LOGBOOK

HELP

1 / 36
Other keys: showSpace: good1-4: rate0: skip5: flag

Question

The shopping app Temu is a well-known case study in privacy risk. What does it reveal about "automatic data collection" and the limits of claimed anonymization?

Answer

Temu's privacy policy describes broad "automatic" data collection without explicit consent, and it claims to anonymize the data, but experts warn that de-identified data can still be re-identified, so the anonymization claim offers little real protection.

The automatic-collection problem. Temu's policy lists a striking amount of information it gathers automatically, without asking the user first: operating system type and version, device manufacturer and model, browser type, screen resolution, RAM and disk size, CPU load, device type, IP address, unique identifiers (including advertising IDs), and general location. None of this requires you to fill in a form, it is collected in the background simply by using the app.

The anonymization claim. Temu states it may use the collected data broadly (for research, development, and "improving our service and business") and claims to anonymize it, but provides no concrete detail on how. The source quotes Calli Schroeder, a privacy lawyer at EPIC (the Electronic Privacy Information Center): de-identified data removes explicit identifiers like names, but it often still contains several personal data elements that can be linked back to a person through a number instead of a name.

Why it matters. Studies show that location and purchase data alone are frequently enough to re-identify individuals. This is the same re-identification risk that PETs are designed to counter, and it shows why "we anonymize your data" is not a guarantee of privacy. The case study's real lesson: read privacy policies critically and understand what apps actually collect and how they use it.

or press any other key

Question

For cookie consent, Swiss law and EU law take different default stances. How do nDSG (Switzerland) and the DSGVO (EU) compare on opt-out versus opt-in?

Answer

For standard cookies, Switzerland generally allows opt-out (an informational banner with a right to object), whereas the EU requires opt-in consent. For sensitive data and newsletters, both require opt-in.

Aspect Switzerland (nDSG) EU (DSGVO)
Standard cookies Mostly opt-out (banner with information and a right to object) Opt-in is mandatory
Sensitive data Opt-in required Opt-in required
Newsletter Opt-in (due to the UWG, the unfair-competition law) Opt-in
Focus Transparency and good faith ("Treu und Glauben") Explicit consent

The key takeaway. The EU's default is "ask first" (explicit consent), while Switzerland's default for ordinary cookies is "inform and allow objection." But this Swiss leniency is narrow: it only covers standard, non-sensitive cookies. The moment sensitive personal data is involved, or you want to send a newsletter, Swiss law also demands opt-in. A common mistake is assuming Switzerland is "opt-out for everything" — it is not.

or press any other key