The California Consumer Privacy Act Should Be Condemned, Not Celebrated
blog.ericgoldman.org
blog.ericgoldman.org
> Thus, consumers will pay for the CaCPA-mandated offerings one way or another, regardless of whether they value, or take advantage of, them.
There was a study showing that if you randomly ask people on the street, many will give you their e-mail password in exchange for a literal chocolate bar. Does that imply that we should freely post password leaks online as they apparently have very low value?
From my understanding, the proposition of everyone deciding about a value for themselves requires that they have enough information to assess that value. This is not the case with privacy: The consequences of someone tracking you are often completely unclear and businesses have little interest in making it clearer.
> Facebook may have been the target, but the local pizzeria will bear the law’s brunt.
If the local pizzeria would sell my data to some shady third-parties, I don't see how that would be better than Facebook using it itself.
But more importantly, I think it's extremely difficult to write legislation that is exclusively targeted at large companies. Those will always have more resources to find loopholes than small companies. E.g., if the limit was set higher, I could imagine Facebook/Google/etc inventing an army of small "subcontractors" who would, on paper, handle the data, so they could benefit from the exception, too.
How would a legislation look that (a) responds to the OP's criticism and (b) is not completely toothless?
Especially if they give you a point of sale system, and it automatically generates reports for tracking sales tax or ties into accounting software for small businesses, it’s difficult to imagine them not joining such a program and choosing to do paperwork manually instead.
The author says he gets about $400/month from ads, but would stop if the cost/effort to comply was more than that. It sounds like the service didn’t just outsource the process of finding advertisers who want to display an ad, it also outsources the collection of data about visitors and selling it to data brokers.
Whether the law is bad has a lot to do with whether it is beneficial or not to have every blog and every local pizza shop involved in selling customer data. The services that are paying $400/month for negligible additional effort are not going to be unaware of legislation, and will adapt their practices to comply with whatever privacy standards are chosen by the society where they operate. If $300 of that income comes from data brokers rather than advertisers then that part of the income simply wouldn’t be legal without extra work, and it is the prerogative of societies to make such decisions about the property rights of data.
Also probably doesn't matter what they do with the data but the mere fact they have it means they have to comply with all the requirements of this new law so even if they just use it so you don't have to tell them your address every time you call they still have to treat it like they are selling it to some marketing megacorp.
Specifically, the law reaches businesses that collect personal information from 50,000-plus consumers per year, regardless of revenue. This applies to businesses that accept credit cards from 137-plus unique customers per day, including Walmart, Amazon, and a typical frozen yogurt stand"
1) 50000 / 365,25 = 136,89 and 50000 / 365 = 136,986. That's 137 unique customers per day, over the entire year.
2) This number does not take into account paying by cash. I know, I know, Americans love credit cards. But for a simple frozen yogurt stand everyone uses credit card? Really???
3) This number does not take into account returning customers over the entire year. Many customers are going to be regular, loyal customers. Depends on location and such (touristy area probably far less).
4) Revenue can be gamed...
No, it implies that giving low-value, supposed studies as evidence of something is completely worthless. Someone asked someone for a password for a candy bar - supposedly. Come one now, really?
There was a study showing that if you randomly ask people on the street, many will give you their e-mail password in exchange for a literal chocolate bar. Does that imply that we should freely post password leaks online as they apparently have very low value?
This is the generic argument always given that most people are too stupid or too lazy to figure it out for themselves so we must involve the state. There's a grain of truth to the argument, but it's somewhat of a hateful argument - usually with the presenter of the argument thinking they understand the issues and could decide for themselves, but that others aren't capable of it.
> Duplicative CaCPA/GDPR compliance. Because the CaCPA’s requirements don’t track the EU General Data Protection Regulation, GDPR-compliant businesses will incur additional compliance costs.
How many Californian pizzerias deliver to Europe?
As it should. Why are they collecting it in the first place? The requirement is not onerous; simply refrain from actively collecting data that you don’t actually need. That’s it.
Just think of data as a liability rather than an asset and everything else comes naturally.
I need to read the actual bill closer but I would want political campaigns, charities, and PACs, subject to it as well. It is depressing how many "protection" bills exclude political committees and related PACs.
[1] https://iapp.org/news/a/top-five-operational-impacts-of-cacp...
That's because they're quasi-government entities or related, and above the fray.
No, they’re not. If anything, the distinction should be more clear for these entities than other private businesses who could at least be contracted by the government. Political campaigns are entirely private marketing arrangements. The extent to which they are “quasi-government” should be perfectly obvious in light of their intentions, which is to become elected in the future. Even if the candidate is serving in office, that office’s duties and the campaign they run are separate projects. There is no blurry line here.
It's an important distinction because Facebook and Google don't really sell your data per se, they sell you a service that does heuristic targeting for you based on their data. A small component of that product lets you use some shared data to track things like conversions, but that's not core of the objection to how Facebook does advertising.