I can't help thinking of the DoD's definition of 'collection', where gathered data has to be processed and analyzed to count as 'collected'. Even if the bot doesn't do anything more sinister than phone home with error logs to help fix bugs, that should still be viewed as compromising the identities and message contents of everyone participating in the chat.
> where gathered data has to be processed and analyzed to count as 'collected'
I thought even then they didn't count it as "collected" until a human sees the result.
So they could ~~collect~~ record all your conversations, ~~analyze it with a computer~~ have a computer analyze it, and then then only have a human look at it if they think they will be able to justify having collected it.
> I thought even then they didn't count it as "collected" until a human sees the result.
Yeah, I was never quite clear on whether it meant "scraped for data" or "scraped for data and then that data was used". I tried to look it up before I posted, but since "we don't collect..." seems to have been a lie under any of those definitions, I'm not convinced it actually had a clear 'technical' meaning.
Of course, if reading algorithmic output without specific records doesn't count as seeing the data, there's always the possibility that info is making it all the way to the 'trigger a drone strike' step without ever being "collected"...
Ah I see, so it's the same as when I buy food at the grocery store, store it in my freezer for a month, cook it and then finally eat it during lunch. It doesn't count as being collected until I eat it since I obviously don't know if it tastes good until then.
Gather enough non-PII data and that trove of information can sometimes itself build an identifiable picture of a person. PII in aggregate is still a problem in a GDPR conscious organization.
Is that the same as "doesn't"? And does that apply to all the other components that get access to the chat logs it sends back home?