Vermont passes first law to crack down on data brokers
techcrunch.com
techcrunch.com
My home country has a Privacy Act, it’s terribly weak and has little enforcement but the principals in it were drilled into me from the very start of my career. Customer data is really important. It must be kept private and not shared. And we should only have what we need to have for whatever we’re doing for them. I don’t know why those principals are so hard for people to swallow. Now in the states when I hear mobile carriers are selling my location data without my consent, and so on, I get completely irate. It boggles my mind why people think that kind of behavior should be allowed.
A Saas company that does nothing fishy with users data, may still be concerned with the harsh, company destroying penalties associated with GDPR. Indeed there have been dozens of discussions on HN about this. It may be FUD, but it’s real.
The other people are doing terrible things.
Please don’t assert the people in the first group are actually in the second.
> The people doing terrible things are trying to convince other companies that they will be destroyed by the GDPR
Not saying the GDPR is bad, I’d personally like to see it applied every where.
You can be doing good, normal things and still not be compliant with the law.
These are entirely imagined, most likely by Americans spreading FUD, or people interpreting the terms "maximum fine" as a minimum fine.
The top comment from a post yesterday explains it very well: https://news.ycombinator.com/item?id=17165707
> Because Facebook and Google have been guided by the principal: if it's not illegal, it's ethical.
The problem with that philosophy is that if you've normalized any questionable behavior on the basis that it is legal, the natural response will be stronger legislation. The "unstated rules" around privacy and people's personal information have been broken.
Any ire at forthcoming regulation should be directed at the bad actors, like Facebook and Google.
Agreed, but the buyers of said information should be scrutinized too. If they are willing to pay money for that information, what are they using it for?
Because it puts a whole bunch of people out of a job and ruins the user experience for many things. Every news site I go to I get greeted by a pop up that won't go away until I interact with it. Apparently similar things are happening with phone apps as well. And while this is happening I've read about people having their app revenue drop 90% in some cases.
We're not even a full week in yet, so we don't know what the full effects of this are going to be.
>It boggles my mind why people think that kind of behavior should be allowed.
It's not about whether data abuse is okay or not, but rather it's about the consequences of taking such a heavy-handed approach as GDPR did.
No, really, it is the advertisers who ruined the experience in the first place. And almost every site tries to make you agree to data collection without giving you another option, or hiding the other option under several menus. That's why I closed the TC page.
I work for an ad arb business. We don’t collect user-identifiable data and still make loads of money.
Your point of view would seem to justify child trafficking if that would pay the bills for most of the people in the industry.
It absolutely starts from "whether data abuse is okay or not". If data abuse is unacceptable, then the question is "what is the law currently doing to address that?" The industry had ample opportunity to self-regulate, but all we've received in breach after breach is long-delayed shallow apologies. The running joke is that Zuckerberg and FB have been on a 15-year "apology tour", giving hollow apologies for seemingly grave transgressions that other people warned about [1].
And given how tech unicorns like Uber treats fines [2], a heavy-handed approach seems to be the only way to actually curb the behavior in questions.
[1] EFF in 2009 warned that companies could take advantage of the leaky Facebook API, predicting the Cambridge Analytica situation 4 years in advance.
[2] In multiple jurisdictions that do not allow ride sharing, Uber has told drivers that they would pay the fines that drivers incur.
Progress is not linear. Perhaps we'll have some AI soon to deal with that issue.
Yup, that's the reason behind the hysteria.
> and ruins the user experience for many things.
Let's put the blame where it belongs. It's not GDPR that is ruining the experience. It's the sites that refuse to take a hint and stop abusing users' data. When you prepare this popup that will "ruin the user experience", you list a bunch of things in it. All of those are the things you should strongly consider stopping doing.
> And while this is happening I've read about people having their app revenue drop 90% in some cases.
Honestly, I was strongly hoping this would happen. Good to hear the new law is working.
> It's not about whether data abuse is okay or not, but rather it's about the consequences of taking such a heavy-handed approach as GDPR did.
As others said, the industry had plenty of time to avoid this. For instance, the Cookie Directive is a decade old now, with previous regulations touching this sphere as early as 16 years ago. The industry instead doubled down on user-hostile practices. So now we've got GDPR.
Clicking a few checkboxes is a very small price to pay for the benefits of improved data protection.
The scary part is the big companies will have the money to lobby for regulations to be written in a way that is easy for them to comply with while shutting out smaller companies and startups.
