惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

The Last Watchdog
The Last Watchdog
freeCodeCamp Programming Tutorials: Python, JavaScript, Git & More
GbyAI
GbyAI
Y
Y Combinator Blog
CTFtime.org: upcoming CTF events
CTFtime.org: upcoming CTF events
The GitHub Blog
The GitHub Blog
博客园_首页
小众软件
小众软件
I
InfoQ
J
Java Code Geeks
月光博客
月光博客
S
Secure Thoughts
Microsoft Security Blog
Microsoft Security Blog
V
Visual Studio Blog
Hacker News - Newest:
Hacker News - Newest: "LLM"
钛媒体:引领未来商业与生活新知
钛媒体:引领未来商业与生活新知
Stack Overflow Blog
Stack Overflow Blog
cs.CV updates on arXiv.org
cs.CV updates on arXiv.org
N
News and Events Feed by Topic
Exploit-DB.com RSS Feed
Exploit-DB.com RSS Feed
Threat Intelligence Blog | Flashpoint
Threat Intelligence Blog | Flashpoint
The Cloudflare Blog
T
Threat Research - Cisco Blogs
A
About on SuperTechFans
H
Help Net Security
MongoDB | Blog
MongoDB | Blog
博客园 - 聂微东
人人都是产品经理
人人都是产品经理
H
Hackread – Cybersecurity News, Data Breaches, AI and More
Recent Commits to openclaw:main
Recent Commits to openclaw:main
Latest news
Latest news
G
GRAHAM CLULEY
IT之家
IT之家
C
Cisco Blogs
Last Week in AI
Last Week in AI
Engineering at Meta
Engineering at Meta
L
LangChain Blog
The Register - Security
The Register - Security
SecWiki News
SecWiki News
M
MIT News - Artificial intelligence
NISL@THU
NISL@THU
T
Tenable Blog
博客园 - Franky
美团技术团队
I
Intezer
U
Unit 42
雷峰网
雷峰网
cs.AI updates on arXiv.org
cs.AI updates on arXiv.org
S
SegmentFault 最新的问题
C
Cyber Attacks, Cyber Crime and Cyber Security

