[HN Gopher] California passes bill to make it easier to delete d...
___________________________________________________________________
California passes bill to make it easier to delete data from data
brokers
Author : pseudolus
Score : 172 points
Date : 2023-09-15 15:03 UTC (7 hours ago)
(HTM) web link (www.latimes.com)
(TXT) w3m dump (www.latimes.com)
| yieldcrv wrote:
| or else what?
| coding123 wrote:
| Hopefully we get to sue them out of existence this time
| jhart99 wrote:
| Doesn't look like it will be a private action. We will still
| need to get the State Attorney General to initiate it which
| will mean nothing will happen.
| smcin wrote:
| DC Attorney General Karl Racine has been the most
| impressive on data privacy. More than CA, WA, NY, MA.
|
| It probably keeps him pure that he represents a district
| that mainly feels the impact of the credit industry, and
| doesn't proportionately have that many tech jobs (as CA).
| [deleted]
| striking wrote:
| From the bill:
|
| > This bill would provide that a data broker that fails to
| comply with the requirements pertaining to the accessible
| deletion mechanism described above is liable for civil
| penalties, administrative fines, fees, and costs, as specified,
| and would raise the amount of the existing civil penalty
| provisions described above. The bill would require that moneys
| collected or received by the agency and the Department of
| Justice under these provisions be deposited in the Data
| Brokers' Registry Fund, which the bill would require to be
| administered by the agency, instead of the Consumer Privacy
| Fund and would expand the specified uses of moneys in the Data
| Brokers' Registry Fund to include the costs incurred by the
| state courts and the agency in connection with enforcing these
| provisions and the costs of establishing, maintaining, and
| providing access to the accessible deletion mechanism described
| above.
|
| https://leginfo.legislature.ca.gov/faces/billTextClient.xhtm...
| JumpCrisscross wrote:
| Is there a route for private action? As in, could my parents
| sue a data broker for not complying? Or is this only enforced
| by California?
| TheCaptain4815 wrote:
| Very few things I'm jealous of in blue states, but their online
| privacy protection is up there. I've pondered why no party has
| made this a major priority, but the reality is the vast majority
| of Americans simply don't care.
|
| I would love to tell these big tech companies I want all traces
| of myself removed from their search engines. I understand it gets
| a bit nuanced with first amendment n such (what about a news
| article of me committing "x crime"), but give citizens SOME
| protection. At least Europe tries and pushes back.
| c420 wrote:
| I'd wager that lobbyist$ play a larger role than citizen apathy
| for the lack of legislation.
| fossuser wrote:
| I'm in California - reality is even with this stuff it's hard.
| I'd say maybe 20% companies you send CCPA request emails to
| don't know what to do, have broken forms, etc. It does work
| probably 80% of the time though.
|
| I also use this which seems to work, but it's hard to know how
| effective it is really: https://joindeleteme.com/
| [deleted]
| azinman2 wrote:
| Curious about the issues surrounding credit scores and how much
| this gets into it.
| hedora wrote:
| Back when interest rates were low, Rocket Mortgage incorrectly
| tanked my credit score. They refused to fix it, which means
| they were liable for whatever economic damage that causes.
|
| When I refinanced, I explained the situation to the other
| bank's loan agent. They emailed their underwriting division,
| and the underwriters simply issued an override.
|
| Not sure if that works these days or not, but my point is that
| credit scores are complete bullshit. Hopefully most people will
| push the button, inadvertently opting out of credit reporting,
| and that corner of the industry will simply stop existing.
|
| Lenders already do more due diligence than the credit agencies
| do.
|
| If you default on a loan, there could be a central record (say,
| at the court house) of this, and lenders could consult that.
| That would fill in the remaining missing functionality of the
| score (and do so in a way that is transparently free of
| institutional racism, etc).
| adrr wrote:
| Besides defaults how would you get precision in a model
| without any other data? Payment history and total outstanding
| credit wouldn't be there. You would have to trust the
| customer to provide you with all these details.
|
| Without precision in the risk model, cost to the consumer
| will go up to mitigate risk. Someone who has paid all their
| credit lines for 10 years but and has never defaulted has the
| same risk profile as a person who has frequently missed
| payments.
| JumpCrisscross wrote:
| > _credit scores are complete bullshit_
|
| You can also juice it up or down by over a hundred points by
| accumulating and then rapidly paying down balances.
