[HN Gopher] Attorney General Bonta Announces Settlement with Sep...
       ___________________________________________________________________
        
       Attorney General Bonta Announces Settlement with Sephora on
       CCPA/GPC Enforcement
        
       Author : sebastian_z
       Score  : 31 points
       Date   : 2022-08-24 17:32 UTC (5 hours ago)
        
 (HTM) web link (oag.ca.gov)
 (TXT) w3m dump (oag.ca.gov)
        
       | henryfjordan wrote:
       | The settlement was for $1.2M and some promises.
       | 
       | Sephora has more than 100 locations in California. I bet some of
       | their more prominent locations charge close to that $1.2M in
       | rent.
       | 
       | What a pittance of a settlement...
        
       | sillystuff wrote:
       | I'm curious what HN folks' experiences with CCPA have been (from
       | the consumer side)?
       | 
       | For instance, I filled out a form for CCPA data deletion, at a
       | very large data broker, to receive a report on data they had
       | collected and to request my data not be sold, and then had
       | evidence that my data was both retained and continued to be sold
       | several months later.
       | 
       | I wish surveillance was opt-in (yes, no one would and that is the
       | point). It is quite a burden to try to "opt out" from data
       | collection and sales with so many companies collecting,
       | aggregating and selling this personal information.
        
         | lelandfe wrote:
         | You can cancel your NYTimes subscription with a click if you
         | live in California. Anywhere else and you have to call and
         | suffer their customer retention haranguing.
         | 
         | Pretty much the only CCPA benefit I've seen.
        
           | Shank wrote:
           | > You can cancel your NYTimes subscription with a click if
           | you live in California
           | 
           | This is frequently echoed on HN, but my experience in
           | California trying to cancel NYT is that option wasn't present
           | at all. In fact, when I couldn't reach a human to cancel for
           | an hour, I gave up and paused the credit card associated with
           | NYT. They then got declined 3 times, and force posted the
           | transaction without approval. Then, it took a credit card
           | dispute to resolve, at which point NYT lost because posting
           | transactions without approval turns out to be a per-se
           | violation of Visa's merchant guidelines.
           | 
           | So, I'm not sure if this is an account-based flag or AB test,
           | but it isn't a universal fact that you can cancel NYT in
           | 1-click in CA.
        
             | chmod600 wrote:
             | What is "force posting"?
        
             | lelandfe wrote:
             | Hm, well, they used to - and they're required to: https://l
             | eginfo.legislature.ca.gov/faces/billTextClient.xhtm...
             | 
             | > _The bill would require the business to provide a method
             | of termination [of automatic renewal or continuous service
             | offer] that is either online in the form of a prominently
             | located direct link or button to cancel or by a termination
             | email, as provided_
             | 
             | If you've got some, uh, spare time and money - sue away!
        
           | keneda7 wrote:
           | I sure wish EPIC passes auto renew would be like this for CA.
           | Even after calling EPIC its nearly impossible to get auto
           | renew cancelled.
        
         | AlotOfReading wrote:
         | Most of the companies I've tried to opt-out from either don't
         | recognize their obligations (you're not a 'customer' even
         | though we're collecting your data), don't have a way to opt out
         | short of contacting a legal department that has no public
         | contact info, or failed to actually resolve the issue.
         | 
         | I can only recall one case where I succeeded, in a couple dozen
         | attempts.
        
           | ThrustVectoring wrote:
           | > short of contacting a legal department that has no public
           | contact info
           | 
           | All corporations are required to have an "agent for service
           | of process" in the state they are registered in, and the
           | secretary of state should maintain a lookup tool for this
           | (haven't checked all 50 but it's common). Opt-out should take
           | you approximately ten minutes - look up their agent for
           | service of process, and send a certified letter explaining
           | the action you want them to take to avoid the lawsuit you are
           | considering.
        
         | __derek__ wrote:
         | > I wish surveillance was opt-in (yes, no one would and that is
         | the point).
         | 
         | The European Data Protection Board is moving in that direction
         | for "virtual voice assistants": requiring active consent to
         | store data beyond what's necessary to execute the immediate
         | request.[1]
         | 
         | [1]: https://edpb.europa.eu/news/news/2021/july-7-12-plenaries-
         | ad...
        
       | keneda7 wrote:
       | The fact that the CCPA does not apply to government agencies is
       | completely outrageous in my opinion. The CA DOJ leaked thousands
       | of citizens private information recently and nothing is happening
       | to them. They even went through the trouble of building a UI to
       | search the data released, so its pretty hard to claim it wasn't
       | intentional.
       | 
       | If we are going to hold companies to the CCPA should the agency
       | in charge of enforcement not be held to the same standard?
        
