Our product is ruining users privacy, without telling them [closed]












71














The current start-up I'm working with for now is obviously a threat for its users privacy. The product we're producing (which I'm involved in a HUGE part of it) records the user contacts. It's stated in the Privacy Policy that they're being recorded for "the sake of usability and ease of access" and "they can erased by user request". However, even if a person requests us to, all of his/her contacts are being soft-deleted without telling them.



It gets worse that we're also logging the user location history, without stating it in the privacy policy. I told them to state this, but they just ignore me.



The only way I had, was to tell my close friends and family to not to install this spyware.



What should I do? Do I have to concern about being accused by the government?










share|improve this question















closed as off-topic by gnat, solarflare, Monica Cellio Dec 12 '18 at 3:51


This question appears to be off-topic. The users who voted to close gave these specific reasons:



  • "Questions require a goal that we can address. Rather than explaining the difficulties of your situation, explain what you want to do to make it better. For more information, see this meta post." – Monica Cellio

  • "Questions seeking advice on company-specific regulations, agreements, or policies should be directed to your manager or HR department. Questions that address only a specific company or position are of limited use to future visitors. Questions seeking legal advice should be directed to legal professionals. For more information, click here." – gnat, solarflare


If this question can be reworded to fit the rules in the help center, please edit the question.









  • 11




    You don't state where you are... that would help in providing specific advice for this situation.
    – Stese
    Dec 11 '18 at 13:28






  • 2




    @Stese he can state if the app is available globally or only locally.
    – Simon
    Dec 11 '18 at 13:35






  • 142




    You should change your picture / user name, dude.
    – Roman
    Dec 11 '18 at 13:36






  • 1




    "Do I have to concern about being accused by the government?" sounds like asking for legal advice. "What should I do?" is often quoted as an example of a bad question format. I don't want to VTC because I think this is an interesting question, I'm just stuck on how it could be reformatted to keep it clearly valid.
    – dwizum
    Dec 11 '18 at 13:51






  • 28




    I really hope you are not using your real name and the avatar picture is not your own. Cover your assets and good luck.
    – Mindwin
    Dec 11 '18 at 16:27
















71














The current start-up I'm working with for now is obviously a threat for its users privacy. The product we're producing (which I'm involved in a HUGE part of it) records the user contacts. It's stated in the Privacy Policy that they're being recorded for "the sake of usability and ease of access" and "they can erased by user request". However, even if a person requests us to, all of his/her contacts are being soft-deleted without telling them.



It gets worse that we're also logging the user location history, without stating it in the privacy policy. I told them to state this, but they just ignore me.



The only way I had, was to tell my close friends and family to not to install this spyware.



What should I do? Do I have to concern about being accused by the government?










share|improve this question















closed as off-topic by gnat, solarflare, Monica Cellio Dec 12 '18 at 3:51


This question appears to be off-topic. The users who voted to close gave these specific reasons:



  • "Questions require a goal that we can address. Rather than explaining the difficulties of your situation, explain what you want to do to make it better. For more information, see this meta post." – Monica Cellio

  • "Questions seeking advice on company-specific regulations, agreements, or policies should be directed to your manager or HR department. Questions that address only a specific company or position are of limited use to future visitors. Questions seeking legal advice should be directed to legal professionals. For more information, click here." – gnat, solarflare


If this question can be reworded to fit the rules in the help center, please edit the question.









  • 11




    You don't state where you are... that would help in providing specific advice for this situation.
    – Stese
    Dec 11 '18 at 13:28






  • 2




    @Stese he can state if the app is available globally or only locally.
    – Simon
    Dec 11 '18 at 13:35






  • 142




    You should change your picture / user name, dude.
    – Roman
    Dec 11 '18 at 13:36






  • 1




    "Do I have to concern about being accused by the government?" sounds like asking for legal advice. "What should I do?" is often quoted as an example of a bad question format. I don't want to VTC because I think this is an interesting question, I'm just stuck on how it could be reformatted to keep it clearly valid.
    – dwizum
    Dec 11 '18 at 13:51






  • 28




    I really hope you are not using your real name and the avatar picture is not your own. Cover your assets and good luck.
    – Mindwin
    Dec 11 '18 at 16:27














71












71








71


9





The current start-up I'm working with for now is obviously a threat for its users privacy. The product we're producing (which I'm involved in a HUGE part of it) records the user contacts. It's stated in the Privacy Policy that they're being recorded for "the sake of usability and ease of access" and "they can erased by user request". However, even if a person requests us to, all of his/her contacts are being soft-deleted without telling them.



It gets worse that we're also logging the user location history, without stating it in the privacy policy. I told them to state this, but they just ignore me.



The only way I had, was to tell my close friends and family to not to install this spyware.



What should I do? Do I have to concern about being accused by the government?










share|improve this question















The current start-up I'm working with for now is obviously a threat for its users privacy. The product we're producing (which I'm involved in a HUGE part of it) records the user contacts. It's stated in the Privacy Policy that they're being recorded for "the sake of usability and ease of access" and "they can erased by user request". However, even if a person requests us to, all of his/her contacts are being soft-deleted without telling them.



It gets worse that we're also logging the user location history, without stating it in the privacy policy. I told them to state this, but they just ignore me.



The only way I had, was to tell my close friends and family to not to install this spyware.



What should I do? Do I have to concern about being accused by the government?







software-industry privacy






share|improve this question















share|improve this question













share|improve this question




share|improve this question








edited Dec 11 '18 at 13:32









David K

23.9k1581118




23.9k1581118










asked Dec 11 '18 at 13:21









ehsaan

28424




28424




closed as off-topic by gnat, solarflare, Monica Cellio Dec 12 '18 at 3:51


This question appears to be off-topic. The users who voted to close gave these specific reasons:



  • "Questions require a goal that we can address. Rather than explaining the difficulties of your situation, explain what you want to do to make it better. For more information, see this meta post." – Monica Cellio

  • "Questions seeking advice on company-specific regulations, agreements, or policies should be directed to your manager or HR department. Questions that address only a specific company or position are of limited use to future visitors. Questions seeking legal advice should be directed to legal professionals. For more information, click here." – gnat, solarflare


If this question can be reworded to fit the rules in the help center, please edit the question.




closed as off-topic by gnat, solarflare, Monica Cellio Dec 12 '18 at 3:51


This question appears to be off-topic. The users who voted to close gave these specific reasons:



  • "Questions require a goal that we can address. Rather than explaining the difficulties of your situation, explain what you want to do to make it better. For more information, see this meta post." – Monica Cellio

  • "Questions seeking advice on company-specific regulations, agreements, or policies should be directed to your manager or HR department. Questions that address only a specific company or position are of limited use to future visitors. Questions seeking legal advice should be directed to legal professionals. For more information, click here." – gnat, solarflare


If this question can be reworded to fit the rules in the help center, please edit the question.