| galoisscobi wrote:
| > juice it up or down
|
| So what here determines if the score goes up instead of
| down? I'm planning on getting a mortgage soon but wife's
| credit score is in high 600s. If we can make it past, 720,
| we are told we'll get a better rate. So I'm curious as to
| how to bump up the score.
| PascLeRasc wrote:
| There are communities where you can rent someone else's
| credit score as an authorized user.
| toast0 wrote:
| There's lots of articles everywhere, but the basics are:
| make sure everything is paid on time; if you have any
| earned negative items, see if you can get them removed by
| asking nicely etc.
|
| Then there's things like age of oldest account, average
| age of accounts, etc. You may be able to add her to your
| accounts to improve this factor, if your accounts are
| older than hers.
|
| Then balances. You get dinged for having a balance on too
| many accounts. I think you also get dinged for having
| zero balance everywhere. I think 'ideal' is 3ish cards
| with balances (you can (and should) pay the whole balance
| every statement, reporting is usually done just after the
| statements). Highest ever balance should be less than
| credit available or you get dinged; ask for credit
| increases on cards where you ever went over the limit.
| Total balance shouldn't be more than some % of total
| credit, I think 35%? You also get dinged for high %
| current balance on any one card. Again, you can add her
| on high limit, low usage cards to help her score. She'll
| get more score points as a joint account holder than an
| authorizer card holder.
|
| You get dinged for recent (6 month?) credit inquiries,
| but inquiries are grouped, so if you apply for new
| credit, try to get it all done in a few days; mortgage
| inquiries have longer to be grouped.
|
| If you know when your creditors do reporting, you can
| adjust your payment dates to tweak things. You might make
| a payment to your credit card before the statement closes
| even in order to show a lower utilization % and that
| could move your score a lot depending on details.
| AJ007 wrote:
| I assume it would be similar to declaring bankruptcy
| TrendyCPU wrote:
| I would also be curious to learn how it impacts Early Warning
| Services which collects/reports data on bank accounts and
| transactions.
|
| The Privacy, Security, & OSINT Show did a podcast on it.[0]
|
| 0. https://inteltechniques.com/blog/2022/04/15/the-privacy-
| secu...
| TrendyCPU wrote:
| The legislation appears to be limited to data brokers. While this
| is nice and welcomed, this also means it doesn't cover entities
| like Google or Facebook.
| theptip wrote:
| CCPA already requires Google to delete your data on request.
| Though AFAIK CCPA didn't produce any changes as Google already
| allowed you to do that.
|
| The same applies to any non-small business that you have a
| direct relationship with and provide your information to; CCPA
| requires that business to delete the info if you request it.
|
| Data brokers are a special case because they don't get their
| information directly from you, instead they slurp up whatever
| public and private data they can scrape or buy, and then resell
| that to other companies. Given you don't have a direct
| relationship with the data brokers, it's hard to even figure
| out who has your information.
|
| Note, CCPA seems to have excluded the credit bureaus from
| designation as data brokers, even though those guys are
| responsible for leaking SSN and full personal information on
| the majority of US citizens.
|
| The US system of credit surveillance is pretty unusual (EU
| countries don't do anywhere near that much stalking and they
| have functioning debt markets) so I'd love to learn what would
| actually break if people were allowed to opt out of that
| tracking. Presumably there are some government records you
| can't opt out of like UCC filings and bankruptcy, and any
| potential creditor could just look up the primary sources
| themselves.
| CharlesW wrote:
| I'm astounded that they aren't considered data brokers in the
| eyes of U.S. law.
| 0xcde4c3db wrote:
| The standard answer (at least for Google, not sure about
| Facebook) is that they're not considered data brokers because
| they only sell ad placement based on the data, not the data
| itself.
| hedora wrote:
| Google helped craft these laws. This is classic regulatory
| capture.
|
| In particular, it is banning horizontally integrated
| surveillance capitalism (which requires the sale of data
| between the data gathering companies and the people using
| it), but not vertically integrated surveillance capitalism.
|
| In all likelihood, some companies in this ecosystem will be
| forced to sell at fire sales to conglomerates (like Google)
| simply to avoid having to comply with this law. Of course,
| this benefits organizations that are large enough to
| acquire the companies, and no one else.
|
| So, people with financial conflicts of interest are picking
| winners and losers, which is pretty much standard practice
| in US politics these days.
|
| I personally think this whole consumer tracking industry
| should be shut down. It should be illegal to gather the
| types of information that this bill regulates.
