upvote
Any kind of lending facility, for example, is required, by law, to retain identity documents for an extended period of time - we're talking around five years _post_ account closure.

So most businesses are not permitted to just delete the data.

reply
I believe we need to criminalize possession of the data, with statutory damages per violation.
reply
Some laws for protection do exist — eg requirement that sensitive data needs to be kept on systems that have been pen tested. But those laws are hardly ever followed and authorities have no real way to check if the 'protected' status of digital storage is actually maintained. What's worse is there are actually voices inside the government that are calling for an end on encryption stating that it encourages criminal activity.
reply
Exactly. Personal data should be treated like radioactive material. Strictly regulated to such an extent that no one wants anything to do with it unless they absolutely have to use it in the course of their business. After that, their primary concern should be how to dispose of it quickly and safely.
reply
Not quite the same, but the GDPR gives you a right to erasure.
reply
Negligence is already illegal.

Just locate a prosecutor.

reply
It's not clear that this came from a point in time dump, but like it has been getting harvested by someone for awhile. They may be deleting it, but by then a copy is made? Speculation after reading the article but that's what it sounded like to me.
reply
Good point, "we have been continuously exfiltrating new data for over a year into our private database". I missed that line on first read.
reply
It's obvious they are keeping them all. 150 million didn't get all re-scanned at once.
reply
The whole point is they keep it forever. You think any id verification services actually delete the data?
reply
I mean, just because all your friends are jumping off a cliff...
reply
It feels like we need to tweak the analogy for the surveillance industry. Something more like if all of your friends are pushing people off a cliff...
reply
If you and your friends are all sociopaths, you're going to feel left out if you don't join in on the cliff jumping.
reply
The last time I had to read a law about ID verification it required keeping that data for a number of days. They wanted you to have it available in case something happened and the police opened an investigation.

Combine that with a service that is compromised unknowingly for a long period of time and the attackers can siphon out a lot of IDs. Even a service which didn't retain IDs could leak a lot of data if the attackers tapped the verification server and exfiltrated all IDs as they passed through

reply