Let me paint a picture. I walk up to you and say, "Hey, I'd like to conduct a survey. Just one question. Would you be interested in participating?" You say yes, because you're a genuinely helpful person. And then I slap you across the face as hard as I can. "So, on a scale of one to ten, how badly did that hurt?"
You consented to the survey. But there's a difference between consent and informed consent. Informed consent would have gone like this: "I'm conducting a survey on pain studies. I'd like to slap you across the face, then have you rate the pain on a scale of one to ten." Same slap, same question, completely different transaction, because you knew what you were agreeing to.
I equate this to data privacy by comparing it to terms and conditions. Accepting terms and conditions is consent. You're agreeing to whatever they've arbitrated, and mostly you're just saying, "Sure, fine, whatever, I'll use your site."
Unfortunately, that consent has started digging deeper and deeper rabbit holes for your data to fall into. Terms and conditions likely will include language like, "We work with third parties to provide you a service and may use third parties to process various bits of your data." What it doesn't tell you is that this third-party processor may partner with other companies, and those companies may collect and sell your data because of the terms and conditions they agreed to when partnering with the initial company.
Here's the example I like to use. Say Acme Corp is perfectly happy to sell sticks of dynamite to Wile E. Coyote on their online store, but they don't have the infrastructure to handle online selling themselves. So Acme Corp partners with an e-commerce platform and agrees to that platform's terms of service. "Yeah, that's fine. You guys do whatever you need to do. Just let me sell explosives to Wile E. Coyote." And those terms and conditions for the e-commerce platform may say that they collect and sell customer data. You'd have no idea, going to the Acme Corp website. They might say, "We work with third parties. You can request a list if you want," but you'd have no idea what those third parties actually agreed to. That rabbit hole, of consent stacked on consent stacked on consent, is where your data gets packaged and sold. The "I agree" button is consent. It just isn't informed consent.
Why ACCS Exists
ACCS, a data privacy company, exists to help take back that uninformed consent. We're here to help you reclaim your online data, because it's the oil of the twenty-first century. This isn't something you should be giving away for free, and it isn't something you should be giving away unwillingly. When you use free services like Google and Facebook, there's an understanding that you're working with them, that they're going to use your data as part of that deal. But when you use a service like the Acme Corp app, and then find out Acme Corp allowed an e-commerce site to sell your data, that's where we step in. We go to that e-commerce site and say, "Don't sell my data. Remove everything you've got on me." We're clawing back data that's been flowing through the internet unchecked.
I'd be remiss if I didn't state what the ultimate goal of this company is. I don't want this to be something my children or grandchildren have to deal with. My goal is for ACCS to be put out of business, because we've done our job at both the state and federal level, making data privacy about informed consent instead of just consent. That's the big driver here. I don't think my kids, my grandkids, my neighbors, my friends, my family, should have their data sold for pennies on the dollar without them saying, "Yeah, that's fine."
Questions We Get a Lot
What’s the real-world difference between consent and informed consent, in plain terms?
That's the analogy from the top; agreeing to participate in a survey, then getting slapped, versus agreeing to participate in a survey on pain studies where I'm going to slap you, then getting slapped. Same slap. Different consent.
If clicking “I agree” is legally binding, how can it not be real consent?
It is real consent. It's one hundred percent legally binding. I'm not familiar with any cases where terms and conditions were easily swept aside. So it is real consent, but my argument is that it isn't informed consent. You don't actually know what all the terms and conditions are for every third-party site being used to help facilitate whatever company you're working with. It's real consent. It's just not, in my opinion, informed consent.
Is there anything I can actually do about this, or is this just how things are now?
There are some things we can do. One is reclaiming your online data, either through a DIY process (which we'll be coming out with) or a paid service like our ACCS Privacy Protection. We're not trying to make a big enough dent that data brokers shut down. We're raising awareness and raising capital so that we can eventually help change the laws that govern these companies. That's really the only lever available. But it's never too late to put effort into it.
Are terms and conditions intentionally written to be confusing, or is that just how legal documents are?
Honestly, that's how legal documents are. There's a reason they're written in legalese, and a reason attorneys are required to draft a lot of them. They can be intentionally vague or misleading, but I like to think the vast majority of companies aren't writing these to be confusing on purpose. They're writing them because they need a terms of service or privacy policy to inform you as best they can, and legalese is just generally confusing. I wouldn't get too caught up in whether it's intentional. Instead, focus on the actual problem, which is being a conscientious consumer who knows what's going on with their data, as best you can.
How does my data actually get from a website’s terms and conditions into a data broker’s database?
Companies partner together. My company partners with other companies for data processing and request management. It's just how it works. There's no company that can handle the massive amount of data processing the internet demands, unless you're the size of Google or Facebook. So instead they partner with companies that offer a specific service, like location services.
