Also outside of perhaps the EU, are there any legal enforcement mechanisms to hold them accountable for lying about it, if an audit showed that they were?

  • MagosInformaticus
    link
    fedilink
    English
    arrow-up
    28
    ·
    edit-2
    10 months ago

    It becomes inherently difficult to make datasets actually anonymous the more data points they have about a given individual - it doesn’t much matter whether names and such are listed data points if they can be inferred from the rest. This investigation by Svea Eckert and Andreas Dewes, for instance, managed to identify a named German member of parliament (Valerie Wilms) and other public functionaries within a data set on web browsing habits they received from data brokers.

    Most countries do have data privacy legislation and relevant regulatory/enforcement agencies, but the data brokerage business is big and intensely international so the picture on audits is kind of unavoidably complicated.

      • 1rre@discuss.tchncs.de
        link
        fedilink
        arrow-up
        3
        ·
        10 months ago

        You’re not really missing anything, other than how easy it is for a collection of datapoints to become unique… If you had burrito Monday, spaghetti Tuesday, oatmeal Wednesday, Banana Thursday, then I doubt there’d be more than a few hundred people that match that pattern.

        Some people don’t like that because they think it’s the same as being identified by name, others don’t really care

  • key@lemmy.keychat.org
    link
    fedilink
    English
    arrow-up
    13
    ·
    10 months ago

    Privacy Compliance audits are a thing. Usually companies will hire a firm to do the audit which will culminate in a report of any violations and recommendations. That might be taken on for a company to cover its ass or because a client company asks them to as part of a contract. There’s not usually a “punishment” for those but a contract could have a clause to that effect.

    Legal enforcement depends on the law in question. There’s a number of data privacy laws beyond GDPR each with different investigation and enforcement actions. They definitely can result in an audit by the enforcement body with risk of stick.

    • a4ng3l@lemmy.world
      link
      fedilink
      arrow-up
      2
      ·
      10 months ago

      Let’s see a company weasel out of iso27001 audit and explain their customers that they aren’t so much compliant anymore. That’s what is getting companies to stay within the lines and that should count as a punishment. Privacy authorities aren’t generally staffed enough to be a concern for the moment unless you are very unlucky.