Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

First-party (inter-db) data use #123

Open
secretrobotron opened this issue Apr 4, 2019 · 1 comment
Open

First-party (inter-db) data use #123

secretrobotron opened this issue Apr 4, 2019 · 1 comment

Comments

@secretrobotron
Copy link
Contributor

In our "Data Use" section, we say "The company clearly discloses what user information it shares.", but the rest of the section implies this is about third-party sharing. But, when large companies purchase one another and combine data sets, or when a company has multiple potential sources of personal data (e.g. Facebook & Instagram; Microsoft & LinkedIn; Yahoo! & Tumblr), should the rules or expectations of data use be disclosed?

For example, Facebook's Data Policy has a section titled, "How do the Facebook Companies work together?"

Facebook and Instagram share infrastructure, systems and technology with other Facebook Companies (which include WhatsApp and Oculus) to provide an innovative, relevant, consistent and safe experience across all Facebook Company Products you use. We also process information about you across the Facebook Companies for these purposes, as permitted by applicable law and in accordance with their terms and policies. For example, we process information from WhatsApp about accounts sending spam on its service so we can take appropriate action against those accounts on Facebook, Instagram or Messenger. We also work to understand how people use and interact with Facebook Company Products, such as understanding the number of unique users on different Facebook Company Products.

It's possible that the "Data Collection" section covers this, since it seeks to ask where companies get all of their data, but for very large/broad data policies, that is perhaps not enough detail to do a reasonable evaluation.

@j-br0 @KatieMcInnis @TatevSarg thoughts?

@KatieMcInnis
Copy link
Collaborator

So lets see, how would this look in the Standard itself? "The company clearly discloses the categories of information is shares or receives from affiliates, parent company, or subsidiaries and whether any anonymization techniques are used."

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants