Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

EU data protection laws are a useful model.

An organisation should only collectthe information it needs to; it should not keep that information longer than it needs; it should be transparent about the information it gathers and the reason for doing so.

In this case a company is searching public information (reasonable) but using education databases to get contact info for the student (not reasonable). This is unreasonable because they should be using things like warrants to get addresses -- something with judicial oversight. The student's personal contact information should be protected from this kind of trawling.



Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: