toad.social is one of the many independent Mastodon servers you can use to participate in the fediverse.
Mastodon server operated by David Troy, a tech pioneer and investigative journalist addressing threats to democracy. Thoughtful participation and discussion welcome.

Administered by:

Server stats:

387
active users

#gdpr

49 posts36 participants1 post today
Continued thread

Then, a couple of months later, I get spam from a seller trying to get me to buy knockoff designer handbags, or a Nigerian prince trying to secret his fortune away, or something else odious.

But look -- the email was sent to the address "crappytire@example.net"!

Now I know, with absolute certainty, that this spammer got my address, directly or indirectly, from Crappy Tire. Maybe they sold their mailing list far and wide. Maybe their systems were hacked and every customer's email was exfiltrated.

I can now take action. If I think they sold my address, I can write a nastygram referencing their privacy policy or Canada's PIPEDA act, or Europe's GDPR, or whatever. If I think my address was stolen from their systems, I can report the security incident to them, or publicize it so others know it may have happened to them.

And most importantly, I can disable that email address. Just refuse all mail sent to it. It's no longer of use to spammers or crooks. If I ever deal with Crappy Tire again, I give them a new unique address.

Anyway, that's a lot of backstory. I use this technique extensively. I have caught many, many companies selling/renting their mailing lists in violation of their own policies. I have caught many others that have been hacked, and they didn't even know it.

So what's the thing that happens to me occasionally regarding this?

2/x

Replied in thread

@data @datadon 🧵

In its judgment, the General Court of the European Union strengthened the conciliation and regulatory powers of the European Data Protection Board.

"The DPC will have to continue its investigations into Meta unless it chooses to refer the matter to the European Court of Justice. Given the timeline of the original investigation, which began in 2018, it may still take several years before a final determination is made regarding the GDPR compliance of Meta’s business model, particularly in relation to behavioural advertising."

dpoblog.eu/cjeu-and-the-powers by Christina Etteldorf, Institut of European #Media #Law, Saarbrücken (Germany)

dpoblog.euCJEU and the Powers of EDPB – DPOblog
Replied in thread

#dataleak #infosec #GDPR
Some figures about the "recent" #twitter #dataleak

382 CSV files, 438 GB uncompressed.

94 twitter_users_extra_ZZZ.csv files which contain few things. 835 M lines.

288 twitter_users_NNN.csv files, 3.1 billions of lines.
Few really personal data, only 9 millions lines with an e-mail address (valid or not).

Some rare lines also include a description or an URL.

TikTok faces a €500m fine over EU data illegally sent to China.

TikTok’s parent company ByteDance is reportedly set to be hit with a fine of over €500 million for illegally shipping European user data to China.

The fine could be one of the largest handed down by Ireland’s Data Protection Commission, TikTok’s main European regulator.

mediafaro.org/article/20250403

The TikTok logo on a smartphone. | Copyright AP Photo/Michael Dwyer, File
Euronews · TikTok faces a €500m fine over EU data illegally sent to China.By Euronews

📣 𝗖𝗼𝗹𝗹𝗲𝗰𝘁𝗶𝗻𝗴 𝘂𝗻𝗻𝗲𝗰𝗲𝘀𝘀𝗮𝗿𝘆 𝗱𝗮𝘁𝗮 𝗶𝘀 𝗹𝗶𝗸𝗲 𝗯𝗿𝗶𝗻𝗴𝗶𝗻𝗴 𝘁𝘄𝗲𝗻𝘁𝘆 𝘀𝘂𝗶𝘁𝗰𝗮𝘀𝗲𝘀 🧳 𝗳𝗼𝗿 𝗮 𝘄𝗲𝗲𝗸𝗲𝗻𝗱 𝘁𝗿𝗶𝗽😱! The GDPR provides us with great guidelines for conducting safe research, for example regarding 𝗱𝗮𝘁𝗮 𝗺𝗶𝗻𝗶𝗺𝗶𝘇𝗮𝘁𝗶𝗼𝗻: only collect what you need.

𝗧𝗵𝗲 @𝘂𝗴_𝗱𝗰𝗰 & the 𝗨𝗚 ‘𝗪𝗲 𝗹𝗼𝘃𝗲 𝗣𝗿𝗶𝘃𝗮𝗰𝘆 𝗮𝗻𝗱 𝗦𝗲𝗰𝘂𝗿𝗶𝘁𝘆’ 𝗰𝗮𝗺𝗽𝗮𝗶𝗴𝗻 have compiled a list of 12 essentials to help you conduct research in a safe way. Tips with a wink 😉, but no less serious because of that!

👉edu.nl/cgwc3

Peggio dei dazi: vogliono uccidere il GDPR è sotto attacco. Il killer è la Commissione e i mandanti sono le solite lobby della sorveglianza

Considerato a lungo intoccabile a Bruxelles, il GDPR è il prossimo nella lista della crociata dell'UE contro l'eccessiva regolamentazione.

La legge europea più famosa in materia di tecnologia, il #GDPR, è la prossima sulla lista degli obiettivi, mentre l'Unione Europea prosegue con la sua furia distruttiva in materia di normative per tagliare le leggi che ritiene stiano ostacolando le sue attività.

politico.eu/article/eu-gdpr-pr…

@politica

Grazie a @calamarim per la segnalazione
POLITICO · Europe’s GDPR privacy law is headed for red tape bonfire within ‘weeks’By Ellen O'Regan

I will reserve the full judgement until we see what exactly EU will propose, but this doesn't look good politico.eu/article/eu-gdpr-pr

when we need better privacy laws, closing loopholes, simplification for small businesses, and focus on ethical usage of personal data - EU seems to aim doing quite the opposite in the upcoming GDPR overhaul. I can expect gigantic lobbying, especially from American lobbyists, to water it down as much as possible

POLITICO · Europe’s GDPR privacy law is headed for red tape bonfire within ‘weeks’By Ellen O'Regan

Sweden just isn't what it used to be...

"In most countries, the government knows when you were born, your social security number, where you live, how much you earn and how much your house is worth. Sweden is a bit different though. There, the tax authority doesn’t just use this information for administrative purposes – but sells it to data brokers who publish it online. This is a violation of EU law. Earlier this year, a Swedish data subject asked the country’s tax authority to stop selling his data. The country’s Supreme Court has recently ruled that freedom of information and privacy rights must be balanced and data must be marked as confidential, if the recipient is likely to process it in conflict with the GDPR. The tax authority rejected the request, claiming it simply follows the Swedish constitutional principle of transparency rather than the ruling by the Supreme Court. noyb now takes the authority to court."

noyb.eu/en/noyb-takes-swedish-

noyb.eunoyb takes Swedish tax authority to court for selling people’s personal dataIn Sweden, the tax authority doesn’t just use people's personal information for administrative purposes – but sells it to data brokers who publish it online.
#Sweden#EU#Taxes

The UK Data Bill could unleash unchecked automated decision-making in policing ⚠️👮

ORG has signed Big Brother Watch's open letter to warn that removing safeguards could greatly expand "possibilities for bias, discrimination and lack of transparency".

Read more ➡️ bigbrotherwatch.org.uk/press-r