Here's an example I bring up a lot in live presentations. Bob's Sandwich Shop has an app that shows you the nearest location. Bob's Sandwich Shop is a five-location business. They don't have the infrastructure to build custom GPS integration themselves, so they say, "There's a company that already does this. Let's use them." It might be a Russian nesting doll of companies, but eventually that data lands with a company that handles location services, or accounting, or database management. On top of providing that service, that company might pick up another revenue stream: packaging and selling the customer data that runs through their infrastructure. Bob's Sandwich Shop would have to read every layer of terms and conditions all the way down, and it's almost an infinite chain, which makes real informed consent virtually impossible.
If I never technically agreed to have my data sold, why is it legal for data brokers to sell it?
There are a couple of things going on here. One is open source intelligence gathering, or OSINT. OSINT is companies going out and scraping public records. Any court filing you were part of is a court record. Did you get married? Sign a property deed? Sign a mortgage? The details themselves might not be publicly accessible, but the fact that it happened is there. Loyalty programs, credit cards, general internet use, that's all fair game, too. There's nothing you can do about OSINT specifically; your information is out there, and they're just scraping it. Even if you're a Luddite who never touches the internet, writes only handwritten letters, and lives on land that's been in your family for generations, there's still open source intelligence out there about you.
The other part is those Russian nesting dolls of terms and conditions. My company's own terms and conditions state that we work with third-party apps for data processing. We do our best to review those companies and make sure your data isn't being sold, partly by working toward HIPAA compliance wherever we can, since that restricts how companies bound by it can handle anything that could be medical-record related. We don't store medical records ourselves, but third-party services that do handle medical data tend to cost more, and they're more restricted from selling that data as a side revenue stream. In the end, if you've accessed a computer, if you've lived on this planet, you've tacitly accepted that people can access your data. If you use the internet at all, you're using the consent model of the internet. As a society, we've let that ride instead of demanding actual honest, informed consent, where companies tell you their intentions upfront, in plain language.
Why I Started This
What personally got me into this? I actually started ACCS as an education company, many years ago, teaching people how to securely write down their passwords. My grandmother had a password sheet in her purse, first name, last name, password, like Grandma would. Ever since then, my mission in cybersecurity has been to move complexity off of the individual and onto the organization.
If a company says you need a password, and it has to be this many characters, this many letters, change it every 90 days, blah blah blah, I hate that idea. Instead I prescribe to password blacklisting: pick whatever password you want. I don't care if it's eight characters. If we see it on the dark web, or find it's been breached, we tell you to change it. Not arbitrary complexity for complexity's sake. That's not helpful.
If ACCS wants to eventually make itself unnecessary, what happens to paying subscribers when that day comes?
That's the beauty of it. When that day comes, there shouldn't be any paid subscribers, because we'll be sending out information on how to opt yourself out. The goal is something like a do-not-call registry, but for your data. If you're on it, you've revoked consent for any company anywhere to sell your data, regardless of what you've previously signed, and it's on the data brokers to check the list before they sell. When that day comes, there's no need for our service anymore. We'd run sign-up drives, walk people through it, and shut the service down, because this new registry would protect you without us. We're not planning on leaving anyone high and dry. We're planning on making ourselves redundant.
Our employees know this is what we're fighting for. When we get to the point of lobbying organizations and governments, we'll set aside capital to cover a substantial severance for them. When we shut the doors, they won't be left high and dry either. We'll all go tackle another issue.
Yeah, I know, it's just another company profiting off of the same fear it's describing. Fair. We are profiting off of a scary thing. But this isn't "Don't worry about it, here's a scary thing, and oh by the way, we offer a service." The information on how to do it yourself will never be behind a paywall. We're profiting off people who don't have the time or energy to do it themselves but want it done. We'd rather give you the information. If you can't or don't have the time, we'll take care of it for you.
What’s the difference between what ACCS does and just reading the terms and conditions myself?
We don't read the terms and conditions for you. That's comparing apples and oranges, because I have no interest in reading what you sign off on. What we do instead is go to data brokers and say, "We understand how you got consent to sell this data, but we're revoking that consent." Right now, you have to do that every time they collect your data again. If they re-collect it two weeks later, you have to request removal again. We handle that for you.
So when you click "accept" on terms and conditions, you become an informed consumer, because you know the data is likely getting sold, and you know you can reclaim it yourself through our DIY resources, or let us handle revoking consent on things you probably didn't mean to consent to in the first place. There's a real difference between reading the terms and conditions yourself and what our service does. And for people who don't live online at all, data brokers are still pulling from courthouses, from public directories, from every public source that's free, compiling it all into one simple, searchable database. Which is its own problem entirely.
Leave a Reply