Skip to main content
Markkula Center for Applied Ethics

All About Ethics Blog

Keyboard with a lock icon

Keyboard with a lock icon

Your Very Own Data Privacy Policy

With tongue planted firmly in cheek, Internet Ethics Director Irina Raicu created a privacy policy that corporations must sign in order to do business with her.

With tongue planted firmly in cheek, Internet Ethics Director Irina Raicu created a privacy policy that corporations must sign in order to do business with her.  The piece, which appears in Slate, includes these provisions:

Scope: This policy covers only me. It does not apply to related entities that I do not own or control, such as my friends, my children, or my husband.

Age restriction and parental participation: Please specify if you are a startup; if so, note how long you’ve been in business. Please include the ages of the founders/innovators who came up with your product and your business model. Please also include the ages of any investors who have asserted, through their investment in your company, that they thought this product or service was a good idea.

Information about you: For each piece of personal information about me that you wish to collect, analyze, and store, you must first disclose the following: a) Do you need this particular piece of information in order for your product/service to work for me? If not, you are not authorized to collect it. If yes, please explain how this piece of information is necessary for your product to work for me. b) What types of analytics do you intend to do perform with this information? c) Will you share this piece of information with anyone outside your company? If so, list each entity with which you intend to share it, and for what purpose; you must update this disclosure every time you add a new third party with which you’d like to share. d) Will you make efforts to anonymize the personal information that you’re collecting? e) Are you aware of the research that shows that anonymization doesn’t really work because it’s easy to put together information from several categories and/or several databases and so figure out the identity of an “anonymous” source of data? f) How long will you retain this particular piece of information about me? g) If I ask you to delete it, will you, and if so, how quickly? Note: by “delete” I don’t mean “make it invisible to others”—I mean “get it out of your system entirely.”

Ethics
blog, internet,ESG, ESG-SOC

Subscribe to Our Blogs

* indicates required
Subscribe me to the following blogs: