This week data from all Brazilians were leaked, and when I say "all", it is in the literal sense. The refinement and depth of this data are frightening. @carissaveliz @TweetinChar @johnchavens @DorotheaBaur @privacyint @maria_axente 1/n 👇

There is still no certainty about where the data leaked, but there are suspicions (still not confirmed) that they are from Serasa: an Experian company in Brazil. The leak was of everything imaginable of 220 million inhabitants. 2/n 👇
Being all citizens, this includes ordinary citizens, including minors, police, ministers, presidents, judges, military, deputies, senators, judges, businessmen, religious leaders, people with disabilities, etc. But what kind of data? 3/n 👇
The list is really big: full name, date of birth, home address including lat/lon, social security numbers, ID, driver's license, relatives up to the 3rd degree, credit score, bank account, employer history, salary, working hours per week... 4/n 👇
...car brand, color, plate, chassis, phone number, phone provider, billing, credit score, social class, companies you own or have participation, where and when you graduated, 401(k), IRS, consumer behavior...well, think of any data, and it seems to be there 5/n 👇
Now think of this data in the hands of fugitives from justice, vengeful ex-convicts, kidnappers, swindlers, scammers, angry ex-spouses, child abusers, blackmailers ... all available at a cost of between $ 0.075 and $ 1.00 for each person of your interest. 6/n 👇
This can also end up in the hands of authoritarian leaders, companies that can delimit your life like insurance, banks, recruiters, even landlords, and lawyers in a case against you...We are all now on our own against all this. 7/n 👇
In Brazil, we have the LGPD (similar to the GDPR), but its fines (2% on annual sales, up to ~US$10M) only come into effect in Aug/21. An important point is that millions of Brazilians are also European citizens, and I assume that it can create implications for GDPR as well. 8/n👇
Investigations are ongoing, but we can already ask a few questions: how can a single source of data have all this together, extrapolating any sense of legitimate use? How will this damage be contained and repaired? How do people protect themselves from the possible effects? 9/n👇
There is a symbiotic relationship of many years between companies and the State, which we hoped to curb such a concentration of power. This now seems to be just a kind of childish utopia. https://t.co/iBtOGR3Tho (you can easily translate it if needed) 10/10🤛

More from World

You May Also Like

Recently, the @CNIL issued a decision regarding the GDPR compliance of an unknown French adtech company named "Vectaury". It may seem like small fry, but the decision has potential wide-ranging impacts for Google, the IAB framework, and today's adtech. It's thread time! 👇

It's all in French, but if you're up for it you can read:
• Their blog post (lacks the most interesting details):
https://t.co/PHkDcOT1hy
• Their high-level legal decision: https://t.co/hwpiEvjodt
• The full notification: https://t.co/QQB7rfynha

I've read it so you needn't!

Vectaury was collecting geolocation data in order to create profiles (eg. people who often go to this or that type of shop) so as to power ad targeting. They operate through embedded SDKs and ad bidding, making them invisible to users.

The @CNIL notes that profiling based off of geolocation presents particular risks since it reveals people's movements and habits. As risky, the processing requires consent — this will be the heart of their assessment.

Interesting point: they justify the decision in part because of how many people COULD be targeted in this way (rather than how many have — though they note that too). Because it's on a phone, and many have phones, it is considered large-scale processing no matter what.