Close Menu
TechCentralTechCentral

    Subscribe to the newsletter

    Get the best South African technology news and analysis delivered to your e-mail inbox every morning.

    Facebook X (Twitter) YouTube LinkedIn
    WhatsApp Facebook X (Twitter) LinkedIn YouTube
    TechCentralTechCentral
    • News
      Starlink wait set to drag on as Icasa flags legal hurdle

      Starlink wait set to drag on as Icasa flags legal hurdle

      13 May 2026
      Malatsi opens door to 'some' partial privatisations of SOEs - communications minister Solly Malatsi

      Malatsi opens door to ‘some’ partial privatisations of SOEs

      13 May 2026
      Sam Altman denies betraying Elon Musk. Shelby Tauber/Reuters

      Sam Altman denies betraying Elon Musk

      13 May 2026
      Naked Insurance launches native app in ChatGPT - Alex Thomson

      Naked Insurance launches native app in ChatGPT

      13 May 2026
      Canal+ firms up 3 June JSE listing

      Canal+ firms up 3 June JSE listing

      13 May 2026
    • World
      Pop star sues Samsung for $15-million - Dua Lipa

      Pop star sues Samsung for $15-million

      11 May 2026
      OpenAI's new audio APIs aim for conversational voice agents

      OpenAI’s new audio APIs aim for conversational voice agents

      8 May 2026
      'It was my idea': Musk claims paternity of OpenAI - Elon Musk

      ‘It was my idea’: Musk claims paternity of OpenAI

      29 April 2026
      Pivotal week for US tech stocks

      Pivotal week for US tech stocks

      28 April 2026
      Sam Altman denies betraying Elon Musk. Shelby Tauber/Reuters

      Worries over OpenAI’s growth as Anthropic gains ground

      28 April 2026
    • In-depth
      Alfa's electric rebel - Alfa Romeo Junior Elettrica Veloce

      Alfa’s electric rebel

      29 April 2026
      Africa switches on as Europe dims the lights

      Africa switches on as Europe dims the lights

      9 April 2026
      The biggest untapped EV market on Earth is hiding in plain sight

      The biggest untapped EV market on Earth is hiding in plain sight

      1 April 2026
      Datatec is firing on all cylinders - Jens Montanana

      The R16-billion tech giant hiding in plain sight

      26 March 2026
      The last generation of coders

      The last generation of coders

      18 February 2026
    • TCS
      TCS+ | The Up&Up Group on the hidden cost of AI - Jason Harrison

      TCS+ | The Up&Up Group on the hidden cost of AI

      13 May 2026
      Michael Rossouw

      TCS+ | The retirement decision most South Africans get wrong

      6 May 2026
      TCS | The Cape Town start-up listening for TB with AI - Braden van Breda

      TCS | The Cape Town start-up listening for TB with AI

      4 May 2026

      TCS+ | ‘The ISP for ISPs’: Vox’s shift to wholesale aggregator

      20 April 2026
      TCS | Werner Lindemann on how AI is rewriting the infosec rulebook

      TCS | Werner Lindemann on how AI is rewriting the infosec rulebook

      15 April 2026
    • Opinion
      Free calls, dead voice and Shameel Joosub's Spanish ghost - Duncan McLeod

      Free calls, dead voice and Shameel Joosub’s Spanish ghost

      22 April 2026
      The conflict of interest at the heart of PayShap's slow adoption - Cheslyn Jacobs

      The conflict of interest at the heart of PayShap’s slow adoption

      26 March 2026
      South Africa's energy future hinges on getting wheeling right - Aishah Gire

      South Africa’s energy future hinges on getting wheeling right

      10 March 2026
      Free calls, dead voice and Shameel Joosub's Spanish ghost - Duncan McLeod

      Apple just dropped a bomb on the Windows world

      5 March 2026
      R230-million in the bag for Endeavor's third Harvest Fund - Alison Collier

      VC’s centre of gravity is shifting – and South Africa is in the frame

      3 March 2026
    • Company Hubs
      • 1Stream
      • Africa Data Centres
      • AfriGIS
      • Altron Digital Business
      • Altron Document Solutions
      • Altron Group
      • Arctic Wolf
      • Ascent Technology
      • AvertITD
      • BBD
      • Braintree
      • CallMiner
      • CambriLearn
      • Contactable
      • CYBER1 Solutions
      • Digicloud Africa
      • Digimune
      • Domains.co.za
      • ESET
      • Euphoria Telecom
      • HOSTAFRICA
      • Incredible Business
      • iONLINE
      • IQbusiness
      • Iris Network Systems
      • Kaspersky
      • LSD Open
      • Mitel
      • NEC XON
      • Netstar
      • Network Platforms
      • Next DLP
      • Ovations
      • Paracon
      • Paratus
      • Q-KON
      • SevenC
      • SkyWire
      • Solid8 Technologies
      • Telit Cinterion
      • Telviva
      • Tenable
      • Vertiv
      • Videri Digital
      • Vodacom Business
      • Wipro
      • Workday
      • XLink
    • Sections
      • AI and machine learning
      • Banking
      • Broadcasting and Media
      • Cloud services
      • Contact centres and CX
      • Cryptocurrencies
