Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

This same BS is perpetuated by YC backed Apollo.io by simply scraping public LinkedIn profiles & then masking asterisked emails & numbers(usually your company public numbers) & asking people to sign up.

And when you do request them to remove the same, they ask you to provide ID proof. As if one would provide the same to a company which didn't take your consent for the initial profile data either.

I somehow managed to get hold of the CEO's mail ID got mine removed. But I can only imagine what everyone else would have to do when they want to control their web-presence.



There are at least 50 data brokers I've had my information removed from. They will say whatever they can--"we need proof," "it's just public information anyway."

Every time I insisted they take it down, right now. Every time they have complied.

There's so many it's basically pulling weeds at this point.

The scarier companies are the ones collecting pictures of your face to train their private facial recognition software.

(Hell I'm hesitant to post HERE because you can't manage the privacy, content or existence of your comments)


Some data brokers are threatening you with "if you get removed from our database you will be marked as high risk of fraud and your transactions/orders you do online like hotel reservations will get rejected/put on hold for screening".

Well played. Absolutely legal but totally immoral


But is it true? If not then I'm pretty sure in the UK at least there's some law against it.


There are certainly rules in the GDPR about automated decision-making that might be relevant.

https://gdpr-info.eu/art-22-gdpr/

https://gdpr-info.eu/recitals/no-71/


I don't know, but I'd think it's slightly true I'd guess you'll be marked in THEIR database, so if the hotel happens to use that company's lists, you might be marked, but not be high risk in anyone else's books...


That's not legal, because that is still personal information being stored. They have to delete it all, upon request.


The implication (whether true or false) is that some company might treat the absence of a record in their database as suspicious.


> There's so many it's basically pulling weeds at this point.

...and they are often run by the same people. They use shell companies to basically avoid take-down requests.

Their goals is to make it sufficiently annoying to take down your information, that most people give up. While at the same time removing it (regardless of the process) for anyone that occupies them too much time - because your individual data isn't valuable enough to waste defending against a take-down.

I suspect a (faux) lawyers letter is easier to get these takedowns processed than the calls/emails that most people try.


I'd be interested to know if anyone has had success with any legal measure that would enjoin them or any other entity they're in any way affiliated with or that shares common ownership.


I've been in touch with a company called Acxiom, who shared my details on Facebook. I've never heard of it, so I submitted a Data subject request to see what they know about me.

They then asked me to provide my address to confirm my identity. Given that I moved quite frequently, and that I'm now asked to share more personal data with a company who's mishandling my data, I wasn't keen on it.

I mentioned that my full name is globally unique, but they refused. I tried to ask them to share some masked data that I can confirm in full (e.g. "give me a partial address and house number, I can give you the full address"). They refused.

They definitely try to make it hard for you, and to dodge responsibility.


Acxiom is one of the largest (and oldest, they started in the 1970s) data brokers in the world. I think they, like a lot of other creaky corporations, don't necessarily make things difficult on purpose but they...don't go out of their way to make the bureaucracy any more navigable than it has to be.

In other words, it's not a bug, it's an accidental feature.


I am sorry, how does that resolve the issue of them operating illegally?

The fact that you’re a old mess means you should be destroyed as a business to allow for newer, more ethical businesses to pop up.

If this is an accidental feature it means you should be accidentally run out of business.


> how does that resolve the issue of them operating illegally?

Which part of the process described is illegal? The GDPR explicitly requires[1] controllers to verify subjects' identities in an access request:

The controller should use all reasonable measures to verify the identity of a data subject who requests access, in particular in the context of online services and online identifiers.

1. https://gdpr.eu/recital-64-identity-verification/


That is true, but the word "reasonable" is significant. Taking reasonable steps to confirm a data subject's claimed identity is fair and necessary. Giving them the run around and hiding behind that verification obligation as an excuse is not.


I mean, sure, but OP indicated that he didn't want to provide the info they requested for verification. I don't see how their action here could be considered unreasonable.

"I promise you that I am the only person on earth with this name" doesn't really seem like a sufficiently secure attestation.


OP here. My name is unique globally (there are no other people with this name), easily searchable, linked to my personal domain, and my personal email address on that domain.

But even if we can't go by that, I gave them plenty of options that won't involve me disclosing my entire address history. How on earth am I supposed to give all my address history to a company I never heard of, and who shared my data without my consent...

