ADVERTISEMENT

ISP selling data: why you should actually care

Bernard Meyer
Bernard Meyer Senior Researcher
October 3, 2019 Updated: October 11, 2021 3 min read

Should you really care about your ISP selling data?

Cybernews pro tip

Increase your online security and privacy by sending your data through an encrypted tunnel.

Protect your data now
ADVERTISEMENT
  • USA – In 2016, the FCC mandated that ISPs would have to obtain consent for information harvesting, but officials from the Trump administration rescinded these regulations back in 2017, before Congress rejected them, and Trump signed his ISP Privacy Bill into law in April 2017. This made harvesting information absolutely legal. So users in the US have very few protections unless they use a VPN.
  • UK – The situation is different in the United Kingdom, where citizens can now ask ISPs to remove their personal data under a version of the "right to be forgotten." However, at the same time, the Investigatory Powers Act 2016 forced ISPs to retain certain data for security reasons. It looks like "best practice" guidelines discourage selling this data, but the UK's protections are far weaker than the EU.
  • EU – The European Union introduced the landmark General Data Protection Regulation back in 2017, which made it very difficult for ISPs to capitalize on user data. Everything they do regarding data now has to be subject to informed consent, with huge fines for breaching these regulations.
  • China – Chinese data laws aren't as transparent as those in the USA or Europe, but we do know that there have been cases of data reaching the open market – such as insurers accessing detailed information of when car insurance policies are up for renewal. China's digital environment is like the Wild West in terms of data at the moment, making VPN use highly recommended.

Nobody is safe from the shadow data market

VPNs: the solution to ISPs selling browsing history data?

ADVERTISEMENT