| paulddraper wrote:
| You do understand that there is a real difference between
| selling ad placement and selling personal data, right?
|
| Maybe you hate both, but there is a meaningful
| difference.
| hef19898 wrote:
| One could make a case for splitting the data collection
| activities from the ad sales business as part of an anti
| trust case. Or pass regulations and laws to that effect.
| [deleted]
| vineyardmike wrote:
| That would be a pretty weird case to make. Typically anti
| trust is used to prevent a business from using market
| dominance in one market from entering another market.
| Considering they don't participate in the data sales
| business it'd be a weird scenario to force them to start.
| I'd prefer we don't force them to start.
|
| Gmail with ads seems way preferable to Gmail who sells
| your data to others.
| hef19898 wrote:
| Well, I m affraid it is both, ads and data selling...
| chimeracoder wrote:
| > One could make a case for splitting the data collection
| activities from the ad sales business as part of an anti
| trust case. Or pass regulations and laws to that effect.
|
| That would be a net negative for privacy, because it
| would mean more parties having access to your data
| (without your consent or even knowledge). And given the
| state of security in ad-tech _aside_ from Google, that
| means the chances of your data getting breached and
| leaked would increase exponentially.
| adrr wrote:
| They don't sell your data.
| majormajor wrote:
| They don't sell your data TODAY.
|
| Who knows what they'd sell if their business declined for a
| while and there was a hostile takeover or they otherwise got
| desperate for new revenue streams.
|
| And then if you were paying attention you could make a new
| one of these requests... but maybe you'd miss it for a bit,
| and then it would be too late.
|
| The law should be based on what you collect instead of what
| you sell to better protect against this sort of thing.
| adrr wrote:
| Thats not relevant of what they could do. This laws covers
| what you are doing and applies to entities selling your
| data. Big ad players don't sell their data because that is
| their secret sauce in ad targeting.
|
| Companies selling your data are your bank(credit card
| purchases), mobile carriers(location), your DMV(photos,
| driving record, misc PII including address, dob etc),
| state/county government(public records like marriage
| licenses). Its weird everyone bashes on google and FB for
| something they don't even do.
| noizejoy wrote:
| > They don't sell your data.
|
| ... except when they sell their domain registration business.
|
| And yes, I realize that there's a (technical) difference
| between selling data and selling a business including its
| data assets.
|
| But then again, maybe a really big chunk of the value of that
| business is its customer data.
|
| For some business acquisitions special terminology like
| "aqui-hiring"[0] has evolved so it's understood that not
| every sale of a business is of the same nature.
|
| And since the value of data has arguably become much higher
| than ever before, the distinction of selling data by itself
| and selling the entire business is becoming smaller as time
| goes on.
|
| [0]https://en.wikipedia.org/wiki/Acqui-hiring
| qwerty456127 wrote:
| I want a bill which would let me just ban all data brokers
| forever. I don't mind first parties to save some relevant data
| necessary for them to do their job, I can even understand 3rd
| parties like Google Analytics involved, but data brokers - I
| really don't want any of them to have any data about me ever.
| pauldenton wrote:
| Do you want to ban Manual Data Brokers. Private Investigators?
| willio58 wrote:
| Yeah this is it. I want to have full knowledge over who has my
| data and for what purpose. I think we'll get there eventually
| but it'll take a while.
| hackncheese wrote:
| This reminds me of a company my friend used to work for, Ketch
| [1]. Basically described their service as automation that
| fulfills this exact requirement on customers databases. Sounds
| like they were ahead of the game.
|
| [1] https://www.ketch.com/
| kepler1 wrote:
| Are we talking actual data deletion, or just "not serving it up
| when queried" or attaching a "do not use" flag to the data but
| keeping it?
|
| Because if there's one thing I've almost never seen, it's data
| being deleted from a db.
| striking wrote:
| From the bill:
|
| > The bill would, beginning January 1, 2028, and every 3 years
| thereafter, require a data broker to undergo an audit by an
| independent third party to determine compliance with these
| provisions and would require the data broker to submit an audit
| report to the agency upon the agency's written request, as
| specified.
|
| https://leginfo.legislature.ca.gov/faces/billTextClient.xhtm...
| d3w4s9 wrote:
| I don't think that section answers the question.
| kepler1 wrote:
| Thanks, that spurred me to read about it given the link
| above.
