Thread · 15 tweets · 12 Apr 2019

First, the idea that privacy is the "right to be left alone" feels at best dated. Even Warren & Brandeis, who discuss a "right to be let alone" (attributed to Judge Cooley) in their 1890 classic only see it as perhaps a component of privacy.
In Nissenbaum's framework, you can absolutely be a bunch of serfs piled up in a small dwelling and have privacy if your norms of contextual integrity were respected.
Historians can jump in here but I would be surprised if that weren't the case. At the very least the Confessional comes to mind for Catholic Europe — but I am sure that many other norms of what to tell whom when prevailed. The opposite would be anthropologically surprising.
In fact I would posit the opposite: privacy rights only started gelling recently because it had previously been difficult to violate much privacy beyond gossip without direct social policing. You don't posit a right if it has no real counterfactual.
Second, it is true that our data and attention have become desirable assets, but that misses the third big one: our behaviour. A major (unanswered) question is "when does influence become control?" It's a shame to skip past that.
Third, a pet peeve: the notion that data is "shared". The data industry is full of euphemisms that contribute to its general obfuscation, eg. pixels, relevance, cookies, etc. "Sharing" is one of them. Sharing is caring! Sharing is cute and nice!
People are often confused about trackers because some of them (processors, service providers) are just tools for the first party and therefore the data isn't "given" to anyone else, while others (controller trackers) give full secondary use rights to the data to third parties.
In the latter case, that data is always provided in exchange for value. Usually not money directly (which is why it's not legally a sale in most places) but value that could be exchanged for money. That's why the CCPA calls it a sale, because it's a sale. Let's call a cat a cat.
Finally, I like the idea we could use our buying power to prefer privacy-friendly companies, but that relies on three things: 1) Genuine transparency, not the kind that the @iab writes about. Not notice-and-consent. No deception (see @hartzog's "Privacy's Blueprint").
2) There should be no third-party controllers. Only the first party that the user is aware they are interacting with should have any control over collecting and processing the user's data. That's the only way the user can really know who to talk to.
3) There should be a specific set of draconian privacy rules for services operating in an industry in which the Herfindahl–Hirschman Index is too high. It's only natural that consumers would be protected more when there is too little competition for them to have a choice.