Live data from Hacker News

23andMe updates their TOS to force binding arbitration

stackdiary.com

11–20 of 252 posts

Re: 23andMe updates their TOS to force binding arbitration

#11

My mother innocently used this service, and filled out the form identifying all relatives by name. The results she received were entirely unenlightening, 50% of my DNA is now in their sketchy database, and I have no way to opt-out of anything. I truly despise this organization.

I fully agree with everything you say, but until legislation is enforced you can hardly blame a company for capitalizing on the lack of privacy laws (you can still hate them). Point is, start demanding legislation around data privacy and security to anyone who will listen.

You can absolutely blame a company for unethical but legal actions.

Re: 23andMe updates their TOS to force binding arbitration

#12

My mother innocently used this service, and filled out the form identifying all relatives by name. The results she received were entirely unenlightening, 50% of my DNA is now in their sketchy database, and I have no way to opt-out of anything. I truly despise this organization.

What does "innocently" mean in this context?

Re: 23andMe updates their TOS to force binding arbitration

#14

My mother innocently used this service, and filled out the form identifying all relatives by name. The results she received were entirely unenlightening, 50% of my DNA is now in their sketchy database, and I have no way to opt-out of anything. I truly despise this organization.

Sue your mother

Re: 23andMe updates their TOS to force binding arbitration

#15
post #9

"If you have not notified us... you will be deemed to have agreed..." Is changing the terms of a service agreement with no confirmation/acceptance from the user even legal or enforceable?

Yes, companies do it all the time.

That doesn't mean it's legal or enforceable, that just means they do it all the time.

Re: 23andMe updates their TOS to force binding arbitration

#16

My mother innocently used this service, and filled out the form identifying all relatives by name. The results she received were entirely unenlightening, 50% of my DNA is now in their sketchy database, and I have no way to opt-out of anything. I truly despise this organization.

I fully agree with everything you say, but until legislation is enforced you can hardly blame a company for capitalizing on the lack of privacy laws (you can still hate them). Point is, start demanding legislation around data privacy and security to anyone who will listen.

I feel like I can blame the humans involved with 23andMe specifically, as they are the specific humans who allowed unknown 3rd parties to have enough of my DNA to profile my family and myself.

However, I entirely agree with your last statement. I would like to call upon anyone who appreciates privacy to get behind a neural bill of rights. While it sounds a bit "tin foil hat" at the moment, non-invasive brain–computer interfaces are coming very soon. Especially using infrared techniques.

Today, TSA scans your face, soon enough it will be your brain. This is not a joke.

If the USA misses the boat on regulating neural interfaces, we will sail through the final frontier of personal privacy, and even agency.

I highly recommend that everyone listens to, or reads the transcript of Sean Carroll's podcast with Nina Farahany on the topic. It is dense with legal and technical information.

"Nita Farahany on Ethics, Law, and Neurotechnology"

https://www.preposterousuniverse.com/podcast/2023/03/13/229-...

Re: 23andMe updates their TOS to force binding arbitration

#17
post #10
post #7

The more TOS I read through, the more it seems we need a "common law" solution. (I use the term "common law" loosely here) Something like a couple of pre-defined categories for software services (e.g. info provider, social network, real-world interface) with pre-set rules (e.g. the client cannot attempt to break the social network; the owner of the social network cannot re-sell data to a third party). We have somethi…

Terms of service and end-user license agreements essentially serve more as private legislation than an actually negotiated contract.

Well stated. The only reason it’s not actually legislated is probably because this was just the path of least resistance.

Re: 23andMe updates their TOS to force binding arbitration

#18

"If you have not notified us... you will be deemed to have agreed..." Is changing the terms of a service agreement with no confirmation/acceptance from the user even legal or enforceable?

Part of the initial terms of service that you agree to is that the terms can be changed by the company at any time as long as they give you X days of notice.

Re: 23andMe updates their TOS to force binding arbitration

#19
post #7

The more TOS I read through, the more it seems we need a "common law" solution. (I use the term "common law" loosely here) Something like a couple of pre-defined categories for software services (e.g. info provider, social network, real-world interface) with pre-set rules (e.g. the client cannot attempt to break the social network; the owner of the social network cannot re-sell data to a third party). We have somethi…

It's difficult because digital ToS are so tightly tailored to your business, and digital businesses are so malleable and formless.

If you went through the effort to standardize your ToS, it would only be "useful" to a tiny handful of businesses at specific points in their growth trajectory.

Regulations like GDPR are a top-down approach to the privacy component of a Terms of Service (i.e. there are only so many variations to the privacy sections within a ToS that comply with GDPR), but there are so many more components than just customer data locality.

That being said, as a privacy-respecting entrepreneur, coming up with a "user-respecting" (i.e. win/win, legible, minimally-demanding/withholding) ToS is a sizable challenge. It'd be nice to have templates. I basically resort to reading the ToS of companies I respect in similar verticals.

Post reply on HN