|
| > " _This bill would require the agency to establish, by
| January 1, 2026, an accessible deletion mechanism that,
| among other things, allows a consumer, through a single
| verifiable consumer request, to request that every data
| broker that maintains any personal information delete any
| personal information related to that consumer held by the
| data broker or associated service provider or contractor.
| The bill would specify requirements for this accessible
| deletion mechanism, and would, beginning August 1, 2026,
| require a data broker to access the mechanism at least once
| every 45 days and, among other things, process all deletion
| requests, except as specified. Beginning July August 1,
| 2026, after a consumer has submitted a deletion request and
| a data broker has deleted the consumer's data pursuant to
| the bill's provisions, the bill would require the data
| broker to delete all personal information of the consumer
| at least once every 45 days, as specified, and would
| prohibit the data broker from selling or sharing new
| personal information of the consumer, as specified_....
|
| > " _This bill would provide that a data broker that fails
| to comply with the requirements pertaining to the
| accessible deletion mechanism described above is liable for
| civil penalties, administrative fines, fees, and costs, as
| specified, and would raise the amount of the existing civil
| penalty provisions described above_.... "
|
| I guess it all comes down to the implementation level how
| specific and "actually deleting" they will be. And whether
| the new agency (ugh) charged with enforcing this will
| actually have teeth in the details.
|
| And I don't know why such a long 45 day period is required.
| For reasons we're all too familiar with, people are quite
| able to gather data within seconds, but somehow need 45
| days to delete it?
| addaon wrote:
| Deleting data from backups (or, more often, aging out
| backups and deleting them wholesale) is usually a batch
| process. You really don't want to have to do online
| modification of backups... they're not really backups at
| that point. 45 days doesn't seem unreasonable.
| kepler1 wrote:
| Well... doesn't that circumvent the point of backups?
| Backups in my mind are supposed to be like read-only, can
| never be modified so that the system that was corrupted
| can't do anything harmful to the safe previous
| checkpoint.
|
| I guess it has to have some method of what you mention
| then. If someone wants their data deleted, yes, what
| about the backups?
| callalex wrote:
| If it's so much work to handle the data responsibly,
| maybe it shouldn't be collected in the first place.
| neonate wrote:
| http://web.archive.org/web/20230915153457/https://www.latime...
|
| https://archive.ph/1ebn0
| maaand wrote:
| Question is what are the loop-holes available for the databrokers
| to ignore data deletion requests?
| NelsonMinar wrote:
| I've been grateful as a Californian for our regulations of online
| businesses. I regularly invoke our right-to-unsubscribe and the
| CCPA gives us something similar to the GDPR in various ways.
|
| To what extent do companies extend these rights to all Americans
| because it's easier than building a California-specific version
| of a website or online product?
| gochi wrote:
| Likely depends on the scale of the company. The likes of Google
| (I know they aren't specifically on the line for this law
| anyways) will have more than enough resources to ensure you're
| a California resident before allowing such. Hard to see others
| caring and just adhering your request as a non-California
| resident when it's always a small margin of people that even
| take advantage of privacy respecting laws.
| Alupis wrote:
| Exactly. The Parent comment strikes me as being very naive.
|
| Right to Unsubscribe? Gmail and other email providers do this
| for you even if you are not a CA resident and even if the
| Marketer does not have a built-in Unsubscribe link. From a
| Marketer perspective, you cost money to send emails to, and
| if you are not going to open, they kind of don't want you on
| the list anyway.
|
| CCPA == GDPR? Not even close. Majority of CA businesses do
| not reach the compliance threshold and therefore do not have
| to or will not comply with requests. Additionally, you have
| no way to validate if the request was actually carried out.
| The company's "best efforts" to remove data from _their_
| systems is all that 's required at best - and a lot of data
| can be retained for valid business reasons.
|
| Lastly - despite what CA residents believe (and similar to EU
| residents with GDPR) - CA laws do not apply to the rest of
| the country simply because they are unenforceable except in
| the most egregious cases - and even then it would have to be
| a very large business anyway.
|
| > because it's easier than building a California-specific
| version of a website or online product
|
| Nobody is doing this in practice. At best, they use some
| GeoIP thing or if you are logged into an account (which means
| they have your data anyway). The law does not require them to
| validate the user anyway, so it's all "best effort" again
| which usually means low effort.
|
| But hey, if it makes you feel warm and fuzzy believing these
| things - more power to you.
| callalex wrote:
| The right to unsubscribe being discussed here has nothing
| to do with emails. It states that if you paid for a
| subscription online, you must be able to cancel it online
| within a few clicks as well. No "call us" or "send a
| registered letter during a full moon and low tide only"
| nonsense. It's really great.
