home.social

#datarights — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #datarights, aggregated by home.social.

fetched live
  1. Big news for digital privacy in Delaware! The state legislature has passed a major amendment to the Delaware Personal Data Privacy Act (DPDPA). If signed into law, it will take effect on January 1, 2027, making it one of the most robust privacy frameworks in the U.S. 🛡️

    Here is what you need to know:

    Tighter Controls: It significantly lowers the number of consumers a company can process data for before being required to comply, bringing more businesses under the law's reach.

    Expanded "Sensitive Data": The definition now includes neural data, national origin, reproductive health status, government IDs, and financial account info. Companies will generally be prohibited from selling this data without your explicit consent.

    AI & Profiling Rights: You gain more control over how algorithms use your data to make life-altering decisions (like credit, housing, or hiring). If you are hit with an "adverse action" due to automated profiling, you have new rights to be notified and informed of the data used.

    Transparency: You can now request a list of the specific third parties your data has been shared with, rather than just vague categories.

    Read the full breakdown here: insideprivacy.com/state-privac

    #Privacy #DataRights #Delaware #TechPolicy #DigitalRights #news

  2. Participation in Crisis? Appraising Acute Challenges and Exploring Prospects for Revitalising the Inclusive Democratic Voice.
    isa-sociology.org/uploads/imge

    Call for Papers for a symposium on 2–3 July 2026 in Rome organised by ISA RC10, the Hans Böckler Foundation, and Link Campus University.

    Deadline for Abstracts: 10 June 2026.

    Some of the topics are related to digital issues:
    – Algorithmic Management and Worker Autonomy
    – Digital Authoritarianism in the Workplace
    – Data Rights as Democratic Rights
    – AI as a Participatory Tool

    #CfP #Sociology #AlgorithmicManagament #Authoritarianism #DataRights #DemocraticRights

  3. "This is what free costs." A new dispatch—taken. vol. IV of since you arrived—reveals a single page detailing what a browser silently disclosed the moment a visitor arrived. Essential reading on online tracking and data trade-offs. sinceyouarrived.world/taken 📰🔍 #Privacy #WebTracking #DataRights

  4. RE: rbfirehose.com/2026/05/15/reut

    Meta took publisher content without compensation.
    Fought paying for it.
    Lost in Europe's highest court.
    This is the extraction model meeting accountability.
    The same pattern applies to AI training data.
    Take content created by others.
    Use it to build systems worth billions.
    Fight any attempt to compensate the people who made it possible.
    Europe keeps being the place
    where extraction meets consequence.
    The rest of the world is watching, and hopefully follow
    #Meta #AI #OpenSource #FOSS #DataRights

  5. Many of us still treat privacy as a personal habit: stronger passwords, cleaner settings, fewer things shared.

    But privacy is also about power: who gets to know, classify, predict, influence, and decide what happens next.

    The fight for privacy is a fight for rights.

    associationredefine.substack.c

    #Privacy #DigitalRights #HumanRights #DataRights #DigitalFreedom #CivicRights #TechAndSociety #Surveillance #OnlinePrivacy #CivicIntelligence

  6. 𝗛𝗼𝘄 𝘁𝗼 𝗣𝗿𝗼𝘁𝗲𝗰𝘁 𝗬𝗼𝘂𝗿 𝗣𝗿𝗶𝘃𝗮𝗰𝘆 𝗶𝗻 𝘁𝗵𝗲 𝗔𝗜 𝗘𝗿𝗮: 𝗨𝗞 𝗚𝗗𝗣𝗥 & 𝗧𝗵𝗲 𝗡𝗲𝘄 𝗖𝗼𝗱𝗲 𝗼𝗳 𝗣𝗿𝗮𝗰𝘁𝗶𝗰𝗲

    #ArtificialIntelligence #UKGDPR #DataProtection #PrivacyLaw #AutomatedDecisionMaking #DataRights #TechLaw #AICodeOfPractice #MachineLearning #DigitalRights

    youtu.be/qTiqqX2YukU

  7. FYI: Belgian DPA's guide on AI and privacy: what your data rights actually mean: The Belgian DPA today published its first citizen-focused guide on AI and privacy, covering data rights, profiling risks, and GDPR protections under the AI Act. ppc.land/belgian-dpas-guide-on #DataRights #Privacy #AI #GDPR #DataProtection

  8. ICYMI: Belgian DPA's guide on AI and privacy: what your data rights actually mean: The Belgian DPA today published its first citizen-focused guide on AI and privacy, covering data rights, profiling risks, and GDPR protections under the AI Act. ppc.land/belgian-dpas-guide-on #Privacy #DataRights #AI #GDPR #DataProtection

  9. Belgian DPA's guide on AI and privacy: what your data rights actually mean: The Belgian DPA today published its first citizen-focused guide on AI and privacy, covering data rights, profiling risks, and GDPR protections under the AI Act. ppc.land/belgian-dpas-guide-on #AI #Privacy #DataRights #GDPR #Belgium

  10. @cloudskater wrote:

    Some instances are run by bad people. Hell, a few projects like Lemmy and Matrix are DEVELOPED by assholes, but the FLOSS and federated nature of these platforms allows us to bypass/fork them and create healthy spaces outside their reach.

    Nope, that is actually what is killing the fediverse. I just explained here:

    The issue is the divergence in semantic interpretation that emerges at the interpretation layer. ActivityPub standardizes message delivery and defines common activity types. However, it leaves extension semantics and application-layer policy decisions to individual implementations. Servers may introduce custom JSON-LD namespaces and enforce local behaviors, such as reply restrictions, while remaining protocol-compliant. But, the noise created by divergences are problematic, because it creates unexpected, unintended, and unpredictable behavior.

    Divergence appears when implementations rely on non-normative metadata and assume reciprocal handling to preserve a consistent user experience. Behavioral alignment then varies. Syntactic exchange succeeds, but behavioral consistency is not guaranteed. Though instances continue to federate at the transport level, policy semantics and processing logic differ across deployments. Those differences produce inconsistent experiences and results between implementations.

    That leads to fragmentation, specifically semantic or behavioral fragmentation and an inconsistent user experiences. ActivityPub ensures syntactic interoperability, but semantic interoperability (everyone interprets and enforces rules the same way) varies. This creates a system that is federated at the transport level yet fragmented in behavior and expectations across implementations. It is funny how the thing that the fediverse touted has made the entire thing very brittle. ActivityPub technically federates correctly, but semantically falls apart once servers start adding their own behavioral rules.

    https://neon-blue-demon-wyrm.x10.network/archives/16932

    FYI, I’m not doing culture wars or political debates. I’m just saying this idea of “forking away” from them is literally breaking the fediverse’s distributed network and creating all kinds of issues with semantic interoperability. Yes, federation is still happening at the delivery level, but the semantic issues are out of fucking control. You are a federation by the very sheer skin of your teeth.

    The reason why developers are leaving the fediverse is because you folks don’t take criticism. You respond to criticism with — I’m being so serious right now — political manifestos and harassing developers. ActivityPub developers and authors oversold you folks on the capabilities of ActivityStreams. They flat-out lied to y’all.

    ↬bark.lgbt/@cloudskater/116080965694723006

  11. ActivityPub Server’s Custom Reply‑Control Extensions Undermine Federation

    It seems like Activitbypub developers are extending ActivityPub with optional metadata to fix a lot of its issues, but that is still problematic. Trying to add moderation tools and user control to threads seems to be the ongoing battle. I am fascinated by dumpster fires, so I’ve started looking at the ActivityPub protocol in detail. I tend to become fascinated with things that are going down in flames.

    As a brief recap of the problem:

    So, one of the very popular features on Bluesky—also popular on Twitter—is the ability to select who can reply to a post. A major issue in the Fediverse is the inability to decide who can reply, and once you block someone, their harassing reply is still there. I honestly thought it was simply a case of them choosing not to add or address it for cultural reasons. What is clear from that thread is that they were always aware that the ActivityPub protocol and most Fediverse implementations don’t provide a universal way to control reply visibility or enforce blocks across instances.

    An ActivityPub server that has reply control is GoToSocial. ActivityPub, as defined by the W3C specification, standardizes how servers federate activities. It defines actors, inboxes, outboxes, and activity types (Create, Follow, Like, Announce, etc.) expressed using ActivityStreams 2.0. It also specifies delivery mechanics (including how a Create activity reaches another server’s inbox) and how collections behave.

    The specification does not include interaction policy semantics such as “only followers may reply” or “replies require manual approval.” There is no field in the normative vocabulary requiring conforming servers to enforce reply permissions. That category of rule is outside the protocol’s defined contract.

    GoToSocial implements reply controls through what it calls interaction policies. These appear as additional properties on ActivityStreams objects using a custom JSON-LD namespace controlled by the GoToSocial project.

    JSON-LD permits additional namespaced terms. This means the document remains structurally valid ActivityStreams and federates normally. The meaning of those custom fields, however, comes from GoToSocial’s own documentation and implementation. Other servers can ignore them without violating ActivityPub because they are not part of the interoperable core vocabulary.

    Enforcement occurs locally. When a remote server sends a reply—a Create activity whose object references another via inReplyTo—ActivityPub governs delivery, not acceptance criteria. Whether the receiving server checks a reply policy, rejects the activity, queues it, or displays it is determined in the server’s inbox-processing code. The decision to accept, display, or require approval happens after successful protocol-level delivery. This behavior belongs to the application layer.

    These are server-side features layered on top of ActivityPub’s transport and data model that are not actually part of ActivityPub. The protocol ensures standardized delivery of activities; however, the server implementation defines additional constraints and user-facing behavior. Two GoToSocial instances may both recognize and act on the same extension fields. However, a different implementation, such as Mastodon, has no obligation under the specification to interpret or enforce GoToSocial’s interactionPolicy properties. These fields function as extension metadata rather than protocol requirements.