Data brokers in Vermont will now have to register as such with the state; they must take standard security measures and notify authorities of security breaches (no, they weren’t before); and using their data for criminal purposes like fraud is now its own actionable offense.
It defines data brokers as businesses in Vermont that buy and sell data on people with whom they have no direct relationship. Seems like a reasonable law - unlike GDPR, they aren’t trying to reach outside of their jurisdiction, they aren’t trying to wipe out entire business models, there are no absurd fines, it’s easy to know if you’re violating it (because you would know that you have setup a data brokerage in Vermont), etc. My guess is there are only a handful of “data brokers” as they define that term within Vermont, so this affects very few people.
Data brokers are scum. They do not produce any value, they do not improve the society, they have no positive effect on anyone. No reasonable person should stand up to protect them from liability.
Some excerpts that define some key terms:
"(2) "Business" means a commercial entity, including a sole proprietorship, partnership, corporation, association, limited liability company, or other group, however organized and whether or not organized to operate at a profit, including a financial institution organized, charterd, or holding a license or authorization certificate under the laws of this State, any other state, the United States, or any other country, or the parent, affiliate, or subsidiary of a financial institution, but does not include the State, a State agency, any political subdivision of the State, or a vendor acting solely on behalf of, and at the direction of, the State.
(3) "Consumer" means an individual residing in this State.
(4)(A) "Data broker" means a business, or unit or units of a business, separately or together, that knowingly collects and sells or licenses to third parties the brokered personal information of a consumer with whom the business does not have a direct relationship."
They use the broad definition of a “business” because in the US you can be incorporated in Delaware and actually operate in Vermont. This is actually a common thing - most US corporations are incorporated under the laws of either Delaware or Nevada but operate within their home state. But the state only has the ability to regulate the actual operations of businesses operating within Vermont.
Yes, that's the point: at the moment, vacuuming up every bit of data is essentially free, so companies take a maximalist approach to it, and aren't paying nearly their fair share of the resulting externality costs. Personal data storage needs to become costly enough that companies are forced to decide if it's actually worth it.
I would also add that, just like every other time an industry failed completely at self-regulation and just ran wild until public outrage forced the government to step in, this wouldn't be happening if companies had been responsible. But CA and Experia and Unroll.me proved that was never a possibility.
IMO, it's that a) people in EU care more about privacy and b) the political influence of the data processors in question isn't as strong as in the USA.
b) (with swapped roles) is the reason why the diesel emissions cheating and the FIFA bribery cases were investigated in the USA. They were open secrets, but nobody did anything about them in their countries of origin because of regulatory capture.
The other thing is that the EU parliament has some internal political shuffling that most people aren't even aware of. I don't know anybody in real life that can name even one of the parties (or groups) in the EU parliament. It's very difficult to say that they're definitely doing what the people want.
>How do you think that GDPR is the optimal way to achieve... Well, what exactly are you saying is the goal? You are only alluding, thus letting everyone complete your argument with whatever they may find most credible.
Simply make it more difficult for established/outside companies to target the EU market. It's not a conspiracy, so there isn't like a step by step plan that could be taken by the EU to actually do this. Only some people and groups in the EU seem to be really interested in something like this.
I could in principle not see it anything less than a form of unlawful surveillance.
For example, what’s the point in showing ads for custom quadcopter parts to an 80 year old grandmother who doesn’t know what a quadcopter is?
Data should be regulated and protected much more than it currently is. But the idea of banning it entirely would have a lot of negative effects. Let’s be smarter than that.
Oh the horror.
I need you to build a good product and display it in a good store.
Though sometimes you want to get the word out about a specific thing. But this is where getting people's social circles hearing about something and trying it is important.
I definitely see a few needs for advertisement. But mostly down sides IMO.
All advertising should be strictly confined to designated areas specifically intended for consumer searching.
> Consumers aren't going to search for something they don't know exists in the first place
If a consumer doesn't buy something they don't know exists, does it really matter?
Life, at least for me and the people I know, doesn't revolve around finding things to spend money on.
Adding an ad blocker a few years ago this trend is likely to continue, though now my web pages work better and my privacy is enhanced :)
All we need is a push towards criminalization of ads in public spaces where they are forced on people not based on their need, but based on their ability to be manipulated into buying shit they don't need.
And suppose that happens. Do you know what the system ends up as? Cable TV. Congratulations, net neutrality was unnecessary after all.