| NelsonMinar wrote:
| There are numerous summaries of that right available
| here: https://www.google.com/search?q=california+right+to
| +unsubscr...
| Alupis wrote:
| > No "call us" or "send a registered letter during a full
| moon and low tide only" nonsense. It's really great.
|
| I am very skeptical even this is as great as some think.
| Outside CA, most companies can simply ignore these
| "viral" style laws with no consequences.
| r00fus wrote:
| As another Californian, I'd love examples of where this
| is ignored, or where non-californians also benefit from
| these.
|
| I also gladly unsubscribe easily without frustration -
| just not sure if this is common in other states.
| Alupis wrote:
| How about a concrete example of a big business that did
| not allow you to cancel online _prior_ to this law?
|
| Netflix? Nope. Comcast? Nope. Google? Nope. Verizon?
| Nope. AT&T? Nope. Apple? Nope. PG&E? Nope...
|
| Where is this mythical renaissance of _new_ online
| cancellations?
|
| Turns out - most big businesses did this already... oh,
| but now it's the law but who's enforcing? Lawyers who
| gain private settlements? That's not enforcement, that's
| a racket.
| callalex wrote:
| I can assure you as a Californian that this law is not
| ignored. They are taking payment from my credit card so
| they can't claim ignorance of my California address.
| Alupis wrote:
| There's no citizen enforcement clause for most of these
| laws and therefore this mostly means nothing - and where
| there is it just turns into a money grab/shakedown by
| bottom feeding lawyers (see existing FAL & P65 suits).
| Suits get settled, lawyers get paid, plaintiff gets a
| cut, no wrongdoing is admitted, and nothing changes.
|
| It's not about claiming ignorance. It's about not caring
| about CA viral laws and CA's inability to effectively
| enforce them around the world.
|
| Much like how most companies laugh when some EU citizens
| tries to flex GDPR in the US... hilarious unless you're
| Google...
|
| People lock-in on the intent and names of these things
| and believe they've "won" the privacy war. Just like the
| "Inflation Reduction Act" these laws do very little if
| anything for their namesake.
| callalex wrote:
| It's really odd to me that you are telling me that my
| lived experience is false and impossible. Every
| subscription I have made since this law passed, I have
| been able to cancel online. This includes newspapers,
| store club memberships, random podcasts and other online
| entertainment, educational software, and more.
|
| Sometimes the government really does work for the people.
| It is actually possible.
| Alupis wrote:
| Overwhelming majority of those things you listed could
| already be cancelled online.
|
| You can read the laws yourself. There's not a lot of
| teeth for small businesses to comply.
|
| Go look at the state AG website for P65 complaints (they
| are all by law published). 99% are privately settled
| without wrongdoing (you can see this on AG website too),
| and some fee is paid to the plaintiff's attorneys.
| Sometimes the math says it's cheaper to comply, but often
| not. Small (and even big) businesses around the country
| freely ignore P65 despite the law having citizen
| enforcement. If you search on the AG website you will
| find _many_ repeat offenders. P65 laws have been around
| for decades...
|
| There's a difference between what people believe should
| happen and what actually happens. If you believe these
| laws have "won" the privacy war - you are mistaken.
| r00fus wrote:
| Why are you conflating right-to-unsubscribe with P65?
| They are different laws with different enforcement
| mechanisms. Also consumers don't find P65 useful whereas
| we see benefit from unsubscribing.
| Alupis wrote:
| The point was we have these sort of consumer protection
| laws and nothing has changed. The enforcement mechanisms
| are weak and designed to make lawyers money more than
| actually gain compliance.
|
| Given the decades of P65 enforcement - and given the
| prevalence of "harmful" chemicals imported into this
| state every day, we have no reason to believe this
| unsubscribe law will be any different.
|
| Having this law makes people feel like something was
| accomplished, despite reality.
| r00fus wrote:
| The unsubscribe law has been on the books for nearly 2
| years. Most vendors have changed their processes. I have
| personally benefited.
|
| I expect nothing less for this law. Show me an example
| for a relevant law not the P65 BS.
| nolroz wrote:
| I would think a lot. Everyone would rather not have wait for
| legal to answer a new set of questions every time a state
| changes their laws. Easier to align on the strictest
| legislation and go from there, IMHO.
___________________________________________________________________
(page generated 2023-09-15 23:01 UTC)