Posted on

Data access requests as a way to inspect an assembled profile

The easiest way to misunderstand a data profile is to imagine it contains only things you personally typed into a form.

A real profile may be much stranger.

It can contain facts you volunteered, records acquired from other sources, device identifiers, inferred interests, household links, marketing segments, and internal labels you never saw.

That is why a data access request can be useful.

It turns an invisible profile into something inspectable.

Access can reveal the difference between supplied and inferred data

California’s current privacy guidance describes a consumer’s right to know what personal information covered businesses have collected and how they use and share it. See CalPrivacy’s CCPA FAQ.

Depending on the applicable law, company, and request, an access response may include categories or specific pieces of personal information, sources, purposes, or disclosures.

The most interesting comparison is often between what the person remembers supplying and what the company has assembled.

For example:

  • Volunteered: name, shipping address, email.
  • Observed: pages viewed, purchases, devices used.
  • Acquired: demographic or commercial attributes from another source.
  • Inferred: likely interests, household status, audience segment, predicted preference.

Those categories have different evidentiary meanings.

An inference is not automatically a fact merely because it appears in a company database.

The response can expose errors too

A profile might contain an outdated address, a device belonging to another household member, a purchase made as a gift, or an interest category inferred from one accidental click.

Without access, those errors can remain invisible while still influencing advertising, personalization, or other systems.

This connects directly to the data-broker problem. The Federal Trade Commission’s 2014 data broker report documented how brokers combine information from many sources into composite profiles and derive additional classifications from those records.

Access provides one way to inspect the result instead of merely guessing what the system knows.

An access response is not necessarily the whole backend

There are important limits.

Legal rights vary by jurisdiction. Exceptions can apply. Security-sensitive material may be withheld. A company may describe categories rather than expose every internal model. Data held by a separate company may require a separate request.

And a response from one organization does not reconstruct every copy that has already moved through the advertising or broker ecosystem.

So an access request should not be treated as a magical database dump.

It is evidence about a specific organization’s records and obligations at a specific time.

That is still valuable.

The Surveillance Economy is difficult to evaluate when every profile is hypothetical.

Access rights can turn at least part of the hypothesis into a document.

Posted on

Privacy policies that obscure the identities of data recipients

“We share information with trusted partners.”

That sentence may be true.

It may also tell you almost nothing.

Privacy policies often describe recipients by category: service providers, advertising partners, analytics companies, affiliates, vendors, processors, business partners, or other third parties.

Those labels can be useful.

They are not the same thing as knowing who actually receives the data.

A category explains a role, not an identity

Suppose a policy says location data may be shared with analytics and advertising partners.

The reader still does not know:

  • which companies,
  • how many companies,
  • whether the recipients change regularly,
  • whether those companies receive raw location or derived segments,
  • whether they can combine it with their own records,
  • whether they pass it onward.

The category gives the reader a general purpose.

It does not reconstruct the supply chain.

California’s privacy framework illustrates why both kinds of information matter. CalPrivacy describes a consumer’s right to know what personal information a covered business has collected and how it uses and shares that information. See CalPrivacy’s CCPA FAQ.

The practical value of that right depends heavily on how specifically the relationship can be described.

Vague language may be accurate and still hard to use

There are legitimate reasons policies use categories.

Vendors change. Large services may use hundreds of processors. Naming every infrastructure provider in the main policy can turn the document into a phone book that goes stale immediately.

The problem is not that categories exist.

The problem appears when the category is the only useful detail available about an important data flow.

“Business partners” can cover a lot of ground.

So can “service improvement.”

A reader trying to understand whether a location broker, ad exchange, cloud processor, fraud vendor, measurement company, or social platform receives the data may still be stuck.

Better transparency separates role from recipient

A more informative system can combine layers:

  • a plain-language explanation of the purpose,
  • the category of recipient,
  • a current vendor or subprocessors list,
  • the type of data each recipient gets,
  • and a change log when important relationships change.

That is more work than writing we may share data with partners.

It is also more useful.

The Federal Trade Commission’s long-running work on data brokers has repeatedly emphasized how difficult it can be for consumers to understand where information came from and where it travels once multiple intermediaries are involved. See the FTC’s Data Brokers: A Call for Transparency and Accountability.

The Surveillance Economy is a supply chain.

A privacy policy that names only categories may describe the boxes on the diagram while leaving all the arrows unlabeled.

Sometimes the most important privacy question is simply:

Who, exactly, got it?

Posted on

Funding trails behind apparently independent online advocacy

Follow the money is good advice.

It is not a magic spell.

Funding records can reveal that an apparently independent organization receives money from a company, foundation, trade group, union, political organization, or other interested sponsor. That relationship may be extremely important.

It still does not tell you everything about who wrote every sentence or controlled every decision.

Public records can expose relationships

For U.S. tax-exempt organizations, Form 990 filings can reveal information about revenue, major expenses, grants, officers, related organizations, contractors, and other parts of an organization’s structure.

But the records have important limits. The IRS says contributor names and addresses on Schedule B generally are not required to be publicly disclosed for most organizations filing Form 990 or 990-EZ. Different rules apply to private foundations and certain section 527 political organizations. See the IRS guidance on public disclosure of contributor identities.

So a researcher may be able to see that an organization received substantial contributions without being able to identify every donor from the public filing alone.

Other useful records can include corporate registrations, grant databases, lobbying filings, contracts, board biographies, archived sponsor pages, annual reports, and disclosures from the funder itself.

Funding establishes a relationship, not automatically control

Suppose an advocacy site receives a $250,000 grant from an industry foundation.

That fact matters.

It does not automatically prove the funder selected the site’s conclusions, approved its articles, or dictated its strategy.

The stronger case for sponsor control needs stronger evidence: contractual language, internal correspondence, shared staff, approval rights, campaign instructions, governance ties, or documented coordination.

The opposite mistake is also possible. A site can describe itself as independent while leaving out a financial relationship that a reasonable reader would consider important.

In commercial endorsement settings, the FTC uses the idea of a material connection: a relationship that could affect how an audience evaluates an endorsement should be disclosed clearly and conspicuously. See the FTC’s Endorsement Guides.

Advocacy funding is not governed by exactly the same rules in every setting, but the interpretive principle is useful.

Hidden relationships change how evidence is weighed.

Motive is the hardest claim

A payment can establish that money moved.

It cannot read anybody’s mind.

A donor may fund an organization because it already shares the donor’s views. An organization may accept money and retain substantial independence. A sponsor may also exert direct control.

Those possibilities require different evidence.

A rigorous funding investigation therefore reports layers separately:

Who paid whom?

What formal relationship existed?

What evidence shows influence over the message?

What remains unknown?

Manufactured Consensus becomes visible when apparently independent voices are connected by relationships the audience was not shown.

The money trail can reveal the wiring.

It should not be asked to prove more than the records actually say.