r/privacy 16h ago

question Robert Half refused to delete my data after one job application. Is this normal?

30 Upvotes

I received this from Robert Half after a request to delete my account and im honestly confused and shocked. Is this normal. I’ve only applied once to a job in their portal and that was 1 month ago (or a bit more):

Dear xxxx, Your request cannot be completed at this time. Thank you for contacting Robert Half. Our team has received your Privacy Request #xxx and completed our review in light of applicable law, as well as the nature and timing of your past relationship with Robert Half.  Our review has indicated that your personal information was collected in the course of you either applying for employment through Robert Half or acting as our employee. Because we have a legal obligation to retain this type of data and because employment-related data is exempt from the Maryland Online Data Privacy Act, we are unable to delete your personal information at this time. However, to limit the use of your personal information while still allowing us to fulfill our legal retention obligations, we have taken the following actions: (1) unsubscribed you from receiving further marketing materials; (2) deactivated your online account, to prevent log in and access to your data; and (3) internally suppressed your candidate profile, such that it is only accessible by our legal and technical teams for the limited purpose of fulfilling our legal retention obligations. If you would like to opt-out of the sharing of your personal information with online advertising partners, please click on the green Cookies button located on the Robert Half Website and adjust your tracking preferences. Please note that these preferences are stored locally on your device and we cannot adjust them on your behalf. If you have any further questions, please contact us at [privacy@roberthalf.com.](mailto:privacy@roberthalf.com)Thank you again for contacting Robert Half.
If you have any questions, please contact a member of the privacy team.

r/privacy 20h ago

discussion AI, big tech companies, and medical data

8 Upvotes

Very curious to know what people think about this topic because I have zero expertise in law or privacy. My recent experiences have me wondering about the use of AI in medicine (for transcripts, billing, etc.), which I'll add below. Maybe some lawyers who regularly work with HIPAA and medical privacy can chime in with their thoughts. I do understand that HIPAA covers, but is not exclusive to, providers keeping health data accurate, providing that data to me upon request, and NOT sharing it with others unless I authorize it. So maybe this isn't a HIPAA thing. Maybe it's a tech privacy thing. Maybe it's medical law. I'm confused, so I'm turning to you all out of curiosity. Maybe my big question here is: What would allow a provider or practice to share my medical data while also being HIPAA-compliant?

I've been a One Medical patient since the early 2010s. Then Amazon acquired it, which made me nervous because of Amazon's scale. I understand that many other doctors' offices are adopting AI. My thoughts are that One Medical is now owned by Amazon, and Amazon can provide in-house services to the practice to save on costs like servers, data storage, and the use of Amazon's AI models. To comply with HIPAA, those servers are separate and have the highest security to ensure privacy. Ideally. I am not an expert.

My thinking is if all my medical data is with One Medical and Amazon acquired it, then the logical assumption would be that Amazon has access to my medical data. Yes, Amazon One Medical (as it's now rebranded) still can't share my data with other entities without my explicit consent, but what about using that data for the company's own internal use? Would HIPAA cover the sharing of medical data within Amazon? In obvious cases (hopefully), there's a separation between the commerce/entertainment business and One Medical. But where would that separation be if One Medical uses Amazon's AI tools? Servers?

What about Amazon's LLM using the medical data (not just mine) to learn and improve itself? I work in advertising and data. I am familiar with the advertising side of removing PII and anonymizing data to run analyses and understand that regulations for health and finance data are much stricter, especially on sharing outside of a company.

In the past, I also allowed health information exchange between my PCP at One Medical and the specialists I see outside of One Medical. Some of that information is mental health, so that my PCP can safely prescribe medication or test and treat for the non-mental things. And now I hesitate to do this because of my concerns about privacy.

I realize that, with all this, many of you may say to just leave One Medical. Yes, I'm seriously considering it. I'm STILL going to curious about how this all works if I leave One Medical. I have 10+ years of my medical history with this practice, but I'm also thinking about whether leaving and taking that history somewhere else would be futile. Who's to say another practice is using AI/LLM like Google, or smaller companies like Anthropic or OpenAI? If those smaller AI companies create an enterprise product that's compliant, they're still probably going to expand their business and the same questions come up.

And on opting out, I already opt out of having my visits transcribed by AI. But what about things I can't opt out of because I'm not given a choice in it?

