Scanning QR codes to induce membership and forcing location information are illegal! More than 500 companies in Shanghai have been interviewed

Release time:Apr 24, 2024 02:50 AM

It is a common consumption scenario to open a drink mini program to order remotely and then pick up the meal after scanning the QR code to place an order. However, in the eyes of Shanghai Cyberspace Administration of China law enforcement officers, the ordering process set by some merchants has hidden mysteries: after scanning the QR code and a smooth authorization process, personal information may be excessively collected during "immediate consumption", and may be unknowingly used. It has been leaked and become the "source" of black and gray Internet products and telecommunications fraud.

Since June this year, the "Special Law Enforcement Action for the Protection of Personal Information Rights in the Consumer Sector" has targeted food scanning, parking payment, children's learning and training, online financial management and small loans, shared power bank, supermarket shopping, real estate agency, automobile 4S Comprehensive rectification of personal information protection and special law enforcement were carried out in eight major consumption scenarios including stores. A few days ago, law enforcement officers from the Shanghai Cyberspace Administration and Municipal Market Supervision Bureau gathered at Raffles City on the North Bund to conduct a "look back." Have merchants that originally collected personal information in violation of laws and regulations made thorough rectifications? Will new problems arise? Jiefang Daily and Shangguan News reporters followed law enforcement officers and Municipal People's Congress deputies to conduct surprise inspections.

Catering companies are inconsistent in their rectifications, and there are "secret" incentives for information leakage

On the B2 floor of a shopping mall lined with various catering stores, Zhan Tingting, a representative of the Municipal People's Congress, scanned the code at a table corner of the catering company "Chua Lam Hong Kong Style Dim Sum", and a "User Privacy Policy Reminder" pop-up window appeared. She clicked to disagree, but was unable to open the menu. Zhan Tingting frowned and was forced to choose "Agree and continue". The pop-up window prompted her to apply for location information. When you scan the QR code to place an order, the mini program displays a prompt to "become a member with one click" to enjoy privileges; when you scan the QR code to check out, a prompt to join the membership appears. "This is obviously inducing consumers to become members and ask for more personal information!" Zhan Tingting lamented that catering companies are not aware enough of protecting user privacy, and the problem of scanning QR codes to order meals still needs to be solved.

The merchant "Chua Lam Hong Kong Style Dim Sum" has the problem of frequently inducing consumers to join the membership.

The restaurant staff looked embarrassed and said that at the beginning, there was no privacy statement set up in the ordering applet. Subsequent rectification and setting up of pop-up prompts attracted the attention of many customers and they switched to paper menu ordering. Today I learned from law enforcement officials that there is a problem in the ordering system that induces members, and we will report it to the public to continue optimizing and adjusting.

"It turns out that I have already registered for this store!" Zhan Tingting scanned the QR code to order in front of the "7 Fen Sweet" store of the fresh fruit tea company, and found that because she had purchased the brand in other stores, she could order directly without registering or logging in. order. She looked for the entrance to the logout information, but couldn't find it. After carefully looking through the dense privacy terms agreement, I found that the company will authorize users to third parties and use it in various scenarios. "Without a convenient personal information exit mechanism, the protection of personal information can hardly be said to be complete." Zhan Tingting came up with a suggestion.

Law enforcement officers conduct on-site legal education and compliance guidance for catering merchants.

Subsequently, the law enforcement officers came to the Starbucks store. The previous problem of inducing consumers to join the membership in the personal information collection process of the mini program has been completely rectified after testing by technical personnel. "Companies must be aware of the need to allow ordering permissions in tourist mode. Even if users choose to join as members, the destination and scope of use of relevant personal information must be clearly informed." Zhu Tao, a law enforcement officer at the Shanghai Cyberspace Administration, pointed out.

Keep the line of defense by classification and grading, and scan the QR code to make consumption more "pure"

A children's training institution called "Children's Painting Forest Innovative Art Education" attracted the attention of law enforcement officials. Outside the store, there are many small program consultation and registration portals for themed study tours and online and offline courses. After scanning the QR code, the institution requires the child's name, age, gender, contact information, WeChat ID and other information to be filled in.

