Posted on

Data retention beyond the original reason for collection

A company can have a good reason to collect data today and a bad reason to keep it forever.

Those are separate questions.

A delivery service needs an address to deliver a package.

A fraud system may need transaction records long enough to investigate abuse.

A support desk may need logs while a problem is active.

The privacy issue changes when the original task ends but the information stays available indefinitely.

Storage creates future options

Data that no longer serves its original purpose can still be useful for something else.

Old location records may later support audience segmentation.

Old purchase histories may become training data.

Support logs may be mined for product analytics.

Account activity may be combined with newer records to create long-term behavioral profiles.

None of those later uses is guaranteed merely because the data was retained.

But retention makes them possible.

That is why retention policy is part of data governance rather than just storage housekeeping.

Current privacy rules increasingly connect retention to purpose

CalPrivacy’s current CCPA guidance says covered businesses must limit collection, use, and retention of personal information to purposes that are reasonably expected, compatible and disclosed, or separately agreed to, and that the activity must be reasonably necessary and proportionate. See CalPrivacy’s CCPA FAQ.

The agency’s enforcement guidance on data minimization makes the same principle explicit: retaining personal information is supposed to remain tied to the purposes for which it was collected or to another compatible disclosed purpose. See CalPrivacy Enforcement Advisory 2024-01.

Those rules are jurisdiction-specific.

The engineering principle is broader.

If nobody can explain why a dataset still exists, “we already have it” is not much of a retention policy.

A useful retention policy needs clocks, not poetry

Statements such as we retain information as long as necessary sound reassuring.

They become meaningful only when somebody has defined necessary.

A stronger policy identifies:

  • which dataset is retained,
  • for what purpose,
  • the retention period or decision rule,
  • what event starts the deletion clock,
  • what legal or security exceptions apply,
  • what happens to backups,
  • and who can approve a longer period.

Different data may need different clocks.

A chargeback record and a precise location history do not automatically deserve the same lifespan.

Old data attracts new explanations

The longer information survives, the more organizations, employees, products, and business models can change around it.

A dataset collected under one privacy policy can outlive the team that collected it.

A company can be acquired.

A product can be repurposed.

A vendor can change.

That does not mean old data is inevitably abused.

It means retention increases the number of future contexts in which the data might matter.

The Surveillance Economy does not only depend on collecting information.

It also depends on not throwing it away.

Posted on

Wearable-device data and secondary commercial uses

A fitness tracker can collect a remarkable amount of information while doing exactly what the customer bought it to do.

Steps. Heart rate. Sleep stages. Exercise. Distance. Weight. Calories. Location during workouts. Sometimes manually entered health information as well.

None of that collection is mysterious when the feature depends on it.

The harder question is what happens after the measurement has served its obvious purpose.

Useful data can have more than one use

Google’s current Google Health documentation says Fitbit and related services can collect health and wellness data including steps, distance, calories burned, weight, heart rate, sleep stages, active minutes, and information from connected services. See Google Health’s privacy FAQ and Fitbit’s privacy policy.

Those records can support the expected functions: showing trends, calculating goals, producing sleep insights, or syncing a workout.

A dataset that rich can also be useful for analytics, product improvement, research, connected services, coaching, fraud prevention, or other secondary processing depending on the product and the user’s choices.

That does not mean every wearable vendor sells health data to advertisers.

In fact, Google currently states that Fitbit and Google Health wellness data is not used for Google Ads. See Google’s continued privacy commitment and Google Health data controls.

That is an important example because it shows why this subject has to be studied from actual policies and data flows rather than assumptions.

“Collected” is not the same as “commercially exploited”

The mere presence of a heart-rate database does not establish an advertising use.

Likewise, a promise not to use health data for ads does not tell you everything about research, service improvement, connected applications, retention, or other forms of processing.

A responsible audit asks separate questions:

  • What measurements are collected?
  • Which features require them?
  • Which outside services can receive them?
  • Is research participation optional?
  • Are analytics separated from health data?
  • Can users download or delete records?
  • What happens when a connected third-party app receives a copy?

The distinction between primary use and secondary use is the important one.

Wearables make intimate data routine

A browser history can hint at health interests.

A wearable may directly measure sleep, pulse, movement, or exercise.

That does not automatically make the device sinister. It makes transparency unusually important because the product works by collecting information the user would rarely have generated before wearing it.

The Surveillance Economy is not only about secret collection.

Sometimes the user knowingly supplies the raw material because the feature is genuinely useful.

The harder question comes later:

What else is the dataset allowed to become?