The Great Privacy Policy Email Avalanche

The Great Privacy Policy Email Avalanche

Personal email gdpr net-neutrality privacy

So here's what my inbox looked like this morning: forty-one unread emails, and I'd say thirty of them are some variation of "We're Updating Our Privacy Policy" with a little padlock icon or a friendly cartoon shield graphic. Airbnb sent one. So did LinkedIn, Spotify, IFTTT, Todoist, some mailing list I signed up for in 2014 to win a t-shirt, and a web host I'm pretty sure I stopped using three years ago. GDPR kicks in on the 25th, which is four days from now, and every company on earth that has ever collected an email address is apparently required to tell me about it personally.

I want to be clear that I think GDPR itself is good, or at least good in the way that eating vegetables is good, not fun, mostly correct, overdue. Companies hoovering up data with zero accountability has been a genuine problem for a decade and somebody finally wrote a law with actual teeth (fines up to 4% of global revenue will do that). But the compliance theater happening in my inbox right now has almost nothing to do with any of that. It's mostly just liability CYA emails, worded by a lawyer, sent to everyone regardless of whether they're in the EU, because nobody wants to be the company that skipped the memo. I'm in the US. My data protection rights under this new law are, generously, unclear. I'm getting the email anyway.

The genre has a formula already and it's only been a week or two of this. Subject line with an emoji or exclamation point. First paragraph explaining that "your privacy matters to us" (does it though). Second paragraph, three sentences, that actually says something, usually "we've updated section 4.2." Then a big blue button that says "Review Changes" which I have clicked exactly zero times because nobody is reading a privacy policy at 11pm on a Tuesday, least of all me, and the people who wrote it know that too. It's a legal artifact, not a communication. I appreciate the honesty when a company just says "here's the new policy, link's at the bottom" and skips the theater. Basecamp did that. Fastmail did that. Most didn't.

My actual, unhedged opinion: this is going to get worse before the 25th and then quietly disappear from my inbox forever, the same way every "we miss you!" re-engagement campaign eventually does. I already unsubscribed from four lists today purely out of spite, not because I cared about their data practices, just because getting a privacy email from a company reminded me I never use their product and don't need to be on their list at all. So in a weird roundabout way GDPR is doing some inbox hygiene for me that I never would have bothered with otherwise. Silver lining, I guess.

Meanwhile, actually important internet-policy news got buried under all this. The Senate voted 52 to 47 last Wednesday to overturn the FCC's net neutrality repeal, using the Congressional Review Act, with three Republicans crossing over. It's mostly symbolic, the House isn't going to touch it, and everyone involved knows that, but it's still the first real vote where a majority of the Senate went on record against the repeal, and I think that matters more than the privacy policy avalanche does, honestly. Nobody I know outside of tech circles even mentioned it to me this week. Everyone's talking about their inboxes instead, myself very much included right now.

I've been running this blog since November 2011 and I don't think I've ever written a post that was basically "email is annoying," but here we are. Four more days of this. I'm tempted to set up a filter that just auto-archives anything with "privacy policy" in the subject line until June, and I might actually do it tonight instead of writing the rest of this post. Actually, no, I just did it while typing that sentence. Filter's live. We'll see how long it holds up once the real deadline emails start hitting on the 24th and 25th, which I suspect will be a whole second wave worse than this one.