Posts

tiktok

TikTok Facing New Privacy Investigation From Europe Over China Data Transfers 

Popular social media app TikTok is facing a new privacy investigation from the European Union due to user data being sent to China, regulators stated this week. 

Embed from Getty Images

The Data Protection Commission opened up the inquiry as a follow up to a previous investigation that ended earlier this year with a 530 million euro ($620 million) fine. The fine was enforced after it was found that TikTok put its user’s data at risk of being exposed and spied on by allowing remote access from China. 

TikTok’s European headquarters are based in Dublin, Ireland, so the Irish national watchdog will be serving as TikTok’s lead data privacy regulator in the 27-nation EU. 

During a previous investigation, TikTok told the regulator that they didn’t store European user data in China, and the data itself was remotely accessible by staff in China. 

Later on, it backtracked and stated that some data had been stored on Chinese servers, and the watchdog responded by stating they would consider regulatory action, according to the Associated Press.

“As a result of that consideration, the DPC has now decided to open this new inquiry into TikTok,” the watchdog stated.

“The purpose of the inquiry is to determine whether TikTok has complied with its relevant obligations under the GDPR in the context of the transfers now at issue, including the lawfulness of the transfers,” the regulator said, referencing the General Data Protection Regulation which is the European Union’s privacy rules.  

Embed from Getty Images

TikTok is owned by China’s ByteDance, and has been under scrutiny from multiple nations over how they handle personal user information and data. Western officials specifically believe that the app poses a security risk which the EU has also cited. 

“Our teams proactively discovered this issue through the comprehensive monitoring TikTok implemented under Project Clover,” the company said in a statement

“We promptly deleted this minimal amount of data from the servers and informed the DPC. Our proactive report to the DPC underscores our commitment to transparency and data security.”

Under the GDPR, European user data can only be transferred outside of the bloc if there are safeguards in place. These safeguards ensure a certain level of protection, and only 15 countries or territories are deemed to have an equal data privacy obligation as the EU.

23andMe

As 23andMe Files for Bankruptcy, Advocates Urge Users to Delete Their Genetic Data

Millions of customers initially joined 23andMe to discover intriguing insights about their ancestries and genetic health profiles. However, amid the company’s recent bankruptcy filing and planned sale, consumer advocates are now encouraging users to delete their accounts and data to protect their genetic information from potential misuse.

San Francisco-based 23andMe announced on Sunday it was seeking Chapter 11 bankruptcy protection and actively pursuing a buyer after failing to achieve a sustainable business model. This move puts the genetic data of its estimated 15 million users in a precarious position, potentially available to the highest bidder.

Although 23andMe claims that it will maintain its current data protection practices throughout the bankruptcy proceedings, board chairman Mark Jensen emphasized in a statement that data privacy would play a large part in any sale. Nonetheless, advocates warn that a change in ownership could drastically alter how user information is managed and shared.

“We want to thank our employees for their dedication to 23andMe’s mission. We are committed to supporting them as we move through the process. In addition, we are committed to continuing to safeguard customer data and being transparent about the management of user data going forward, and data privacy will be an important consideration in any potential transaction.”

“There are health insurance companies that are interested in this data, there are life insurance companies that are interested in this data,” California Attorney General Rob Bonta cautioned in an interview with ABC News7, prompting his office to release a consumer alert advising users to delete their accounts.

Embed from Getty Images

Similarly, New York Attorney General Letitia James urged customers to proactively secure their genetic data in light of the company’s financial troubles.

23andMe reassured users by highlighting its current privacy policy, stating that identifiable genetic data will not be sold and user consent is required before sharing data with researchers. However, the policy clearly stipulates that it is subject to change at any time, including during a corporate acquisition or restructuring.

Legal expert Anya Prince from the University of Iowa College of Law explained on CNN’s “Terms of Service” podcast that genetic data could disclose more than ancestry—it could predict future health conditions.

