[HN Gopher] California passes bill to make it easier to delete d...
       ___________________________________________________________________
        
       California passes bill to make it easier to delete data from data
       brokers
        
       Author : pseudolus
       Score  : 172 points
       Date   : 2023-09-15 15:03 UTC (7 hours ago)
        
 (HTM) web link (www.latimes.com)
 (TXT) w3m dump (www.latimes.com)
        
       | yieldcrv wrote:
       | or else what?
        
         | coding123 wrote:
         | Hopefully we get to sue them out of existence this time
        
           | jhart99 wrote:
           | Doesn't look like it will be a private action. We will still
           | need to get the State Attorney General to initiate it which
           | will mean nothing will happen.
        
             | smcin wrote:
             | DC Attorney General Karl Racine has been the most
             | impressive on data privacy. More than CA, WA, NY, MA.
             | 
             | It probably keeps him pure that he represents a district
             | that mainly feels the impact of the credit industry, and
             | doesn't proportionately have that many tech jobs (as CA).
        
             | [deleted]
        
         | striking wrote:
         | From the bill:
         | 
         | > This bill would provide that a data broker that fails to
         | comply with the requirements pertaining to the accessible
         | deletion mechanism described above is liable for civil
         | penalties, administrative fines, fees, and costs, as specified,
         | and would raise the amount of the existing civil penalty
         | provisions described above. The bill would require that moneys
         | collected or received by the agency and the Department of
         | Justice under these provisions be deposited in the Data
         | Brokers' Registry Fund, which the bill would require to be
         | administered by the agency, instead of the Consumer Privacy
         | Fund and would expand the specified uses of moneys in the Data
         | Brokers' Registry Fund to include the costs incurred by the
         | state courts and the agency in connection with enforcing these
         | provisions and the costs of establishing, maintaining, and
         | providing access to the accessible deletion mechanism described
         | above.
         | 
         | https://leginfo.legislature.ca.gov/faces/billTextClient.xhtm...
        
           | JumpCrisscross wrote:
           | Is there a route for private action? As in, could my parents
           | sue a data broker for not complying? Or is this only enforced
           | by California?
        
       | TheCaptain4815 wrote:
       | Very few things I'm jealous of in blue states, but their online
       | privacy protection is up there. I've pondered why no party has
       | made this a major priority, but the reality is the vast majority
       | of Americans simply don't care.
       | 
       | I would love to tell these big tech companies I want all traces
       | of myself removed from their search engines. I understand it gets
       | a bit nuanced with first amendment n such (what about a news
       | article of me committing "x crime"), but give citizens SOME
       | protection. At least Europe tries and pushes back.
        
         | c420 wrote:
         | I'd wager that lobbyist$ play a larger role than citizen apathy
         | for the lack of legislation.
        
         | fossuser wrote:
         | I'm in California - reality is even with this stuff it's hard.
         | I'd say maybe 20% companies you send CCPA request emails to
         | don't know what to do, have broken forms, etc. It does work
         | probably 80% of the time though.
         | 
         | I also use this which seems to work, but it's hard to know how
         | effective it is really: https://joindeleteme.com/
        
           | [deleted]
        
       | azinman2 wrote:
       | Curious about the issues surrounding credit scores and how much
       | this gets into it.
        
         | hedora wrote:
         | Back when interest rates were low, Rocket Mortgage incorrectly
         | tanked my credit score. They refused to fix it, which means
         | they were liable for whatever economic damage that causes.
         | 
         | When I refinanced, I explained the situation to the other
         | bank's loan agent. They emailed their underwriting division,
         | and the underwriters simply issued an override.
         | 
         | Not sure if that works these days or not, but my point is that
         | credit scores are complete bullshit. Hopefully most people will
         | push the button, inadvertently opting out of credit reporting,
         | and that corner of the industry will simply stop existing.
         | 
         | Lenders already do more due diligence than the credit agencies
         | do.
         | 
         | If you default on a loan, there could be a central record (say,
         | at the court house) of this, and lenders could consult that.
         | That would fill in the remaining missing functionality of the
         | score (and do so in a way that is transparently free of
         | institutional racism, etc).
        