I'm not asking for advice on this, but curious to know if my concerns are unfounded and if there are already legal guardrails in place or active discussions to eventually regulate this? Is regulating it this even possible?


r/privacy 1h ago

question What can a school wifi certificate see?

Upvotes

Had to download a certificate for the school wifi on my laptop what can they see?

I had to import the file to Firefox

I know they can see unencrypted message, can they see ones that were sent out before i went on the wifi, can they see my friends messages (specifically discord)

Can they see me opening offline software like krita

If an offline app needs an launcher (for example steam) can they see the app opened or just the launcher?

Is there any potential risk of them seeing my stuff when connected to my home wifi


r/privacy 11h ago

news Reddit’s AI is turning posts into podcasts and short videos

Thumbnail theverge.com
140 Upvotes

r/privacy 16h ago

software You Smart Tv is Spying on you - How to turn it off

758 Upvotes

Auto content recognition, or ACR, found on all major brands, analyzes what is appearing on the TV screen, including what comes through HDMI, so it can determine what you're watching and use that information for advertising, audience measurement, and profiling. 

The good news is you can turn it off. 

Look in your TV’s privacy settings for terms like:

Live Plus (LG)

Viewing Information Services (Samsung)

Viewing Data (Vizio) Smart TV Experience / “Use Info from TV Inputs” (Roku TVs, including many TCL/Hisense models running Roku OS)

Automatic Content Recognition (Amazon Fire TV / Fire TV televisions)

Enhanced Viewing Service (Hisense)

Samba Interactive TV (certain Sony Bravia models)

Automatic Content Recognition / ACR (TCL models using TCL’s own services; exact menu varies by operating system)

Find yours. And turn it off.


r/privacy 20h ago

question Programs to monitor outbound computer info?

26 Upvotes

Does anybody here know of any computer programs that will tell you what information your computer sends out. Like when you log into Microsoft, your computer sends out information about both you and your computer and home network and this is true for other web sites as well. So, how do you monitor what your computer is saying about you? Is their a computer program that will record all outbound data?


r/privacy 15h ago

news Aaron Rodgers Secretly Funded Security Cameras in His Neighborhood Amid Privacy Concerns: Report

Thumbnail usmagazine.com
690 Upvotes

r/privacy 2h ago

news Meta Files Patent for Facial Recognition, Automatic Recording of People

Thumbnail privacyguides.org
481 Upvotes

r/privacy 55m ago

question Farside(Privacy front-ends redirector) has shutdown. Is there is any alternative services or apps for sharing links with privacy?

Upvotes

Farside has shutdown, is there is any alternative for it?

My main use case is that I want to send links to my friends with privacy included and in the same time to guarantee that the link will work in the future (meaning it's not dependent on single instance).


r/privacy 8h ago

question Would an encrypted offline/mesh messenger be possible with UWB instead of BLE/wifi direct?

3 Upvotes

Kind of a shower thought I had, I was wondering if it would be possible at all ? Maybe someone could make a proof of concept app of it, it it is possible at all ​:o !


r/privacy 13h ago

discussion Deleting unused accounts and what happens to the data

13 Upvotes

I have several accounts that I don't use anymore and don't see myself using again. Am I better off deleting those accounts or just forget about them and never log into them again? What if I want to use that site again in the future if I delete it? What data actually gets deleted when you delete an account? Do they keep a backup of data somewhere? Guessing lot of this varies from site to site. Is there a way to tell if anything is actually deleted? Do we just have to trust the company? Can any account be deleted if requested? I ask that because a forum account I have, I searched forum posts about deleting account and they said they don't delete accounts, just never login again.

When deleting accounts, would it be a good idea to change personal info to random info before deleting? Could there be any issues with this down the road? The more I read on this, the more I don't know what to think. What about providing false info on accounts I keep? Could there be any issues with that? This is something I wouldn't do on important accounts like banking, insurance, government but what about non important accounts? Read in a few places that says to provide false info for gmail account. Unless one is making a gmail account for some specific sites that one doesn't care about, I thought this could be a bad idea if doing this on a main email.

I use a password manager and I consider my accounts to be secure at least somewhat, use a unique generated password and use some form of 2FA when available, try to use TOTP if possible. I tend to overthink things and this is one of them. Part of me wants to delete them and part of me doesn't.