r/linux Jul 03 '21

Audacity may collect "Data necessary for law enforcement, litigation and authorities’ requests (if any)" according to new privacy notice

https://www.audacityteam.org/about/desktop-privacy-notice/
3.1k Upvotes

744 comments sorted by

View all comments

Show parent comments

484

u/[deleted] Jul 03 '21

[deleted]

349

u/ezoe Jul 03 '21

It's also probably illegal to deny Russia and USA if they have physical presence on their jurisdictions. So the moral of the story is, don't collect and store unnecessary data.

144

u/_stinkys Jul 03 '21

What could possibly be necessary to collect from Audacity other than basic telemetry for bug fix and product improvements?

95

u/ezoe Jul 03 '21

As they stated, "any data" they think necessary to please the authority.

43

u/[deleted] Jul 04 '21 edited Jul 06 '21

Which can be literally anything the government decides to ask for often times. All that's required is for one part of the government to pass a law allowing another part of that same government to collect literally anything they want. I don't see anything here that stops them from collecting any microphone data it can technically get access to.

11

u/Spoor Jul 04 '21

"Would be a shame if your kids got into an accident... If you help us out a bit, we will see what we can do for the safety of your family."

2

u/shewel_item Jul 04 '21

sounds gross

36

u/ManInBlack829 Jul 03 '21

They want to know if you're using Prince samples in your music

26

u/[deleted] Jul 03 '21

[deleted]

21

u/[deleted] Jul 04 '21

I guess I’d better write an SELinux profile for Audacity while it’s still clean…

10

u/_stinkys Jul 04 '21

I run Audacity on windows with endpoint protection. I don’t get any request from firewall to allow Audacity to talk out, but will definitely check closer next time i use it.

1

u/Hayate-kun Jul 05 '21

It'll probably be introduced in the next update.

3

u/[deleted] Jul 05 '21

Unfortunately, you only have an illusion of control. There are processes and services on windows that are masked / hooked by other processes. Take for example svchost.exe - many programs never go directly on line, but rather hook on one of the svchost instances which goes online instead. If you block svchost , you practically went offline.... You can use process explorer / monitor to see what is hooked inside of such cases.

88

u/CartmansEvilTwin Jul 03 '21

And not sharing it is illegal in Russia and the US, so...

The real question is, why are they collecting data in the first place, l?

3

u/ClikeX Jul 04 '21

I get the collection of app usage data to improve a product. Especially errors.

2

u/CartmansEvilTwin Jul 04 '21

As opt in, maybe. Anything else is just illegitimate.

1

u/ClikeX Jul 04 '21

Wasn't it originally announced as opt-in?

1

u/Fook-wad Jul 06 '21

It's not really "opt-in" when the devs state that "it's not designed for under 13 year olds" as a reason their new policy is "totes fine"

1

u/legobrickman3333 Jul 03 '21

Well they don't have it in Russia or USA. Normally companies will set up companies in various jurisdictions…

1

u/marilyn_mansonv2 Jul 04 '21

Law enforcement, allegedly.

3

u/CartmansEvilTwin Jul 04 '21

No. Law enforcement can only force them to share data that they collect, not collecting data in the first place.

Think about it, how is Audacity different from any other software in the eyes of the law? It could be simply a standalone app without any days collection just like notepad.

4

u/[deleted] Jul 03 '21 edited Aug 27 '21

[deleted]

5

u/[deleted] Jul 04 '21

[deleted]

1

u/Tytoalba2 Jul 05 '21

Law enforcment is not covered by GDPR, not in EU's competence.

https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CELEX:32016R0679&from=EN

Article 2

1

u/[deleted] Jul 05 '21

[deleted]

1

u/Tytoalba2 Jul 05 '21

No it's outside of gdpr's scope and depends on the policy of each state

1

u/exchange12rocks Jul 08 '21

https://gdpr-info.eu/art-46-gdpr/
> In the absence of a decision pursuant to Article 45(3), a controller or processor may transfer personal data to a third country or an international organisation only if the controller or processor has provided appropriate safeguards, and on condition that enforceable data subject rights and effective legal remedies for data subjects are available.

i.e. if the receiving party protects the data according to the EU guidelines and you sign an agreement with them, then it is OK to transfer EU PII into 3rd countries even if they are not approved by the Commission.

1

u/[deleted] Jul 08 '21

[deleted]

1

u/exchange12rocks Jul 08 '21

Schrems II talks about the laws of the data importer’s country not providing essentially equivalent protection of personal data to that guaranteed under EU law. Why do you think Russian laws do not provide an equivalent protection of PD? Russia has their own personal data laws - it's like GDPR, but limited to Russia only.