    The semantics of GoToSocial are not part of the specification’s defined vocabulary and processing rules for ActivityPub. They no longer operate purely at the protocol layer; it has become an application-layer contract implemented by specific servers.

    Let’s use the AT Protocol as an example. Bluesky’s direct messages (DMs) are not currently part of the AT Protocol (ATProto). The AT Protocol has nothing that specifies anything for DMs, so DMs are not part of the AT Protocol. The AT Protocol was designed to handle public social interactions, but it does not define private or encrypted messaging. Bluesky implemented DMs at the application level, outside of the core protocol. DMs are centralized and stored on Bluesky’s servers. What is happening with servers like GoToSocial is sort of like that. The difference is that the AT Protocol was designed for different app views; ActivityPub was not.

    The issue is the divergence in semantic interpretation that emerges at the interpretation layer. ActivityPub standardizes message delivery and defines common activity types. However, it leaves extension semantics and application-layer policy decisions to individual implementations. Servers may introduce custom JSON-LD namespaces and enforce local behaviors, such as reply restrictions, while remaining protocol-compliant. But, the noise created by divergences are problematic, because it creates unexpected, unintended, and unpredictable behavior.

    Divergence appears when implementations rely on non-normative metadata and assume reciprocal handling to preserve a consistent user experience. Behavioral alignment then varies. Syntactic exchange succeeds, but behavioral consistency is not guaranteed. Though instances continue to federate at the transport level, policy semantics and processing logic differ across deployments. Those differences produce inconsistent experiences and results between implementations.

    That leads to fragmentation, specifically semantic or behavioral fragmentation and an inconsistent user experiences. ActivityPub ensures syntactic interoperability, but semantic interoperability (everyone interprets and enforces rules the same way) varies. This creates a system that is federated at the transport level yet fragmented in behavior and expectations across implementations. It is funny how the thing that the fediverse touted has made the entire thing very brittle. ActivityPub technically federates correctly, but semantically falls apart once servers start adding their own behavioral rules.

  12. ### **HILO EN INGLÉS (Public-ready)**

    **(1/7) FINAL THREAD:** My 12+ day battle with @protonprivacy A case study on a critical synchronization bug and the total collapse of their technical support. #ProtonFail #GDPR #DataRights

  13. Corporate “loyalty” programs aren’t about rewarding us—they’re about tracking us. This podcast exposes how companies exploit data from their most faithful customers. Convenience is the bait, surveillance is the hook. Time to question who really benefits.
    🎧
    think.kera.org/2025/12/02/how-
    #KERAThink
    #Privacy #SurveillanceCapitalism #LoyaltyPrograms #DataRights

  14. No bark. No bite.

    The Information Commissioner's Office (UK) has shied away from enforcing data protection laws one too many times.

    Yesterday over 70 groups and experts joined ORG's demand for an inquiry into the regulator.

    Evidence shows that when enforcement goes down, breaches go up. We say enough.

    openrightsgroup.org/press-rele

    #dataprotection #gdpr #privacy #ICO #cybersecurity #ukpolitics #ukpol #datarights

  15. The ICO refused to investigate the UK Ministry of Defence for the most serious data breach in UK history – the leaking of data on 19,000 Afghans fleeing the Taliban.

    They said it was a one-off.

    But what about the 49 data breaches at the MoD over the last 4 years?

    bbc.co.uk/news/articles/cp8950

    #dataprotection #gdpr #privacy #ICO #cybersecurity #ukpolitics #ukpol #datarights

  16. For the last 3-4 years, the ICO has shifted away from using enforcement powers against public sector organisations except as a last resort.

    Since then, the ICO's own review of this public sector approach showed “the average number of reported breaches increased by 11%” and an 8% increase in data protection complaints.

    By removing the deterrence of regulatory sanctions, this approach has worsen the status quo.

    #dataprotection #gdpr #privacy #ICO #cybersecurity #ukpolitics #ukpol #datarights

  17. A slap on the wrist isn't a deterrent.

    The failure to investigate even the most serious data breach in UK history is the final straw.

    We need a strong data regulator that will take action against the government and private sector at a time of escalating threats.

    We need an inquiry into the Information Commissioner's Office if we're to have data protection laws with teeth and resilience against cyber attacks.

    #dataprotection #gdpr #privacy #ICO #cybersecurity #ukpolitics #ukpol #datarights

  18. #opensource #privacy #techpolicy #hardware #iot #surveillance #qualcomm #arduino #makers #infosec #datarights #termsandconditions #cloudcomputing | Adafruit Industries

    Qualcomm-owned Arduino has quietly comprehensively rewritten its terms of service and privacy policy, and the changes signal a clear break from the open-hardware ethos that built the platform. The new documents introduce an irrevocable, perpetual license on anything uploaded by users, mass…

    cnznews.com/opensource-privacy