The solution is obvious: make it illegal for companies to collect and store user data where it is not strictly necessary to fulfill the direct customer needs. Collecting less data and storing it in fewer systems is the most effective way to reduce data breaches and their impact.
That is already the case for where I live, and yet I am on that breach, with names, addresses, etc. all leaked. Unfortunately it's not enough to collect "only necessary" if what's necessary is too much in the hands of the attacker.
There are people that pre-ordered their latest PC that are currently waiting for the remaining batches to become available, finish paying the PC price in full, and have it shipped to them. So this information does fullfill a direct customer need.
I have never made a purchase via Framework and still got the email from them. Probably because I once put in my data to see final shipping and import costs.
This would be nice, and I hope I get to see a future like this, but I moreso meant that I don't see a solution for this issue given the current landscape of things. Ideally, yes, companies wouldn't collect the data and it would be illegal to do so. However, this currently isn't the case, so what can be done that lets all sides win? Something has to give, and I'm certain users will receive the short end of the stick at all times - at least, until there are better laws in place.
Comments
The solution is obvious: make it illegal for companies to collect and store user data where it is not strictly necessary to fulfill the direct customer needs. Collecting less data and storing it in fewer systems is the most effective way to reduce data breaches and their impact.
That is already the case for where I live, and yet I am on that breach, with names, addresses, etc. all leaked. Unfortunately it's not enough to collect "only necessary" if what's necessary is too much in the hands of the attacker.
There are people that pre-ordered their latest PC that are currently waiting for the remaining batches to become available, finish paying the PC price in full, and have it shipped to them. So this information does fullfill a direct customer need.
I have never made a purchase via Framework and still got the email from them. Probably because I once put in my data to see final shipping and import costs.
This would be nice, and I hope I get to see a future like this, but I moreso meant that I don't see a solution for this issue given the current landscape of things. Ideally, yes, companies wouldn't collect the data and it would be illegal to do so. However, this currently isn't the case, so what can be done that lets all sides win? Something has to give, and I'm certain users will receive the short end of the stick at all times - at least, until there are better laws in place.
Can't they store that information encrypted? What analytics can be extracted from phone numbers? It's only good to sell on black market.
I'm waiting for this for 7 years already: I'm too lazy to setup proper analytics with 800 "legitimate partners" on my website
If framework did as you suggest, they would have no way to validate warranty status and recalls.
Motherboard died after 3 months? Tough luck, they have no record of you being a customer.
Battery tends to catch fire? I guess they should just post a recall notice to Twitter and hope most people see it somehow.
These are bad examples.
Warranty status is tied to hardware* serials. It's not like there are third-party Framework sellers.
Sending a recall notice via email doesn't require name, address, dob, etc.
Companies are in a bad habit of not actually clearing customer data they don't need.
Of course they do. How do you think warranty works for in-person cash purchases?
Put a sticker with a unique ID on parts.
Sounds like GDPR?