  • 11




    You don't state where you are... that would help in providing specific advice for this situation.
    – Stese
    Dec 11 '18 at 13:28






  • 2




    @Stese he can state if the app is available globally or only locally.
    – Simon
    Dec 11 '18 at 13:35






  • 142




    You should change your picture / user name, dude.
    – Roman
    Dec 11 '18 at 13:36






  • 1




    "Do I have to concern about being accused by the government?" sounds like asking for legal advice. "What should I do?" is often quoted as an example of a bad question format. I don't want to VTC because I think this is an interesting question, I'm just stuck on how it could be reformatted to keep it clearly valid.
    – dwizum
    Dec 11 '18 at 13:51






  • 28




    I really hope you are not using your real name and the avatar picture is not your own. Cover your assets and good luck.
    – Mindwin
    Dec 11 '18 at 16:27














  • 11




    You don't state where you are... that would help in providing specific advice for this situation.
    – Stese
    Dec 11 '18 at 13:28






  • 2




    @Stese he can state if the app is available globally or only locally.
    – Simon
    Dec 11 '18 at 13:35






  • 142




    You should change your picture / user name, dude.
    – Roman
    Dec 11 '18 at 13:36






  • 1




    "Do I have to concern about being accused by the government?" sounds like asking for legal advice. "What should I do?" is often quoted as an example of a bad question format. I don't want to VTC because I think this is an interesting question, I'm just stuck on how it could be reformatted to keep it clearly valid.
    – dwizum
    Dec 11 '18 at 13:51






  • 28




    I really hope you are not using your real name and the avatar picture is not your own. Cover your assets and good luck.
    – Mindwin
    Dec 11 '18 at 16:27








11




11




You don't state where you are... that would help in providing specific advice for this situation.
– Stese
Dec 11 '18 at 13:28




You don't state where you are... that would help in providing specific advice for this situation.
– Stese
Dec 11 '18 at 13:28




2




2




@Stese he can state if the app is available globally or only locally.
– Simon
Dec 11 '18 at 13:35




@Stese he can state if the app is available globally or only locally.
– Simon
Dec 11 '18 at 13:35




142




142




You should change your picture / user name, dude.
– Roman
Dec 11 '18 at 13:36




You should change your picture / user name, dude.
– Roman
Dec 11 '18 at 13:36




1




1




"Do I have to concern about being accused by the government?" sounds like asking for legal advice. "What should I do?" is often quoted as an example of a bad question format. I don't want to VTC because I think this is an interesting question, I'm just stuck on how it could be reformatted to keep it clearly valid.
– dwizum
Dec 11 '18 at 13:51




"Do I have to concern about being accused by the government?" sounds like asking for legal advice. "What should I do?" is often quoted as an example of a bad question format. I don't want to VTC because I think this is an interesting question, I'm just stuck on how it could be reformatted to keep it clearly valid.
– dwizum
Dec 11 '18 at 13:51




28




28




I really hope you are not using your real name and the avatar picture is not your own. Cover your assets and good luck.
– Mindwin
Dec 11 '18 at 16:27




I really hope you are not using your real name and the avatar picture is not your own. Cover your assets and good luck.
– Mindwin
Dec 11 '18 at 16:27










6 Answers
6






active

oldest

votes


















100














If you don't agree with what the company is doing ethically, then you should probably quit asap.



If you think they are doing something illegal or in breach of regulations, then you may want to consider reporting them to the relevant authorities.






share|improve this answer

















  • 13




    Reporting can often be done anonymously, or while keeping you name out of it. Do think about the timing though (you leave, they get checked is "odd timing" to say the least).
    – Martijn
    Dec 11 '18 at 16:03






  • 2




    @Martijn Yes, but if you've already left then what's the issue?
    – Tashus
    Dec 11 '18 at 16:04






  • 14




    Pissed of previous employers/colleages who take revenge in some unforseen way.
    – Martijn
    Dec 11 '18 at 16:05






  • 4




    @Adonalsium IANAL; however, I believe an NDA usually protects against someone disclosing specific proprietary information. I would think someone could 'tip off' a regulatory agency to malpractice, without violating an NDA by disclosing any proprietary material.
    – Time4Tea
    Dec 11 '18 at 16:39






  • 3




    @Time4Tea That's generally supposed to be covered by whistleblower protections. Whether or not it is is... complicated, and you'll probably need to hire a lawyer to get the full answer (they won't be able to answer in the free 30 minute thing that some lawyers have). That said, most NDAs only cover proprietary information, so if you just say "this product has severe privacy violations; it records [blah] and [blah]", that might not fall under your NDA. Depends on the specific wording, of course, but I'm 90% sure it's possible to do. You just might need to be vague.
    – Nic Hartley
    Dec 11 '18 at 17:52





















77














What I do in such situations. (had a situation where my employer did not want to buy some licenses of software we used commercially)



Step one: Make sure I get my facts straight and have evidence of my claim.



Step two: Make management aware of the Problem. Leave a paper-trail of doing so. Assume no malice and make no accusations. Just describe the Problem and offer a solution.



Step tree: After some time, ask if action has been taken. If not ask for a timeline. Again, leave a paper-trail.



If it gets clear to you no action will be taken, think about



A. Do you want to keep working there?



B. Do you want to / have to report this to the police etc. I´d ask a lawyer about this.



The thinking is (in my jurisdiction, Germany) you have the obligation to protect your employer from harm. You also have the obligation not to break the law. So the first step if your employer is doing something (unintentionally?) unlawful, would be to make them aware of that. If they decide to take no action, and you make their misconduct public, harm is not on you, but on them, since they ignored you.



If you want to keep working there or not is up to you. Either way, be prepared to be fired immediately, especially if they do violate the rules intentionally. An never knowingly contribute to any unlawful conduct yourself.






share|improve this answer























  • About list of things to ask yourself, you should add "C. Do I want the risk of being considered guilty" because OP can no longer claim being ignorant, and if this privacy breach is illegal, he will be the one dev that was knowingly and willingly developing it. One more thing to ask yourself, and your lawyer I guess.
    – Mołot
    Dec 11 '18 at 15:26








  • 3




    @Mołot: It will be hard to prove that. First, OP is probably not a legal professional and normally he has to trust his employer to get those things sorted out by professionals. Secondly, you´d have to prove that he was actively contributing to the malicious element. Third, as long as the Data does not get used for fraud, it will be hard to proof any harm done by OP. I think, at least in Germany, my approach is pretty safe. Of course IANAL so when in doubt, please get appropriate legal counsel yourself!
    – Daniel
    Dec 11 '18 at 15:36












  • process of proving one way or another can be long, tiring and problematic for career, even if he finally is found innocent... That's why I'd add it as third point to things he should think and talk to his lawyer about.
    – Mołot
    Dec 11 '18 at 15:39






  • 3




    There are sensible reasons to use soft-delete as the default handling for data, and times when a carefully-written more thorough deletion is required, as here. +1 for step 2 here, making sure that it's not a genuine oversight.
    – chrylis
    Dec 11 '18 at 18:55






  • 1




    @chrylis: Step two is also the most effective way to remedy the situation while allowing everyone to safe face, even if it was intentional.
    – Daniel
    Dec 12 '18 at 8:40



















17















Do I have to concern about being accused by the government?




If you have to ask the question the answer is probably "yes", but I am not a lawyer.



You're deep into "flee right now" territory.






share|improve this answer





























    8














    Get a lawyer. Yesterday. They can help you navigate local laws. They can tell you if anything you did was complicit or illegal. They can help you mitigate that if you are. And they can help you navigate whistleblowing.



