Comment by cogman10
4 days ago
You can have privacy and an institution can collect data.
HIPAA is an example of that.
All personal data should be treated with at or near HIPAA levels of security. If I give my personal information to my bank, or google, that's fine for them to look at it, but it's not ok if that information magically lands in the hands of Coca Cola for marketing.
Yes, mostly, but google shouldn't be able to "look" at it either. No entity should be able to derive a commercial benefit from my data; any commercial value of my own data should accrue entirely to me.
You could build a test: the company should not be able to derive any additional value from 100 fully anonymized interactions with the same person as from 100 interactions with a deanonymized individual. Google obviously fails this test since targeted advertising is much more valuable if you have non-anonymized entities.
The doctor can store my data because it is necessary to provide me with the service, but the doctor shouldn't be able to sell my data, nor correlate it with their other patients' data.
Of course, a doctor will learn from treating me and become a better doctor, so you can't actually enforce this totally in practice. But it's like porn - you know when you see the violation.
Let me get it straight. You want to be able to engage with a commercial entity, but you don't want that commercial entity to be able to look at anything that results from you interacting with them? That doesn't even sound like a good user experience. I want the companies I engage in business with to be able to look at the data within the confines of our relationship and be able to do useful things with it.
If you don't want Google to be able to do anything at all with information you put into their system, easy, don't open an account!
I can agree with some of the other points, Google shouldn't be hoovering up mountains of data, etc. Just have to be careful of extremes. If you enshrine something bad in something as difficult to change as a constitution, you're stuck with it, and all your unintended consequences, potentially forever. You say "you can't actually enforce this totally in practice" but have you ever met a law firm? They would absolutely take the most extreme possible interpretation and milk all of society for billions a year if they can find an appropriate avenue.
This kind of extremism is what derailed some constitutional reforms in South America over the past decade. It started with reasonable center-left people saying some reasonable things, the radical left seized the process and wrote the final draft and faced with a choice between insanity and an unsatisfactory status quo people made the only palatable choice.
Your argument applies to the grocery pricing situation: "if you don't want the grocery store to aggregate all of your interactions, don't shop there".
All aspects of the commercial transaction should be clear and transparent: I give the grocery store cash, it gives me food. My data shouldn't be taken from me, and nor should I have to consent to my data to be taken from me in order to shop there.
Google can store and serve me my data. It cannot use my data for commercial purposes that do not directly serve me. Nor should it be able to aggregate my interactions in a way that serves to increase its own profit, as this, over time, increases the relative power of the firm.
21 replies →
If you pay a bank for use of a secure deposit box to store private documents, would you be upset if they started advertising services to you based on the contents of those documents?
Or if your telephone service began messaging with offers for products on what you discussed in your phonecalls?
Yet it's extremism to think Google etc shouldnt be able to do this.
But Google is a monopoly, so you have little choice in the matter.
Unfortunately these things are never so clean as in the theoretical model. As a monopoly, there are likely many situations where interaction with said monopoly is unavoidable.
> nor correlate it with their other patients' data.
Halting that would pretty much be the end of public health analysis or real-world work on medication effectiveness/adverse reactions. We do a lot of work with deidenitifed data to find health patterns in populations.
I agree. One of the things this debate reflects is that societies really do need substantial trust: I want to trust that if my healthcare data is aggregated, then it will actually be used to serve society (and me).
In practice, data is often aggregated and then used to deprive some folks of healthcare, or sold to a pharma company below cost, with the pharma company then turning around and maximizing drug profits, where the drug was developed from the underpriced public data.
Maybe the law needs to be more like code and less up to the whims of whatever judicial interests are present at the time.
Tracing code manually isn’t hard for a seasoned dev. Write it in BASIC if you have to lmao
> but the doctor shouldn't be able to sell my data, nor correlate it with their other patients' data
This definitely happens, at least in the UK. With anonymised data.
I love the downvotes, probably from the people who like making money screwing over their fellow citizens.