I personally don't believe that privacy policies are useful at all. They are at best the web equivalent of a verbal agreement.
People need to adopt the security-oriented attitude that says, if you post anything, anywhere, the entire Internet may very well see it. Period. You cannot trust every server, protection mechanism and employee in between. (You wouldn't really know who to sue, anyway.)
If something really "must" be private or controlled, then you don't need a policy, you need actual control over your data. For example, don't post the thing on an Internet-enabled computer in the first place. Or, strongly encrypt it, and have absolute trust in the recipients of keys. If you've made your key recipients sign something legally binding, and retained proof that no one else could have received keys from you, then at least you'd know who to sue for violating your trust.
Ideally, the mechanism for transferring the keys doesn't use a network either, e.g. physically hand something to your intended audience that will let them decrypt whatever you do send. The data should also have a built-in "time bomb" that makes it impossible to decrypt anything after some specified period of time (for peace of mind). Of course, the recipient could do something stupid like save the decrypted data somewhere, which is why the legal binding to key recipients is so important.
This is a pipe dream. I totally get the engineery argument for certainty and perfection, but this can't work in the real world. It's too inconvenient, and relies on users being responsible and educated.
Nothing is written in stone. People decades ago weren't locking their doors, but factors such as urbanization (with higher crime in cities) created a reality that made people change the way they think. It wouldn't have taken many friends or neighbors having TVs and cars stolen, to make them change their minds. So does it really seem that unlikely that people will not learn from the experiences of being online, and learn the digital equivalent of locking their doors?
In Europe the protections are better, and there are requirements that must be complied with including no data processing outside of the EEA without consent.
Comments
I personally don't believe that privacy policies are useful at all. They are at best the web equivalent of a verbal agreement.
People need to adopt the security-oriented attitude that says, if you post anything, anywhere, the entire Internet may very well see it. Period. You cannot trust every server, protection mechanism and employee in between. (You wouldn't really know who to sue, anyway.)
If something really "must" be private or controlled, then you don't need a policy, you need actual control over your data. For example, don't post the thing on an Internet-enabled computer in the first place. Or, strongly encrypt it, and have absolute trust in the recipients of keys. If you've made your key recipients sign something legally binding, and retained proof that no one else could have received keys from you, then at least you'd know who to sue for violating your trust.
Ideally, the mechanism for transferring the keys doesn't use a network either, e.g. physically hand something to your intended audience that will let them decrypt whatever you do send. The data should also have a built-in "time bomb" that makes it impossible to decrypt anything after some specified period of time (for peace of mind). Of course, the recipient could do something stupid like save the decrypted data somewhere, which is why the legal binding to key recipients is so important.
This is a pipe dream. I totally get the engineery argument for certainty and perfection, but this can't work in the real world. It's too inconvenient, and relies on users being responsible and educated.
Nothing is written in stone. People decades ago weren't locking their doors, but factors such as urbanization (with higher crime in cities) created a reality that made people change the way they think. It wouldn't have taken many friends or neighbors having TVs and cars stolen, to make them change their minds. So does it really seem that unlikely that people will not learn from the experiences of being online, and learn the digital equivalent of locking their doors?
And a several-page "privacy policy" is the solution?
In Europe the protections are better, and there are requirements that must be complied with including no data processing outside of the EEA without consent.
You can read about the UK variant here: http://www.ico.gov.uk/
At their current state, privacy policies are indeed not useful.
But maybe we can change that.