    What you need now more than anything is legal help and a well-informed exit strategy.






    share|improve this answer





























      5














      You need to quit, and then you need to blow a whistle. Get on Twitter or snitch really hard to whichever government agency would do something about this. Ethics exist for a reason.



      A speculation over the legality of such actions has reminded me to advise you to get a lawyer to check to see if whistle blowing is legal in your situation.






      share|improve this answer



















      • 6




        If the conduct isn't illegal in OPs country, it could be a violation of the NDA to whistleblow.
        – Adonalsium
        Dec 11 '18 at 16:36






      • 1




        @Adonalsium: If the conduct isn't illegal in OPs country, than OPs country has corrupted law. (the conduct is illegal due to the false claim in the EULA even if the law would normally permit it)
        – Joshua
        Dec 11 '18 at 20:04






      • 5




        @Joshua The US has very weak privacy protections, and a false claim in the EULA would probably be actionable rather than criminal. If I were affected, I'd have to show damages in a lawsuit, and that could be difficult. Not that I'm necessarily disagreeing with you.
        – David Thornley
        Dec 11 '18 at 20:56










      • @DavidThornley: What makes it criminal is entering the contract already intending to break it.
        – Joshua
        Dec 12 '18 at 15:40



















      -1














      Why have websites all had popups about cookies for the last year? What is the last Supreme Court ruling in this area? You don't know? Ok. Take some perspective here and embrace the fact that you are not a lawyer, not a compliance officer, and not even very experienced in this sort of thing. Your concerns are fair but you're "in over your head" legally as to what to do.





      Harvesting contacts by logging into their email is rude in my opinion, but it's also gold standard - Facebook does it, Linkedin does it, Twitter does it, everybody does it. No legal issue there. You could try to make an issue, but you'll have to "make new law*" in that area, and you would be a legal superhero if you pulled it off.



      Deleting the data on request is fair.



      "soft delete", that really is a matter of what happens next. It may be reasonable, for load-balancing reasons, to flip a "soft delete" bit, then have a scrubber process run nightly or weekly that looks for accounts with soft-delete set, and does hard-delete on the data. Delaying that delete a few days is also reasonable where users tend to "rage-quit", delete their account and then regret it and want it restored.



      As far as logging user location, that is a side-effect of logging IP address, and that is the first thing any web log records; again gold standard. And very helpful for troubleshooting and abuse prevention reasons. If you mean "using the app to get their GPS geolocation" the user consented to that, and that consent is enforced by the phone OS because they know developers can't be trusted.





      So when you look at all that in balance, there are obviously a lot of fine distinctions and other gotchas in this entire area of practice. It isn't clear. What's clear is You need to become much more of an expert on these subjects than you presently are.



      So instead of asking "How can I report", you should be asking "How can I distinguish exactly what is legal and proper, and what is not?", or on a case by case basis, "My company is doing X. Is that OK?" For this you should be turning to security and privacy experts.





      * "make new law" is slang for having a legal case with a unique enough situation that an appeals court decides and makes it precedent. You must a) sue someome, b) have the case turn on a a question not yet resolved in legislative law or case law, c) lose so you can d) appeal the case on up into the appeals system (or win and convince the opponent to appeal), then e) win at appeal, and f) convince the appeals court that their decision is unique and solid enough to publish as a precedent. I know someone who did this; he is an aggressive, malicious [censored] and that's kinda what it takes.






      share|improve this answer




























        6 Answers
        6






        active

        oldest

        votes








        6 Answers
        6






        active

        oldest

        votes









        active

        oldest

        votes






        active

        oldest

        votes









        100














        If you don't agree with what the company is doing ethically, then you should probably quit asap.



        If you think they are doing something illegal or in breach of regulations, then you may want to consider reporting them to the relevant authorities.






        share|improve this answer

















        • 13




          Reporting can often be done anonymously, or while keeping you name out of it. Do think about the timing though (you leave, they get checked is "odd timing" to say the least).
          – Martijn
          Dec 11 '18 at 16:03






        • 2




          @Martijn Yes, but if you've already left then what's the issue?
          – Tashus
          Dec 11 '18 at 16:04






        • 14




          Pissed of previous employers/colleages who take revenge in some unforseen way.
          – Martijn
          Dec 11 '18 at 16:05






        • 4




          @Adonalsium IANAL; however, I believe an NDA usually protects against someone disclosing specific proprietary information. I would think someone could 'tip off' a regulatory agency to malpractice, without violating an NDA by disclosing any proprietary material.
          – Time4Tea
          Dec 11 '18 at 16:39






        • 3




          @Time4Tea That's generally supposed to be covered by whistleblower protections. Whether or not it is is... complicated, and you'll probably need to hire a lawyer to get the full answer (they won't be able to answer in the free 30 minute thing that some lawyers have). That said, most NDAs only cover proprietary information, so if you just say "this product has severe privacy violations; it records [blah] and [blah]", that might not fall under your NDA. Depends on the specific wording, of course, but I'm 90% sure it's possible to do. You just might need to be vague.
          – Nic Hartley
          Dec 11 '18 at 17:52


















        100














        If you don't agree with what the company is doing ethically, then you should probably quit asap.



        If you think they are doing something illegal or in breach of regulations, then you may want to consider reporting them to the relevant authorities.






        share|improve this answer

















        • 13




          Reporting can often be done anonymously, or while keeping you name out of it. Do think about the timing though (you leave, they get checked is "odd timing" to say the least).
          – Martijn
          Dec 11 '18 at 16:03






        • 2




          @Martijn Yes, but if you've already left then what's the issue?
          – Tashus
          Dec 11 '18 at 16:04






        • 14




          Pissed of previous employers/colleages who take revenge in some unforseen way.
          – Martijn
          Dec 11 '18 at 16:05






        • 4




          @Adonalsium IANAL; however, I believe an NDA usually protects against someone disclosing specific proprietary information. I would think someone could 'tip off' a regulatory agency to malpractice, without violating an NDA by disclosing any proprietary material.
          – Time4Tea
          Dec 11 '18 at 16:39






        • 3




          @Time4Tea That's generally supposed to be covered by whistleblower protections. Whether or not it is is... complicated, and you'll probably need to hire a lawyer to get the full answer (they won't be able to answer in the free 30 minute thing that some lawyers have). That said, most NDAs only cover proprietary information, so if you just say "this product has severe privacy violations; it records [blah] and [blah]", that might not fall under your NDA. Depends on the specific wording, of course, but I'm 90% sure it's possible to do. You just might need to be vague.
          – Nic Hartley
          Dec 11 '18 at 17:52
















        100












        100








        100






        If you don't agree with what the company is doing ethically, then you should probably quit asap.



        If you think they are doing something illegal or in breach of regulations, then you may want to consider reporting them to the relevant authorities.






        share|improve this answer












        If you don't agree with what the company is doing ethically, then you should probably quit asap.