           | adrr wrote:
           | Besides defaults how would you get precision in a model
           | without any other data? Payment history and total outstanding
           | credit wouldn't be there. You would have to trust the
           | customer to provide you with all these details.
           | 
           | Without precision in the risk model, cost to the consumer
           | will go up to mitigate risk. Someone who has paid all their
           | credit lines for 10 years but and has never defaulted has the
           | same risk profile as a person who has frequently missed
           | payments.
        
           | JumpCrisscross wrote:
           | > _credit scores are complete bullshit_
           | 
           | You can also juice it up or down by over a hundred points by
           | accumulating and then rapidly paying down balances.
        
             | galoisscobi wrote:
             | > juice it up or down
             | 
             | So what here determines if the score goes up instead of
             | down? I'm planning on getting a mortgage soon but wife's
             | credit score is in high 600s. If we can make it past, 720,
             | we are told we'll get a better rate. So I'm curious as to
             | how to bump up the score.
        
               | PascLeRasc wrote:
               | There are communities where you can rent someone else's
               | credit score as an authorized user.
        
               | toast0 wrote:
               | There's lots of articles everywhere, but the basics are:
               | make sure everything is paid on time; if you have any
               | earned negative items, see if you can get them removed by
               | asking nicely etc.
               | 
               | Then there's things like age of oldest account, average
               | age of accounts, etc. You may be able to add her to your
               | accounts to improve this factor, if your accounts are
               | older than hers.
               | 
               | Then balances. You get dinged for having a balance on too
               | many accounts. I think you also get dinged for having
               | zero balance everywhere. I think 'ideal' is 3ish cards
               | with balances (you can (and should) pay the whole balance
               | every statement, reporting is usually done just after the
               | statements). Highest ever balance should be less than
               | credit available or you get dinged; ask for credit
               | increases on cards where you ever went over the limit.
               | Total balance shouldn't be more than some % of total
               | credit, I think 35%? You also get dinged for high %
               | current balance on any one card. Again, you can add her
               | on high limit, low usage cards to help her score. She'll
               | get more score points as a joint account holder than an
               | authorizer card holder.
               | 
               | You get dinged for recent (6 month?) credit inquiries,
               | but inquiries are grouped, so if you apply for new
               | credit, try to get it all done in a few days; mortgage
               | inquiries have longer to be grouped.
               | 
               | If you know when your creditors do reporting, you can
               | adjust your payment dates to tweak things. You might make
               | a payment to your credit card before the statement closes
               | even in order to show a lower utilization % and that
               | could move your score a lot depending on details.
        
         | AJ007 wrote:
         | I assume it would be similar to declaring bankruptcy
        
         | TrendyCPU wrote:
         | I would also be curious to learn how it impacts Early Warning
         | Services which collects/reports data on bank accounts and
         | transactions.
         | 
         | The Privacy, Security, & OSINT Show did a podcast on it.[0]
         | 
         | 0. https://inteltechniques.com/blog/2022/04/15/the-privacy-
         | secu...
        
       | TrendyCPU wrote:
       | The legislation appears to be limited to data brokers. While this
       | is nice and welcomed, this also means it doesn't cover entities
       | like Google or Facebook.
        
         | theptip wrote:
         | CCPA already requires Google to delete your data on request.
         | Though AFAIK CCPA didn't produce any changes as Google already
         | allowed you to do that.
         | 
         | The same applies to any non-small business that you have a
         | direct relationship with and provide your information to; CCPA
         | requires that business to delete the info if you request it.
         | 
         | Data brokers are a special case because they don't get their
         | information directly from you, instead they slurp up whatever
         | public and private data they can scrape or buy, and then resell
         | that to other companies. Given you don't have a direct
         | relationship with the data brokers, it's hard to even figure
         | out who has your information.
         | 
         | Note, CCPA seems to have excluded the credit bureaus from
         | designation as data brokers, even though those guys are
         | responsible for leaking SSN and full personal information on
         | the majority of US citizens.
         | 
         | The US system of credit surveillance is pretty unusual (EU
         | countries don't do anywhere near that much stalking and they
         | have functioning debt markets) so I'd love to learn what would
         | actually break if people were allowed to opt out of that
         | tracking. Presumably there are some government records you
         | can't opt out of like UCC filings and bankruptcy, and any
         | potential creditor could just look up the primary sources
         | themselves.
        
