Live data from Hacker News

We caught companies making it harder to delete your personal data online

themarkup.org

51–60 of 76 posts

Re: We caught companies making it harder to delete your personal data online

#52

Here's how the law should work. You own the data you produce, both intentionally (writing, making videos) and unintentionally ("metadata", logs). You have to explicitly give others permission to use that data for any purpose where money exchanges hands (and many where it does not). You can limit or revoke the permission at any time.

This is the case. In every aspect of life in which personal data is indexed/transmitted, the point of origin at least is some place you've explicitly indicated approval of this process. IF you walk into walmart, you are granting them the ability to sell your facial data and card metadata to whoever. No third party is calling your mobile provider to ask them to leak info. They are PAYING the mobile provider to leak th…

And this is exactly the problem.

It used to be the case that you exchanged money for a good or service. It was a transaction of 1 thing for 1 thing.

Now you're exchanging your money AND personal information for goods or services (sometimes both mixed in a way that is optimized to get as much money out of you as possible). And because those providing goods or services all have the same incentives, you don't have a free choice to pay a competitor who doesn't use these business practices.

Freedom absolutists (such as ancaps) will claim you can always start a competitor. But that's just not true, these business practices are so advantageous that you either use them too or go out of business.

The real solution is for people to unite and demand change together. And that's what governments are for.

Re: We caught companies making it harder to delete your personal data online

#53

Here's how the law should work. You own the data you produce, both intentionally (writing, making videos) and unintentionally ("metadata", logs). You have to explicitly give others permission to use that data for any purpose where money exchanges hands (and many where it does not). You can limit or revoke the permission at any time.

> You have to explicitly give others permission to use that data for any purpose This is already the case. All the contracts and terms of service documents already contain these permission clauses. People don't even read such things. The funniest contracts are the ones that say "by using this site, you agree to [surveillance capitalism]". People have to navigate the site in order to even read the contract so it's log…

Yep, just like it's illegal to sell your organs or sell yourself into slavery, society needs to recognize that even through the severity of exploiting personal data is much lower, the principle is the same - the power differential between the two parties is so large that the weaker one has no choice but to agree.

It's the illusion of choice that gives is the veneer of legitimacy.

Re: We caught companies making it harder to delete your personal data online

#54

And as important: making it impossible or very hard and annoying to export and own your data.

We didn't set out to hide our GDPR requests, we put them behind our Support/Legal button. But we got sued anyway, and we lost. Now we have to have the "delete my data" and "request my data" as part of our main settings list. Result: flooded with requests. People are clicking the buttons just because they are there. For me it's not a big deal, I automate all the requests. But, I still feel like this went too far.

Can we get the full story? I don't believe that's what happened because GDPR does not prescribe any specific avenue of requesting data. You're not required to have a button on your website at all, it's completely valid to accept and respond to requests by mail, but it's obviously much cheaper to offer automated data export.

Re: We caught companies making it harder to delete your personal data online

#55
I'm not in support of the practice laid out in the article, but we're talking about robots.txt, right?

I guess it was written for a less technical audience, but it makes it seem like they have JS or 'code' was specifically written to hide these from web crawlers.

It makes more sense, in context, that companies could be unaware. Sure, a 'noindex' doesn't just show up, but how many were old configs disallowing *, and only allowing indexing on a few sites

Edit: I didn't see the screenshot section. Most (of the few I spot-checked) are, in fact, noindex. I stand corrected

Re: We caught companies making it harder to delete your personal data online

#56

Has anyone used deleteme or a similar service? What was your experience, and do you feel it was worth it? It feels like such a cat and mouse game, that should be easy to automate, that said, I'm not sure it'll be effective.

I have used Incogni for a few years now, I was a little worried after the first year things wouldn't be worth the price, but I'm noticing that there are data brokers who will happily remove you but not put you on a block-list, meaning that they will happily ingest your information again if it comes to them, and another request from Incogni will be needed to remove it again. I'm on the fence about whether that's real…

> but not put you on a block-list, meaning that they will happily ingest your information again if it comes to them

So since you don't know if they information or not, you should start sending them delete request every second? You know, just in case they got new data since the last request and we know it takes a while to actually process those requests.

Re: We caught companies making it harder to delete your personal data online

#57

Earlier quoted context omitted.

We didn't set out to hide our GDPR requests, we put them behind our Support/Legal button. But we got sued anyway, and we lost. Now we have to have the "delete my data" and "request my data" as part of our main settings list. Result: flooded with requests. People are clicking the buttons just because they are there. For me it's not a big deal, I automate all the requests. But, I still feel like this went too far.

> People are clicking the buttons just because they are there. I think this isn't a very charitable opinion of why people click buttons. > But, I still feel like this went too far. Why?

[deleted]

Re: We caught companies making it harder to delete your personal data online

#58

Earlier quoted context omitted.

We didn't set out to hide our GDPR requests, we put them behind our Support/Legal button. But we got sued anyway, and we lost. Now we have to have the "delete my data" and "request my data" as part of our main settings list. Result: flooded with requests. People are clicking the buttons just because they are there. For me it's not a big deal, I automate all the requests. But, I still feel like this went too far.

> People are clicking the buttons just because they are there. The reasons why they click the buttons are utterly irrelevant to anyone except them. Let them click the buttons. It's their right. > But, I still feel like this went too far. Not far enough. I think data should be a massive liability. It should actively cost you lots of money to know any fact at all about any person anywhere on the planet. In other words,…

[deleted]

Re: We caught companies making it harder to delete your personal data online

#59
post #31

Earlier quoted context omitted.

Those pricks throttled the download to 30 kbps. When I tried to download with aria, after a few failed attempts (not straight forward ofc) I got a message saying I can only download it 6 times, and that I should send a new request. This is evil.

Yes, I am sure this is a mustache-twirling power move by Google, and not a bug in your obscure 20-year-old HTTP utility.

considering google is evil, yes I would expect this is google's fault

Re: We caught companies making it harder to delete your personal data online

#60

Earlier quoted context omitted.

We didn't set out to hide our GDPR requests, we put them behind our Support/Legal button. But we got sued anyway, and we lost. Now we have to have the "delete my data" and "request my data" as part of our main settings list. Result: flooded with requests. People are clicking the buttons just because they are there. For me it's not a big deal, I automate all the requests. But, I still feel like this went too far.

> People are clicking the buttons just because they are there. The reasons why they click the buttons are utterly irrelevant to anyone except them. Let them click the buttons. It's their right. > But, I still feel like this went too far. Not far enough. I think data should be a massive liability. It should actively cost you lots of money to know any fact at all about any person anywhere on the planet. In other words,…

At the moment, holding data about someone is not a significant recurrent cost, but it is a liability in the form of a risk that could get you in serious trouble if you get something wrong. However, that particular business risk doesn't tend to be recognised by many many organisations. It should be.
Post reply on HN