Live data from Hacker News

Ask Microsoft: Are you using our personal data to train AI?

foundation.mozilla.org

31–40 of 164 posts

Re: Ask Microsoft: Are you using our personal data to train AI?

#31
post #20
post #16

Earlier quoted context omitted.

yeah, that's basically one of core tenants of GDPR. >Consent must be a specific, freely given, plainly worded, and unambiguous affirmation given by the data subject;

GDPR and indeed any data protection laws may well be completely irrelevant in the context of Microsoft's services. Even if relevant, consent is unlikely to be a relevant as a processing basis under GDPR in the context of usage of MS services. Performance of contract or legitimate interests much more likely to be relevant...

I'm my experience GDPR is relevant.

I need to inform my customers what I do with their personal data. That includes to which companies I share that data with.

Having an excel with customer data is providing that data to Microsoft. So I need, as responsible of the data, to know how they will use it. Any use case that isn't obvious have to be cleared stated in the data privacy agreement. Including moving data outside EU into other countries like America (where US government can request that data without even informing us) or using their data to train AI.

Come'on. If we need to inform that we used chatgpt (just in case they provide PI), why we will not need to inform about Microsoft.

Re: Ask Microsoft: Are you using our personal data to train AI?

#32
post #17

If nine experts in privacy can't understand what Microsoft does with your data, then in my opinion a court should step in and declare it void so that Microsoft isn't allowed to use any private data until they get their act together. If it's so vague that it becomes meaningless that should default to granting no rights. Otherwise, why not publish your all-rights-granting privacy policy in Klingonian in a locked drawer…

To an extent, think about vested interests here. Mozilla has little to gain by showcasing how clear a rival's new service agreement is! The AI services section seems pretty clear in terms of limiting the use cases of user content: "iv. Use of Your Content. As part of providing the AI services, Microsoft will process and store your inputs to the service as well as output from the service, for purposes of monitoring fo…

If I understand the below correctly then it seems they can use your data for whatever purpose they want. Also training AI even though it does not explicitly say so.

"2b. To the extent necessary to provide the Services to you and others, to protect you and the Services, and to improve Microsoft products and services, you grant to Microsoft a worldwide and royalty-free intellectual property license to use Your Content, for example, to make copies of, retain, transmit, reformat, display, and distribute via communication tools Your Content on the Services."

[1] https://www.microsoft.com/en-us/servicesagreement/upcoming.a...

Re: Ask Microsoft: Are you using our personal data to train AI?

#34
post #17

If nine experts in privacy can't understand what Microsoft does with your data, then in my opinion a court should step in and declare it void so that Microsoft isn't allowed to use any private data until they get their act together. If it's so vague that it becomes meaningless that should default to granting no rights. Otherwise, why not publish your all-rights-granting privacy policy in Klingonian in a locked drawer…

To an extent, think about vested interests here. Mozilla has little to gain by showcasing how clear a rival's new service agreement is! The AI services section seems pretty clear in terms of limiting the use cases of user content: "iv. Use of Your Content. As part of providing the AI services, Microsoft will process and store your inputs to the service as well as output from the service, for purposes of monitoring fo…

That's the only mention of AI using content. So it can be read in a few ways:

1. They will sometimes use the data for training their RLHF stuff, to "prevent harmful use" of the services.

2. The clause is exhaustive and therefore they won't use it for training, as otherwise that'd be mentioned, and are just going to log stuff for the usual monitoring purposes.

This is a storm in a teacup. I don't even know why I should care. If MS crawl some web pages I've written and AI gets slightly smarter by reading them, or if I have a chat with the AI and some engineers use it to make the AI work better, great. It's very hard to imagine concrete, real harm from them being able to do this, though I can understand why companies might worry about it spitting out their source code verbatim in some cases.

Re: Ask Microsoft: Are you using our personal data to train AI?

#35

If nine experts in privacy can't understand what Microsoft does with your data, then in my opinion a court should step in and declare it void so that Microsoft isn't allowed to use any private data until they get their act together. If it's so vague that it becomes meaningless that should default to granting no rights. Otherwise, why not publish your all-rights-granting privacy policy in Klingonian in a locked drawer…

Thanks.

Synthetic data might be one perspective.

Re: Ask Microsoft: Are you using our personal data to train AI?

#37
post #11

While we are talking about it... can we make ToS ilegal? Why do we have to abide by rules while browsing the web? Why do businesses fear litigation so much, they hire lawyers to write and maintain a huge document nobody can ever read or understand? This is failure from governments that can't set basic rules for human interaction. All this

> While we are talking about it... can we make ToS ilegal? What does that even mean? Laws trump Terms of service/agreements and contracts of any kind. Do they not?

I think he meant that instead of each company creating their own ToS, the government should set the standard or limitations on what a company can do.

> Laws trump Terms of service/agreements and contracts of any kind.

Web is not regulated by the government.

Re: Ask Microsoft: Are you using our personal data to train AI?

#38

If nine experts in privacy can't understand what Microsoft does with your data, then in my opinion a court should step in and declare it void so that Microsoft isn't allowed to use any private data until they get their act together. If it's so vague that it becomes meaningless that should default to granting no rights. Otherwise, why not publish your all-rights-granting privacy policy in Klingonian in a locked drawer…

> then in my opinion a court should step in and declare it void so that Microsoft isn't allowed to use any private data until they get their act together. I hear what you're driving at, but "a court" cannot be both prosecutor and judge at the same time. This page is about that, possibly starting a civil suit to have a judge look at this and act accordingly.

The true failure is government. Mozilla shouldn’t have to lead this. The prosecutor should be the regulator.

Re: Ask Microsoft: Are you using our personal data to train AI?

#39
> We had four lawyers, three privacy experts, and two campaigners look at Microsoft's new Service Agreement, which will go into effect on 30 September, and none of our experts could tell if Microsoft [will use your data] to train its AI models.

* in the USA, I assume?

With GDPR, if it's not a defined goal then the answer is no. In the USA, I hear things of some states having a similar law now but as a blanket statement without defined region (not even country) I'm not surprised if you can't give a definitive "no".

Re: Ask Microsoft: Are you using our personal data to train AI?

#40
post #20

Earlier quoted context omitted.

GDPR and indeed any data protection laws may well be completely irrelevant in the context of Microsoft's services. Even if relevant, consent is unlikely to be a relevant as a processing basis under GDPR in the context of usage of MS services. Performance of contract or legitimate interests much more likely to be relevant...

I'm my experience GDPR is relevant. I need to inform my customers what I do with their personal data. That includes to which companies I share that data with. Having an excel with customer data is providing that data to Microsoft. So I need, as responsible of the data, to know how they will use it. Any use case that isn't obvious have to be cleared stated in the data privacy agreement. Including moving data outside E…

Key word is "may" be completely irrelevant! Of course, if you're providing an Excel of customer data, it will be relevant if the user is in the EU. But still, consent won't be relevant in that context.

User content may include personal data but may also not...so in some senses, better to include totality of use cases in a non-data protection related document.

Post reply on HN