Law enforcement officers proposed to the head of the agency to investigate and test the collection of personal information in the background. The person in charge of the organization quickly said: "Only principals and teachers at the academic level can view it. Ordinary teachers cannot see parents' phone calls." However, actual inspection shows that the viewing permissions for such sensitive content are still too low. In addition, the training institution’s mini program does not have a special privacy policy for minors under the age of 14 and requires mandatory request for precise location information.

There is no special privacy policy for minors under the age of 14 in the training structure of the mini program.

Regarding the issue of customer information data protection of training institutions, Lu Lei, deputy to the Municipal People's Congress and secretary-general of the Shanghai Information Service Industry Association, believes that such institutions hold consumers' more sensitive personal information, so the viewing permissions and storage of sensitive information must be limited. You need to pay special attention to it, and put the particularly important ones in the "safe".

"Keep two bottom lines, firstly, make sure not to sell; secondly, 'lock the door' and take appropriate protection." In Lu Lei's view, the problem of information leakage in small and medium-sized enterprises is mostly due to the selfish interests of relevant personnel within the enterprise. Data protection is generated by reselling, so data protection depends to a large extent on how the company strictly controls the management system of reselling by internal personnel.

It is worth noting that in this "look back", no problems were found in the companies involved in parking fees and renting power banks, and the rectification effects were obvious. In the underground garage of Raffles City Mall, the "pure version" parking payment code logo is enlarged and prominently posted, with clear guidance. After scanning the QR code, a reporter from Jiefang Daily and Shangguan News saw the interface for entering the license plate number, and could jump directly to the payment interface. The option "Become a member and pay more conveniently" is placed below to avoid the possibility of misleading clicks.

Law enforcement officers conduct on-site inspections of merchants’ collection, viewing permissions, and storage of sensitive information.

Law enforcement officers from the Shanghai Cyberspace Administration said that through “look-back” inspections, many companies have achieved good rectification results and are able to regulate the collection and storage of personal information in accordance with the requirements of the Personal Information Protection Law. However, some companies still have some violations of laws and regulations. On the one hand, regulatory authorities need to continue to increase legal education, compliance guidance and administrative enforcement. On the other hand, they also need to build social consensus. We hope that every consumer and every member of society can actively discover and report personal information violations around them. Violation issues.

According to reports, in the past six months, the "Liang Jian Pujiang" special law enforcement action on personal information protection has inspected a total of 6,043 companies, interviewed more than 520 companies in accordance with the law, and investigated and dealt with more than 50 personal information protection cases of various types. Recently, the city's two-level Internet information and market supervision departments are simultaneously carrying out "look-back" inspections of key local business districts.


Scanning QR codes to induce membership and forcing location information are illegal! More than 500 companies in Shanghai have been interviewed
I brought "equipment" to take pictures on the Binjiang River in Shanghai but was stopped by security: Do I need to "report" in advance?
I brought "equipment" to take pictures on the Binjiang River in Shanghai but was stopped by security: Do I need to "report" in advance?

Citizen Mr. Liu recently left a message to Liberation Daily and Shangguan News, saying that in mid-September this year, he accompanied four friends to the riverside viewing platform in the North Bund section of Hongkou to take portrait photos. The group and three photographers totaled eight people. . Since they were shooting at night, they also brought more professional equipment, including lighting lights with power of 30 watts and 40 watts respectively. Unexpectedly, as soon as the filming started, he was stopped by the on-site security guard. The security guard judged that Mr. Liu's behavior was obviously a "commercial shooting" and said that according to regulations, he needed to report first, so the filming on that day could not continue. Afterwards, Mr. Liu believed that although the formation looked relatively large, they were indeed not a fee-charging studio. They were just simple photography enthusiasts, and the shooting was not a commercial activity. He asked: Is Binjiang managing a similar filming business?