         | [deleted]
        
         | mistrial9 wrote:
         | on the other side, arguments like this can be used to stall and
         | diffuse the actual implementation upon the most egregious
         | violators. In an extreme scenario (like say tribe gaming laws)
         | said violators could actually hire and "astroturf" this kind of
         | "look, over there" sort of outrage. Perhaps you are genuine,
         | but .. congratulations California and AG Bonta on at least this
         | action, right?
        
           | keneda7 wrote:
           | So my argument that MORE people should have to follow the
           | CCPA is somehow an argument to prevent implementations of the
           | CCPA.
           | 
           | Could you please explain your logic there?
        
             | mistrial9 wrote:
             | yes of course - the phrase is "the perfect is the enemy of
             | the good" which means.. implementation of the law could be
             | stalled or delayed, or the law could be challenged in court
             | and reversed in the extreme case.. based on an argument
             | that it is fundamentally flawed. A reason to be flawed is
             | "not all covered parties are treated fairly" or something
             | .. IANAL
             | 
             | secondly, from a public relations "swindle" side, an ad
             | campaign could be purchased that makes the argument that
             | "this kind of law is obviously not OK" look at this
             | ridiculous example, the State is not following the same
             | requirements as business is.. or similar..
        
               | keneda7 wrote:
               | So I could see your argument if in my original post I
               | said something about the law being wrong and needs to be
               | removed. But I was careful not do that as I agree with
               | most of the CCPA. I simply stated it is ridiculous that
               | this law does not apply to more people. Especially when
               | those people just leaked 200k+ sets of PII.
               | 
               | Again I simply said more people should have to follow the
               | CCPA, nothing about stopping or slowing it down. Yet you
               | choose to try and invalidate my point by connecting it to
               | something I very clearly did not say.
               | 
               | From my point of view it appears that you just wanted to
               | shut down criticism of the CA government because... well
               | I have no idea.
        
         | __derek__ wrote:
         | While I think that data leak was horrible (and potentially
         | disastrous), it's not clear how CCPA would apply in that case.
        
           | keneda7 wrote:
           | Check under Section A number 8.
           | 
           | https://oag.ca.gov/privacy/ccpa
        
             | __derek__ wrote:
             | Thanks. Somehow I didn't realize that driver's license
             | number counted, but there it is.[1]
             | 
             | [1]: https://leginfo.legislature.ca.gov/faces/codes_display
             | Text.x...
        
         | KennyBlanken wrote:
         | The incident you're referring to was a concealed carry permit
         | site that exposed data and it happened about a month or two
         | ago, so it's premature to say "nothing happened to them." The
         | data was accessible for about 24 hours.
         | 
         | https://www.latimes.com/california/story/2022-06-29/californ...
         | 
         | You made up "thousands" as no numbers have been given . The
         | incident has been widely condemned including by the state AG,
         | and they're contacting anyone affected / providing credit
         | monitoring.
        
           | staringback wrote:
           | I'm sure credit monitoring will help when criminals go and
           | break into their homes to steal their firearms
        
           | keneda7 wrote:
           | The leak did not just expose ccw holders. It exposed ccw
           | applications that were denied as well. DROS info was also
           | available for a short time. I know exactly what was exposed
           | because I looked myself up and I also received a the letter
           | offering the IDX monitoring.
           | 
           | I did not make up thousands, in fact the actual number is way
           | higher... 200k ccw holders in ca. Simple google search: https
           | ://www.google.com/search?q=how+many+ccw+holders+are+in+...
           | 
           | The state AG is literally the person responsible so to say
           | they condemned it is laughable. For example lets say I,
           | keneda, somehow had all of your, KennyBlaken's, bank account
           | numbers. I then pay someone to make a website with a UI to
           | search for any of your account numbers. Then after all your
           | account numbers publicly available and stolen I take it down
           | and say oh I'm sorry I shouldn't have done that it was wrong.
           | Sure I condemned the action but guess what I am still 100%
           | responsible for making a publicly searchable user interface
           | to expose data that is supposed to be private. The CA DOJ
           | choose to have this searchable site made, it did not just
           | magically appear on the internet.
        
         | systemvoltage wrote:
         | CA DOJ is completely and utterly shameless/corrupt. It is one
         | of the most eggregeious institutions of America. They continue
         | to violate basic fundamental rights guaranteed by the US
         | constitution and then citizens of CA have to wait for 2 years
         | of lawsuits to get their rights restored. They are also morally
         | corrupt and will do anything in their power to tighten control
         | over citizens of California.
        
           | chmod600 wrote:
           | Examples?
        
       ___________________________________________________________________
       (page generated 2022-08-24 23:01 UTC)