Although the Genetic Information Nondiscrimination Act (GINA) provides some safeguards against genetic discrimination by employers and health insurers, it does not extend protections against life insurers and other entities, leaving significant privacy gaps. Prince emphasized the inherent uncertainty of transitioning user data to a new company.

“Theoretically, the new company could have a similar ethos that the consumer feels good about, but the new company might have a completely different ethos.”

Several customers have already faced challenges attempting to remove their data. Danielle Landriscina, for instance, struggled to access her 23andMe account multiple times starting Tuesday morning, encountering delays with two-factor authentication codes arriving only after their validity had expired. After repeated attempts and receiving advice from the company’s overwhelmed online chat service to “try again later,” she finally managed to delete her account by Tuesday night.

Embed from Getty Images

“If anyone has any issues accessing their account or deleting their data, they can go to our customer care site for support,” a 23andMe spokesperson told the BBC. However, the company did not respond to further inquiries regarding additional customer complaints.

Another customer, Pauline Long from Alabama, described her experience as “a nightmare,” expressing frustration after spending two hours waiting for customer service assistance. “I am now going to be more cautious about doing anything online,” she said.

Although she succeeded in deleting her account by Tuesday evening, she remains skeptical about whether the company truly removed her data. “I am concerned that 23andMe will hold onto data,” Long stated.

To safeguard their privacy, users wishing to delete their data should log into their 23andMe account, select “Settings,” then “23andMe Data,” and then “View.” After downloading any personal genetic information, users can choose “Permanently Delete Data.” Those who previously allowed 23andMe to retain saliva samples can request disposal under the “Preferences” tab. Consent previously granted for third-party research can also be revoked.

Attorney General Bonta warned users might encounter technical issues due to high traffic on the website, advising persistence in trying to delete their information. “I was attempting to delete my data today, and the website was down today at times,” Bonta said, adding that the outage may have been caused by many people seeking to delete their data.

tiktok

US House Of Representatives Banned From Using TikTok On Their Electronic Devices 

According to an internal notice sent to the staff of the House of Representatives – obtained by CNN from the Office of the Chief Administrative Officer – TikTok has been banned from any and all electronic devices used and owned by members of the House of Representatives and prospective staff.

The notice stated that the app must be uninstalled from any House mobile device if it’s already installed. This is due to the government’s view of TikTok being a “high risk to users due to a number of security risks.” 

Embed from Getty Images

The US government has also been in talks to ban TikTok from all federal devices in the near future. This ban is a part of a piece of legislation included in the omnibus bill recently signed by President Joe Biden. More than a dozen states throughout the US have also already implemented their own restrictions and prohibitions on TikTok on government devices.

While TikTok hasn’t made any official comment regarding this recent ban on House devices, the company previously stated that the government’s moves to ban the app is a “political gesture that will do nothing to advance national security interests.”

One of the biggest concerns coming from lawmakers regarding TikTok involves the social media app’s parent company, ByteDance. 

US policymakers are concerned about national security and the risk of the Chinese government pressuring either TikTok or its parent company into acquiring, using, and sharing personal information specifically from its US users. 

This information is thought to be potentially used for Chinese intelligence operations or the sharing of disinformation backed by China’s government. 

Embed from Getty Images

While there hasn’t been any direct instances or attempts of these security breaches occurring, the platform did confirm last week that four employees were fired for accessing user data on TikTok from two journalists. 

The battle between the US government and TikTok has been ongoing since 2020, when the app truly began rising in popularity; partially due to the pandemic and quarantine restrictions that left citizens at home yearning for entertainment. 

Both the government and the platform have been working on negotiations to resolve any potential national security risks so that the app can continue to be used by US citizens. 

“The potential agreement under review covers key concerns around corporate governance, content recommendation and moderation, and data security and access,” TikTok has stated

For now, the US government is moving forward with its plans to ban the social media platform from all government used/connected devices, with the potential for wider bans to be implemented in the future.