Can operating vehicles such as taxis and online ride-hailing vehicles be equipped with child safety seats?
Can operating vehicles such as taxis and online ride-hailing vehicles be equipped with child safety seats?

Wang Ye Children's safety is no small matter. Nowadays, more and more families are installing child safety seats in their family passenger cars. However, currently taxis and online ride-hailing services are generally not equipped with child safety seats. If parents need to take their minors with them, There are certain safety risks when people take taxis, online ride-hailing and other operating vehicles. Scientific experiments have proven that if the vehicle is not equipped with a child safety seat, but instead uses the method of carrying a minor, when the vehicle impacts at a speed of 40 kilometers per hour, an impact equivalent to 30 times the body weight will occur at the moment of impact. For example, a child weighing 10 kilograms will have an impact force of 300 kilograms at the moment of collision. This child cannot be held by the strength of human hands alone. And the reality also proves the importance of child safety seats

A set of cables is still hanging high in the air, or is it illegally erected? It has been half a year since the undergrounding of the Zhapu Road overhead line was completed, but the grounding was forgotten.
A set of cables is still hanging high in the air, or is it illegally erected? It has been half a year since the undergrounding of the Zhapu Road overhead line was completed, but the grounding was forgotten.

On Zhapu Road, where the overhead line undergrounding project was completed at the end of last year, a set of communication cables that should have been buried underground strangely appeared in the air, causing considerable trouble to the Kunshan Park nearby. On September 22, Xia Zhongyi, the manager of Kunshan Park on Zhapu Road, called the 12345 citizen service hotline for help. He said that a set of cables had been hanging at the entrance of the park, and the middle section was "stretched" on two trees at the entrance of the park for more than half a year. Not to mention affecting the image of the park, below are the benches set up along the street in the park. Old people often sit and rest. "What if the black cable box hits someone on the head?" What's more important is that this section of Zhapu Road was completed at the end of last year. This means that the overhead line entry project should not be in the air at all. The section of Zhapu Road from North Suzhou Road in the south to Kunshan Road in the north was opened as early as the second half of last year.

Impersonating a staff member of the Cyberspace Administration to commit fraud! Many people in Shanghai have already encountered scams
Impersonating a staff member of the Cyberspace Administration to commit fraud! Many people in Shanghai have already encountered scams

"Since you have recently released more than 20000 pieces of fraud information, you will face the penalty of downtime, please find a quiet place to close the door and cooperate with the record..." Recently, the Shanghai Internet Illegal and Bad Information Reporting Center received a number of citizens who reported that a fraudster had posed as a staff member of the Shanghai Internet Information Office to launch a video call and requested to make a record on the ground that the victim had released fraud information, in order to obtain personal privacy and commit fraud. The Shanghai Internet Illegal and Bad Information Reporting Center stated that such calls are counterfeit. If you receive such a call, do not disclose any personal information or join any unfamiliar groups. Call "96110" in a timely manner or go to the local police station for registration. According to the victim, Citizen Wang, on the morning of September 20th, he received a video call starting with+86

Will the bank permanently freeze some deposit accounts? This kind of fake news has tricks!, Rumors started in September | Bank | Account
Will the bank permanently freeze some deposit accounts? This kind of fake news has tricks!, Rumors started in September | Bank | Account

Recently, the Shanghai debunking platform received a message hoping to verify the authenticity of the online rumor that "starting from September, banks will permanently freeze some deposit accounts.". After verification, all relevant statements are false. In March, there was similar news, but industry insiders said that the Shanghai debunking platform found that since March this year, various online news titled "Amazing Decision Making of Banks" and "Major Reform of Banks" have appeared, all from individual netizens or self media named "* * Finance Talk" and "* * Technology". The content posted by these accounts is roughly the same, meaning "the bank has made a new decision to permanently freeze some deposit accounts."; The "effective time" is different, some are more vague, while others say it is "August", "September", etc. However, neither the People's Bank of China nor various commercial banks have released any information