      • Education and skills
      • Electronics and hardware
      • Energy and sustainability
      • Enterprise software
      • Financial services
      • HealthTech
      • Information security
      • Internet and connectivity
      • Internet of Things
      • Investment
      • IT services
      • Lifestyle
      • Motoring
      • Policy and regulation
      • Public sector
      • Retail and e-commerce
      • Satellite communications
      • Science
      • SMEs and start-ups
      • Social media
      • Talent and leadership
      • Telecoms
    • Events
    • Advertise
    TechCentralTechCentral
    Home » In-depth » How tech companies are getting privacy all wrong

    How tech companies are getting privacy all wrong

    By Leonid Bershidsky25 April 2018
    Twitter LinkedIn Facebook WhatsApp Email Telegram Copy Link
    News Alerts
    WhatsApp

    Internet users throughout the European Union — and, in some cases, in the rest of the world as well — are starting to get gently pushed toward accepting various companies’ new service and privacy terms that comply with the EU’s General Data Protection Regulation, which is going into effect on 25 May. Trying to deal with it has convinced me that the tech industry is still determined to get privacy wrong, and the GDPR as applied by them doesn’t prevent it.

    The GDPR-related reminders are coming from stores, electronics manufacturers, social networks, even non-profits. One needs to be intensely privacy-minded to go through the legal documents updated by Facebook, Twitter, Fitbit, Sonos, an e-commerce site you may have visited a few years ago or a local theatre company and not get confused about which disclosures you saw in which statement. Though most firms have made an attempt to write the new terms in plain language, as the GDPR requires, these are still lengthy documents crafted for legal compliance first and understanding second.

    The standard approach is to hit the user with thousands of words explaining what data is collected and how it is used and, within the text, provide links to settings pages where one can opt in and out of the data harvesting and processing. Here’s how Fitbit handles it:

    We give you account settings and tools to control our data use. For example, through your privacy settings, you can limit how your information is visible to other users of the services; using your notification settings, you can limit the notifications you receive from us; and under your application settings, you can revoke the access of third-party applications that you previously connected to your Fitbit account.

    Now, which link will you click? Perhaps all four? Will you do it and then go back to the text (there’s still plenty of it), or will you get lost in the first set of preferences, curse and look for the “I agree” button? This is what I’d call obfuscation through confusion.

    Facebook, by the way, has a big blue button for consent, but a mere hyperlink for deleting your account if you disagree with the new rules — even though deletion is the more momentous decision. We all know the trick that sends us looking frantically for the “X” we need to click to close an ad. The way Facebook has laid out its new policy pages is a subtler version of that intentional annoyance, a form of mild psychological pressure to sign on the dotted line and be done with it. Most people will: there’s no way to reject specific parts of the rules except indirectly, through tweaking certain settings, and then not in every case — even though very little data collection is actually required to provide the basic Facebook service. That’s unfair to users whose data is coming to Facebook from a multitude of hard-to-track sources, some of which they’d surely like to cut off.

    Verbosity

    Twitter’s updated privacy policy runs to more than 8 800 words, and it’s distinct from its terms of service and Twitter rules. I know some people — lawyers and reporters — capable of getting through all three documents with a magnifying glass, but most users aren’t like that. There’s no reason for the multiple documents and the verbosity except to induce boredom.

    The GDPR rules aren’t complicated. They mainly require organisations that collect and process data to ask Internet users in clear language whether they’re okay with it. But what users get is, as ever, a lengthy legal text — no, three of them and wait, there’s also this linked page and that one, and a separate privacy policy for children, and another one for pets (okay, I made that last one up).

    There is a right way to do it. Among all the organisations whose updated policies I’ve seen in recent days, the unlikeliest one came the closest to it — London’s recently renamed Kiln Theatre, which sent a policy change notification to my London-based editor. Its new privacy policy is, of course, another morass of legal verbiage — but it contains a handy table that lists the purposes for which data are collected and matches them with specific data types used.