Blog of Simple Analytics

The EU wants to kill cookie banners Google is tracking you (even when you use DuckDuckGo) German court rules Meta’s tracking tech violates GDPR Closing the data gap - Simple Analytics x Usercentrics The EU-US data deal may be dead in the water You are missing 20% of your website data with GA4 How a reverse trial will push Simple Analytics to the next level Google will start tracking all your devices (WTF?) Big Tech Fails EU’s Digital Services Act: Only Wikipedia Passes the Test Meta fined $102 million by the Irish Data Protection Commission Europeans spend 575 Million hours per year clicking cookie banners The most interesting GDPR fines GDPR and fines: all there is to know Google loses key antitrust case Web Analytics for Crypto Companies Web analytics for publishers Google pulls Uno Reverse card: Rolls back decision to kill third-party cookies Privacy Monthly July 2024 Privacy Perspectives June 2024 Privacy Monthly June APRA fumbles targeted advertising Privacy Monthly May Meta loses key privacy battle Google delays cookie phase-out once again Privacy Monthly April 2024 Web Analytics and Consent Cookies 101 Privacy Monthly March 2024 German authority cracks down on cookie banners Google Tag Manager vs Google Analytics Google search alternative Data retention in Google Analytics Guide to Google Analytics and Cookie consent What are Google Analytics' identifiers? How to export data from Google Analytics Privacy Monthly February 2024 The Criteo case: a big deal for Big Tech Privacy Monthy January 2024 What the Digital Markets Act means for privacy Google Settles in $5B Incognito Mode Lawsuit Legal troubles for Adobe Analytics Web analytics for nonprofits HIPAA and mental health Why Meta subscriptions are under attack, and why it matters for privacy Privacy Monthly: December Simple Analytics AI Host analytics on Cloudflare Zaraz Add Google Analytics to Convertkit Google Analytics Pricing - Paid vs Free Road to 1 Million ARR - October update CCPA and Data Protection: all there is to know Analytics without a cookie banner Enterprise Analytics Privacy Monthly: November 2023 Delete Act: all you need to know Mobile App Tracking Under Fire The road to 1 Million ARR - September Update Privacy Monthly: October 2023 HIPAA violations First challenge to the EU-US data transfer framework Direct Marketing under GDPR Road to 1 million ARR - August Update CCPA vs CPRA: what is new? Privacy Monthly: September 2023 A/B Testing with Simple Analytics Privacy Monthly: August 2023 What are your rights under the CCPA? When does the CCPA apply? How does the HIPAA compare to the CCPA and GDPR? Why Meta is in a world of trouble CJEU: cookie-based analytics collects sensitive data Road to 1 million ARR - July update All about the new Data Transfer Framework Road to 1 Million ARR - June update What is PHI under HIPAA? Sweden declares Google Analytics illegal Searching for GA4 Alternatives? Top 10 Reliable Options for Google Analyticss Ultimate HIPAA Compliance Checklist: Essential Steps for Healthcare Providers Privacy Monthly: June 2023 More troubles for Google Analytics The path to 1M ARR - May Update Data Processing Agreements Minimal Product Analytics Facebook data transfers declared illegal Is Google Analytics CCPA-compliant? Help us with your input Cookie banners: How to stay GDPR compliant? GDPR Compliance Checklist Privacy Monthly: May 2023 Simple Analytics: Privacy-first website analytics Improve your e-commerce performance with analytics European Facebook blackout is closer than we think Know your website’s Carbon Emissions - and how to reduce it The path to 1M ARR - April 2023 How to add video tracking using Google Tag Manager? How to track form submissions using Google Tag Manager? Why is my Simple Analytics data different from Google Analytics? Debug Simple Analytics script How to Import Google Analytics Data to Simple Analytics
Dobbs v. Jackson ruling is a privacy mess
Carlo Cilent · 2023-08-29 · via Blog of Simple Analytics

Last year the Dobbs v. Jackson ruling of the Supreme Court marked a drastic change in US constitutional law with regards to abortion rights.

The decision itself got plenty of media coverage worldwide but the privacy crisis it ushered in largely flew under the radar outside the US. So here is what is going on in the US after Dobbs v. Jackson, and what the EU can learn from it.

  1. Background
  2. Dobbs v. Jackson is a privacy crisis
  3. Big Tech are not helping
  4. The HIPAA is not enough
  5. What are the US doing to control the damage?
  6. What can Europe learn from this privacy crisis?
    1. “Health data” is a broad category
    2. Privacy by design needs to be enforced better
    3. Location data is more dangerous than you think
    4. Final Thoughts

Background

On 24 June 2022 the U.S. Supreme Court decided the Dobbs v. Jackson case. In doing so, it overturned Roe vs. Wade, a 1973 precedent that protected the right to abortion in the U.S. As a result of Dobbs, the Court now holds that the US Constitution does not protect the right to abortion, and that States are free to regulate the matter as they please.

The controversial ruling opened the floodgates to a wave of anti-abortion legislation in conservative States**.** A year from the decision, about half the States have legislation that limit or ban abortion and, in some instances, criminalizes abortion seekers and those who provide help.

The decision was harshly criticized by governments, international organizations, and many voices from academia and civil society. A letter signed by almost 200 NGOs highlights Dobbs' harsh impact on women's rights and bodily autonomy, as well as its disproportionate impact on already disadvantaged communities.

Dobbs v. Jackson is a privacy crisis

Dobbs v. Jackson dealt a blow to women’s rights and autonomy, and also ushered in a large-scale privacy crisis.

Law enforcement from conservative States is currently using women’s digital footprints to prosecute abortion seekers, including location data, Google searches, and chats with family members. Women’s data are collected through a mandate or just bought on the market, which is all too convenient and does not require involvement from a court of law. Even civilians sometimes buy these data to report abortion seekers to the authorities, in order to cash in the bounties offered by some States.

How is such a dramatic privacy crisis possible in a first world country?

