• chevron_right

      Elon Musk’s X under pressure from regulators over data harvesting for Grok AI

      news.movim.eu / TheGuardian · Yesterday - 22:49


    Social media platform uses pre-ticked boxes of consent, a practice that violates UK and EU GDPR rules

    Elon Musk’s X platform is under pressure from data regulators after it emerged that users are consenting to their posts being used to build artificial intelligence systems via a default setting on the app.

    The UK and Irish data watchdogs said they have contacted X over the apparent attempt to gain user consent for data harvesting without them knowing about it.

    Continue reading...
    • chevron_right

      Meta pulls plug on release of advanced AI model in EU

      news.movim.eu / TheGuardian · Thursday, 18 July - 12:51

    ‘Unpredictable’ privacy regulations prompt Facebook owner to scrap regional plans for multimodal Llama

    Mark Zuckerberg’s Meta will not release an advanced version of its artificial intelligence model in the EU, blaming the decision on the “unpredictable” behaviour of regulators.

    The owner of Facebook, Instagram and WhatsApp is preparing to issue its Llama model in multimodal form, meaning it is able to work across text, video, images and audio instead of just one format. Llama is an open source model, allowing it to be freely downloaded and adapted by users.

    Continue reading...
    • chevron_right

      Meta defends charging fee for privacy amid showdown with EU

      news.movim.eu / ArsTechnica · Monday, 1 July - 15:26

    Meta defends charging fee for privacy amid showdown with EU

    Enlarge (credit: Anadolu / Contributor | Anadolu )

    Meta continues to hit walls with its heavily scrutinized plan to comply with the European Union's strict online competition law, the Digital Markets Act (DMA), by offering Facebook and Instagram subscriptions as an alternative for privacy-inclined users who want to opt out of ad targeting.

    Today, the European Commission (EC) announced preliminary findings that Meta's so-called "pay or consent" or "pay or OK" model—which gives users a choice to either pay for access to its platforms or give consent to collect user data to target ads—is not compliant with the DMA.

    According to the EC, Meta's advertising model violates the DMA in two ways. First, it "does not allow users to opt for a service that uses less of their personal data but is otherwise equivalent to the 'personalized ads-based service." And second, it "does not allow users to exercise their right to freely consent to the combination of their personal data," the press release said.

    Read 19 remaining paragraphs | Comments

    • chevron_right

      Meta halts plans to train AI on Facebook, Instagram posts in EU

      news.movim.eu / ArsTechnica · Friday, 14 June - 18:44

    Meta halts plans to train AI on Facebook, Instagram posts in EU

    Enlarge (credit: GreyParrot | iStock / Getty Images Plus )

    Meta has apparently paused plans to process mounds of user data to bring new AI experiences to Europe.

    The decision comes after data regulators rebuffed the tech giant's claims that it had "legitimate interests" in processing European Union- and European Economic Area (EEA)-based Facebook and Instagram users' data—including personal posts and pictures—to train future AI tools.

    There's not much information available yet on Meta's decision. But Meta's EU regulator, the Irish Data Protection Commission (DPC), posted a statement confirming that Meta made the move after ongoing discussions with the DPC about compliance with the EU's strict data privacy laws, including the General Data Protection Regulation (GDPR).

    Read 8 remaining paragraphs | Comments

    • chevron_right

      A misleading website designs urges people to purchase a high-priced "InfoPass" instead of giving a free copy of their data

      Mathias Poujol-Rost ✅ · Friday, 14 June - 14:14

    • chevron_right

      Meta uses “dark patterns” to thwart AI opt-outs in EU, complaint says

      news.movim.eu / ArsTechnica · Thursday, 6 June - 21:25 · 1 minute

    Meta uses “dark patterns” to thwart AI opt-outs in EU, complaint says

    Enlarge (credit: Boris Zhitkov | Moment )

    The European Center for Digital Rights, known as Noyb, has filed complaints in 11 European countries to halt Meta's plan to start training vague new AI technologies on European Union-based Facebook and Instagram users' personal posts and pictures.

    Meta's AI training data will also be collected from third parties and from using Meta's generative AI features and interacting with pages, the company has said. Additionally, Meta plans to collect information about people who aren't on Facebook or Instagram but are featured in users' posts or photos. The only exception from AI training is made for private messages sent between "friends and family," which will not be processed, Meta's blog said, but private messages sent to businesses and Meta are fair game. And any data collected for AI training could be shared with third parties.

    "Unlike the already problematic situation of companies using certain (public) data to train a specific AI system (e.g. a chatbot), Meta's new privacy policy basically says that the company wants to take all public and non-public user data that it has collected since 2007 and use it for any undefined type of current and future 'artificial intelligence technology,'" Noyb alleged in a press release.