        If you think they are doing something illegal or in breach of regulations, then you may want to consider reporting them to the relevant authorities.







        share|improve this answer












        share|improve this answer



        share|improve this answer










        answered Dec 11 '18 at 13:35









        Time4Tea

        3,49541130




        3,49541130








        • 13




          Reporting can often be done anonymously, or while keeping you name out of it. Do think about the timing though (you leave, they get checked is "odd timing" to say the least).
          – Martijn
          Dec 11 '18 at 16:03






        • 2




          @Martijn Yes, but if you've already left then what's the issue?
          – Tashus
          Dec 11 '18 at 16:04






        • 14




          Pissed of previous employers/colleages who take revenge in some unforseen way.
          – Martijn
          Dec 11 '18 at 16:05






        • 4




          @Adonalsium IANAL; however, I believe an NDA usually protects against someone disclosing specific proprietary information. I would think someone could 'tip off' a regulatory agency to malpractice, without violating an NDA by disclosing any proprietary material.
          – Time4Tea
          Dec 11 '18 at 16:39






        • 3




          @Time4Tea That's generally supposed to be covered by whistleblower protections. Whether or not it is is... complicated, and you'll probably need to hire a lawyer to get the full answer (they won't be able to answer in the free 30 minute thing that some lawyers have). That said, most NDAs only cover proprietary information, so if you just say "this product has severe privacy violations; it records [blah] and [blah]", that might not fall under your NDA. Depends on the specific wording, of course, but I'm 90% sure it's possible to do. You just might need to be vague.
          – Nic Hartley
          Dec 11 '18 at 17:52
















        • 13




          Reporting can often be done anonymously, or while keeping you name out of it. Do think about the timing though (you leave, they get checked is "odd timing" to say the least).
          – Martijn
          Dec 11 '18 at 16:03






        • 2




          @Martijn Yes, but if you've already left then what's the issue?
          – Tashus
          Dec 11 '18 at 16:04






        • 14




          Pissed of previous employers/colleages who take revenge in some unforseen way.
          – Martijn
          Dec 11 '18 at 16:05






        • 4




          @Adonalsium IANAL; however, I believe an NDA usually protects against someone disclosing specific proprietary information. I would think someone could 'tip off' a regulatory agency to malpractice, without violating an NDA by disclosing any proprietary material.
          – Time4Tea
          Dec 11 '18 at 16:39






        • 3




          @Time4Tea That's generally supposed to be covered by whistleblower protections. Whether or not it is is... complicated, and you'll probably need to hire a lawyer to get the full answer (they won't be able to answer in the free 30 minute thing that some lawyers have). That said, most NDAs only cover proprietary information, so if you just say "this product has severe privacy violations; it records [blah] and [blah]", that might not fall under your NDA. Depends on the specific wording, of course, but I'm 90% sure it's possible to do. You just might need to be vague.
          – Nic Hartley
          Dec 11 '18 at 17:52










        13




        13




        Reporting can often be done anonymously, or while keeping you name out of it. Do think about the timing though (you leave, they get checked is "odd timing" to say the least).
        – Martijn
        Dec 11 '18 at 16:03




        Reporting can often be done anonymously, or while keeping you name out of it. Do think about the timing though (you leave, they get checked is "odd timing" to say the least).
        – Martijn
        Dec 11 '18 at 16:03




        2




        2




        @Martijn Yes, but if you've already left then what's the issue?
        – Tashus
        Dec 11 '18 at 16:04




        @Martijn Yes, but if you've already left then what's the issue?
        – Tashus
        Dec 11 '18 at 16:04




        14




        14




        Pissed of previous employers/colleages who take revenge in some unforseen way.
        – Martijn
        Dec 11 '18 at 16:05




        Pissed of previous employers/colleages who take revenge in some unforseen way.
        – Martijn
        Dec 11 '18 at 16:05




        4




        4




        @Adonalsium IANAL; however, I believe an NDA usually protects against someone disclosing specific proprietary information. I would think someone could 'tip off' a regulatory agency to malpractice, without violating an NDA by disclosing any proprietary material.
        – Time4Tea
        Dec 11 '18 at 16:39




        @Adonalsium IANAL; however, I believe an NDA usually protects against someone disclosing specific proprietary information. I would think someone could 'tip off' a regulatory agency to malpractice, without violating an NDA by disclosing any proprietary material.
        – Time4Tea
        Dec 11 '18 at 16:39




        3




        3




        @Time4Tea That's generally supposed to be covered by whistleblower protections. Whether or not it is is... complicated, and you'll probably need to hire a lawyer to get the full answer (they won't be able to answer in the free 30 minute thing that some lawyers have). That said, most NDAs only cover proprietary information, so if you just say "this product has severe privacy violations; it records [blah] and [blah]", that might not fall under your NDA. Depends on the specific wording, of course, but I'm 90% sure it's possible to do. You just might need to be vague.
        – Nic Hartley
        Dec 11 '18 at 17:52






        @Time4Tea That's generally supposed to be covered by whistleblower protections. Whether or not it is is... complicated, and you'll probably need to hire a lawyer to get the full answer (they won't be able to answer in the free 30 minute thing that some lawyers have). That said, most NDAs only cover proprietary information, so if you just say "this product has severe privacy violations; it records [blah] and [blah]", that might not fall under your NDA. Depends on the specific wording, of course, but I'm 90% sure it's possible to do. You just might need to be vague.
        – Nic Hartley
        Dec 11 '18 at 17:52















        77














        What I do in such situations. (had a situation where my employer did not want to buy some licenses of software we used commercially)



        Step one: Make sure I get my facts straight and have evidence of my claim.



        Step two: Make management aware of the Problem. Leave a paper-trail of doing so. Assume no malice and make no accusations. Just describe the Problem and offer a solution.



        Step tree: After some time, ask if action has been taken. If not ask for a timeline. Again, leave a paper-trail.



        If it gets clear to you no action will be taken, think about



        A. Do you want to keep working there?



        B. Do you want to / have to report this to the police etc. I´d ask a lawyer about this.



        The thinking is (in my jurisdiction, Germany) you have the obligation to protect your employer from harm. You also have the obligation not to break the law. So the first step if your employer is doing something (unintentionally?) unlawful, would be to make them aware of that. If they decide to take no action, and you make their misconduct public, harm is not on you, but on them, since they ignored you.



        If you want to keep working there or not is up to you. Either way, be prepared to be fired immediately, especially if they do violate the rules intentionally. An never knowingly contribute to any unlawful conduct yourself.






        share|improve this answer























        • About list of things to ask yourself, you should add "C. Do I want the risk of being considered guilty" because OP can no longer claim being ignorant, and if this privacy breach is illegal, he will be the one dev that was knowingly and willingly developing it. One more thing to ask yourself, and your lawyer I guess.
          – Mołot
          Dec 11 '18 at 15:26








        • 3




          @Mołot: It will be hard to prove that. First, OP is probably not a legal professional and normally he has to trust his employer to get those things sorted out by professionals. Secondly, you´d have to prove that he was actively contributing to the malicious element. Third, as long as the Data does not get used for fraud, it will be hard to proof any harm done by OP. I think, at least in Germany, my approach is pretty safe. Of course IANAL so when in doubt, please get appropriate legal counsel yourself!
          – Daniel
          Dec 11 '18 at 15:36












        • process of proving one way or another can be long, tiring and problematic for career, even if he finally is found innocent... That's why I'd add it as third point to things he should think and talk to his lawyer about.
          – Mołot
          Dec 11 '18 at 15:39






        • 3




          There are sensible reasons to use soft-delete as the default handling for data, and times when a carefully-written more thorough deletion is required, as here. +1 for step 2 here, making sure that it's not a genuine oversight.
          – chrylis
          Dec 11 '18 at 18:55






        • 1




          @chrylis: Step two is also the most effective way to remedy the situation while allowing everyone to safe face, even if it was intentional.
          – Daniel
          Dec 12 '18 at 8:40
















        77














        What I do in such situations. (had a situation where my employer did not want to buy some licenses of software we used commercially)



        Step one: Make sure I get my facts straight and have evidence of my claim.