A key issue is that the US has no federal data protection law but only laws for specific sectors such as health care and finance, along with State legislation such as California’s CCPA and Colorado’s CPA. A federal privacy law (the American Data Protection and Privacy Act) has been proposed but is nowhere close to being finalized.

Without any privacy protections at a federal level, the online privacy of most US citizens largely depends on the privacy culture and practices of the companies they entrust with their data, and this is bad news. Many companies are willing to sell data to the highest bidder, and most States have no laws in place to prevent them from doing so.

States with privacy laws do not fare much better. Legislations tend to frame privacy rights in terms of opt-out rights as opposed to prohibitions. But most people are simply too busy to opt-out from invasive data collection practices from every single service they use and every website they visit.

Bottom line, online services hoard enormous amounts of personal data for profit, and most of them are fair game if you have the cash.

This is nothing new. Privacy advocates have long been raising awareness of the enormous dangers of the online surveillance economy. Dobbs v. Jackson only made these risks dramatically tangible for American women.

Big Tech are not helping

For all its promises to honor and safeguard privacy, Big Tech is not doing much to protect women. A recent article from Insider found that Meta receives over 400.000 government requests for personal information a year and rarely challenges them in court.

To make things worse, even when Big Tech attempts to control the damage, it may or may not work.

Last year Google promised to delete sensitive locations such as abortion clinics from Google Maps’ location history. Later, The Washington Post and Accountable Tech both experimented with Google Maps and found that the deletion of sensitive location data is inconsistent and very unreliable.

Why can’t Google deliver on its promise after one year?

Well, Google services are privacy-invasive by design. They were built to grab the data first and worry about privacy and data governance later-if ever. Privacy-preserving measures are now desperately needed, but they are difficult to implement because were completely absent at the start. Implementing them is much like trying to install brakes on a car that is running full speed and was never designed to brake in the first place.

Data hunger is the core issue. And it is much, much bigger than Google. Countless other services hoard all the data they can with little or no concern about privacy and data governance. As a result, the user’s digital footprint grows to the point where not even the companies themselves can keep the data under control- see Meta's candid admission that it has little or no control over the monstrous amounts of data they collect from users.

Google and Meta are the rule rather than the exception. Companies have an incentive to hoard all the data they can profit from. Data hunger leads to poor data governance, and poor data governance leads to privacy disasters because you cannot protect data you have no control over.

The HIPAA is not enough

But doesn’t the US have the HIPAA? Why doesn’t that solve the issue?

Here’s the thing. The Health Insurance Portability and Accountability Act (HIPAA) is not a privacy law in a proper sense, but rather a sector-focused law for healthcare providers (as we explained in another blog). Its privacy rules are very narrow in scope because the HIPAA only covers healthcare providers and companies working from them.

While HIPAA violations play a part in the US privacy crisis, the main problem is the vast amounts of health data that do not fall under the HIPAA in the first place. Googling information about medication you are taking, or using Google Maps while driving to the hospital, can add some dangerously sensitive data to your online footprint. And yet, these data do not fall under HIPAA because Google is not a health care provider.

Menstruation apps are a prominent example of the issue. These apps collect very detailed information on the reproductive status of the millions of women who use them. This information does not fall under the HIPAA and can be sold with little or no restrictions in most States.

In a nutshell, the very narrow scope of the HIPAA, combined with the lack of federal privacy laws, results in a dangerous lack of protections for sensitive data.

What are the US doing to control the damage?

Washington was the first State to react to the privacy crisis by adopting the My Health, My Data Act in April 2023. The My Health, My Data Act provides stronger protections for health data and prohibits geofencing near health care providers- that is, the use of location data (typically from smartphones) to figure out who visited a certain location. The States of Connecticut and Nevada later followed the example and passed similar laws to protect health data.

On the one hand, there is hope that this legislative trend will lead to strong protections for health data (and sensitive information in general) in the proposed American Data Protection and Privacy Act. On the other hand, States that already have strong protections for health data, will likely push back against any draft of the ADPPA that weakens those protections. So, these laws might have the perverse effect of delaying the political negotiations behind the Act by making the already thorny issue of State preemption even more complicated.

