Thread · 3 tweets · 27 Dec 2020

Replying to @montezumachavez and @hartzog, @profcarroll, @JuliaHlna, @neilmrichards

I like that but I worry about enforcement strategies. Do you just grant a PRA and pray for the best? One approach I think could be fruitful is to look more specifically at the fiduciary duties of software agents (instead of data processors in general).
A huge part of the data that enters the system is through them and we would gain a lot by ensuring they are trustworthy. They're also much much easier to audit and far fewer in numbers. You'd basically look at browsers, operating systems, identity providers.