How we can build web applications that respect the user's privacy

This video features Hanna Kollo at DjangoCon Europe 2024 in Vigo, Spain.

How we can build web applications that respect the user's privacy
0:21:31
Published July 10, 2024
333 views

Talk: How can we build web applications that respect the user's privacy by Hanna Kollo

https://pretalx.evolutio.pt/djangocon-europe-2024/talk/ZY7T3J/

Summary

Privacy begins with treating every piece of user data—including metadata such as searches, clicks, timing, navigation paths, and locations—as sensitive. Hanna Kollo argues that developers must think like both users and custodians of data: collect it for a clear purpose, limit access, know where and how long it is stored, delete it automatically, and anonymise it as early as possible. She illustrates the risks through a hobby app whose social login exposed far more personal information than users might expect, and explains how GDPR and the Digital Markets Act shape data handling. She closes by recommending that developers listen to children, whose direct questions often reveal privacy and usability concerns adults may not express.

Key takeaways

  • Metadata such as searches, clicks, locations, and navigation history can reveal a great deal about users and deserves careful protection.
  • Social login can grant an application access to far more personal information than users realise, so convenience should not override informed consent.
  • Developers should define the purpose of each piece of data, restrict access by need and duration, track retention, and automate deletion.
  • Anonymise data as early as possible, while recognising that techniques such as k-anonymity and differential privacy require careful implementation.
  • Privacy responsibilities include earning and maintaining user trust as well as complying with regulations such as GDPR and the Digital Markets Act.
  • Children’s candid questions can expose important privacy, security, and user-experience problems that adults may leave unstated.

Summarised automatically from the transcript.

Transcript

3,318 words · auto-generated Show

Automatically transcribed, so expect mistakes in names and technical terms.

0:00

Thank you Daniele, thank you everyone. So last time I gave a talk at Django Crony in 2015, I was very junior, very experien inexperienced, so hopefully this will be a bit better now, but we'll see. So today's topic uh is about about uh privacy. Privacy is a hot topic um for everyone who builds web applications and I will go I'm going to tell you some stories about my recent life of how it is a hot topic for me and I'm going to talk about some uh experiences that I had which were outside work through volunteering where uh the children uh that I was teaching were asking me questions about privacy.

0:45

in a very surprising and I think interesting way. So, uh hello again. Uh a bit about myself. I'm Honma Kele , Hungarian as Tamina said. I'm a senior software engineer. been in the industry for at least fifteen years. I um work with big data. That's what usually I say to people who are not in IT. Uh for people who are in IT I say a bit more. So I am um Working in a team at a big tech company, uh building a data analytics platform for this tech company. Uh and about you, as I imagine, and my target audience, you are jungle. developers who build web applications

1:33

and these web applications do contain almost always some sort of user data and therefore privacy is a a question. So what is actually Actually, user data in in the context of today's talk. For example, uh in case of uh Google, your search query history is user data. Or in case of a social network, your tweets of posts or reels uh are user data. Personal photos, you upload them somewhere. That is user data in a uh in a next level way, very private. Uh location history. is also user user data. So if the app is location

2:18

based that you're using or you're developing, uh you think twice if you want to trust this application with sharing your location history or not. And uh Comments and likes are also user data, maybe not that sensitive as location history. And there's metadata, which is also in this context user data. And in fact, I'm gonna focus on that more. So metadata is like what pages you visited, what buttons you clicked, when did you click them? Uh where did what was the the the chain of the the the clicks how you got there? Because you actually uh can find out a lot about the user just by this metadata. So That's really much very much in focus and in fact

3:04

I'm going to focus this talk on the metadata mostly because my I'm the principle going to apply for all of them, but I'm going to focus on the metadata. because everything else is uh domain specific. So if you have uh a finance app then the finance rules apply and that domain is even regulated regarding you uh with regards to user data or if you do a health app then that domain is also has its rules. So uh for domain specific user data you need uh a specific specific talk per domain. So I'm not going to cover all of those. Let's focus on the metadata for today and um the principles will apply anyway for the others.

