This same BS is perpetuated by YC backed Apollo.io by simply scraping public LinkedIn profiles & then masking asterisked emails & numbers(usually your company public numbers) & asking people to sign up.
And when you do request them to remove the same, they ask you to provide ID proof. As if one would provide the same to a company which didn't take your consent for the initial profile data either.
I somehow managed to get hold of the CEO's mail ID got mine removed. But I can only imagine what everyone else would have to do when they want to control their web-presence.
There are at least 50 data brokers I've had my information removed from.
They will say whatever they can--"we need proof," "it's just public information anyway."
Every time I insisted they take it down, right now. Every time they have complied.
There's so many it's basically pulling weeds at this point.
The scarier companies are the ones collecting pictures of your face to train their private facial recognition software.
(Hell I'm hesitant to post HERE because you can't manage the privacy, content or existence of your comments)
Some data brokers are threatening you with "if you get removed from our database you will be marked as high risk of fraud and your transactions/orders you do online like hotel reservations will get rejected/put on hold for screening".
I don't know, but I'd think it's slightly true
I'd guess you'll be marked in THEIR database, so if the hotel happens to use that company's lists, you might be marked, but not be high risk in anyone else's books...
> There's so many it's basically pulling weeds at this point.
...and they are often run by the same people. They use shell companies to basically avoid take-down requests.
Their goals is to make it sufficiently annoying to take down your information, that most people give up. While at the same time removing it (regardless of the process) for anyone that occupies them too much time - because your individual data isn't valuable enough to waste defending against a take-down.
I suspect a (faux) lawyers letter is easier to get these takedowns processed than the calls/emails that most people try.
I'd be interested to know if anyone has had success with any legal measure that would enjoin them or any other entity they're in any way affiliated with or that shares common ownership.
I've been in touch with a company called Acxiom, who shared my details on Facebook. I've never heard of it, so I submitted a Data subject request to see what they know about me.
They then asked me to provide my address to confirm my identity. Given that I moved quite frequently, and that I'm now asked to share more personal data with a company who's mishandling my data, I wasn't keen on it.
I mentioned that my full name is globally unique, but they refused. I tried to ask them to share some masked data that I can confirm in full (e.g. "give me a partial address and house number, I can give you the full address"). They refused.
They definitely try to make it hard for you, and to dodge responsibility.
Acxiom is one of the largest (and oldest, they started in the 1970s) data brokers in the world. I think they, like a lot of other creaky corporations, don't necessarily make things difficult on purpose but they...don't go out of their way to make the bureaucracy any more navigable than it has to be.
In other words, it's not a bug, it's an accidental feature.
> how does that resolve the issue of them operating illegally?
Which part of the process described is illegal? The GDPR explicitly requires[1] controllers to verify subjects' identities in an access request:
The controller should use all reasonable measures to verify the identity of a data subject who requests access, in particular in the context of online services and online identifiers.
That is true, but the word "reasonable" is significant. Taking reasonable steps to confirm a data subject's claimed identity is fair and necessary. Giving them the run around and hiding behind that verification obligation as an excuse is not.
I mean, sure, but OP indicated that he didn't want to provide the info they requested for verification. I don't see how their action here could be considered unreasonable.
"I promise you that I am the only person on earth with this name" doesn't really seem like a sufficiently secure attestation.
OP here. My name is unique globally (there are no other people with this name), easily searchable, linked to my personal domain, and my personal email address on that domain.
But even if we can't go by that, I gave them plenty of options that won't involve me disclosing my entire address history. How on earth am I supposed to give all my address history to a company I never heard of, and who shared my data without my consent...
They didn't come up with any concrete suggestions that won't involve disclosing much more information about myself than I think it's reasonable to require in order to release my own personal info.
I think I was very reasonable, and they weren't. Legally I'm not sure what the situation is. IANAL.
I'll be honest - based entirely on your description of events, with no other context, I wouldn't have approved this request either. Here's my reasoning:
> They then asked me to provide my address to confirm my identity...I wasn't keen on it.
This means one of the primary avenues of verification (possibly the only avenue for some shops) is unavailable. In the scope of GDPR, it's important to remember that they aren't allowed to retain any information you provide for this purpose for any reason other than keeping a record of the request.
> I mentioned that my full name is globally unique, but they refused.
I would have absolutely no way to validate this, because I don't have a comprehensive listing of all 7 billion-odd people in the world. Even if I did, and it was, it's still only a single factor - I doubt you'd want me to release your data to anyone else based only on them knowing your name and that it's unique.