         | CharlesW wrote:
         | I'm astounded that they aren't considered data brokers in the
         | eyes of U.S. law.
        
           | 0xcde4c3db wrote:
           | The standard answer (at least for Google, not sure about
           | Facebook) is that they're not considered data brokers because
           | they only sell ad placement based on the data, not the data
           | itself.
        
             | hedora wrote:
             | Google helped craft these laws. This is classic regulatory
             | capture.
             | 
             | In particular, it is banning horizontally integrated
             | surveillance capitalism (which requires the sale of data
             | between the data gathering companies and the people using
             | it), but not vertically integrated surveillance capitalism.
             | 
             | In all likelihood, some companies in this ecosystem will be
             | forced to sell at fire sales to conglomerates (like Google)
             | simply to avoid having to comply with this law. Of course,
             | this benefits organizations that are large enough to
             | acquire the companies, and no one else.
             | 
             | So, people with financial conflicts of interest are picking
             | winners and losers, which is pretty much standard practice
             | in US politics these days.
             | 
             | I personally think this whole consumer tracking industry
             | should be shut down. It should be illegal to gather the
             | types of information that this bill regulates.
        
               | paulddraper wrote:
               | You do understand that there is a real difference between
               | selling ad placement and selling personal data, right?
               | 
               | Maybe you hate both, but there is a meaningful
               | difference.
        
             | hef19898 wrote:
             | One could make a case for splitting the data collection
             | activities from the ad sales business as part of an anti
             | trust case. Or pass regulations and laws to that effect.
        
               | [deleted]
        
               | vineyardmike wrote:
               | That would be a pretty weird case to make. Typically anti
               | trust is used to prevent a business from using market
               | dominance in one market from entering another market.
               | Considering they don't participate in the data sales
               | business it'd be a weird scenario to force them to start.
               | I'd prefer we don't force them to start.
               | 
               | Gmail with ads seems way preferable to Gmail who sells
               | your data to others.
        
               | hef19898 wrote:
               | Well, I m affraid it is both, ads and data selling...
        
               | chimeracoder wrote:
               | > One could make a case for splitting the data collection
               | activities from the ad sales business as part of an anti
               | trust case. Or pass regulations and laws to that effect.
               | 
               | That would be a net negative for privacy, because it
               | would mean more parties having access to your data
               | (without your consent or even knowledge). And given the
               | state of security in ad-tech _aside_ from Google, that
               | means the chances of your data getting breached and
               | leaked would increase exponentially.
        
         | adrr wrote:
         | They don't sell your data.
        
           | majormajor wrote:
           | They don't sell your data TODAY.
           | 
           | Who knows what they'd sell if their business declined for a
           | while and there was a hostile takeover or they otherwise got
           | desperate for new revenue streams.
           | 
           | And then if you were paying attention you could make a new
           | one of these requests... but maybe you'd miss it for a bit,
           | and then it would be too late.
           | 
           | The law should be based on what you collect instead of what
           | you sell to better protect against this sort of thing.
        
             | adrr wrote:
             | Thats not relevant of what they could do. This laws covers
             | what you are doing and applies to entities selling your
             | data. Big ad players don't sell their data because that is
             | their secret sauce in ad targeting.
             | 
             | Companies selling your data are your bank(credit card
             | purchases), mobile carriers(location), your DMV(photos,
             | driving record, misc PII including address, dob etc),
             | state/county government(public records like marriage
             | licenses). Its weird everyone bashes on google and FB for
             | something they don't even do.
        