Other important developments are coming from California. Since Dobbs v. Jackson, California has reinforced its traditional position as a sanctuary State by passing legislation to prevent the prosecution of women seeking reproductive health care in the State.

Right now, the State is working on an amendment to the California Criminal Code that would shield Californian companies from warrants for reverse-keyword and reverse-location requests. In other words, Californian companies will be allowed to ignore certain highly-invasive out-of-State search warrants.

The amendment could be a game-changer because it covers Silicon Valley companies that control vast amounts of personal data. By shielding Big Tech such as Apple and Meta, from warrants, the amendment could substantially impact the privacy of women outside California. But the political negotiations around the bill are complex because it has the potential to hamper the investigation of non-abortion related crimes.

What can Europe learn from this privacy crisis?

Unlike the US, Europe has a general privacy law in the GDPR which includes specific and strict rules for sensitive data. But that does not mean that our sensitive data are safe. Europe should take a close look at what is happening in the US right now, because there are some important lessons to learn from the mess.

“Health data” is a broad category

When we think of health data, we usually think of medical files, X-rays, and so on. But these data are not the main issue in the US privacy crisis. In fact, some of the most urgent privacy threats come from search histories, location data, and (non end-to-end encrypted) personal communications such as chats and emails.

On the European side, the GDPR does not (explicitly) list these data as sensitive. As a result, many organizations in Europe do not think too much about these data and do not handle them with the required care.

Two important rulings of the EU Court of Justice might change the situation. In light of the Court’s recent case law, data that might reveal sensitive data, are themselves sensitive data (see our blogs on Sensitive data and the Bundeskartellamt ruling for more information).

This case law is an important step in the right direction and substantially broadens the scope of the notion of sensitive data. However, the Court's approach is a far cry from the conveniently formalistic approach most companies adopt when dealing with sensitive data. It will take time for the paradigm to shift in practice- and in the meantime, our sensitive data will not be as safe as they could and should be.

Privacy by design needs to be enforced better

You need to plan for privacy ahead of time. If you do not set up a system in a privacy-friendly way, then it becomes very difficult to implement solid privacy down the road, as shown by Google’s data deletion fiasco.

This is why the GDPR insists on the privacy by design principle. Privacy by design means that you need to plan the processing of personal data with privacy in mind from the start.

Privacy by design is no mere suggestion but rather a binding legal principle. Nonetheless, privacy by design is often ignored by the industry. This is a shame, because a privacy by design approach can greatly reduce digital footprints. We can only hope that GDPR enforcement eventually catches up and brings organizations back in line.

The same goes for other principles connected to privacy by design. For instance, data minimization means that you can only collect the personal data you really need, and storage limitation means that you cannot not store personal data any longer than needed. Too many organizations violate these principles and things won’t change until more fines start coming.

Location data is more dangerous than you think

Geolocation data plays a key role in the post-Dobbs privacy landscape. This is why the My Health My Data Act prohibits geofencing around health care providers, and why the proposed changes to the California Criminal Code deal with reverse-location requests from law enforcement.

On the European side, the GDPR has no specific provisions to protect location data, and does not count them as sensitive data (unlike the California CCPA). So, location data are only subject to the general rules of the GDPR

These general rules are probably not enough to protect location data. Or rather: they would be if enforcement caught up. The principles of privacy by design and storage limitation could play a vital role in the protection of location data, but again, they are still too underenforced to make a real impact.

Bottom line: consumers and companies alike should be very careful with location data. And again, GDPR enforcement needs to catch up!

Final Thoughts

At the end of the day, vulnerable people pay the highest price for the surveillance economy. To paraphrase the Grumpy GDPR podcast: if you think you have nothing to hide, then you are very, very privileged

This is nothing new: the impact of privacy practices on vulnerable individuals and communities is well researched by legal scholars and social scientists alike, and is an important topic of discussion in the privacy community.

Sadly, this angle is lost in the public debate around privacy. Hopefully, Dobbs v. Jackson- and the privacy mess it caused- will serve as a reminder that privacy is a necessary condition for a fair society and something we should all be striving for.