> My name is...easily searchable, linked to my personal domain, and my personal email address on that domain
This can't be relied on, obviously, because there's no identity verification on (most) domain registrations. For all I know, the email address that I have attached to your profile isn't even yours (because we have no preexisting relationship, this has never been proven.)
> I tried to ask them to share some masked data that I can confirm in full...They refused.
I don't think this is actually allowed under GDPR, but assume it is. Let's say you do this twice with two different data controllers - they each provide you with a masked address, but they've masked different parts (because there's no standard).
If you were a malicious actor, you'd now have the subject's complete address and could use that to gain access to the rest of their data. It opens up a significant attack vector.
> How on earth am I supposed to give all my address history to a company I never heard of, and who shared my data without my consent...
Assuming this was someone unknown and not Acxiom, this is a valid point and unfortunately I don't think there's a great answer. In this case, it is Acxiom and you could've quite easily discovered that they're a major corporation and not a random data harvesting shop.
> I think I was very reasonable, and they weren't.
At the end of the day, you're going to have to give them something to prove who you are. If you won't even provide your old addresses, then absent a government-issued ID (which I assume you also would be reticent to provide on the same grounds) I don't know how else I would even attempt to conduct verification.
I think you miss the elephant in the room, which is my email address. That's not something that easy to fake, and I'm pretty darn sure they have it in their database.
If they have other details about me, like my phone number or address, they can offer to give me a call, or send a letter to confirm my identity (btw, another company I filed a request with did just that). This won't expose any further details. The fact is, they didn't suggest any reasonable alternative.
> Assuming this was someone unknown and not Acxiom, this is a valid point and unfortunately I don't think there's a great answer. In this case, it is Acxiom and you could've quite easily discovered that they're a major corporation and not a random data harvesting shop.
The fact that they're big is irrelevant. They already shared my data without my explicit consent. They're a company I never ever signed-up for, interacted with in any way, yet they hold data on me. They share it and make profit out of it. I'm definitely not keen on sharing any additional info with a company that aggregates my data as their core business.
I hope you see the huge imbalance here. To get my data I need to jump through hoops and expose even more data about myself (to a data broker which makes money off of it). To sell, aggregate, share and abuse my data without my consent and very likely in violation of GDPR requires no validation that indeed the data belongs to me, nor even an attempt to contact me and ask for consent.
I'm leaving aside the consent piece, because frankly it's unlikely that they ingested this data without receiving it from a third party to whom you did give explicit consent. This is one of the problems inherent in GDPR as written, and needs to be addressed in the next revision.
> I think you miss the elephant in the room, which is my email address. That's not something that easy to fake, and I'm pretty darn sure they have it in their database.
As I wrote earlier, the issue here is that because they have no direct relationship with people in their data lake, there's no way for them to know with certainty that the email address associated with a person belongs to that person without some form of additional validation.
You can prove that you have access to that email, but you still need to prove that you're you.
> If they have other details about me, like my phone number or address, they can offer to give me a call, or send a letter to confirm my identity
This brings up the same problems as before: what if the number has been recycled? What if the letter is intercepted by someone living at an old address? Then they've given up the store again. Just because someone else is doing it doesn't mean it's a good idea.
> I hope you see the huge imbalance here.
I do, but you also need to look at it from the other side of the screen. As much as you have a legal interest in accessing your own data, they have a legal interest in ensuring that you are actually the one accessing it.
What you've run into here is one of the other...accidental features of GDPR: it incentivizes companies like Acxiom to be as strict as possible when verifying identities for access requests. They'd much rather be forced to defend the stringency of their access policies than to be strung up by the EC for enabling large-scale identity fraud because they weren't vigilant enough.
> I'm leaving aside the consent piece, because frankly it's unlikely that they ingested this data without receiving it from a third party to whom you did give explicit consent.
Well, I definitely didn't. Even if I did give consent for processing my data, sharing with Facebook isn't something I would ever in a million years agree to. An explicit consent should have been specific about it. Evidently Acxiom shared my details with Facebook. But let's leave it aside for now.
> You can prove that you have access to that email, but you still need to prove that you're you.
That's where the huge imbalance lies, isn't it? They link my email, along other details, and they also share my email with Facebook. Yet, when I'm contacting them, from the same email address, then suddenly it's not enough.
But let's say one piece of info isn't enough, they have other pieces? let's match them. Send me a letter, give me a phone call, give me the postal code and ask me to complete the address (or other parts of the address), provide a reasonable way for me to prove my identity. Without effectively asking for my entire address history, or compromising even more data about myself.
> it incentivizes companies like Acxiom to be as strict as possible when verifying identities for access requests. They'd much rather be forced to defend the stringency of their access policies than to be strung up by the EC for enabling large-scale identity fraud because they weren't vigilant enough.
