• towerful@programming.dev
    link
    fedilink
    English
    arrow-up
    13
    ·
    9 months ago

    Where does it say they have access to PII?
    I would imagine reddit would be anonymising the data. Hashes of usernames (and any matches of usernames in content), post/comment content with upvote/downvote counts. I would hope they are also screening content for PII.
    I dont think the deal is for PII, just for training data

    • just_change_it@lemmy.world
      link
      fedilink
      English
      arrow-up
      1
      arrow-down
      1
      ·
      9 months ago

      Where does it say they have access to PII?

      So technically they haven’t sold any PII if all they do is provide IP addresses. Legally an IP address is not PII. Google knows all our IP addresses if we have an account with them or interact with them in certain ways. Sure, some people aren’t trackable but i’m just going to call it out that for all intents and purposes basically everyone is tracked by google.

      Only the most security paranoid individuals would be anonymous.

      • towerful@programming.dev
        link
        fedilink
        English
        arrow-up
        2
        ·
        9 months ago

        Depends where and how its applied.
        Under GDPR, IP addresses are essential to the opperation of websites and security, so the logging/processing of them can be suitably justified without requiring consent (just disclosure).
        Under CCPA, it seems like it isnt PII if it cant be linked to a person/household.

        However, an ip address isnt needed as a part of AI training data, and alongside comment/post data could potentially identify a person/household. So, seems risky under GDPR and CCPA.

        I think Reddit would be risking huge legal exposure if they included IP addresses in the data set.
        And i dont think google would accept a data set that includes information like that due to the legal exposure.