feel like this went too far.

I don’t know what business you work for, but what makes you sure users aren’t clicking the buttons because it’s what they want AND it’s convenient?
Post reply on HN