        Step two: Make management aware of the Problem. Leave a paper-trail of doing so. Assume no malice and make no accusations. Just describe the Problem and offer a solution.



        Step tree: After some time, ask if action has been taken. If not ask for a timeline. Again, leave a paper-trail.



        If it gets clear to you no action will be taken, think about



        A. Do you want to keep working there?



        B. Do you want to / have to report this to the police etc. I´d ask a lawyer about this.



        The thinking is (in my jurisdiction, Germany) you have the obligation to protect your employer from harm. You also have the obligation not to break the law. So the first step if your employer is doing something (unintentionally?) unlawful, would be to make them aware of that. If they decide to take no action, and you make their misconduct public, harm is not on you, but on them, since they ignored you.



        If you want to keep working there or not is up to you. Either way, be prepared to be fired immediately, especially if they do violate the rules intentionally. An never knowingly contribute to any unlawful conduct yourself.






        share|improve this answer























        • About list of things to ask yourself, you should add "C. Do I want the risk of being considered guilty" because OP can no longer claim being ignorant, and if this privacy breach is illegal, he will be the one dev that was knowingly and willingly developing it. One more thing to ask yourself, and your lawyer I guess.
          – Mołot
          Dec 11 '18 at 15:26








        • 3




          @Mołot: It will be hard to prove that. First, OP is probably not a legal professional and normally he has to trust his employer to get those things sorted out by professionals. Secondly, you´d have to prove that he was actively contributing to the malicious element. Third, as long as the Data does not get used for fraud, it will be hard to proof any harm done by OP. I think, at least in Germany, my approach is pretty safe. Of course IANAL so when in doubt, please get appropriate legal counsel yourself!
          – Daniel
          Dec 11 '18 at 15:36












        • process of proving one way or another can be long, tiring and problematic for career, even if he finally is found innocent... That's why I'd add it as third point to things he should think and talk to his lawyer about.
          – Mołot
          Dec 11 '18 at 15:39






        • 3




          There are sensible reasons to use soft-delete as the default handling for data, and times when a carefully-written more thorough deletion is required, as here. +1 for step 2 here, making sure that it's not a genuine oversight.
          – chrylis
          Dec 11 '18 at 18:55






        • 1




          @chrylis: Step two is also the most effective way to remedy the situation while allowing everyone to safe face, even if it was intentional.
          – Daniel
          Dec 12 '18 at 8:40














        77












        77








        77






        What I do in such situations. (had a situation where my employer did not want to buy some licenses of software we used commercially)



        Step one: Make sure I get my facts straight and have evidence of my claim.



        Step two: Make management aware of the Problem. Leave a paper-trail of doing so. Assume no malice and make no accusations. Just describe the Problem and offer a solution.



        Step tree: After some time, ask if action has been taken. If not ask for a timeline. Again, leave a paper-trail.



        If it gets clear to you no action will be taken, think about



        A. Do you want to keep working there?



        B. Do you want to / have to report this to the police etc. I´d ask a lawyer about this.



        The thinking is (in my jurisdiction, Germany) you have the obligation to protect your employer from harm. You also have the obligation not to break the law. So the first step if your employer is doing something (unintentionally?) unlawful, would be to make them aware of that. If they decide to take no action, and you make their misconduct public, harm is not on you, but on them, since they ignored you.



        If you want to keep working there or not is up to you. Either way, be prepared to be fired immediately, especially if they do violate the rules intentionally. An never knowingly contribute to any unlawful conduct yourself.






        share|improve this answer














        What I do in such situations. (had a situation where my employer did not want to buy some licenses of software we used commercially)



        Step one: Make sure I get my facts straight and have evidence of my claim.



        Step two: Make management aware of the Problem. Leave a paper-trail of doing so. Assume no malice and make no accusations. Just describe the Problem and offer a solution.



        Step tree: After some time, ask if action has been taken. If not ask for a timeline. Again, leave a paper-trail.



        If it gets clear to you no action will be taken, think about



        A. Do you want to keep working there?



        B. Do you want to / have to report this to the police etc. I´d ask a lawyer about this.



        The thinking is (in my jurisdiction, Germany) you have the obligation to protect your employer from harm. You also have the obligation not to break the law. So the first step if your employer is doing something (unintentionally?) unlawful, would be to make them aware of that. If they decide to take no action, and you make their misconduct public, harm is not on you, but on them, since they ignored you.



        If you want to keep working there or not is up to you. Either way, be prepared to be fired immediately, especially if they do violate the rules intentionally. An never knowingly contribute to any unlawful conduct yourself.







        share|improve this answer














        share|improve this answer



        share|improve this answer








        edited Dec 11 '18 at 15:38

























        answered Dec 11 '18 at 14:57









        Daniel

        15.6k93560




        15.6k93560












        • About list of things to ask yourself, you should add "C. Do I want the risk of being considered guilty" because OP can no longer claim being ignorant, and if this privacy breach is illegal, he will be the one dev that was knowingly and willingly developing it. One more thing to ask yourself, and your lawyer I guess.
          – Mołot
          Dec 11 '18 at 15:26








        • 3




          @Mołot: It will be hard to prove that. First, OP is probably not a legal professional and normally he has to trust his employer to get those things sorted out by professionals. Secondly, you´d have to prove that he was actively contributing to the malicious element. Third, as long as the Data does not get used for fraud, it will be hard to proof any harm done by OP. I think, at least in Germany, my approach is pretty safe. Of course IANAL so when in doubt, please get appropriate legal counsel yourself!
          – Daniel
          Dec 11 '18 at 15:36












        • process of proving one way or another can be long, tiring and problematic for career, even if he finally is found innocent... That's why I'd add it as third point to things he should think and talk to his lawyer about.
          – Mołot
          Dec 11 '18 at 15:39






        • 3




          There are sensible reasons to use soft-delete as the default handling for data, and times when a carefully-written more thorough deletion is required, as here. +1 for step 2 here, making sure that it's not a genuine oversight.
          – chrylis
          Dec 11 '18 at 18:55






        • 1




          @chrylis: Step two is also the most effective way to remedy the situation while allowing everyone to safe face, even if it was intentional.
          – Daniel
          Dec 12 '18 at 8:40


















        • About list of things to ask yourself, you should add "C. Do I want the risk of being considered guilty" because OP can no longer claim being ignorant, and if this privacy breach is illegal, he will be the one dev that was knowingly and willingly developing it. One more thing to ask yourself, and your lawyer I guess.
          – Mołot
          Dec 11 '18 at 15:26