We completely agree on this one. They're as strict as possible when subjects try to exercise their rights, but loose as a cannon when it comes to sharing data, making sure they get real and explicit consent etc.
I'm leaving aside the consent piece, because frankly it's unlikely that they ingested this data without receiving it from a third party to whom you did give explicit consent.
That seems a rather optimistic assumption, given the historical way data brokers and those who use them have operated. Plenty of businesses, including some household names, have been caught with their hands in the cookie jar on this one before. No doubt plenty are still doing it and hoping not to get caught or that any penalties will be small enough to be worth it.
As I wrote earlier, the issue here is that because they have no direct relationship with people in their data lake, there's no way for them to know with certainty that the email address associated with a person belongs to that person without some form of additional validation.
There are few ways to know anything with true certainty unless someone in your organisation personally knows someone you're dealing with. It is more about being reasonable.
If an organisation maintaining large amounts of personal data about people without their consent can't find a reasonable way to verify identity and allow the data subjects to exercise their rights, the GDPR-esque solution to the problem is to shut that processing down entirely until the organisation can get its house in order, or permanently if it can't find a way to do that. If that kills the data broker's business model, maybe they shouldn't have been using that business model in the first place, or should have discontinued it when the GDPR came into effect.
Allowing the organisation to deny data subjects their legal rights by hiding behind the verification obligation is at best against the spirit of the law but probably against its letter as well, and certainly justifies a regulatory investigation if it's being done systematically by a big organisation that should know better.
I'm just basing this on my experience working on products in this space and specifically dealing with compliance and "retroactive" consent in the run-up to GDPR implementation. I could definitely be wrong.
> If an organisation maintaining large amounts of personal data about people without their consent can't find a reasonable way to verify identity and allow the data subjects to exercise their rights...
I'm genuinely curious: if you were them, what would you do to resolve this without asking the subject to provide any additional data for verification?
I'm genuinely curious: if you were them, what would you do to resolve this without asking the subject to provide any additional data for verification?
There obviously needs to be something confirmed to verify the identity, but by definition personal data is data about an identifiable subject, so there must be something that can be checked.
If a big data hoarder has personal contact details, attempting to reach someone using those in response to a subject request isn't unreasonable. The hoarder will also have obligations under the GDPR regarding keeping data correct and up-to-date, so they should be in a position to do this in most cases or they're probably in violation already.
Some contact details might be checkable against an external reference to confirm they really are still up-to-date before relying on them, in which case a single attempt using that method might be sufficient.
Otherwise, if you can reach someone via two different and reasonably secure methods associated with their profile then it's probably reasonable to assume they are who they say they are.
If the hoarder doesn't have contact details they can use, then apparently there is some other identifying characteristic of the data subjects that makes it personal data, and in that case presumably you'd have to look at that and see how it could be used for verification.
One good thing about the GDPR is that it was basically designed to allow the regulators to beat up businesses that do that. If you're too old or inflexible to live up to your obligations, congratulations, it's now a liability that could into substantial fines.
Note that in principle it's not up to the EU to enforce because the GPDR is a directive; it's up to the individual member states to enforce the directive as enshrined in their law.
GDPR isn't a directive, it's a regulation. It's literally what the R stands for.
The major difference between the two in terms of how the EU makes laws is that directives are the indirect one: individual member states are required to incorporate the provisions into their own legal systems to give them force of law. An EU regulation is the direct equivalent: it carries force of law across all member states immediately. In the case of the GDPR, the UK government has also stated that its provisions will continue here after Brexit and the related transition arrangements.
However, you're right that enforcement will normally be done by an individual member state, because it is typically the national data protection or privacy authority in each state that acts as regulator and has enforcement powers under the GDPR. In theory, there's supposed to be some coordination so one of those regulators will take the lead on any given investigation or enforcement action instead of 28 different organisations all diving in at once, but it doesn't seem to be clear yet how that aspect will work post-Brexit.
In theory, yes. In practice... I'm not so sure. These processes are slow and I imagine that the regulators are drowning in complaints and are hugely understaffed.
And there's no recourse besides filing a complaint. Even if I'm legally right, what damage was caused to me that I can seek compensation for? (assuming I go and try to take them to court directly).
It feels like that, but I wonder how long it will be before one of the regulators decides to make an example of one of the big data-hoarding companies. Their whole business model is morally and now also legally dubious, and it's so obviously against the spirit of the GDPR that it seems like a matter of time before someone decides to pick a fight. I doubt it will be a single case like yours that starts it, unless perhaps it provides a convenient excuse to start an investigation, but it will be a thousand or a million situations like yours that motivate it.
