Live data from Hacker News

TeleSign profiles half of the world’s mobile phone users

noyb.eu

11–20 of 78 posts

Re: TeleSign profiles half of the world’s mobile phone users

#11
post #9

Side note/doubt. By asking to have your data through a GDPR request you are effectively giving to the receiver of the request: 1) your full name 2) your phone number 3) your e-mail i.e. basically a confirmation that both the phone number and e-mail are good/active/attended and that they are yours (and that you "exist"), while the data they may already have likely is only the telephone number and the patterns of its u…

Does the full name have to be your legal name?

I use different names/email on every site, but phone numbers are always these 2~3 numbers. If I'm going to send a deletion request under GDPR alike laws, it would be under different names.

Re: TeleSign profiles half of the world’s mobile phone users

#12
post #11
post #9

Side note/doubt. By asking to have your data through a GDPR request you are effectively giving to the receiver of the request: 1) your full name 2) your phone number 3) your e-mail i.e. basically a confirmation that both the phone number and e-mail are good/active/attended and that they are yours (and that you "exist"), while the data they may already have likely is only the telephone number and the patterns of its u…

Does the full name have to be your legal name? I use different names/email on every site, but phone numbers are always these 2~3 numbers. If I'm going to send a deletion request under GDPR alike laws, it would be under different names.

> Does the full name have to be your legal name?

Pretty much. Only your person has rights, not the fake identities you created. They can actually request a copy of an ID or something comparable to confirm your identity. You might have a hard time removing your data, in some cases, when using fake names since then your identity can't be confirmed.

Re: TeleSign profiles half of the world’s mobile phone users

#13
post #9

Side note/doubt. By asking to have your data through a GDPR request you are effectively giving to the receiver of the request: 1) your full name 2) your phone number 3) your e-mail i.e. basically a confirmation that both the phone number and e-mail are good/active/attended and that they are yours (and that you "exist"), while the data they may already have likely is only the telephone number and the patterns of its u…

these are the (not so) digital equivalent to what appeared in phone book anyway.

Then, your phone number and emails are in any of your resumes, business card, subscription forms, contact details for any web service... They're not exactly private information anyway

And I'm sure anyone can call your phone number and listen to the message of the voicemail, in which most ppl say their name out loud anyway. Lastly, isn't your email address firstname.lastname@gmail.com, as for most folks ?

Re: TeleSign profiles half of the world’s mobile phone users

#14
post #9

Side note/doubt. By asking to have your data through a GDPR request you are effectively giving to the receiver of the request: 1) your full name 2) your phone number 3) your e-mail i.e. basically a confirmation that both the phone number and e-mail are good/active/attended and that they are yours (and that you "exist"), while the data they may already have likely is only the telephone number and the patterns of its u…

I agree that this might be a gap in the law, in theory. However, I've seen how many businesses work and they often don't have a process for randomly enriching production data from e-mails to the privacy department.

There's also the fact that the law does say that this personal data can only be use for the purpose of providing user data and must then be deleted. But we also know that there's little chance companies like this will do that.

It's a double edged sword, but I'm going to err on the side of danger and send in a data request anyway. My curiosity is much bigger than my fear of providing them my e-mail address.

Re: TeleSign profiles half of the world’s mobile phone users

#15

Earlier quoted context omitted.

Would this be a breach of GDPR for us EU residents? I'm getting seriously disillusioned with all this surveillance stuff. At first I thought, you know, these were isolated incidents falling through the cracks, but in truth it's become pervasive and global. The scariest aspect is how individual actors have the ability these days to gather, interpret and isolate individuals from massive datasets, anonymising the data s…

It is, and this article announced Noyb filed a complaint against BICS, TeleSign and Proximus with the Belgian DPA to request actions be taken (investigation, fines, removal of data, …). A translated complaint is available at https://noyb.eu/sites/default/files/2023-06/DRAT%20TELESIGN%...

Original in French for those who speak it: https://noyb.eu/sites/default/files/2023-06/DRAT%20TELESIGN%...

Re: TeleSign profiles half of the world’s mobile phone users

#16
post #9

Side note/doubt. By asking to have your data through a GDPR request you are effectively giving to the receiver of the request: 1) your full name 2) your phone number 3) your e-mail i.e. basically a confirmation that both the phone number and e-mail are good/active/attended and that they are yours (and that you "exist"), while the data they may already have likely is only the telephone number and the patterns of its u…

these are the (not so) digital equivalent to what appeared in phone book anyway. Then, your phone number and emails are in any of your resumes, business card, subscription forms, contact details for any web service... They're not exactly private information anyway And I'm sure anyone can call your phone number and listen to the message of the voicemail, in which most ppl say their name out loud anyway. Lastly, isn't…

> isn't your email address firstname.lastname@gmail.com, as for most folks

I'm going to guess that for 'most folks' there's probably someone else with the same name and therefore this way of guessing someone's email address is far from reliable.

It's actually so unreliable that one email address I have receives mail for others who for some reason think it's their email. This includes plane tickets, accounts for phone contracts and order confirmations.

Re: TeleSign profiles half of the world’s mobile phone users

#17
post #5

Earlier quoted context omitted.

Would this be a breach of GDPR for us EU residents? I'm getting seriously disillusioned with all this surveillance stuff. At first I thought, you know, these were isolated incidents falling through the cracks, but in truth it's become pervasive and global. The scariest aspect is how individual actors have the ability these days to gather, interpret and isolate individuals from massive datasets, anonymising the data s…

It definitely would, but GDPR is not being enforced anywhere near enough to matter. Facebook and Google are still alive and you bet their tracking and profiles are much more accurate than these clowns.

> Facebook and Google are still alive

Well, literally billions of people accept their privacy agreements and actively provide them with data from their phones by using their software. That's quite different from an unknown party telling other companies whether you're reliable without your knowledge based on data neither you nor your provider ever agreed to give them.

Re: TeleSign profiles half of the world’s mobile phone users

#18

I do not agree with these practices. However, I do think there is room for protocols that verify phone numbers in a way. The spam and fraudulent calls that people receive and are hard to distinguish from “good” calls is a problem that deserves more attention.

This would be a nice use case but the reality is everyone still gets a boatload of scam calls, so these companies are farming the data and using it against us instead of for us

Re: TeleSign profiles half of the world’s mobile phone users

#19
post #2

Remember when global surveillance used to be a meme among conspiracy theorists ? Pepperidge Farm remembers What can we say about a corporation doing a trust score for half of the connected population in the world ? I wonder about their ego, or what went wrong in their management.

> I wonder about their ego, or what went wrong in their management.

The article didn't insinuate that data is being used to objectively harm users. It's being used to generate "trust scores" for anti-fraud systems. The specific example given in their piece is allowing a user to attach a certain number for SMS verification.

Rather, the point here is that such data could be used to objectively harm users, so those users should have to provide consent. Second to that is that BICS doesn't appear to inform users requesting GDPR data that their data was shared.

I'm not sure I'd label that failures in ego, it smells like failures in process and compliance, which also need to be dealt with in lawsuits.

Re: TeleSign profiles half of the world’s mobile phone users

#20

I do not agree with these practices. However, I do think there is room for protocols that verify phone numbers in a way. The spam and fraudulent calls that people receive and are hard to distinguish from “good” calls is a problem that deserves more attention.

This would be a nice use case but the reality is everyone still gets a boatload of scam calls, so these companies are farming the data and using it against us instead of for us

Yes, exactly, as expected.
Post reply on HN