        • 3




          @Mołot: It will be hard to prove that. First, OP is probably not a legal professional and normally he has to trust his employer to get those things sorted out by professionals. Secondly, you´d have to prove that he was actively contributing to the malicious element. Third, as long as the Data does not get used for fraud, it will be hard to proof any harm done by OP. I think, at least in Germany, my approach is pretty safe. Of course IANAL so when in doubt, please get appropriate legal counsel yourself!
          – Daniel
          Dec 11 '18 at 15:36












        • process of proving one way or another can be long, tiring and problematic for career, even if he finally is found innocent... That's why I'd add it as third point to things he should think and talk to his lawyer about.
          – Mołot
          Dec 11 '18 at 15:39






        • 3




          There are sensible reasons to use soft-delete as the default handling for data, and times when a carefully-written more thorough deletion is required, as here. +1 for step 2 here, making sure that it's not a genuine oversight.
          – chrylis
          Dec 11 '18 at 18:55






        • 1




          @chrylis: Step two is also the most effective way to remedy the situation while allowing everyone to safe face, even if it was intentional.
          – Daniel
          Dec 12 '18 at 8:40
















        About list of things to ask yourself, you should add "C. Do I want the risk of being considered guilty" because OP can no longer claim being ignorant, and if this privacy breach is illegal, he will be the one dev that was knowingly and willingly developing it. One more thing to ask yourself, and your lawyer I guess.
        – Mołot
        Dec 11 '18 at 15:26






        About list of things to ask yourself, you should add "C. Do I want the risk of being considered guilty" because OP can no longer claim being ignorant, and if this privacy breach is illegal, he will be the one dev that was knowingly and willingly developing it. One more thing to ask yourself, and your lawyer I guess.
        – Mołot
        Dec 11 '18 at 15:26






        3




        3




        @Mołot: It will be hard to prove that. First, OP is probably not a legal professional and normally he has to trust his employer to get those things sorted out by professionals. Secondly, you´d have to prove that he was actively contributing to the malicious element. Third, as long as the Data does not get used for fraud, it will be hard to proof any harm done by OP. I think, at least in Germany, my approach is pretty safe. Of course IANAL so when in doubt, please get appropriate legal counsel yourself!
        – Daniel
        Dec 11 '18 at 15:36






        @Mołot: It will be hard to prove that. First, OP is probably not a legal professional and normally he has to trust his employer to get those things sorted out by professionals. Secondly, you´d have to prove that he was actively contributing to the malicious element. Third, as long as the Data does not get used for fraud, it will be hard to proof any harm done by OP. I think, at least in Germany, my approach is pretty safe. Of course IANAL so when in doubt, please get appropriate legal counsel yourself!
        – Daniel
        Dec 11 '18 at 15:36














        process of proving one way or another can be long, tiring and problematic for career, even if he finally is found innocent... That's why I'd add it as third point to things he should think and talk to his lawyer about.
        – Mołot
        Dec 11 '18 at 15:39




        process of proving one way or another can be long, tiring and problematic for career, even if he finally is found innocent... That's why I'd add it as third point to things he should think and talk to his lawyer about.
        – Mołot
        Dec 11 '18 at 15:39




        3




        3




        There are sensible reasons to use soft-delete as the default handling for data, and times when a carefully-written more thorough deletion is required, as here. +1 for step 2 here, making sure that it's not a genuine oversight.
        – chrylis
        Dec 11 '18 at 18:55




        There are sensible reasons to use soft-delete as the default handling for data, and times when a carefully-written more thorough deletion is required, as here. +1 for step 2 here, making sure that it's not a genuine oversight.
        – chrylis
        Dec 11 '18 at 18:55




        1




        1




        @chrylis: Step two is also the most effective way to remedy the situation while allowing everyone to safe face, even if it was intentional.
        – Daniel
        Dec 12 '18 at 8:40




        @chrylis: Step two is also the most effective way to remedy the situation while allowing everyone to safe face, even if it was intentional.
        – Daniel
        Dec 12 '18 at 8:40











        17















        Do I have to concern about being accused by the government?




        If you have to ask the question the answer is probably "yes", but I am not a lawyer.



        You're deep into "flee right now" territory.






        share|improve this answer


























          17















          Do I have to concern about being accused by the government?




          If you have to ask the question the answer is probably "yes", but I am not a lawyer.



          You're deep into "flee right now" territory.






          share|improve this answer
























            17












            17








            17







            Do I have to concern about being accused by the government?




            If you have to ask the question the answer is probably "yes", but I am not a lawyer.



            You're deep into "flee right now" territory.






            share|improve this answer













            Do I have to concern about being accused by the government?




            If you have to ask the question the answer is probably "yes", but I am not a lawyer.



            You're deep into "flee right now" territory.







            share|improve this answer












            share|improve this answer



            share|improve this answer










            answered Dec 11 '18 at 13:31









            Dark Matter

            3,5031616




            3,5031616























                8














                Get a lawyer. Yesterday. They can help you navigate local laws. They can tell you if anything you did was complicit or illegal. They can help you mitigate that if you are. And they can help you navigate whistleblowing.



                What you need now more than anything is legal help and a well-informed exit strategy.






                share|improve this answer


























                  8














                  Get a lawyer. Yesterday. They can help you navigate local laws. They can tell you if anything you did was complicit or illegal. They can help you mitigate that if you are. And they can help you navigate whistleblowing.



                  What you need now more than anything is legal help and a well-informed exit strategy.






                  share|improve this answer
























                    8












                    8








                    8






                    Get a lawyer. Yesterday. They can help you navigate local laws. They can tell you if anything you did was complicit or illegal. They can help you mitigate that if you are. And they can help you navigate whistleblowing.



                    What you need now more than anything is legal help and a well-informed exit strategy.






                    share|improve this answer












                    Get a lawyer. Yesterday. They can help you navigate local laws. They can tell you if anything you did was complicit or illegal. They can help you mitigate that if you are. And they can help you navigate whistleblowing.



                    What you need now more than anything is legal help and a well-informed exit strategy.







                    share|improve this answer












                    share|improve this answer



                    share|improve this answer










                    answered Dec 11 '18 at 18:56









                    bruglesco

                    1,583426




                    1,583426























                        5














                        You need to quit, and then you need to blow a whistle. Get on Twitter or snitch really hard to whichever government agency would do something about this. Ethics exist for a reason.



                        A speculation over the legality of such actions has reminded me to advise you to get a lawyer to check to see if whistle blowing is legal in your situation.






                        share|improve this answer



















                        • 6




                          If the conduct isn't illegal in OPs country, it could be a violation of the NDA to whistleblow.
                          – Adonalsium
                          Dec 11 '18 at 16:36






                        • 1




                          @Adonalsium: If the conduct isn't illegal in OPs country, than OPs country has corrupted law. (the conduct is illegal due to the false claim in the EULA even if the law would normally permit it)
                          – Joshua
                          Dec 11 '18 at 20:04






                        • 5




                          @Joshua The US has very weak privacy protections, and a false claim in the EULA would probably be actionable rather than criminal. If I were affected, I'd have to show damages in a lawsuit, and that could be difficult. Not that I'm necessarily disagreeing with you.
                          – David Thornley
                          Dec 11 '18 at 20:56










                        • @DavidThornley: What makes it criminal is entering the contract already intending to break it.
                          – Joshua
                          Dec 12 '18 at 15:40
















                        5














                        You need to quit, and then you need to blow a whistle. Get on Twitter or snitch really hard to whichever government agency would do something about this. Ethics exist for a reason.



