Dave Schuler proposes a “radical idea” to safeguard individual privacy “in the wake of the hacking of Sony and the multiple credit card exploits over the last year or so.” It seems reasonable enough:
The personally identifiable information that’s being gathered and retained by businesses from your phone company to Google or Amazon doesn’t belong to them. It’s the property of the persons who are identified by it. That includes names, email addresses, phone numbers, IP addresses, and geolocation information. There should be restrictions placed on the information they retain, how long they retain it, and the manner in which it may be retained. Just as an example, these companies have no excuse for retaining your information indefinitely in unencrypted form.
I’d settle for an even less radical idea: business who collect PII should be prohibited from selling or otherwise sharing said information with other companies, to include companies who acquire them, without express permission from the persons who are identified by it. When I trust Google or Amazon with my information, I’m trusting Google and Amazon—not unspecified companies with whom they might at some point chose to do business.