           | noizejoy wrote:
           | > They don't sell your data.
           | 
           | ... except when they sell their domain registration business.
           | 
           | And yes, I realize that there's a (technical) difference
           | between selling data and selling a business including its
           | data assets.
           | 
           | But then again, maybe a really big chunk of the value of that
           | business is its customer data.
           | 
           | For some business acquisitions special terminology like
           | "aqui-hiring"[0] has evolved so it's understood that not
           | every sale of a business is of the same nature.
           | 
           | And since the value of data has arguably become much higher
           | than ever before, the distinction of selling data by itself
           | and selling the entire business is becoming smaller as time
           | goes on.
           | 
           | [0]https://en.wikipedia.org/wiki/Acqui-hiring
        
       | qwerty456127 wrote:
       | I want a bill which would let me just ban all data brokers
       | forever. I don't mind first parties to save some relevant data
       | necessary for them to do their job, I can even understand 3rd
       | parties like Google Analytics involved, but data brokers - I
       | really don't want any of them to have any data about me ever.
        
         | pauldenton wrote:
         | Do you want to ban Manual Data Brokers. Private Investigators?
        
         | willio58 wrote:
         | Yeah this is it. I want to have full knowledge over who has my
         | data and for what purpose. I think we'll get there eventually
         | but it'll take a while.
        
       | hackncheese wrote:
       | This reminds me of a company my friend used to work for, Ketch
       | [1]. Basically described their service as automation that
       | fulfills this exact requirement on customers databases. Sounds
       | like they were ahead of the game.
       | 
       | [1] https://www.ketch.com/
        
       | kepler1 wrote:
       | Are we talking actual data deletion, or just "not serving it up
       | when queried" or attaching a "do not use" flag to the data but
       | keeping it?
       | 
       | Because if there's one thing I've almost never seen, it's data
       | being deleted from a db.
        
         | striking wrote:
         | From the bill:
         | 
         | > The bill would, beginning January 1, 2028, and every 3 years
         | thereafter, require a data broker to undergo an audit by an
         | independent third party to determine compliance with these
         | provisions and would require the data broker to submit an audit
         | report to the agency upon the agency's written request, as
         | specified.
         | 
         | https://leginfo.legislature.ca.gov/faces/billTextClient.xhtm...
        
           | d3w4s9 wrote:
           | I don't think that section answers the question.
        
             | kepler1 wrote:
             | Thanks, that spurred me to read about it given the link
             | above.
             | 
             | > " _This bill would require the agency to establish, by
             | January 1, 2026, an accessible deletion mechanism that,
             | among other things, allows a consumer, through a single
             | verifiable consumer request, to request that every data
             | broker that maintains any personal information delete any
             | personal information related to that consumer held by the
             | data broker or associated service provider or contractor.
             | The bill would specify requirements for this accessible
             | deletion mechanism, and would, beginning August 1, 2026,
             | require a data broker to access the mechanism at least once
             | every 45 days and, among other things, process all deletion
             | requests, except as specified. Beginning July August 1,
             | 2026, after a consumer has submitted a deletion request and
             | a data broker has deleted the consumer's data pursuant to
             | the bill's provisions, the bill would require the data
             | broker to delete all personal information of the consumer
             | at least once every 45 days, as specified, and would
             | prohibit the data broker from selling or sharing new
             | personal information of the consumer, as specified_....
             | 
             | > " _This bill would provide that a data broker that fails
             | to comply with the requirements pertaining to the
             | accessible deletion mechanism described above is liable for
             | civil penalties, administrative fines, fees, and costs, as
             | specified, and would raise the amount of the existing civil
             | penalty provisions described above_.... "
             | 
             | I guess it all comes down to the implementation level how
             | specific and "actually deleting" they will be. And whether
             | the new agency (ugh) charged with enforcing this will
             | actually have teeth in the details.
             | 
             | And I don't know why such a long 45 day period is required.
             | For reasons we're all too familiar with, people are quite
             | able to gather data within seconds, but somehow need 45
             | days to delete it?
        
               | addaon wrote:
               | Deleting data from backups (or, more often, aging out
               | backups and deleting them wholesale) is usually a batch
               | process. You really don't want to have to do online
               | modification of backups... they're not really backups at
               | that point. 45 days doesn't seem unreasonable.
        