They didn't come up with any concrete suggestions that won't involve disclosing much more information about myself than I think it's reasonable to require in order to release my own personal info.

I think I was very reasonable, and they weren't. Legally I'm not sure what the situation is. IANAL.


I'll be honest - based entirely on your description of events, with no other context, I wouldn't have approved this request either. Here's my reasoning:

> They then asked me to provide my address to confirm my identity...I wasn't keen on it.

This means one of the primary avenues of verification (possibly the only avenue for some shops) is unavailable. In the scope of GDPR, it's important to remember that they aren't allowed to retain any information you provide for this purpose for any reason other than keeping a record of the request.

> I mentioned that my full name is globally unique, but they refused.

I would have absolutely no way to validate this, because I don't have a comprehensive listing of all 7 billion-odd people in the world. Even if I did, and it was, it's still only a single factor - I doubt you'd want me to release your data to anyone else based only on them knowing your name and that it's unique.

> My name is...easily searchable, linked to my personal domain, and my personal email address on that domain

This can't be relied on, obviously, because there's no identity verification on (most) domain registrations. For all I know, the email address that I have attached to your profile isn't even yours (because we have no preexisting relationship, this has never been proven.)

> I tried to ask them to share some masked data that I can confirm in full...They refused.

I don't think this is actually allowed under GDPR, but assume it is. Let's say you do this twice with two different data controllers - they each provide you with a masked address, but they've masked different parts (because there's no standard).

If you were a malicious actor, you'd now have the subject's complete address and could use that to gain access to the rest of their data. It opens up a significant attack vector.

> How on earth am I supposed to give all my address history to a company I never heard of, and who shared my data without my consent...

Assuming this was someone unknown and not Acxiom, this is a valid point and unfortunately I don't think there's a great answer. In this case, it is Acxiom and you could've quite easily discovered that they're a major corporation and not a random data harvesting shop.

> I think I was very reasonable, and they weren't.

At the end of the day, you're going to have to give them something to prove who you are. If you won't even provide your old addresses, then absent a government-issued ID (which I assume you also would be reticent to provide on the same grounds) I don't know how else I would even attempt to conduct verification.


I think you miss the elephant in the room, which is my email address. That's not something that easy to fake, and I'm pretty darn sure they have it in their database.

If they have other details about me, like my phone number or address, they can offer to give me a call, or send a letter to confirm my identity (btw, another company I filed a request with did just that). This won't expose any further details. The fact is, they didn't suggest any reasonable alternative.

> Assuming this was someone unknown and not Acxiom, this is a valid point and unfortunately I don't think there's a great answer. In this case, it is Acxiom and you could've quite easily discovered that they're a major corporation and not a random data harvesting shop.

The fact that they're big is irrelevant. They already shared my data without my explicit consent. They're a company I never ever signed-up for, interacted with in any way, yet they hold data on me. They share it and make profit out of it. I'm definitely not keen on sharing any additional info with a company that aggregates my data as their core business.

I hope you see the huge imbalance here. To get my data I need to jump through hoops and expose even more data about myself (to a data broker which makes money off of it). To sell, aggregate, share and abuse my data without my consent and very likely in violation of GDPR requires no validation that indeed the data belongs to me, nor even an attempt to contact me and ask for consent.


I'm leaving aside the consent piece, because frankly it's unlikely that they ingested this data without receiving it from a third party to whom you did give explicit consent. This is one of the problems inherent in GDPR as written, and needs to be addressed in the next revision.

> I think you miss the elephant in the room, which is my email address. That's not something that easy to fake, and I'm pretty darn sure they have it in their database.

As I wrote earlier, the issue here is that because they have no direct relationship with people in their data lake, there's no way for them to know with certainty that the email address associated with a person belongs to that person without some form of additional validation.

You can prove that you have access to that email, but you still need to prove that you're you.

> If they have other details about me, like my phone number or address, they can offer to give me a call, or send a letter to confirm my identity

This brings up the same problems as before: what if the number has been recycled? What if the letter is intercepted by someone living at an old address? Then they've given up the store again. Just because someone else is doing it doesn't mean it's a good idea.

> I hope you see the huge imbalance here.