3:51

Let me start with a small story. About ten years ago I created a hobby project in Django. at home uh in my private time and this uh project was uh a website where you could uh upload photos of your food. So the idea was that uh when you sit down in a restaurant or made a beautiful meal at home, you take a photo it and you send it to your friends. So I wanted to build an app where you take a photo, you upload it to this website, and uh you uh you see a news feed from other people who you follow uh with their photos and uh You even can can share the location of where you put this photo. That was the idea. And I built this.

4:37

Um and I wanted to save some time, and I didn't want to implement the login mechanism. Mechanism myself, so I said I'm going to use social logging. So there's just some Django plugin or a library for using Facebook authentication for logging into your website, so I'm going to just use that. How to use the Facebook API and how to implement social login. And once I did that, I was a bit surprised because the thing is If you uh if the user of your website agrees to use social login, uh then the website's developer, in this case

5:24

me, gets a lot of information from that user. Things that this user might not consciously uh would be willing to give you, but it's all hidden. So the user, especially if the user is not tech-savvy, will not know. Things about like the full name of the user. The date of birth, the email address, anything public on their Facebook page, like are they married, or who are their friends? All of this, all of this, I got as a developer of this project just because Because the user agreed to use social logging to my website. And as a u as a developer I was like, if my users

6:11

would know this, I'm not sure they would like. I'm not sure they would like to give this data to me. I mean my personal friends were my first users for this web application, so they would o be okay with this, maybe. But even they would like, Hannah, you are a j junior developer I'm not sure if you w what I what are you going to do with this data? Are you going to store it? I'm not sure what we're gonna do with this in the future. And even unintentionally, uh your website might be um uh subject to a cyber attack then the data might get stolen. So I'm not sure if I want to give this data to you. So I just had this thought and I meant a man made a mental note about this being a problem.

6:57

This really is a problem. And this this website was about photos, so uh photos are really personal information, even if it's just about food, and especially if you share the location, then uh one level up. Right. So I really need to uh not risk the trust that the users of this web application have in me with any sort of privacy incident or just sloppy handling of Of the topic of privacy, because I need to get and keep the trust of these users and the data that I uh that I store. So actually, I think two-thirds of the thinking

7:43

went into the privacy concerns when I build this application. And only one third went into the actual features and the development of it. That's the story. And now fast forward nine years , I work at a company which has a app with uh one billion users or more. So I work at Google, that's the company I work at. Um but by the way I'm speaking here on my own account, uh paying my own tickets. Uh I'm not speaking on behalf of of of Google. Anyway, I work in Google Maps, which is a location based app. It has an Android app and an un uh iOS app and a uh a web surface

8:28

and it stores stores fine grained location. So uh Google Maps is not working unless you give uh well most features of the app are not working unless you give the application permission for your fine grained GPS based location. Right? So that's I think super sensitive data, especially if you have the history as well. I have a question to the audience. How many raise your hand if you have used Google Maps today to navigate here? Thank you. Um thank you. Yes, most of the people. Just so you know, if you search for something, if you type something in a search bar.

9:15

That is remembered, stored by Google for some time. If you clicked on a button, Google knows what you clicked, when you clicked it, where you were when you clicked it, in what order. you visited the pages within Google Maps. And if you started navigation, where did you navigate to, how long did it took, when did it start, when did it end, and so on. And Google stores it, this data, and keeps it for um a long time. How long? It's all in the privacy policy. Do you read the privacy policy of Google?

10:04

Yeah. Uh sorry, if it's an understanding question you can ask, but otherwise let's keep it for look later. Okay. I also didn't read the privacy policy, by the way. I don't do that. I tend to And uh at work I have to read so many policies that I just save some time of not reading any any uh extra one which I don't have to. In case I have a legal question I would then go and read the policy. But normally I would just click I I read and accept and then move on. But yeah, um what the point I'm trying to make here that there is a serious privacy a question here, so uh and rightfully so. So there's a lot of scrutiny from users like you and from the media and legal entities.

10:55

Uh for every application, but especially for big applications which have A lot of users and therefore more economic power and so on. So there's a lot of privacy scrutiny. So I learned a lot about how to handle user data at this big uh application, and I'm going to share you some. learnings. So um I think what uh what you need to uh use as a as a as a guiding principle is that you have to wear two hats. As a developer as a does as a user for everything that you do. And me at Google Maps, I'm a user and a developer, no question about that. And at my uh Django project, uh the Hobby project, I was also a developer and a user at the same time.

11:43

And I suppose when you create your own application you are probably a user as well. So you need to wear those two hats and sometimes you have to temporarily forget that you are a developer and only use the wear the user hat. Sometimes you need to wear both and sometimes you need to wear just the developer hat. So, I'm gonna talk briefly about the problems we are facing. I give you some tips and guidance, and I show you share some stories. So, the problems we are facing as developers are one, the users care about their data as they should. So uh why is this a problem? It's because uh you you must respect w m you uh you need to care about your users because you're building for them. They you will not succeed without

12:29

uh The users succeeding. There is power in your hands. Why is this a problem? Because with great power comes great responsibility. And great responsibility is you know a weight on your shoulder and you have to do work. To fulfill that responsibility. Trust is hard to gain and easy to lose. I think I touched on this before. There might be privacy incidents. We have that all every time in the news that this and this company had uh leaked photos or leaked passwords and so on. Uh you really don't want your uh web application to show up in the news in that way. And lastly there are regulations.

13:15

Uh there's GDPR, which is I think a great regulation, and not every country has it, by the way, but at least in the EU I we are pretty good there. And uh there is DMA which is uh more recent and not a lot of people know about it. It uh it's called Digital Market Act and only applies to big applications. Big is defined by the law, so maybe your application is not subject to it, but maybe it is. Google Maps is certainly a subject to DMA. So uh DMA is about um uh uh a rule that Google cannot share the data that it got in Google Maps. It cannot share that data with other parts of Google, for example YouTube or search or ads.

14:00

Unless the user explicitly gives permission to that. So uh this is like siloing big companies into smaller uh chunks and unless the user gives explicit permission uh to to cross-share this data, uh they will not be able to, which is in my opinion a very good thing. However, it comes with annoying pop -ups with questions, which is like, you know, uh annoying. Also it doesn't apply for every kind For example, Switzerland doesn't have DMA because it's not in the EU. Also the US doesn't have DMA. And uh if you are if you didn't hear about hear about DMA then you're lucky because uh I did hear about DMA and my team, which is managing the user data for Google, um

14:49

has worked on the DMA compliance for more than a year. I was working on it. Okay, tips and guidance. Data governance. Data governance is you should know what data you have, where you have it, for how long you want to keep it. Ideally have automatic deletions at the end of this, so expire it automatically. Um and and be careful about not leaking this data. Next, ACS. You should ensure that only the people who absolutely need to access your user data have access To this user data and only for the time and for the scope that you absolutely need to give them access to.

15:36

It's a lot of uh bureaucracy, but you have to do this if you handle user data. Next, know the purpose of um Of what you want to use this user data for. Because the user gives you consent for a specific purpose, that you want to ha uh use it for showing targeted ads or personalized recommendations or train machine learning models, or maybe sell it for free. I don't want to sell it, but uh that could be a purpose. And lastly, anonymization. Anonymizes user data as soon as possible. Uh and that's not an easy thing to do. So I'm going to dive into anonymization just a bit. Oh, okay. Um so I don't want to sorry for the for the slides messed up.

16:21

I don't want to spend too much here. I just wanted to put on this slide because I first thought I'm gonna make this a very technical talk, but then I decided not. But I still keep this slide in case you want to uh Google a bit more or research a bit more about how to do anonymization. There are two keywords you have to uh remember and these are exactly those which are not visible. So first is K anonymity and the second is differential privacy. And in the interest of time and because we are almost at the end of the day, I'm not going to dive into what those mean. Okay? Uh you can take a photo if you want, I'm going Go next. So uh what I wanted to

17:07

have this slide first. We have a personal story. Uh in my free time I'm doing volunteering work and I'm teaching children. Uh Uh I mean I teach them English and computer science, but in this particular case I was just telling them about my life story to show them uh uh how to be how how is life as a software engineer. Earlier today at the jungle girls talk there was a uh a comment about how important it is to have role m role models. I think that's absolutely true. So I'm I was trying to be a role model for these kids. And here comes the interesting, the story part of the talk. These children always ask me very, very interesting questions. So, the stories. The questions I usually ask, like, if I search for something on Google, how long will Google remember it?

17:57

I almost always get this question, and they almost I was always surprised by the answer. Like I usually just say more than a year. Whoa. I didn't expect that. And then I ask I I get questions like which one is which app is more secure? What uh what's up or signal? And it's just they're testing me because Because they usually know the answer that it's signal. And what's your recommended way to send private photo to a friend? That's usually one of the most interesting questions. I'm not gonna answer that here. And the most interesting question I got is the following. Uh it's a bit long. If I am uh at home on the Wi-Fi

18:43

network, on my laptop and I open an incognito browsing window and I log into my Google account, but I'm not yet 13 year old. So my Google account is linked to my mother's account through family link and I search for something. Oh Will my mother see my search results? What I searched for. That's the question. Swart kids. And in this time we were sitting in a circle and when this question uh happened all the kids were at the edge of their seats like I I I really want to know the answer to this one. And I said

19:29

no she won't and I went I remember whoo and uh that's the the the the main story that I wanted to share and one addition to this is after this session the the teacher thanked me and I said goodbye to the kids and we went out, the teacher walked me out, and a teacher asked me, um, what's an incognito browsing window? Yeah. So um and this These are the people, uh the teachers who are teaching the children, uh this case twelve years old children, um how to use the internet. I mean it's very hard to be a teacher, especially if technology is

20:14

uh Uh I have a high respect for the teacher but their work is very hard, especially if technology is is is uh evolving so fast. So I'm not uh I don't want to make the teacher being ridic ridiculed, but uh perhaps it's our job to actually have them need some materials to but know what an incontour browsing window is and know a lot more so that they can teach the kids how to use the internet in a responsible way. So that was the most amazing question that I ever got. And I want to have some concluding thoughts. Um basically if you want to understand your user, you can learn a lot from children because they will say exactly what they think and they will not sugarcoat it for you. Not like uh

21:00

a grown up would even in uh e even a a friend who you trust. And uh if you talk to children you will understand their concerns in a way that grown ups will never tell you and this applies to more broadly than privacy. Because even for UX design and other things, you can learn a lot from children. So my advice to you, uh learn from children when when you design their applications. Thank you.

Questions this talk answers

What counts as user data in a web application?

User data includes obvious content such as searches, posts, photos, locations, comments, and likes. It also includes metadata such as pages visited, buttons clicked, click order, and timing, which can reveal a great deal about a user.

Discussed at 1:33

What privacy risks come with using social login?

Social login can give an application far more information than a user may realize, including their name, birth date, email address, friends, and other public profile details. Developers then have to protect that data from careless handling or breaches, even when users did not knowingly intend to share it all.

Discussed at 5:24

What is the Digital Markets Act, and how does it affect user data sharing?

The DMA restricts large companies from sharing data collected by one service, such as Google Maps, with other services like YouTube, Search, or Ads unless the user gives explicit permission. The aim is to keep services’ data separated, although it can result in additional consent prompts.

Discussed at 13:15

How should developers protect user data in a web application?

Developers should know what data they hold, where it is stored, and how long it should be retained, with automatic deletion where possible. They should limit access to people who need it, define the purpose for using the data, and anonymize it as soon as possible.

Discussed at 14:49

Can a parent see a child’s Google searches when the child uses incognito mode and Family Link?

In the specific situation described—an under-13 child using a laptop at home, signed into Google through Family Link—the speaker answers that the mother will not see what was searched.

Discussed at 19:29

Presenters

Note: We understand that names change, people change, and bodies change. We respect each individual's journey and privacy. If you have any concerns about a video or need us to remove content, please don't hesitate to contact us. We will handle your request with care and promptly address any issues.

More videos from DjangoCon Europe