               | kepler1 wrote:
               | Well... doesn't that circumvent the point of backups?
               | Backups in my mind are supposed to be like read-only, can
               | never be modified so that the system that was corrupted
               | can't do anything harmful to the safe previous
               | checkpoint.
               | 
               | I guess it has to have some method of what you mention
               | then. If someone wants their data deleted, yes, what
               | about the backups?
        
               | callalex wrote:
               | If it's so much work to handle the data responsibly,
               | maybe it shouldn't be collected in the first place.
        
       | neonate wrote:
       | http://web.archive.org/web/20230915153457/https://www.latime...
       | 
       | https://archive.ph/1ebn0
        
       | maaand wrote:
       | Question is what are the loop-holes available for the databrokers
       | to ignore data deletion requests?
        
       | NelsonMinar wrote:
       | I've been grateful as a Californian for our regulations of online
       | businesses. I regularly invoke our right-to-unsubscribe and the
       | CCPA gives us something similar to the GDPR in various ways.
       | 
       | To what extent do companies extend these rights to all Americans
       | because it's easier than building a California-specific version
       | of a website or online product?
        
         | gochi wrote:
         | Likely depends on the scale of the company. The likes of Google
         | (I know they aren't specifically on the line for this law
         | anyways) will have more than enough resources to ensure you're
         | a California resident before allowing such. Hard to see others
         | caring and just adhering your request as a non-California
         | resident when it's always a small margin of people that even
         | take advantage of privacy respecting laws.
        
           | Alupis wrote:
           | Exactly. The Parent comment strikes me as being very naive.
           | 
           | Right to Unsubscribe? Gmail and other email providers do this
           | for you even if you are not a CA resident and even if the
           | Marketer does not have a built-in Unsubscribe link. From a
           | Marketer perspective, you cost money to send emails to, and
           | if you are not going to open, they kind of don't want you on
           | the list anyway.
           | 
           | CCPA == GDPR? Not even close. Majority of CA businesses do
           | not reach the compliance threshold and therefore do not have
           | to or will not comply with requests. Additionally, you have
           | no way to validate if the request was actually carried out.
           | The company's "best efforts" to remove data from _their_
           | systems is all that 's required at best - and a lot of data
           | can be retained for valid business reasons.
           | 
           | Lastly - despite what CA residents believe (and similar to EU
           | residents with GDPR) - CA laws do not apply to the rest of
           | the country simply because they are unenforceable except in
           | the most egregious cases - and even then it would have to be
           | a very large business anyway.
           | 
           | > because it's easier than building a California-specific
           | version of a website or online product
           | 
           | Nobody is doing this in practice. At best, they use some
           | GeoIP thing or if you are logged into an account (which means
           | they have your data anyway). The law does not require them to
           | validate the user anyway, so it's all "best effort" again
           | which usually means low effort.
           | 
           | But hey, if it makes you feel warm and fuzzy believing these
           | things - more power to you.
        
             | callalex wrote:
             | The right to unsubscribe being discussed here has nothing
             | to do with emails. It states that if you paid for a
             | subscription online, you must be able to cancel it online
             | within a few clicks as well. No "call us" or "send a
             | registered letter during a full moon and low tide only"
             | nonsense. It's really great.
        
               | NelsonMinar wrote:
               | There are numerous summaries of that right available
               | here: https://www.google.com/search?q=california+right+to
               | +unsubscr...
        
               | Alupis wrote:
               | > No "call us" or "send a registered letter during a full
               | moon and low tide only" nonsense. It's really great.
               | 
               | I am very skeptical even this is as great as some think.
               | Outside CA, most companies can simply ignore these
               | "viral" style laws with no consequences.
        
               | r00fus wrote:
               | As another Californian, I'd love examples of where this
               | is ignored, or where non-californians also benefit from
               | these.
               | 
               | I also gladly unsubscribe easily without frustration -
               | just not sure if this is common in other states.
        