I do, but you also need to look at it from the other side of the screen. As much as you have a legal interest in accessing your own data, they have a legal interest in ensuring that you are actually the one accessing it.

What you've run into here is one of the other...accidental features of GDPR: it incentivizes companies like Acxiom to be as strict as possible when verifying identities for access requests. They'd much rather be forced to defend the stringency of their access policies than to be strung up by the EC for enabling large-scale identity fraud because they weren't vigilant enough.


> I'm leaving aside the consent piece, because frankly it's unlikely that they ingested this data without receiving it from a third party to whom you did give explicit consent.

Well, I definitely didn't. Even if I did give consent for processing my data, sharing with Facebook isn't something I would ever in a million years agree to. An explicit consent should have been specific about it. Evidently Acxiom shared my details with Facebook. But let's leave it aside for now.

> You can prove that you have access to that email, but you still need to prove that you're you.

That's where the huge imbalance lies, isn't it? They link my email, along other details, and they also share my email with Facebook. Yet, when I'm contacting them, from the same email address, then suddenly it's not enough.

But let's say one piece of info isn't enough, they have other pieces? let's match them. Send me a letter, give me a phone call, give me the postal code and ask me to complete the address (or other parts of the address), provide a reasonable way for me to prove my identity. Without effectively asking for my entire address history, or compromising even more data about myself.

> it incentivizes companies like Acxiom to be as strict as possible when verifying identities for access requests. They'd much rather be forced to defend the stringency of their access policies than to be strung up by the EC for enabling large-scale identity fraud because they weren't vigilant enough.

We completely agree on this one. They're as strict as possible when subjects try to exercise their rights, but loose as a cannon when it comes to sharing data, making sure they get real and explicit consent etc.


I'm leaving aside the consent piece, because frankly it's unlikely that they ingested this data without receiving it from a third party to whom you did give explicit consent.

That seems a rather optimistic assumption, given the historical way data brokers and those who use them have operated. Plenty of businesses, including some household names, have been caught with their hands in the cookie jar on this one before. No doubt plenty are still doing it and hoping not to get caught or that any penalties will be small enough to be worth it.

As I wrote earlier, the issue here is that because they have no direct relationship with people in their data lake, there's no way for them to know with certainty that the email address associated with a person belongs to that person without some form of additional validation.

There are few ways to know anything with true certainty unless someone in your organisation personally knows someone you're dealing with. It is more about being reasonable.

If an organisation maintaining large amounts of personal data about people without their consent can't find a reasonable way to verify identity and allow the data subjects to exercise their rights, the GDPR-esque solution to the problem is to shut that processing down entirely until the organisation can get its house in order, or permanently if it can't find a way to do that. If that kills the data broker's business model, maybe they shouldn't have been using that business model in the first place, or should have discontinued it when the GDPR came into effect.

Allowing the organisation to deny data subjects their legal rights by hiding behind the verification obligation is at best against the spirit of the law but probably against its letter as well, and certainly justifies a regulatory investigation if it's being done systematically by a big organisation that should know better.


> That seems a rather optimistic assumption

I'm just basing this on my experience working on products in this space and specifically dealing with compliance and "retroactive" consent in the run-up to GDPR implementation. I could definitely be wrong.

> If an organisation maintaining large amounts of personal data about people without their consent can't find a reasonable way to verify identity and allow the data subjects to exercise their rights...

I'm genuinely curious: if you were them, what would you do to resolve this without asking the subject to provide any additional data for verification?


I'm genuinely curious: if you were them, what would you do to resolve this without asking the subject to provide any additional data for verification?

There obviously needs to be something confirmed to verify the identity, but by definition personal data is data about an identifiable subject, so there must be something that can be checked.

If a big data hoarder has personal contact details, attempting to reach someone using those in response to a subject request isn't unreasonable. The hoarder will also have obligations under the GDPR regarding keeping data correct and up-to-date, so they should be in a position to do this in most cases or they're probably in violation already.

Some contact details might be checkable against an external reference to confirm they really are still up-to-date before relying on them, in which case a single attempt using that method might be sufficient.

Otherwise, if you can reach someone via two different and reasonably secure methods associated with their profile then it's probably reasonable to assume they are who they say they are.

