Company Y is a data broker (several of these exist already).
Company Z sells airline tickets.
Company X scrapes your email and sells information about you to Company Y to boost their bottom line. Company Z buys information from company Y to target their marketing efforts. Much of the adtech industry is based around interchange like this (but often with even more, and more confusing, layers).
Currently Google and Facebook are a bit different - they sell targeting profiles and serve the ads themselves, instead of directly selling your data - but it's worth thinking about how much you trust them to stay that way.
Just use secure e-mail. No company is selling my e-mail to anyone. Anyone can make this choice, and anyone can also host their own - either you get an unlimited mailbox for free, but of course your data is sold (they need to pay for it somehow), or you pay a few dollars and your data stays yours. It's your choice, we don't need regulations for that. I want to have that choice in my hands.
I don't think this solution works in the current economy - you would also have to refuse to ever exchange email with anyone using a monetized-data email service, i.e. Facebook, Google, etc. Given the wide market control these players have, most people would find it difficult to communicate. I think controls have to be legislated, as the EU has just done.
Or just use a secondary address. But yeah, you have to make a decision, either you really do care about your data, or you don't, just like the people who don't use FB today.
You shouldn't put the burden of your decision on others, others might not care about things you care as is apparent from GDPR. Anecdote: People on sites where I can see the numbers don't care about their data, they want the GDPR thingy away ASAP and will click on anything that makes it disappear, selling even more data than before in the process.
Including me. I despise the popups, it's extremely annoying. I protect myself technologically and with common sense, like my parents teached me to - I don't put personal information in places where I don't believe it's safe. It's that easy.
Agree with you for the most part, but the GDPR extends much further than that.
Even if you've accepted the default consent popup from a website, you can also revoke that consent in the future and request you be forgotten (either your data deleted or completely anonymised). Then there's the obligation of data breaches to be reported quickly, as well as being able to claim damages that result from said breaches.
That last bit will also incentivise companies to be more careful about how much data they can collect, and whether they'll even want to store it longer than absolutely necessary.
> Then there's the obligation of data breaches to be reported quickly, as well as being able to claim damages that result from said breaches.
Yes, this is the only part of GDPR that I support. The rest of what you wrote: Imagine that you're providing a service in exchange for money. Would it be fair for someone to demand money back after they consumed the service? If you do not wish someone to have your data, don't sell it to them.
> Imagine that you're providing a service in exchange for money. Would it be fair for someone to demand money back after they consumed the service?
Note I said delete or anonymise. The point is that the information shouldn't be personally identifiable once the person has asked to be forgotten (within reason of course - you still have to hold as much info as the law mandates whether that person likes it or not).
You're welcome to keep the anonymised data and do whatever ML or other analytics with it.
> If you do not wish someone to have your data, don't sell it to them.
There are plenty of services that gather far more information about you against your will than ordinary folk imagine, IIRC Google and Facebook's tracking of your activity via their ad networks even when you're not visiting pages on their domain. This isn't acceptable, and lots of ordinary people aren't savvy enough to use adblockers or script blockers, yet they never consented to that type of data collection.
The GDPR at least gives them some say in what happens to the data that was collected about them.
> Note I said delete or anonymise. The point is that the information shouldn't be personally identifiable once the person has asked to be forgotten (within reason of course - you still have to hold as much info as the law mandates whether that person likes it or not).
> You're welcome to keep the anonymised data and do whatever ML or other analytics with it.
Oh yeah, I saw the or, but one of the major points of collecting data is to better target ads to the person that created these data, and with this, this use case is eliminated. Yes, in some cases, it'd work, but I'm sure that there are many free services that depend on data about the person, not data in general. I agree that people should be informed, but if I build a service that is paid with data, the data should be mine. If I record you on camera while shopping in my shop, I should be free to do whatever I want with that. Given that you've been informed about recording before entering the shop, you had a choice to not use my services.
About FB/Google tracking on other sites - I think this should be responsibility of the site owner (ensuring you're informed), but other than that, it's the same - you are providing data to the site owner and the site owner is sending them to others; if you don't like it, you don't have to use their services.
We could've spent 10% of what we spent on GDPR on education about tracking and the result (if the goal was to reduce tracking) would be much better. Right now people are tracked more, from my personal experience.
> We could've spent 10% of what we spent on GDPR on education about tracking and the result (if the goal was to reduce tracking) would be much better. How do you know it would be much better?
How would you implement this exactly? The GDPR effectively has global reach as it doesn't apply only to EU citizens, and it's easier to implement one compliant system than have a separate one for non-EU data subjects.
What sort of timeframe and expenditure are we looking at for worldwide education surrounding tracking on the web and privacy? How do you plan to keep people up-to-date with the latest techniques Ad network deploy to defeat past best-practices?
In your example, what sort of recourse would exist for people who are currently privacy-minded, but not savvy enough to know someone's collecting more data than they'd actually have consented to (in your analogy, the equivalent of the Ad network sticking its fingers in people's wallets, taking what they're not entitled to)?
About half of the people I exchange email with are @gmail.com It means that Google reads and possibly sell half of my email conversations even if I don't use Google as email provider. The same probably happens to you. Our choice is limited to not to send email to people with some addresses. Tough luck.
My email address ends with @dotancohen.com, I'm known to be a privacy advocate (no facebook, twitter, whatsapp, etc), but if you send me an email Google _still_ will be able to access:
$ dig MX dotancohen.com | grep MX
; <<>> DiG 9.10.6 <<>> MX dotancohen.com
;dotancohen.com. IN MX
dotancohen.com. 86381 IN MX 5 alt2.aspmx.l.google.com.
dotancohen.com. 86381 IN MX 10 aspmx3.googlemail.com.
dotancohen.com. 86381 IN MX 10 aspmx2.googlemail.com.
dotancohen.com. 86381 IN MX 1 aspmx.l.google.com.
dotancohen.com. 86381 IN MX 5 alt1.aspmx.l.google.com.
Google's services are so far superior to almost anything else that I cannot avoid them behind the scenes without severely undermining my ability to communicate reliably. Of course I'm familiar with Protonmail and Fastmail and I've run Debian web and mail servers and configured everything from qmail to sendmail, hand-writing SPF records, blacklists, etc etc.
And it's a constant battle. I need to be productive, I need to actually work, and I need time to be with the kids. Google handles my MX, Amazon my SMTP. And I'm done with it.
And even people who think that their data isn't going through Google when communicating with me, are having their data going through Google.
Well I think that the solution here would be to convince people to use encryption and make it easier for them, instead of giving them false hope like in your case.
Yeah, I know. However I'm pretty sure that you're not sending your personal identifying information to them. But yeah, minding your privacy often means discomfort, that's just how it is - again, same with people that don't like FB, but their friends use FB messenger. You can use encryption, btw.
Company Y is a data broker (several of these exist already).
Company Z sells airline tickets.
Company X scrapes your email and sells information about you to Company Y to boost their bottom line. Company Z buys information from company Y to target their marketing efforts. Much of the adtech industry is based around interchange like this (but often with even more, and more confusing, layers).
Currently Google and Facebook are a bit different - they sell targeting profiles and serve the ads themselves, instead of directly selling your data - but it's worth thinking about how much you trust them to stay that way.