There's so many copies of personal data all out there, it would blow your mind. I have a friend who works in this industry. Brokers sell to other brokers who sell to other brokers, who might even sell it back to the original broker after it's been "enriched" with more detail from additional brokers.
I'm a pessimist. You will never remove your personal data. If you get it removed by one company, the others will pop up like mushrooms. Also, from what I've seen, a lot of this information is out-of-date or crap that is just plain wrong.
In fact identity verification is one of Acxiom's lines of business, but that is US-centric and probably doesn't work very well for EU or global persons.
Disclaimer: I worked for Acxiom 2007-2009, but not in the data brokerage core business.
My ID contains: first name, last name, date of birth, place of birth, length, issuance and expiration, document number, citizen service number (~SSN), citizenship, photo (2x), gender, issuing authority (in my case: a municipality so small that it's more specific than geoIP), and in some countries it also contains your place of residence.
If they just have my name, now they have a lot of extra information. That's why my government recommends[1] to both watermark the copy and blacken unnecessary fields like the citizen service number and your photo. Such fields don't help them identify you, so you shouldn't share it with them. But imagine actually doing that: the only non-black parts (the parts they can actually match against their database) would be my name. Or in the case of WiFi tracking: nothing. I had to submit ID but really they just looked up whatever MAC address I claimed; I could have claimed my ex girlfriend's MAC address for all they knew. It's also trivial to photoshop a document if all you need to swap around are a few letters.
Identification is completely useless unless done in person when they can actually hold the document against the light and compare it to the European database of what it should look like[2]. (I've never seen anyone do the latter; see also lichtbildausweis[3].) Online, the best you can do is ask to confirm data that you already have about the person. Asking to confirm that same data but on a photoshopped (watermarked and censored) piece of plastic doesn't help anything.
In conclusion, sure I agree that you shouldn't be able to request my data, but the point is about the means rather than the goal. Is providing a censored and watermarked picture of an identity document a means of reaching that goal a better means of reaching that goal than confirming some data like the calendar week during which I was in whatever hotel they have my data from (for example)? That's what GP was offering them: asking to confirm masked data rather than having to provide extra and unnecessary personal data.
[3] Original in Dutch: https://dewinter.com/2012/09/24/de-legitimatiecontrole-in-ne... TL;DR: a "lichtbildausweis" is the german word for "photo ID". But how many Dutch people know that? So when you order a photo ID from germany, for example from a website that sells company badges (like, upload your company logo and employee photo and they'll print a plastic card for you), make sure it contains all the fields that you'd generally expect on an ID card, and they'll take it for being a german ID.
How does this apply to Clearbit which saves the Google Contact list of everyone who installs their extension [0][1] and then sells this data [2] ?
They have >150K extension users, so they are syncing a massive contact list with personal information that they are then selling via their different products like Prospector [3].
>And when you do request them to remove the same, they ask you to provide ID proof.
On the other hand, imagine one day you try to log in to your Twitter/Facebook/whatever-the next-big-thing-is and you can't, because the company has deleted all your data upon your request. You didn't make that request though. Someone else did it, claiming to be you.
It gets even worse when you realize that people can request all the data the company has collected of themselves. What happens when somebody impersonates you and requests all of your data?
You need to have some kind of verification method that leads back to a real identity. Otherwise this can be massively abused. I doubt that even asking for a real ID is enough.
Twitter/Facebook/whatever-the next-big-thing-is doesn't have 9 out of 10 fields that are on my ID card. If I show them a piece of blacked-out plastic with only my first name visible, since that's the only piece of information they have about me, it won't help them identify me.
Yes, you need to prove that you're the data subject matching their records before they should act on your request, whatever that request may be. But uploading a copy of your ID card almost never serves that purpose. See also a bigger comment I wrote elsewhere in this thread with sources and examples: https://news.ycombinator.com/item?id=23957503
OP here - That's the point. They are not a data controller by that very simple fact. They are processing this data on an illegal basis. Any lawyer around that want to assist me suing in the US?
you mean like Estonia's digital signing? ;)
and pretty sure that most sane-ish companies already delay and notify people of major stuff like account deletion and such, less hassle on both parts, company also benefits as it can just batch process requests weekly or monthly or so.
And when you do request them to remove the same, they ask you to provide ID proof. As if one would provide the same to a company which didn't take your consent for the initial profile data either.
I somehow managed to get hold of the CEO's mail ID got mine removed. But I can only imagine what everyone else would have to do when they want to control their web-presence.