
Put it online and it will live forever (Image: Aldo Sperber/picturetank)
They thought they could get away with it. The 37 million people who put nude photos and intimate details of their sexual fantasies on the Ashley Madison website (which has the slogan āLife is short. Have an affairā) had a get-out clause.
Advertisement
Ashley Madison, like some other sites, offers a hard delete ā a guarantee that for a certain amount of money, your data will be scrubbed from all of its internal records. To permanently destroy all traces of your affiliation with the adultery social network costs Ā£15 in the UK.
However, a hacker collective called Impact Team has revealed that customersā details arenāt entirely deleted. Compliance with auditing requirements means that the credit card details and name used to scrub the account , rather defeating the point.
Serves them right, some might say. But this should be a reminder that there is a big gap between what web sites do with our data and what they tell us they will do. And that there is a lot of wiggle room in the technical details. Thatās true even if you havenāt been having an affair on the internet.
Your digital remains
Take Facebook, for example. The site advises that āā. However, just because you can remove your account from the public-facing servers doesnāt mean no data about you remains in Facebookās coffers.
āFacebookās data policy is ambiguous on what exactly it promises to delete after you delete your account,ā says Brendan Van Alsenoy, a legal researcher at the Catholic University of Leuven (KUL) in Belgium. āIt mentions āinformation associated with your accountā,ā he says, but āitās unclear whether this covers any information other than the information that is immediately visible to users themselvesā. So while Facebook is legally bound to delete things like status updates, the same legal protections may not apply to internal business information of the sort that Ashley Madison kept.
āCopies of some material may remain in our database for technical reasons,ā a Facebook representative told Āé¶¹“«Ć½. However, āwhen you delete your account, this material is disassociated from any personal identifiersā. According to European Union law, says Van Alsenoy, āif the data has been sufficiently anonymised, the individual will not be able to insist on deletionā.
Back from the dead
The precise workings of deleting accounts or history with other companies is similarly unclear. A Google spokeswoman directed us to the companyās fine print, which reveals similar caveats: āā, but āif you deleted your Gmail account but want it back, we work to help you recover your deleted account whenever we can.ā
āBecause we maintain backup systems to make sure we donāt lose usersā data,ā she said, āthe deletion process may take time.ā
This makes business sense given the calamity associated with hacked and . While the company lets you delete your search history, it does keeps those search logs, but dissociates them from your Google account: anonymised.
However, data anonymisation is becoming increasingly unrealistic. āRe-identifying supposedly anonymised data has been demonstrated many times,ā says information privacy legal scholar Paul Bernal of the University of East Anglia, UK, and it will only get easier as re-identification techniques become more sophisticated.
Unfortunately, the law often either misunderstands or lags behind technological developments. In health law, for example, squabbles are ongoing over the definition of āsufficientlyā anonymised.
Some say full anonymisation is simply impossible. EU regulators have issued , however, that are sensible, says Van Alsenoy. āWhether or not somebody is āidentifiableā or not is a question of fact,ā he says.
And the proposed reform of the EU Data Protection regime includes an explicit āā motivated by the frustration of Viviane Reding, the European commissioner for justice, fundamental rights and citizenship, with the difficulty of deleting social media profiles.
The bottom line
Perhaps the real reason companies bury their promises in caveats has to do with the bottom line. Facebook accounts are replicated across geographically distributed data centres. āIt would cost Google and Facebook money to delete all data ā just setting up the systems would be complex, I suspect, and tracking down all data might be a little hard too,ā says Bernal.
For the time being, no one knows what data is kept, how identifiable it is, or how it could eventually be strung together. Plenty of people have been convicted of murder partly on the basis of web searches such as and .
But even if your search queries are more anodyne, they or other online traces might come back to haunt you. āPeople tend to think short term, accurately believing that the threat over exposure of ājust one postā over a small time frame is rather minimal,ā says David Dunning, who studies cognitive biases at Cornell University in Ithaca, New York. āItās this neglect of the long term that often gets people into trouble.ā
So how would such information come to light? A hack would do it. But even if every company were scrupulous about storing your information far from a hackable internet connection, there are still other avenues for your information to find its way back into the open internet.
āThe notion of a defunct Facebook seems preposterous today,ā says Bernardo Huberman, director of the Social Computing Lab at Hewlett Packard. But many other social networks like Orkut and Friendster fell to the fickle winds of Silicon Valley. In the future, Facebookās valuable data may become its most valuable commodity.
What guarantee does anyone have that someone canāt one day use Facebookās or Googleās log files to construct a damning narrative about you?
Whether itās an incriminating Facebook back-and-forth from 2004 or a series of late-night Google searches on erectile dysfunction, āmany people likely donāt know just how long their material stays on the internet, what companies can do with it, or how open it is to hackingā, says Dunning.