Earlier quoted context omitted.
That's a reasonable point, but it's also reasonable to observe that businesses rely on other businesses all the time. As a small business, you usually have little meaningful oversight of the internal processes of outside services you use. You don't get to audit your bank's finances to make sure they're safe to trust with your money. You don't get to review your lawyer's office security arrangements to make sure no-on…
> You don't get to review which products your office cleaning firm uses. Seems a bad analogy, do you make a contract with them but not read it? I mean in the contract you will specify what cleaning products can or should be used(like in some hospitals strong cleaning products must be supplied and you ask for those in the contract if the supplier gives you bad quality ones then sure it is not your fault but it is your…
I guess my point is that just knowing of the possibilities isn't particularly helpful on its own. If we're interested in actual privacy and data protection, instead of merely paying lip service to them, what matters is not just what a data subject knows but what control they have and what protections against harm they automatically enjoy. So much of the discussion around the GDPR and privacy policies and this whole subject more generally is only about telling people how they're being exploited instead of just exploiting them quietly without them knowing as happened before. That might be a step in the right direction, but it's far from where I would like the emphasis to be.