I've had to turn off alerts and miss notifications from friends because marketers have run amok. And we go back to the cost: it's been so doggone cheap that so many marketers have gotten to where they just don't care about being annoying.
There should be a higher cost to access me when I'm sitting in my barber's chair. Actually, DON'T contact me when I'm in my barber's chair. Go back to tv commercials, billboards, and snail mail. Put in some effort.
Here's a plot that shows marketing channel fit by product type: http://www.kevinlordbarry.com/uploads/3/6/5/4/3654649/edited...
Just like TV, radio, and magazines before them, advertisers can select which advertisements to put on which sections of websites (or broadly make their decisions on what types of sections they should display on), and individual display requests can and should be de-personalized for privacy measures. Advertisers can still access or determine indicators of demographics for places on the web without individual tracking measures, and measure click-through for various A/B testing for different ads in different contexts.
The contents & general audience of a page should determine the ad, not the individual visitor.
Podcasts, which (so far) have mostly been free from extreme privacy-violating ad networks, have been doing this for ages; I regularly hear relevant ads for Ting, Linux Academy and Digital Ocean when listening to Linux-podcasts, or for bone conducting headphones, fancy mesh network routers and domain name registrars when listening to general tech podcasts. I also hear ads for PC hardware and VPNs when watching tech YouTube-videos. The ads YouTube itself chooses for me, on the other hand, are generally completely unnecessary and poorly targeted ads for movies I don't want to see or cars or soda.
For example, it's a standard practice to use a person's credit history and credit score during insurance underwriting - data shows people who are responsible with credit have less claims, so they have lower premiums. However, say you live in Massachusetts. In Massachusetts it's illegal for insurance companies to take your credit history and credit score into account when determining policy premiums. So insurance companies are not allowed to access your credit if you live in Massachusetts even though that information is widely available and used in other states.
Cynical prediction: Vermont has less than a million residents. It may be both easier (as in less effort) and less expensive, if you're a data broker, to just cease trafficking in the data of anyone tangentially associated [3] with the state of Vermont.
[1] http://ago.vermont.gov/blog/2018/05/24/a-g-new-data-broker-l... [2] https://legislature.vermont.gov/bill/status/2018/H.764 [3] https://en.wikipedia.org/wiki/Vermont#Population_changes
That's assuming the jurisdictions have the same rules as one another. If they have different rules, or conflicting rules, or rules that conflict with some other jurisdiction's data retention requirements, it becomes a huge mess.
And the probability of the US adopting the GDPR verbatim is practically nil.
Though I do have hope that there will be a common base that gives compliance amongst all regulatory areas.
Why would that be? AFAICT, this law merely sets standards for data brokers operating within the state of Vermont. It doesn’t try to dictate what anyone outside the state can do with data from people in Vermont, like GDPR does. Given Vermont’s size, my guess is that there are very few companies in Vermont that this law actually applies to.
Meanwhile, 'data broker' is defined as 'business' that engages in the brokering of data (obviously paraphrasing), where 'business' isn't bound by being incorporated in Vermont, but applies worldwide.
If a state in the US starts saying it has the power to regulate businesses in other states and countries, that would be news.
Also, please read the article we are commenting on:
Data brokers in Vermont will now have to register as such with the state; they must take standard security measures and notify authorities of security breaches (no, they weren’t before); and using their data for criminal purposes like fraud is now its own actionable offense.
That is what this law does. Nothing more, nothing less.
Data isn't neccesarily about unwanted creepy stuff. In other industries, customer data can be used to recomend the right stuff, or make the kind of movies people want to watch. That stuff enhances peoples lives - in individually small but additive ways.
In my industry, data really can save lives. For instance the prime minister of my country apparantly wants to apply AI to peoples GP records to spot people who have undiagnosed cancer. This seems pretty viable to me - even in the most simple case you could quickly spot families with high cancer risk, offer the young women in them gene sequencing, and then offer the ones that are carrying super high risk cancer genes preventative treatement. You'd certainly save lives this way.
There are a lot of very scary ethical questions in my industry. Widespread use of genetics to price insurance. Employers requiring employees give access to medical records before confirming employment. And much more.
But I do worry this backlash will make it much harder to do good.
It's a critical part of medical ethics anyway.
This strikes me as being largely symbolic and not likely to have much of an impact, unless other states follow through with similar consumer protections. However if Deleware were to pass legislation like this, that would be a lot more meaningful.