Tamers Without a Whip – Adtech 101
Complex, legion and over in milliseconds – not your bedroom antics, but the world of adtech and RTB. I took a look at a couple of ICO publications on Adtech and gleaned the following:
Continue reading “Tamers Without a Whip – Adtech 101”GDPR Anniversary – Passing Thoughts (+ Unintended Effects pt 2)
Today, the GDPR celebrates its first anniversary. For an infant, it has accomplished a lot (though admittedly it began to exert its influence whilst it was in the womb, so to speak) – and its repercussions were significant to say the least. There were positive externalities as well – knowledge and discourse of data privacy has never been higher (and thankfully more searched than Kim Kardashian and Beyonce for a time), though some of these statistics reveal a little something more beyond their actual figures.

So what next? There can be some things to continue looking forward to – some distant, others resting on a hair’s breadth away from reality. The former relates to a harmony (or discord) between technological developments and the GDPR, as both regulation and technology are in their nascent stages and need time to “bed in” before they can be fully explored. The latter relates to forthcoming fines (looking at you, UK and Belgium) and further guidances (looking at you, EDPB) relating to technology and regulatory implementation.
But first – some thoughts.
Continue reading “GDPR Anniversary – Passing Thoughts (+ Unintended Effects pt 2)”Anti-Fake News in Singapore – a Step Into 2019, Not 1984
Singapore’s anti-fake news law (aka-ed the Protection from Online Falsehoods and Manipulation Bill) was bound to ruffle some feathers. The Bill, especially when compared to its counterparts in France and Germany, purportedly gives the government far reaching powers and a wide discretion to clamp down on fake news (side note: the Bill also allows the government to police closed platforms like Whatsapp – I’m very curious to see whether this is a scare tactic, or if Whatsapp isn’t as secure as it makes itself out to be). Additionally, Singapore’s reputation for being harsh on free speech didn’t exactly make news of this Bill easy to swallow – comparisons to Orwellian thoughtcrime policing, denouncement of it as “frankly insane”, and calls to have it rejected abound.

Evidently none of which were that successful – calls for amendments were generally rejected and the Bill was passed last week pretty much intact. Still – is this really a free pass for the PAP (the Singaporean government’s ruling party) to go full 1984? Or is this simply part of a largely consistent policy adopted by Singapore so far? I think it’s the latter. Singapore’s distaste for political criticism outside of the political arena is reflected in its approach to enact broad laws to catch instances where unwarranted (and potentially false) criticism can be levied without responsibility – and with such broad laws to be balanced by a pragmatic approach to implementation.
Continue reading “Anti-Fake News in Singapore – a Step Into 2019, Not 1984”A Hostile Environment in Cyberspace
I’m more than slightly critical of the Home Office. I certainly don’t appreciate the introduction of the hostile environment policy and the decision to count foreign students as part of the immigration figures – policies which I believe played on the UK’s worst instincts and contributed to the Brexit sentiment. In other words, the policies spearheaded by Thatcher-in-the-Rye, and whose office hasn’t exactly had the best track record for efficiency or otherwise.
I am therefore highly concerned when a recent inspection report revealed Home Office plans to implement a “Status Checking Project”, which aims to “establish a system that obtains and shares an individual’s immigration status in real time with authorised users, providing proof of entitlement to a range of public and private services, such as work, rented accommodation, healthcare and benefits.”
This is, in effect, a massive hostile environment database.
Continue reading “A Hostile Environment in Cyberspace”Tip of the Zuckerberg
The apex predators of the tech industry can hardly be faulted for prioritising profit maximisation. The digital market favours a winner-takes-all strategy: economies of scale, lock-in effects and the corporate cultures of tech firms favour an ambitious, innovative and opportunistic mindset. By-and-large, they have fought their way to their positions of power through wit, gumption and a healthy amount of luck. Once at the top, they naturally will want to be able to flex the full extent of their power – you don’t see tigers blunting their claws to be a fair sport to the antelopes.
So when Mark Zuckerberg called for increased tech regulation, the reaction was that of surprise – and then of healthy skepticism. Why would Facebook, of all companies, want to regulate itself? It wasn’t so long ago when Zuckerberg explicitly noted (or at least his team noted for him) not to mention GDPR compliance in congress:

Presumably on the next page – “Do not reveal the existence of skynet”, “Do not mention the main ingredient in Soylent Green”, etc.
Seeing Through the Con of Consent
Consent is not the be all end all basis for processing data, contrary to popular belief. I’ve mentioned before that the irony behind the flood of GDPR consent emails in the lead up to it was two-fold: the GDPR precipitated something it was trying to prevent, and the emails themselves were often in breach of the GDPR. Some companies (or perhaps their counsel) seem to be labouring under the mindset to treat consent as akin to an express term of contract – with a clear, black and white agreement, we should be in the clear.
No, you’re not. Obtaining consent isn’t as simple as saying I agree to let you process my data, nor does that provide you with an unlimited remit to do whatever you want with my data. Consent, now as defined under the GDPR, is difficult to obtain, limited in its validity and may be withdrawn with little warning. And – even if consent was obtained pre-GDPR, such consent is only valid if it meets GDPR standards (which I strongly doubt they would without an incentive to).
Continue reading “Seeing Through the Con of Consent”Blockchain/GDPR : problem/solve
The GDPR can be seen to be Blockchain’s stumbling block. As acknowledged by the CNIL (French data protection authority),
“The GDPR, and more broadly classical data protection principles, were designed in a world in which data management is centralised within specific entities. In this respect, the decentralised data governance model used by blockchain technology and the multitude of actors involved in the processing of data lead to a more complex definition of their role.”
In other words: the principles of the GDPR envisage centralised control, whereas the Blockchain is a manifestation of distributed ledger technology with distributed control at its core.
Continue reading “Blockchain/GDPR : problem/solve”Unintended Consequences of the GDPR
In two months, the GDPR will celebrate its first anniversary as the world’s foremost piece of data protection legislation. With its worldwide reach and unprecedented level of fines, the GDPR went from boogeyman to beast as companies were fined not only for non-compliance of the GDPR, but for sub-standard compliance of the GDPR as well (indeed one of the most significant aspects of the CNIL fine was the nature of Google’s wrongdoing: not as a flagrant breach of the GDPR but for insufficient compliance with it). On one hand, this can be celebrated – under the GDPR’s watchful eye individuals can count on basic protection against having their data abused, and are granted important rights in an environment prone to exploitation. On the other, a watchful eye must be cast over the GDPR, for some unintended consequences of the GDPR have already begun to emerge. The article below explores a few of them.
Read moreIntroduction
Is it somewhat ironic that I need a blog to publish and consolidate my thoughts on data privacy?
All writings and opinions expressed therein are my own unless acknowledged. This blog also aims to review and report on articles I think are interesting and worth sharing: to the extent possible, I have cited the source of such articles and from time to time, may even take wording and text from them. As such, this is an exercise in non-commercial research and as an online repository for my own private study – I am in no way remunerated for this, nor is the blog used for commercial purposes.
Those who would give up essential Liberty, to purchase a little temporary Safety, deserve neither Liberty nor Safety. – Benjamin Franklin