If the hoarder doesn't have contact details they can use, then apparently there is some other identifying characteristic of the data subjects that makes it personal data, and in that case presumably you'd have to look at that and see how it could be used for verification.


This. I would go out on a limb and offer that Axciom has likely invested more in compliance in this regard than most other companies on the planet.

People may not agree with their stance, but it has yet to be successfully challenged in court to my knowledge.


One good thing about the GDPR is that it was basically designed to allow the regulators to beat up businesses that do that. If you're too old or inflexible to live up to your obligations, congratulations, it's now a liability that could into substantial fines.


Has the EU actually shown any teeth to these outfits?

It's one thing to say something is illegal but if you don't enforce that these firms will be able to operate with impunity.


Has the EU actually shown any teeth to these outfits?

It's starting to.

https://dataprivacymanager.net/5-biggest-gdpr-fines-so-far-2...

There are 7-8 figure fines already this year, and two 9 figure ones that the UK regulator has given notice on.


Note that in principle it's not up to the EU to enforce because the GPDR is a directive; it's up to the individual member states to enforce the directive as enshrined in their law.


GDPR isn't a directive, it's a regulation. It's literally what the R stands for.

The major difference between the two in terms of how the EU makes laws is that directives are the indirect one: individual member states are required to incorporate the provisions into their own legal systems to give them force of law. An EU regulation is the direct equivalent: it carries force of law across all member states immediately. In the case of the GDPR, the UK government has also stated that its provisions will continue here after Brexit and the related transition arrangements.

However, you're right that enforcement will normally be done by an individual member state, because it is typically the national data protection or privacy authority in each state that acts as regulator and has enforcement powers under the GDPR. In theory, there's supposed to be some coordination so one of those regulators will take the lead on any given investigation or enforcement action instead of 28 different organisations all diving in at once, but it doesn't seem to be clear yet how that aspect will work post-Brexit.


In theory, yes. In practice... I'm not so sure. These processes are slow and I imagine that the regulators are drowning in complaints and are hugely understaffed.

And there's no recourse besides filing a complaint. Even if I'm legally right, what damage was caused to me that I can seek compensation for? (assuming I go and try to take them to court directly).


Isn't the difficulty in proving actual damages in a personal claim one of the main arguments for making this a regulatory matter?

As mentioned in my other comment near here, the regulators have started issuing some reasonably substantial fines already.


Yes, absolutely. Yet the likelihood of Acxiom being fined anything other than some token amount in a case like mine is virtually zero.


It feels like that, but I wonder how long it will be before one of the regulators decides to make an example of one of the big data-hoarding companies. Their whole business model is morally and now also legally dubious, and it's so obviously against the spirit of the GDPR that it seems like a matter of time before someone decides to pick a fight. I doubt it will be a single case like yours that starts it, unless perhaps it provides a convenient excuse to start an investigation, but it will be a thousand or a million situations like yours that motivate it.


There's so many copies of personal data all out there, it would blow your mind. I have a friend who works in this industry. Brokers sell to other brokers who sell to other brokers, who might even sell it back to the original broker after it's been "enriched" with more detail from additional brokers.

I'm a pessimist. You will never remove your personal data. If you get it removed by one company, the others will pop up like mushrooms. Also, from what I've seen, a lot of this information is out-of-date or crap that is just plain wrong.


They obviously need to have a process to validate identity, and it's ridiculous to think that they would tailor that process for every request.

It's also odd that you would want to give them your NEW address if they are likely validating against your OLD address.

Why didn't you just give them your OLD address to check against?


In fact identity verification is one of Acxiom's lines of business, but that is US-centric and probably doesn't work very well for EU or global persons.

Disclaimer: I worked for Acxiom 2007-2009, but not in the data brokerage core business.


> They definitely try to make it hard for you, and to dodge responsibility.

Yes, but at the same time you do not want them handing over all your data with zero checks on identity right..?


My ID contains: first name, last name, date of birth, place of birth, length, issuance and expiration, document number, citizen service number (~SSN), citizenship, photo (2x), gender, issuing authority (in my case: a municipality so small that it's more specific than geoIP), and in some countries it also contains your place of residence.