               | Alupis wrote:
               | How about a concrete example of a big business that did
               | not allow you to cancel online _prior_ to this law?
               | 
               | Netflix? Nope. Comcast? Nope. Google? Nope. Verizon?
               | Nope. AT&T? Nope. Apple? Nope. PG&E? Nope...
               | 
               | Where is this mythical renaissance of _new_ online
               | cancellations?
               | 
               | Turns out - most big businesses did this already... oh,
               | but now it's the law but who's enforcing? Lawyers who
               | gain private settlements? That's not enforcement, that's
               | a racket.
        
               | callalex wrote:
               | I can assure you as a Californian that this law is not
               | ignored. They are taking payment from my credit card so
               | they can't claim ignorance of my California address.
        
               | Alupis wrote:
               | There's no citizen enforcement clause for most of these
               | laws and therefore this mostly means nothing - and where
               | there is it just turns into a money grab/shakedown by
               | bottom feeding lawyers (see existing FAL & P65 suits).
               | Suits get settled, lawyers get paid, plaintiff gets a
               | cut, no wrongdoing is admitted, and nothing changes.
               | 
               | It's not about claiming ignorance. It's about not caring
               | about CA viral laws and CA's inability to effectively
               | enforce them around the world.
               | 
               | Much like how most companies laugh when some EU citizens
               | tries to flex GDPR in the US... hilarious unless you're
               | Google...
               | 
               | People lock-in on the intent and names of these things
               | and believe they've "won" the privacy war. Just like the
               | "Inflation Reduction Act" these laws do very little if
               | anything for their namesake.
        
               | callalex wrote:
               | It's really odd to me that you are telling me that my
               | lived experience is false and impossible. Every
               | subscription I have made since this law passed, I have
               | been able to cancel online. This includes newspapers,
               | store club memberships, random podcasts and other online
               | entertainment, educational software, and more.
               | 
               | Sometimes the government really does work for the people.
               | It is actually possible.
        
               | Alupis wrote:
               | Overwhelming majority of those things you listed could
               | already be cancelled online.
               | 
               | You can read the laws yourself. There's not a lot of
               | teeth for small businesses to comply.
               | 
               | Go look at the state AG website for P65 complaints (they
               | are all by law published). 99% are privately settled
               | without wrongdoing (you can see this on AG website too),
               | and some fee is paid to the plaintiff's attorneys.
               | Sometimes the math says it's cheaper to comply, but often
               | not. Small (and even big) businesses around the country
               | freely ignore P65 despite the law having citizen
               | enforcement. If you search on the AG website you will
               | find _many_ repeat offenders. P65 laws have been around
               | for decades...
               | 
               | There's a difference between what people believe should
               | happen and what actually happens. If you believe these
               | laws have "won" the privacy war - you are mistaken.
        
               | r00fus wrote:
               | Why are you conflating right-to-unsubscribe with P65?
               | They are different laws with different enforcement
               | mechanisms. Also consumers don't find P65 useful whereas
               | we see benefit from unsubscribing.
        
               | Alupis wrote:
               | The point was we have these sort of consumer protection
               | laws and nothing has changed. The enforcement mechanisms
               | are weak and designed to make lawyers money more than
               | actually gain compliance.
               | 
               | Given the decades of P65 enforcement - and given the
               | prevalence of "harmful" chemicals imported into this
               | state every day, we have no reason to believe this
               | unsubscribe law will be any different.
               | 
               | Having this law makes people feel like something was
               | accomplished, despite reality.
        
               | r00fus wrote:
               | The unsubscribe law has been on the books for nearly 2
               | years. Most vendors have changed their processes. I have
               | personally benefited.
               | 
               | I expect nothing less for this law. Show me an example
               | for a relevant law not the P65 BS.
        
         | nolroz wrote:
         | I would think a lot. Everyone would rather not have wait for
         | legal to answer a new set of questions every time a state
         | changes their laws. Easier to align on the strictest
         | legislation and go from there, IMHO.
        
       ___________________________________________________________________
       (page generated 2023-09-15 23:01 UTC)