Privacy is not a soundbite
Privacy is not a soundbite
An unfortunate aspect regarding the privacy discourse is how it has been subverted into a set of meaningless soundbites that detract from actual privacy issues. A commonly used refrain, often used to gatekeep software and services, is about how “they are selling your data”. That’s a gross oversimplification of what privacy is, and actively harms the concept of privacy by framing it as a binary.
It takes just a few seconds of critical thinking to watch it fall apart.
If a company were to give your data away for free, would that be acceptable?
If they use your data as leverage over other entities, would that be acceptable?
If they’re selling your data, but you’ve given them fake data, is that acceptable?
How about if you want your data to be sold, but also want to be paid for it?
These are deliberately rhetorical questions, not meant to be answered, but to illustrate that the evaluation of privacy is not a single question.
Another often used expression is “If it’s free, you are the product”. This is what’s known as a thought terminating cliché; it is little more than a pseudo-aphorism, spoken with a smug sense of self satisfaction, and made possible only by having spent zero time thinking about the expression itself.
Free and open source software, known primarily for respecting user freedom and privacy, exists and is thriving, where users are most certainly not the product. In paid software, there is no magical flag that suddenly makes it privacy friendly for people who pay versus people who don’t pay. Paid, commercial software is by its nature and definition, highly privacy invasive, as their aim is revenue generation, and are incentivised to do so by any means necessary.
This is not limited to a contradicting duality in which they implement both privacy invasive features as well as market themselves as being privacy friendly. I don’t exclude the ever present “we don’t sell your data” and “we take your privacy seriously” lines usually seen in privacy policies. Where they once had meaning, they are now expected opening lines, the equivalent of T&C small talk.
If the immediate response to all of this dissection is “Well, you know what it means”, then that is exactly the problem (and I don’t think it has any meaning) - the purpose of soundbites is to say “don’t pay attention to the stuff going on over here, just focus on this one thing”. They are not automatically understood as proxies to broader underlying concerns.
I don’t really blame us for falling into this trap; privacy is a nuanced topic that requires effort, and we inherently seek the path of least resistance. Soundbites are appealing because they are easy to understand, and make us feel like we’ve grasped a topic. They make companies happy because they’ve successfully avoided scrutiny; you’ll know this is working if you have ever heard justification for other privacy invasive companies with “Well, at least they’re not selling my data”, which is a reluctance to put any further thought into the matter.
Control of data
Privacy is about control of data. It is about whether you control what is happening to your data. It’s not just whether a company profits from it, but what it’s used for and how it’s used. The topic of profiting is an unfortunate bikeshed which dominates conversations, when as individual evaluators, we should be thinking more about what is happening with our data as we use these services.
In some ways, the topics of privacy and security are similar. It would be ridiculous to hear someone say “Yes we are secure” or “If it’s free, you are vulnerable”, because security is not a binary flag, and it would be nonsensical to implement security protections only for paying users. Security is a series of measures and controls that can be implemented based on threat evaluations. It takes effort to be secure, and it takes continuous effort to stay secure. Just the same, it takes effort to be private, and it takes continuous effort to maintain privacy.
The GDPR privacy regulation exemplifies this ongoing effort. We groan at the annoying cookie banners and dialogs, but this is the result of a regulation that requires companies to explain to you what they’re doing with your data, and to give you a choice about it. The intention is absolutely right, it’s the implementation that is overwhelming, fraught with dark patterns, and implemented poorly.
This is how I try to frame it, at least it works for me: if you are given a choice of what happens to your data, that is a privacy gain. If you are not given a choice, that is a privacy loss. It is not enough to be told that something is private, if a company is telling you something is private or something is for your own good, then you are being marketed to and not necessarily in control.
In the real world, services can have privacy gains and losses sitting together, it is up to us as users to evaluate them and ensure that we are...