    Read 41 remaining paragraphs | Comments

    • chevron_right

      CJEU Gives File-Sharer Surveillance & Data Retention a Green Light

      news.movim.eu / TorrentFreak · Tuesday, 30 April - 19:13 · 7 minutes

    Spy As part of anti-piracy scheme featuring warning letters, fines, and ISP disconnections, France has monitored and stored data on millions of internet users since 2010.

    Digital rights groups insist that as a general surveillance and data retention scheme, the ‘Hadopi’ program violates fundamental rights.

    Any program that monitors citizens’ internet activities, retains huge amounts of data, and then links identities to IP addresses, must comply with EU rules. Activists said that under EU law, only “serious crime” qualifies and since petty file-sharing fails to make the grade, the whole program represents a mass violation of EU citizens’ fundamental rights.

    Surveillance and Serious Crime

    Seeking confirmation at the highest level, La Quadrature du Net, Federation of Associative Internet Service Providers, French Data Network, and Franciliens.net, began their challenge in France . The Council of State referred the matter to the Constitutional Council, which in turn referred questions to the Court of Justice of the European Union (CJEU) for interpretation under EU law.

    EU member states may not pass national laws that allow for the general and indiscriminate retention of traffic and location data. Retention of traffic and location data is permitted on a targeted basis as a “preventative measure” but only when the purpose of retention is to fight “serious crime.”

    In his non-binding opinion , CJEU Advocate General Szpunar described Hadopi’s access to personal data corresponding to an IP address as a “serious interference with fundamental rights,” the clearest sign yet that the right to privacy had already taken a blow.

    CJEU judgments have balanced citizens’ rights and rightsholders’ right to copy many times over the years but here, case law was deemed potentially problematic. In fact so much so, AG Szpunar proposed “readjustment of the case-law of the Court” to ensure that rightsholders would not be left in a position where it was impossible to enforce their rights on BitTorrent and similar networks.

    EU Law Shouldn’t Rule Surveillance Out

    By last September, it was clear that a legal basis needed to be found to allow Hadopi and similar programs to continue. For example, the fluid nature of dynamic IP addresses was mentioned as an obstacle to comprehensive tracking.

    Well-constructed arguments stated that balance could be found in securing the harvested data and, to protect fundamental rights, limitations on how much data could be used in the event an alleged file-sharer was prosecuted.

    Ultimately, however, when infringement occurs exclusively online, an IP address may be the only means to track down an alleged infringer, leading to the conclusion that retention and access to civil identifying data is both “necessary” and “wholly proportionate.”

    Copyrights Trump Privacy Rights

    In its decision handed down Tuesday, initially only in French, the CJEU leaves no stone unturned in delivering a win for rightsholders. Despite the problematic case law, the judgment builds a framework for how monitoring and data retention can be conducted within the requirements of EU law.

    The judgment deals with three key questions, summarized as follows:

    1. Is civil identity data corresponding to an IP address included among the traffic and location data which, in principle, requires prior review by a court or administrative entity?

    2. If yes, is EU law to be interpreted as precluding national legislation that provides for the collection of such data, corresponding to users’ IP addresses, without prior review by a court or administrative entity?

    3. If yes, does EU law preclude the review from being performed in an adapted fashion, for example as an automated review?

    In other words, are member states precluded from having a national law that authorizes a copyright authority to access stored IP addresses and civil identity data relating to users, collected by rightsholders monitoring their activities on the internet, for the purpose of taking further action, without a review by a court or administrative body?

    Data collected includes date and time of alleged infringement, IP address, peer-to-peer protocol, user pseudonym, details of copyright works, filename, ISP name.

    Ensuring Privacy and Data Security

    The judgment notes that IP addresses can constitute both traffic data and personal data. However, IP addresses that are public and visible, as they are in file-sharing swarms, are not being used in connection with the provision of an ‘electronic communication service’.

    The judgment also states that, if Member States seek to impose “an obligation to retain IP addresses in a general and indiscriminate manner, in order to attain an objective linked to combating criminal offenses in general”, they should lay down clear and precise rules in legislation relating to retention of data, meeting strict requirements.

    IP and civil identity data must be separated from each other and all other data, in a secure and reliable computer system. When IP addresses and civil data need to be linked, a process that does not undermine the “watertight separation” should be used, and regularly inspected for effectiveness. When these rules are followed, even citizens’ data gathered indiscriminately cannot result in “serious interference” to fundamental rights.

    The judgment notes that EU law does not “preclude the Member State concerned from imposing an obligation to retain IP addresses, in a general and indiscriminate manner, for the purposes of combating criminal offenses in general.”