    That’s what I want to see from each of the data harvesters who want my personal information. A simple three-column table. First column: Purpose of data collection (for example: “To personalise ads” or “To enable academic research.”) Second column: Types of data collected or processed (for example, “Web browsing history” or “information about previous purchases provided by advertisers”). Third column: Consent (two checkboxes opposite every data type: “I agree” and “I object.”) In cases where the company considers consent obligatory for the service it provides — and only in those rare cases — checking the “object” box should result in a pop-up explaining why the company can’t live without this and providing a link to the local privacy watchdog’s complaint form.

    First step

    This would be true GDPR compliance — with the regulation’s spirit, not just its letter. But dealing with the consent part in an honest way would only be the first step. Companies then would have to live up to other requirements such as data portability (Facebook, for example, only allows you to download your contacts in text format, so you can’t really move your online friendships to another service).

    I hope the EU objects to how its regulation is being applied, but somehow I doubt it: the lawyers who wrote the new policies know their job. It has little to do with earning trust and everything with minimising litigation. So, whether users feel cheated or not (I do), the new policies tell them that by continuing to use the services past 25 May, they consent to the rules as the lawyers rewrote them.

    This is a business opportunity waiting for a classic disruptor. Honest GDPR compliance can be marketed. Can anyone get up the courage to do it?  — (c) 2018 Bloomberg LP

    Follow TechCentral on Google News Add TechCentral as your preferred source on Google


    Facebook Fitbit GDPR Leonid Bershidsky top Twitter
    WhatsApp YouTube
    Share. Facebook Twitter LinkedIn WhatsApp Telegram Email Copy Link
    Previous ArticleTwitter takes flight as turnaround gathers steam
    Next Article 4Sight Holdings builds bulk with new acquisitions

    Related Posts

    Jury finds Meta enabled child exploitation

    Jury finds Meta enabled child exploitation

    25 March 2026
    X moves to block bid to revive Twitter brand

    X moves to block bid to revive Twitter brand

    17 December 2025
    Australia has banned kids from social media. Should South Africa follow suit?

    Australia has banned kids from social media. Should South Africa follow suit?

    11 December 2025
    Company News
    In crypto, trust is the new currency - Binance South Africa's Sam Mkhize

    In crypto, trust is the new currency

    13 May 2026
    Don't miss the Telviva Tech Insights webinar

    Don’t miss the Telviva Tech Insights webinar

    13 May 2026

    Don’t miss the Pan African DataCentres Exhibition & Conference

    13 May 2026
    Opinion
    Free calls, dead voice and Shameel Joosub's Spanish ghost - Duncan McLeod

    Free calls, dead voice and Shameel Joosub’s Spanish ghost

    22 April 2026
    The conflict of interest at the heart of PayShap's slow adoption - Cheslyn Jacobs

    The conflict of interest at the heart of PayShap’s slow adoption

    26 March 2026
    South Africa's energy future hinges on getting wheeling right - Aishah Gire

    South Africa’s energy future hinges on getting wheeling right

    10 March 2026

    Subscribe to Updates

    Get the best South African technology news and analysis delivered to your e-mail inbox every morning.

    Latest Posts
    Starlink wait set to drag on as Icasa flags legal hurdle

    Starlink wait set to drag on as Icasa flags legal hurdle

    13 May 2026
    Malatsi opens door to 'some' partial privatisations of SOEs - communications minister Solly Malatsi

    Malatsi opens door to ‘some’ partial privatisations of SOEs

    13 May 2026
    Sam Altman denies betraying Elon Musk. Shelby Tauber/Reuters

    Sam Altman denies betraying Elon Musk

    13 May 2026
    Naked Insurance launches native app in ChatGPT - Alex Thomson

    Naked Insurance launches native app in ChatGPT

    13 May 2026
    © 2009 - 2026 NewsCentral Media
    • Cookie policy (ZA)
    • TechCentral – privacy and Popia

    Type above and press Enter to search. Press Esc to cancel.

    Manage consent

    TechCentral uses cookies to enhance its offerings. Consenting to these technologies allows us to serve you better. Not consenting or withdrawing consent may adversely affect certain features and functions of the website.

    Functional Always active
    The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
    Preferences
    The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
    Statistics
    The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
    Marketing
    The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
    • Manage options
    • Manage services
    • Manage {vendor_count} vendors
    • Read more about these purposes
    View preferences
    • {title}
    • {title}
    • {title}