A security awareness trainer is creating content for employees about mobile security. She wants to explain why 'I have nothing to hide' is an insufficient reason to ignore mobile privacy settings.
What is the 'aggregation problem' in mobile privacy, and why does it make seemingly innocuous data collections individually acceptable but collectively concerning?
- A.The 'nothing to hide' argument is valid for mobile privacy because each individual app's privacy policy discloses data collection, and informed consent through app installation constitutes legal authorization for all subsequent data use
- B.The aggregation problem only affects users in surveillance-heavy countries; in democratic countries data aggregation is prevented by GDPR and similar laws that make combined data profiles illegal
- C.The aggregation problem is relevant only for public figures; private individuals are statistically unlikely to be profiled because data brokers only aggregate data about high-value targets
- D.Individually harmless data points (location check-in at a coffee shop, purchase at a pharmacy, contact name, browsing a medical information site) combine into a highly sensitive profile: the pharmacy purchase + health site browsing + GPS at a specific medical clinic reveal a medical condition the person would not voluntarily disclose. Mobile devices collect all of these simultaneously, and data brokers aggregate cross-app data - each app's individually 'nothing to hide' data becomes a comprehensive sensitive behavioral profile