Live data from Hacker News

Ban the sale of precise geolocation

lawfaremedia.org

151–160 of 205 posts

Re: Ban the sale of precise geolocation

#151
post #145

Earlier quoted context omitted.

Telemetry from machines and data from environmental sensors that is collected for operational purposes (safety, efficiency, reliability) in industrial applications. Old school engineering systems that in modern times have expansive network-connected sensors that may even have onboard classifiers to reduce the quantity of data. The trouble started when lawyers correctly noticed that these are incidentally capable surv…

Eh? The GDPR is there to protect your personal/sensitive data, or data that can personally identify you. If has nothing whatsoever to do with data capture from industrial machinary. I remain astounded how ignorant some people are of basic GDPR principle: protecting your _personal_ data.

Industrial data capture can produce detailed traces of your travel no different than tracking your mobile phone. Some can capture personal details that adtech often can't because the sensor suites are more diverse and operate in different environments. We just don't use it for that.

How is this not your personal data?

Exploitation of these types of data sources has been demonstrated for 15+ years at this point. Abuse is often impractical for technical reasons but GDPR doesn't give you free pass on collecting personal data just because you aren't using it like personal data.

Re: Ban the sale of precise geolocation

#152
post #148

When I had the opportunity to peer into public records, I found some extremely intriguing stuff. There was one person with a feminine name who showed up with a “home address” that would correspond to being my “neighbor” at home, at my clinic, at church, when I went to college, etc. All the years corresponded correctly, and the addresses were some residential place about a block or less away from the places where I we…

> GPS coordinates * coordinates There are many ways of establishing ones latitude and longitude without recourse to one particular GNSS system.

Excuse my colloquialism. All I meant was “universally recognized coördinate format”, okay?

Re: Ban the sale of precise geolocation

#153
post #9

A lot of geolocation data on the market is anonymized, following medium-lived unique IDs that aren't able to be mapped to other identifiers. The problem with that is that if you have precise locations, or enough samples that you can apply statistics to find precise locations, in many cases you can de-anonymize the IDs. You can purchase address and resident listings from a number of different data vendors, and by chec…

There is no such thing as anonymized location data when you have the location of something where and when they sleep and work. It's a rhetorical fiction the ad industry tells itself.

I think this begs the question of what anonymous data means. Sure my visit to HN is "anonymous" in that it doesn't say "abustamam visited this site" but piece together all the other visits that have my "anonymous ID" then eventually it paints a pretty nice picture of who I am.

Re: Ban the sale of precise geolocation

#154
post #121

Earlier quoted context omitted.

Now think what Lavrenti Beria and an LLM could have done with that.

Somebody once said that if Stalin had access to television, he would never have to kill 20+ million ppl. What would he do with all that data? No idea.

Pretty sure it would be hard to enslave these people through television

Re: Ban the sale of precise geolocation

#155
post #146

Earlier quoted context omitted.

> The GDPR is vague and unworkable as written. It fundamentally restricts all data processing with a few, vague exceptions. What utter utter FUD You are free to collect as much personal data as you want, PROVIDING you have my explicit opt-in informed consent to do so. What about this is difficult to understand? > How are you to know whether or not the user is an EU citizen (and thus subject to the GDPR)? The GDPR pro…

> If you aren't protecting users private data regardless of where they live in line with GDPR principles (such as collecting it fairly, and not selling it to randoms) then you are playing fast and loose with your users private, sensitive data. It's interesting and revealing when someone responds to a law that says "You're not allowed to abuse users in countries X, Y, and Z" with "How can I figure out who's in the oth…

Your entire reply is both a non sequitur, and doesn't even attempt to understand what people tell you

Re: Ban the sale of precise geolocation

#156
post #154

Earlier quoted context omitted.

Somebody once said that if Stalin had access to television, he would never have to kill 20+ million ppl. What would he do with all that data? No idea.

Pretty sure it would be hard to enslave these people through television

Would it be? I'd argue the current US administration is entirely propped up by television. Hell, the president seems to "rule" based on what Fox News said last night.

Re: Ban the sale of precise geolocation

#157
post #103
post #44

Earlier quoted context omitted.