If they just have my name, now they have a lot of extra information. That's why my government recommends[1] to both watermark the copy and blacken unnecessary fields like the citizen service number and your photo. Such fields don't help them identify you, so you shouldn't share it with them. But imagine actually doing that: the only non-black parts (the parts they can actually match against their database) would be my name. Or in the case of WiFi tracking: nothing. I had to submit ID but really they just looked up whatever MAC address I claimed; I could have claimed my ex girlfriend's MAC address for all they knew. It's also trivial to photoshop a document if all you need to swap around are a few letters.

Identification is completely useless unless done in person when they can actually hold the document against the light and compare it to the European database of what it should look like[2]. (I've never seen anyone do the latter; see also lichtbildausweis[3].) Online, the best you can do is ask to confirm data that you already have about the person. Asking to confirm that same data but on a photoshopped (watermarked and censored) piece of plastic doesn't help anything.

In conclusion, sure I agree that you shouldn't be able to request my data, but the point is about the means rather than the goal. Is providing a censored and watermarked picture of an identity document a means of reaching that goal a better means of reaching that goal than confirming some data like the calendar week during which I was in whatever hotel they have my data from (for example)? That's what GP was offering them: asking to confirm masked data rather than having to provide extra and unnecessary personal data.

[1] https://www.rijksoverheid.nl/onderwerpen/identiteitsfraude/v... In Dutch, but see the pictures near the bottom. This is the federal Dutch government's recommendation on how to provide a copy of your identity card.

[2] https://www.consilium.europa.eu/prado/en/search-by-document-...

[3] Original in Dutch: https://dewinter.com/2012/09/24/de-legitimatiecontrole-in-ne... TL;DR: a "lichtbildausweis" is the german word for "photo ID". But how many Dutch people know that? So when you order a photo ID from germany, for example from a website that sells company badges (like, upload your company logo and employee photo and they'll print a plastic card for you), make sure it contains all the fields that you'd generally expect on an ID card, and they'll take it for being a german ID.


Maybe post the CEO’s email here so we can all get our data removed as well?


tim


How does this apply to Clearbit which saves the Google Contact list of everyone who installs their extension [0][1] and then sells this data [2] ?

They have >150K extension users, so they are syncing a massive contact list with personal information that they are then selling via their different products like Prospector [3].

[0] https://connect.clearbit.com

[1] https://chrome.google.com/webstore/detail/clearbit-connect-s...

[2] https://clearbit.com

[3] https://clearbit.com/prospector


Couldn't find anything on those links or Google about them scraping your contact list.

Would you have any proof or evidence supporting that statement?


>And when you do request them to remove the same, they ask you to provide ID proof.

On the other hand, imagine one day you try to log in to your Twitter/Facebook/whatever-the next-big-thing-is and you can't, because the company has deleted all your data upon your request. You didn't make that request though. Someone else did it, claiming to be you.

It gets even worse when you realize that people can request all the data the company has collected of themselves. What happens when somebody impersonates you and requests all of your data?

You need to have some kind of verification method that leads back to a real identity. Otherwise this can be massively abused. I doubt that even asking for a real ID is enough.


Twitter/Facebook/whatever-the next-big-thing-is doesn't have 9 out of 10 fields that are on my ID card. If I show them a piece of blacked-out plastic with only my first name visible, since that's the only piece of information they have about me, it won't help them identify me.

Yes, you need to prove that you're the data subject matching their records before they should act on your request, whatever that request may be. But uploading a copy of your ID card almost never serves that purpose. See also a bigger comment I wrote elsewhere in this thread with sources and examples: https://news.ycombinator.com/item?id=23957503


Ok but he didn't subscribe on that website.


OP here - That's the point. They are not a data controller by that very simple fact. They are processing this data on an illegal basis. Any lawyer around that want to assist me suing in the US?


Did you reach La Quadrature Du Net ?

https://www.laquadrature.net/

Also check other CCC co-organizers & the political activist sphere.


Would anyone actually be upset to discover that apollo.io was no longer tracking their information?


Electronic signatures tied to your ID.

Don't delete instantly but after X days. Notify owner immediately.

Problem solved.


you mean like Estonia's digital signing? ;) and pretty sure that most sane-ish companies already delay and notify people of major stuff like account deletion and such, less hassle on both parts, company also benefits as it can just batch process requests weekly or monthly or so.


I have a complaint sitting agains Apollo.io as well. I'll make sure to post the outcome here.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: