...so maybe they should keep their hands off the aggregates as well?
For the surge pricing, I'm a bit at a loss, because you don't need personally identifiable data for it, just a request counter per area ID, right? Maybe I don't understand it right though...
Also, the reasoning should be the other way around: if I cannot provide a service respecting the basic privacy of my users, I should not be providing a service.
> I'm not sure I quite get what you mean. How do you produce an aggregate without profiling customers on an individual basis?
You can easily calculate the average of a set without keeping every individual member of the set by updating the running average each time a new data point comes in. You still collect individual data, but destroy it as soon as possible.
> Secondly, I don't see how a company like Uber can use their data to power something like surge pricing while following the exact letter of the BDSG.
Then Uber should be banned and its employees and shareholders punished appropriately. I don’t see how “this business model can’t work with this law” could possibly be an excuse to ignore the law. Protection rackets don’t really work with the exact letter of the law, either.
Now contrast this e.g. to the principles of data protection that Germany has imposed...(http://en.wikipedia.org/wiki/Bundesdatenschutzgesetz)