logoalt Hacker News

cogman10today at 5:20 PM1 replyview on HN

You can have privacy and an institution can collect data.

HIPAA is an example of that.

All personal data should be treated with at or near HIPAA levels of security. If I give my personal information to my bank, or google, that's fine for them to look at it, but it's not ok if that information magically lands in the hands of Coca Cola for marketing.


Replies

jsroznertoday at 5:29 PM

Yes, mostly, but google shouldn't be able to "look" at it either. No entity should be able to derive a commercial benefit from my data; any commercial value of my own data should accrue entirely to me.

You could build a test: the company should not be able to derive any additional value from 100 fully anonymized interactions with the same person as from 100 interactions with a deanonymized individual. Google obviously fails this test since targeted advertising is much more valuable if you have non-anonymized entities.

The doctor can store my data because it is necessary to provide me with the service, but the doctor shouldn't be able to sell my data, nor correlate it with their other patients' data.

Of course, a doctor will learn from treating me and become a better doctor, so you can't actually enforce this totally in practice. But it's like porn - you know when you see the violation.

show 2 replies