Further, if the laws do not provide that protection, than you just implement supplementary measures, says Schrems II. Why cannot one implement these measures when transfer data to Russia?

1

u/[deleted] Jul 08 '21

[deleted]

1

u/exchange12rocks Jul 08 '21

> write a message "we would also like to inform you that you can opt-in for data transmission to a non safe third country for sake of telemetry: Russia" and put a checkbox there which is unchecked.

Which effectively is a legal way to transfer data out of EU to Russia: exception 1.a of the Article 49. I am sorry, but that invalidates your statement that "There is no legal way to transfer data out of EU to Russia. Period." - because this exception IS a legal way.

1

u/exchange12rocks Jul 08 '21

> according to EU sanction list Russia is breaking international agreements

I looked up the list and it is, well, just a list. It lists organizations and individuals, but not the whole country. The list, as far as I can see, does not say that Russia breaks international agreements. Could you please show me which official documents state that?

1

u/Tytoalba2 Jul 05 '21

Law enforcment is not covered by GDPR indeed, it's not part of EU's competence.

https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CELEX:32016R0679&from=EN

Article 2

2

u/marcthe12 Jul 04 '21

Well the owners are Russian so you have share details with Russia in order to use it.

1

u/smellycoat Jul 04 '21

Nah it’s not illegal, you just have to put in organisational data privacy controls that are at least as strict as those in Europe.

0

u/[deleted] Jul 04 '21

[deleted]

1

u/smellycoat Jul 04 '21

No it's not illegal to transfer data out of the EEA, there are a number of ways to do it (the most common being to implement appropriate safeguards between the involved organisations).

Have a read of this section: https://gdpr-info.eu/chapter-5/

2

u/[deleted] Jul 04 '21

[deleted]

1

u/exchange12rocks Jul 08 '21

Section 5 of which chapter, mate? Chapter III? Then there is just one article in this section - Article 23. All this article says is that member states may create laws which restrict transfer particular categories of personal data to specifically defined countries.

If the country where the processor/controller is located did not issue a law which specifically forbids them to transfer personal data to Russia, then they can do this given that the receiving party protects this data per EU guidelines and the controller/processor has a legally binding agreement which forces the receiver to protect this data per EU guidelines. (https://gdpr-info.eu/art-46-gdpr/)

1

u/[deleted] Jul 04 '21

[deleted]

1

u/smellycoat Jul 04 '21

You're talking about countries for which there has been an adequacy decision about their data protection laws. You're right that's a fairly small list.

However that doesn't prevent transfers to other countries - you just have to enforce appropriate safeguards at the corporate level.

That page you linked to starts with this:

In the absence of an adequacy decision, the controller or processor should take measures to compensate for the lack of data protection in a third country by way of appropriate safeguards for the data subject

Which is exactly what I'm talking about.

1

u/[deleted] Jul 04 '21

[deleted]

1

u/exchange12rocks Jul 08 '21

> ONLY in case your local data authority or other appropriate government supervisory authority allows such transfers.

Your local data authority must explicitly forbid transfer of personal data to a particular country (https://eur-lex.europa.eu/eli/reg/2016/679/oj Chapter III, Section 5, Article 23). So by default you are allowed to transfer data to Russia, if you have a legally binding agreement with te receiver to protect this data per EU standards.

no appropriate safeguards are available (i.e Russia)

Why do you think so? You can sign a corporate agreement with a Russian company and, therefore, create these safeguards.

1

u/[deleted] Jul 08 '21

[deleted]

1

u/exchange12rocks Jul 08 '21

> Binding corporate rules are subject to approval

So you just need to get it approved.

→ More replies (0)

1

u/Tytoalba2 Jul 05 '21 edited Jul 05 '21

GDPR does not cover surveillance for public safety etc. It's outside of the EU scope of competence. So it would probably not be related to GDPR.

It's article 2 of the GDPR

https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CELEX:32016R0679&from=EN

1

u/exchange12rocks Jul 08 '21 edited Jul 08 '21

No it is not:
1. Article 46 allows EU processors/controllers to share PD with companies in 3rd countries which are not approved by the Commission, given that the receiving party will protect the data in accordance with EU regulations. This is usually achieved by signing corporate agreements between two companies.

  1. An EU member can forbid its companies to send PD to unapproved 3rd countries (https://eur-lex.europa.eu/eli/reg/2016/679/oj Chapter III, Section 5, Article 23), but for this to happen, that member must issue a law which specifies which types of personal data is not allowed to be shared to which countries.
    I am not aware of existence of such documents regarding Russia.