    Balancing Competing Rights

    The CJEU says that while EU citizens using internet services “must have a guarantee that their privacy and freedom of expression” will be respected, those fundamental rights are not absolute. The prevention of crime or the protection of the rights and freedoms of others may see those rights deemed less important.

    Then, with some fluidity, the CJEU pulls the rug on excuses and upgrades petty file-sharing to something, well, a bit more serious .

    To prevent crime, it may be strictly necessary and proportional for IP addresses to be captured and retained for “combating criminal offenses such as offenses infringing copyright or related rights committed online.”

    Indeed, not allowing the above “would carry a real risk of systemic impunity not only for criminal offenses infringing copyright or related rights, but also for other types of criminal offenses committed online or the commission or preparation of which is facilitated by the specific characteristics of the internet.”

    Pirate Privacy? Not Here

    The judgment adds that despite the strict security guarding private information, there’s always a chance that a person might find themselves profiled. And that, the court suggests, may be of their own making.

    [S]uch a risk to privacy may arise, inter alia, where a person engages in activities infringing copyright or related rights on peer-to-peer networks repeatedly, or on a large scale, in connection with protected works of particular types that can be grouped together on the basis of the words in their title, revealing potentially sensitive information about aspects of that person’s private life.

    Thus, in the present case, in the context of the graduated response administrative procedure, a holder of an IP address may be particularly exposed to such a risk to his or her privacy where that procedure reaches the stage at which Hadopi must decide whether or not to refer the matter to the public prosecution service with a view to the prosecution of that person for conduct liable to constitute the minor offense of gross negligence or the offense of counterfeiting.

    Throughout the course of the next few paragraphs, the judgment mentions processing data for the “prevention, investigation, detection or prosecution of criminal offenses,” and a quote from the French government stating that “the measures adopted by Hadopi in the context of the graduated response procedure ‘are of a pre-criminal nature directly linked to the judicial proceedings’.”

    That leads to the predictable conclusion that EU law does not preclude national legislation that allows for the surveillance of internet users and the retention of their data, for the purpose of identifying users and taking legal action against them.

    Member states just need to follow the rules to ensure that those who didn’t have their privacy breached when their data was collected, don’t have it breached or leaked as they wait for whatever punishment arrives in the mail.

    La Quadrature du Net says it’s disappointed with the judgment.

    “[T]his decision from the CJEU has, above all, validated the end of online anonymity. While in 2020 it stated that there was a right to online anonymity enshrined in the ePrivacy Directive, it is now abandoning it.

    Unfortunately, by giving the police broad access to the civil identity associated with an IP address and to the content of a communication, it puts a de facto end to online anonymity.”

    The judgment is available here

    From: TF , for the latest news on copyright battles, piracy and more.

    • chevron_right

      Facebook, Instagram may cut fees by nearly 50% in scramble for DMA compliance

      news.movim.eu / ArsTechnica · Tuesday, 19 March - 16:42

    Facebook, Instagram may cut fees by nearly 50% in scramble for DMA compliance

    Enlarge (credit: NurPhoto / Contributor | NurPhoto )

    Meta is considering cutting monthly subscription fees for Facebook and Instagram users in the European Union nearly in half to comply with the Digital Market Act (DMA), Reuters reported .

    During a day-long public workshop on Meta's DMA compliance, Meta's competition and regulatory director, Tim Lamb, told the European Commission (EC) that individual subscriber fees could be slashed from 9.99 euros to 5.99 euros. Meta is hoping that reducing fees will help to speed up the EC's process for resolving Meta's compliance issues. If Meta's offer is accepted, any additional accounts would then cost 4 euros instead of 6 euros.

    Lamb said that these prices are "by far the lowest end of the range that any reasonable person should be paying for services of these quality," calling it a "serious offer."

    Read 22 remaining paragraphs | Comments

    • chevron_right

      Vending machine error reveals secret face image database of college students

      news.movim.eu / ArsTechnica · Friday, 23 February - 22:02

    Vending machine error reveals secret face image database of college students

    Enlarge (credit: Aurich Lawson | Mars | Getty Images)

    Canada-based University of Waterloo is racing to remove M&M-branded smart vending machines from campus after outraged students discovered the machines were covertly collecting facial-recognition data without their consent.

    The scandal started when a student using the alias SquidKid47 posted an image on Reddit showing a campus vending machine error message, "Invenda.Vending.FacialRecognitionApp.exe," displayed after the machine failed to launch a facial recognition application that nobody expected to be part of the process of using a vending machine.

    "Hey, so why do the stupid M&M machines have facial recognition?" SquidKid47 pondered.

    Read 17 remaining paragraphs | Comments