                        A speculation over the legality of such actions has reminded me to advise you to get a lawyer to check to see if whistle blowing is legal in your situation.






                        share|improve this answer



















                        • 6




                          If the conduct isn't illegal in OPs country, it could be a violation of the NDA to whistleblow.
                          – Adonalsium
                          Dec 11 '18 at 16:36






                        • 1




                          @Adonalsium: If the conduct isn't illegal in OPs country, than OPs country has corrupted law. (the conduct is illegal due to the false claim in the EULA even if the law would normally permit it)
                          – Joshua
                          Dec 11 '18 at 20:04






                        • 5




                          @Joshua The US has very weak privacy protections, and a false claim in the EULA would probably be actionable rather than criminal. If I were affected, I'd have to show damages in a lawsuit, and that could be difficult. Not that I'm necessarily disagreeing with you.
                          – David Thornley
                          Dec 11 '18 at 20:56










                        • @DavidThornley: What makes it criminal is entering the contract already intending to break it.
                          – Joshua
                          Dec 12 '18 at 15:40














                        5












                        5








                        5






                        You need to quit, and then you need to blow a whistle. Get on Twitter or snitch really hard to whichever government agency would do something about this. Ethics exist for a reason.



                        A speculation over the legality of such actions has reminded me to advise you to get a lawyer to check to see if whistle blowing is legal in your situation.






                        share|improve this answer














                        You need to quit, and then you need to blow a whistle. Get on Twitter or snitch really hard to whichever government agency would do something about this. Ethics exist for a reason.



                        A speculation over the legality of such actions has reminded me to advise you to get a lawyer to check to see if whistle blowing is legal in your situation.







                        share|improve this answer














                        share|improve this answer



                        share|improve this answer








                        edited Dec 12 '18 at 15:42

























                        answered Dec 11 '18 at 15:20









                        Steve

                        2,097416




                        2,097416








                        • 6




                          If the conduct isn't illegal in OPs country, it could be a violation of the NDA to whistleblow.
                          – Adonalsium
                          Dec 11 '18 at 16:36






                        • 1




                          @Adonalsium: If the conduct isn't illegal in OPs country, than OPs country has corrupted law. (the conduct is illegal due to the false claim in the EULA even if the law would normally permit it)
                          – Joshua
                          Dec 11 '18 at 20:04






                        • 5




                          @Joshua The US has very weak privacy protections, and a false claim in the EULA would probably be actionable rather than criminal. If I were affected, I'd have to show damages in a lawsuit, and that could be difficult. Not that I'm necessarily disagreeing with you.
                          – David Thornley
                          Dec 11 '18 at 20:56










                        • @DavidThornley: What makes it criminal is entering the contract already intending to break it.
                          – Joshua
                          Dec 12 '18 at 15:40














                        • 6




                          If the conduct isn't illegal in OPs country, it could be a violation of the NDA to whistleblow.
                          – Adonalsium
                          Dec 11 '18 at 16:36






                        • 1




                          @Adonalsium: If the conduct isn't illegal in OPs country, than OPs country has corrupted law. (the conduct is illegal due to the false claim in the EULA even if the law would normally permit it)
                          – Joshua
                          Dec 11 '18 at 20:04






                        • 5




                          @Joshua The US has very weak privacy protections, and a false claim in the EULA would probably be actionable rather than criminal. If I were affected, I'd have to show damages in a lawsuit, and that could be difficult. Not that I'm necessarily disagreeing with you.
                          – David Thornley
                          Dec 11 '18 at 20:56










                        • @DavidThornley: What makes it criminal is entering the contract already intending to break it.
                          – Joshua
                          Dec 12 '18 at 15:40








                        6




                        6




                        If the conduct isn't illegal in OPs country, it could be a violation of the NDA to whistleblow.
                        – Adonalsium
                        Dec 11 '18 at 16:36




                        If the conduct isn't illegal in OPs country, it could be a violation of the NDA to whistleblow.
                        – Adonalsium
                        Dec 11 '18 at 16:36




                        1




                        1




                        @Adonalsium: If the conduct isn't illegal in OPs country, than OPs country has corrupted law. (the conduct is illegal due to the false claim in the EULA even if the law would normally permit it)
                        – Joshua
                        Dec 11 '18 at 20:04




                        @Adonalsium: If the conduct isn't illegal in OPs country, than OPs country has corrupted law. (the conduct is illegal due to the false claim in the EULA even if the law would normally permit it)
                        – Joshua
                        Dec 11 '18 at 20:04




                        5




                        5




                        @Joshua The US has very weak privacy protections, and a false claim in the EULA would probably be actionable rather than criminal. If I were affected, I'd have to show damages in a lawsuit, and that could be difficult. Not that I'm necessarily disagreeing with you.
                        – David Thornley
                        Dec 11 '18 at 20:56




                        @Joshua The US has very weak privacy protections, and a false claim in the EULA would probably be actionable rather than criminal. If I were affected, I'd have to show damages in a lawsuit, and that could be difficult. Not that I'm necessarily disagreeing with you.
                        – David Thornley
                        Dec 11 '18 at 20:56












                        @DavidThornley: What makes it criminal is entering the contract already intending to break it.
                        – Joshua
                        Dec 12 '18 at 15:40




                        @DavidThornley: What makes it criminal is entering the contract already intending to break it.
                        – Joshua
                        Dec 12 '18 at 15:40











                        -1














                        Why have websites all had popups about cookies for the last year? What is the last Supreme Court ruling in this area? You don't know? Ok. Take some perspective here and embrace the fact that you are not a lawyer, not a compliance officer, and not even very experienced in this sort of thing. Your concerns are fair but you're "in over your head" legally as to what to do.





                        Harvesting contacts by logging into their email is rude in my opinion, but it's also gold standard - Facebook does it, Linkedin does it, Twitter does it, everybody does it. No legal issue there. You could try to make an issue, but you'll have to "make new law*" in that area, and you would be a legal superhero if you pulled it off.



                        Deleting the data on request is fair.



                        "soft delete", that really is a matter of what happens next. It may be reasonable, for load-balancing reasons, to flip a "soft delete" bit, then have a scrubber process run nightly or weekly that looks for accounts with soft-delete set, and does hard-delete on the data. Delaying that delete a few days is also reasonable where users tend to "rage-quit", delete their account and then regret it and want it restored.



                        As far as logging user location, that is a side-effect of logging IP address, and that is the first thing any web log records; again gold standard. And very helpful for troubleshooting and abuse prevention reasons. If you mean "using the app to get their GPS geolocation" the user consented to that, and that consent is enforced by the phone OS because they know developers can't be trusted.





                        So when you look at all that in balance, there are obviously a lot of fine distinctions and other gotchas in this entire area of practice. It isn't clear. What's clear is You need to become much more of an expert on these subjects than you presently are.



                        So instead of asking "How can I report", you should be asking "How can I distinguish exactly what is legal and proper, and what is not?", or on a case by case basis, "My company is doing X. Is that OK?" For this you should be turning to security and privacy experts.