As someone who has to implement it, it's really not bad at all: Ask the user for consent to use their data, and don't be misleading about it. That's it. The rest of the "It'S So LaRgE AnD UndErSpEciFieD" is just FUD. The regulators don't just slap fines, they work with you to get you to comply, and they just want to see that you're putting in the effort instead of messing them about. I have literally never been surpr…

> for everything in the middle, nobody will punish you for an honest mistake. How do you know that? Again the law establishes a rules making body that can at any time change or add rules, and as far as I can tell there's no public review process.

> Again the law establishes a rules making body that can at any time change or add rules

Please quote the exact text of the law that you claim does that. And since the law has been in force for 10 years, perhaps you can point at the website of said body.

If you say "DPAs", then...erm... perhaps learn something about the world around you? Who do you think monitors compliance, say, for food, or for construction? It just appears out of nowhere? Same here

Re: Ban the sale of precise geolocation

#159
post #91

Earlier quoted context omitted.

What do you mean by "industrial" in this case?

Telemetry from machines and data from environmental sensors that is collected for operational purposes (safety, efficiency, reliability) in industrial applications. Old school engineering systems that in modern times have expansive network-connected sensors that may even have onboard classifiers to reduce the quantity of data. The trouble started when lawyers correctly noticed that these are incidentally capable surv…

> The trouble started when lawyers correctly noticed that these are incidentally capable surveillance systems even though that isn't how we use them or what they were designed for.

Many systems were not explicitly designed for surveillance, and are. Because many systems collect too much data to begin with.

Hence the problem: people who collect too much data claim that GDPR is complicated, complex, convoluted, impossible to comply with... instead of changing what data they collect, and how.

Additionally, people confuse the complexity of human endeavours with the complexity of the law. GDPR itself is neither complex nor complicated. It doesn't try to carve out exceptions, rules, and regulations for every possible activity humans may attempt. Then it would become impossible to understand or comply with.

As is, it has enough carveouts for industries which require more data than strictly necessary, called "legitimate interest" (which still doesn't allow you to just use this data willy-nilly). E.g. banks collect significantly more data about customers than strictly necessary (because KYC, fraud, security etc.), and store that data for significantly longer amount of time than allowed by privacy-related laws (because they are governed by bank laws of respective countries). It doesn'tmean they can sell that data or spy on users.

Same here. It's not on the law to tell you exactly how to operate your "industrial-scale operation". It's on you to fix your shit, stop collecting more data than necessary, have data protection in place, delete data after a reasonable time, anonymize data etc.

Re: Ban the sale of precise geolocation

#160

Earlier quoted context omitted.

Interesting. What are your obligations under GDPR in that case? It's not like a packing machine can request data deletion.

No one has been able to provide a satisfactory answer to this question. I've seen the lawyers try to figure this out at a few companies. GDPR frames everything in the context of a person's data. There is no "person_id" or similar field in these data models. That isn't the purpose of the data, it would be expensive to extract it, and then it would create obvious liability under GDPR. This makes the idea of finding a p…

https://gdpr-info.eu/art-25-gdpr/

--- start quote ---

Taking into account the state of the art, the cost of implementation and the nature, scope, context and purposes of processing as well as the risks of varying likelihood and severity for rights and freedoms of natural persons posed by the processing, the controller shall, both at the time of the determination of the means for processing and at the time of the processing itself, implement appropriate technical and organisational measures, such as pseudonymisation, which are designed to implement data-protection principles, such as data minimisation, in an effective manner and to integrate the necessary safeguards into the processing in order to meet the requirements of this Regulation and protect the rights of data subjects.

The controller shall implement appropriate technical and organisational measures for ensuring that, by default, only personal data which are necessary for each specific purpose of the processing are processed. That obligation applies to the amount of personal data collected, the extent of their processing, the period of their storage and their accessibility. 3In particular, such measures shall ensure that by default personal data are not made accessible without the individual’s intervention to an indefinite number of natural persons.

An approved certification mechanism pursuant to Article 42 may be used as an element to demonstrate compliance with the requirements set out in paragraphs 1 and 2 of this Article.

--- end quote ---

IANAL, but this basically covers all your bases, together with https://gdpr-info.eu/art-32-gdpr/

Unless, of course, your industrial-scale data collection actually collects significantly more data than you let on, and extraction of personal data is not as hard as you make it sound

Post reply on HN