Comment by twoodfin

4 days ago

This is simply untenable. Institutions of all kinds have been keeping records connected to individuals for millennia.

Try to run a school when you can’t maintain data on the students.

You can have privacy and an institution can collect data.

HIPAA is an example of that.

All personal data should be treated with at or near HIPAA levels of security. If I give my personal information to my bank, or google, that's fine for them to look at it, but it's not ok if that information magically lands in the hands of Coca Cola for marketing.

  • Yes, mostly, but google shouldn't be able to "look" at it either. No entity should be able to derive a commercial benefit from my data; any commercial value of my own data should accrue entirely to me.

    You could build a test: the company should not be able to derive any additional value from 100 fully anonymized interactions with the same person as from 100 interactions with a deanonymized individual. Google obviously fails this test since targeted advertising is much more valuable if you have non-anonymized entities.

    The doctor can store my data because it is necessary to provide me with the service, but the doctor shouldn't be able to sell my data, nor correlate it with their other patients' data.

    Of course, a doctor will learn from treating me and become a better doctor, so you can't actually enforce this totally in practice. But it's like porn - you know when you see the violation.

    • Let me get it straight. You want to be able to engage with a commercial entity, but you don't want that commercial entity to be able to look at anything that results from you interacting with them? That doesn't even sound like a good user experience. I want the companies I engage in business with to be able to look at the data within the confines of our relationship and be able to do useful things with it.

      If you don't want Google to be able to do anything at all with information you put into their system, easy, don't open an account!

      I can agree with some of the other points, Google shouldn't be hoovering up mountains of data, etc. Just have to be careful of extremes. If you enshrine something bad in something as difficult to change as a constitution, you're stuck with it, and all your unintended consequences, potentially forever. You say "you can't actually enforce this totally in practice" but have you ever met a law firm? They would absolutely take the most extreme possible interpretation and milk all of society for billions a year if they can find an appropriate avenue.

      This kind of extremism is what derailed some constitutional reforms in South America over the past decade. It started with reasonable center-left people saying some reasonable things, the radical left seized the process and wrote the final draft and faced with a choice between insanity and an unsatisfactory status quo people made the only palatable choice.

      24 replies →

    • > nor correlate it with their other patients' data.

      Halting that would pretty much be the end of public health analysis or real-world work on medication effectiveness/adverse reactions. We do a lot of work with deidenitifed data to find health patterns in populations.

      2 replies →

    • > but the doctor shouldn't be able to sell my data, nor correlate it with their other patients' data

      This definitely happens, at least in the UK. With anonymised data.

    • I love the downvotes, probably from the people who like making money screwing over their fellow citizens.

> This is simply untenable. Institutions of all kinds have been keeping records connected to individuals for millennia.

This is the reason privacy is needed.

> Try to run a school when you can’t maintain data on the students.

Yes, we should try this. Zero-knowledge proofs and other modern technology allows for this. Even the first step of not selling or using student data for commerce is an easy step.

Those who think that we should not try to improve because our privacy is already compromised, should step aside.

  • Teachers sending encrypted report cards home with zero-knowledge proofs attached?

    Reports they can never again consult when gauging a student’s progress over time?

    Say what you will, but at least it’s an ethos!

    • The 90's was people worried they'd be treated as nothing more than a number. 2020's is people wishing they could be known only by a number (an opaque identifier).

It's not - GDPR does that and it could even be much stricter still and we'd be fine.