                        * "make new law" is slang for having a legal case with a unique enough situation that an appeals court decides and makes it precedent. You must a) sue someome, b) have the case turn on a a question not yet resolved in legislative law or case law, c) lose so you can d) appeal the case on up into the appeals system (or win and convince the opponent to appeal), then e) win at appeal, and f) convince the appeals court that their decision is unique and solid enough to publish as a precedent. I know someone who did this; he is an aggressive, malicious [censored] and that's kinda what it takes.






                        share|improve this answer


























                          -1














                          Why have websites all had popups about cookies for the last year? What is the last Supreme Court ruling in this area? You don't know? Ok. Take some perspective here and embrace the fact that you are not a lawyer, not a compliance officer, and not even very experienced in this sort of thing. Your concerns are fair but you're "in over your head" legally as to what to do.





                          Harvesting contacts by logging into their email is rude in my opinion, but it's also gold standard - Facebook does it, Linkedin does it, Twitter does it, everybody does it. No legal issue there. You could try to make an issue, but you'll have to "make new law*" in that area, and you would be a legal superhero if you pulled it off.



                          Deleting the data on request is fair.



                          "soft delete", that really is a matter of what happens next. It may be reasonable, for load-balancing reasons, to flip a "soft delete" bit, then have a scrubber process run nightly or weekly that looks for accounts with soft-delete set, and does hard-delete on the data. Delaying that delete a few days is also reasonable where users tend to "rage-quit", delete their account and then regret it and want it restored.



                          As far as logging user location, that is a side-effect of logging IP address, and that is the first thing any web log records; again gold standard. And very helpful for troubleshooting and abuse prevention reasons. If you mean "using the app to get their GPS geolocation" the user consented to that, and that consent is enforced by the phone OS because they know developers can't be trusted.





                          So when you look at all that in balance, there are obviously a lot of fine distinctions and other gotchas in this entire area of practice. It isn't clear. What's clear is You need to become much more of an expert on these subjects than you presently are.



                          So instead of asking "How can I report", you should be asking "How can I distinguish exactly what is legal and proper, and what is not?", or on a case by case basis, "My company is doing X. Is that OK?" For this you should be turning to security and privacy experts.





                          * "make new law" is slang for having a legal case with a unique enough situation that an appeals court decides and makes it precedent. You must a) sue someome, b) have the case turn on a a question not yet resolved in legislative law or case law, c) lose so you can d) appeal the case on up into the appeals system (or win and convince the opponent to appeal), then e) win at appeal, and f) convince the appeals court that their decision is unique and solid enough to publish as a precedent. I know someone who did this; he is an aggressive, malicious [censored] and that's kinda what it takes.






                          share|improve this answer
























                            -1












                            -1








                            -1






                            Why have websites all had popups about cookies for the last year? What is the last Supreme Court ruling in this area? You don't know? Ok. Take some perspective here and embrace the fact that you are not a lawyer, not a compliance officer, and not even very experienced in this sort of thing. Your concerns are fair but you're "in over your head" legally as to what to do.





                            Harvesting contacts by logging into their email is rude in my opinion, but it's also gold standard - Facebook does it, Linkedin does it, Twitter does it, everybody does it. No legal issue there. You could try to make an issue, but you'll have to "make new law*" in that area, and you would be a legal superhero if you pulled it off.



                            Deleting the data on request is fair.



                            "soft delete", that really is a matter of what happens next. It may be reasonable, for load-balancing reasons, to flip a "soft delete" bit, then have a scrubber process run nightly or weekly that looks for accounts with soft-delete set, and does hard-delete on the data. Delaying that delete a few days is also reasonable where users tend to "rage-quit", delete their account and then regret it and want it restored.



                            As far as logging user location, that is a side-effect of logging IP address, and that is the first thing any web log records; again gold standard. And very helpful for troubleshooting and abuse prevention reasons. If you mean "using the app to get their GPS geolocation" the user consented to that, and that consent is enforced by the phone OS because they know developers can't be trusted.





                            So when you look at all that in balance, there are obviously a lot of fine distinctions and other gotchas in this entire area of practice. It isn't clear. What's clear is You need to become much more of an expert on these subjects than you presently are.



                            So instead of asking "How can I report", you should be asking "How can I distinguish exactly what is legal and proper, and what is not?", or on a case by case basis, "My company is doing X. Is that OK?" For this you should be turning to security and privacy experts.





                            * "make new law" is slang for having a legal case with a unique enough situation that an appeals court decides and makes it precedent. You must a) sue someome, b) have the case turn on a a question not yet resolved in legislative law or case law, c) lose so you can d) appeal the case on up into the appeals system (or win and convince the opponent to appeal), then e) win at appeal, and f) convince the appeals court that their decision is unique and solid enough to publish as a precedent. I know someone who did this; he is an aggressive, malicious [censored] and that's kinda what it takes.






                            share|improve this answer












                            Why have websites all had popups about cookies for the last year? What is the last Supreme Court ruling in this area? You don't know? Ok. Take some perspective here and embrace the fact that you are not a lawyer, not a compliance officer, and not even very experienced in this sort of thing. Your concerns are fair but you're "in over your head" legally as to what to do.





                            Harvesting contacts by logging into their email is rude in my opinion, but it's also gold standard - Facebook does it, Linkedin does it, Twitter does it, everybody does it. No legal issue there. You could try to make an issue, but you'll have to "make new law*" in that area, and you would be a legal superhero if you pulled it off.



                            Deleting the data on request is fair.



                            "soft delete", that really is a matter of what happens next. It may be reasonable, for load-balancing reasons, to flip a "soft delete" bit, then have a scrubber process run nightly or weekly that looks for accounts with soft-delete set, and does hard-delete on the data. Delaying that delete a few days is also reasonable where users tend to "rage-quit", delete their account and then regret it and want it restored.



                            As far as logging user location, that is a side-effect of logging IP address, and that is the first thing any web log records; again gold standard. And very helpful for troubleshooting and abuse prevention reasons. If you mean "using the app to get their GPS geolocation" the user consented to that, and that consent is enforced by the phone OS because they know developers can't be trusted.





                            So when you look at all that in balance, there are obviously a lot of fine distinctions and other gotchas in this entire area of practice. It isn't clear. What's clear is You need to become much more of an expert on these subjects than you presently are.



                            So instead of asking "How can I report", you should be asking "How can I distinguish exactly what is legal and proper, and what is not?", or on a case by case basis, "My company is doing X. Is that OK?" For this you should be turning to security and privacy experts.





                            * "make new law" is slang for having a legal case with a unique enough situation that an appeals court decides and makes it precedent. You must a) sue someome, b) have the case turn on a a question not yet resolved in legislative law or case law, c) lose so you can d) appeal the case on up into the appeals system (or win and convince the opponent to appeal), then e) win at appeal, and f) convince the appeals court that their decision is unique and solid enough to publish as a precedent. I know someone who did this; he is an aggressive, malicious [censored] and that's kinda what it takes.







                            share|improve this answer












                            share|improve this answer



                            share|improve this answer










                            answered Dec 12 '18 at 2:10









                            Harper

                            3,1011514




                            3,1011514















                                Popular posts from this blog

                                Plaza Victoria

                                In PowerPoint, is there a keyboard shortcut for bulleted / numbered list?

                                How to put 3 figures in Latex with 2 figures side by side and 1 below these side by side images but in...