Silicon Valley is terrified of California’s privacy law
techcrunch.com
techcrunch.com
- Businesses must disclose what information they collect, what business purpose they do so for and any third parties they share that data with.
- Businesses would be required to comply with official consumer requests to delete that data.
- Consumers can opt out of their data being sold, and businesses can’t retaliate by changing the price or level of service.
- Businesses can, however, offer “financial incentives” for being allowed to collect data.
- California authorities are empowered to fine companies for violations.
I totally understand that this will impact a lot of tech companies' profits...but that's to be expected if you're making money selling people's data to third parties without their permission.
This is something I object to. It's just fundamentally stupid and doesn't make sense. The entire premise of free exchange is that I give you my services in exchange for something of value of yours. Making it illegal to withhold services if you don't give up your data is crazy. The only reason those services are being provided at all is to get that data. That's effectively a requirement that people provide services for free.
EDIT: I'll also add that it strongly favors incumbent tech companies, by explicitly carving out "selling to third parties" as a disfavored tactic. Google can monetize your data internally. Your average startup may not be able to. Specifically carving out "selling to third parties" favors large, incumbent players over small startups. But then, regulation always does.
That way it feels more transparent to the end-user, and they have to make the conscious choice of either giving a bit of their data in exchance of a free service or be prepared to pay to keep their data private.
What's the practical difference between these two scenarios?
1) I offer a free service if you let me collect your data, but charge you $3/mo if you refuse to let me collect it.
2) I offer a $3/mo service, but give you $3/mo back if you let me collect your data.
Option #1 is explicitly illegal under the new California law. If option #2 is legal, then what is the law supposed to ban?
It might inadvertently assign a price to the data collected.
It also shows a direct discrimination against poor and/or young people who might not afford the service.
The problem is that then you cannot effectively offer a service level that is ad based. Say I want to offer some web services. I provide a free tier with ads (information gathering and selling) and a payed tier with no ads. This law says that I cannot charge more for the non-ads version. OK, so then I make both cost the same, either free or some fixed cost. If they are both free, what stops everyone from just using the non-ads version, it's free too. If both aren't free and cost money, what is the point of even providing the ad version, since people can pay the same and get the no-ads version. Not to mention, everyone that is fine giving their information in order to receive the service for "free" is now not able to do that.
We impose these restrictions for the good of the public. If we decide that exchanging personal data for goods and services should be illegal under certain conditions, I don't see why that's any different than the precedents I mentioned.
> - Businesses can, however, offer “financial incentives” for being allowed to collect data.
This just means your service always costs money, but you can refund the full amount for allowing you to collect data.
Not if the thing I value is my personal data. Because I, as a typical short sighted consumer, will consistently underestimate the value of my data, as well as how my data affects those around me (extreme case: my data is my social graph, which you can use to reconstruct the social graph of my acquaintances).
If I don't know the actual value of what I am giving up, I am naturally going to get swindled.
If Friendo doesn’t have the same relationship I have with Tech.co, how is Friendo benefitting? Where is the exchange there?
Any concern regarding whether consent is likely to be withheld really just points out how stupid a company's business model is. Incumbent vs. Startup is also a false premise because Facebook is an incumbent that relies on selling user data. They do make some money from purely internal advertising, but in total Facebook only makes less than $5 per user when selling data, and that's lifetime, not per year. So the only way to make real profits from selling data is if you sell millions of people's data. Their internal data use however, is just for add targeting which they make more money from each year. This internal use makes more per user and is therefore a more viable strategy for a small company than selling data.
There are already regulations that make it impossible to sell user data that would be valuable that apply to more than just internet collected information. So, any data selling strategy a startup or incumbent company might have will either not earn significant profits or is very likely already illegal.
In any case, advertising revenue rarely ever covers a company's expenses. If a company is only staying afloat because of selling data, then that company is achieving a very poor return on investment and is wasting the time of everyone involved. Either they need better business processes, strategies or they're not offering something of sufficient value to be worth the time put into the business.
In this view, a company offering a discount in exchange for sharing is inherently deceptive.
The service isn't free. The exchange just isn't money. When money is involved a price is put forth. It's an agreed to and published exchange mechanism. When it's data on someone the price isn't shared. It's kept secret. There's always a price. It's just not always money or public. This will make more information public.
I wonder if this will start to change how business operate. Right now they are skewed against consumers towards businesses. I wonder if consumer protections, like this, will cause businesses to re-evaluate business models.
Giovanni Buttarelli, European Data Protection Supervisor “There might well be a market for personal data, just like there is, tragically, a market for live human organs, but that does not mean that we can or should give that market the blessing of legislation.”
Privacy is fundamental human right that you cant trade for. Same as you cant sign a lawfull contract that you want to be someones slave, even if you want to.
However, customers aren't well informed, and if they were, they wouldn't use these services. Currently customers are getting scammed for their data. This is why we need regulation.
The problem is that these companies advertise their products as "free," which means something very different. And they usually don't mention at all that they're collecting shit tons of personal data. It's taking advantage of people's ignorance, and it's practically fraud, IMO.
Every other business tells the customer up front what the price is, and maybe it's time tech companies started doing the same.
Without telling users what data they collect, how much they collect, how they use it, and who they give it to, there's no way for users to make an informed decision.
I never explicitly stated that I'd serve these companies by giving my data. Services cannot be assumed, why do you think there are such long Terms of Service. We as users should also have Terms of Service then.
EDIT: Several comments below point out the innumerable businesses operating in such a way as to make mine an impossible claim.
Enumerating the established methods to avoid meeting the legal parameters of price discrimination is not the same as price discrimination being legal.
My bar for following just laws is higher than the minimum required to avoid being prosecuted. I’m sure experts can help work around any future privacy laws too, so why even worry?
Surveillance already creates a different product one can charge more for, though your lawyer might advise you call it “personalization” in memos.
Demonstrably untrue.
It is illegal to charge a different price based on a protected class like race or gender. But travel sites, for example, are notorious for charging different people different prices based on their GeoIP, whether they're on mobile or desktop, or Windows vs Macintosh.
From refurb's link below:
"Price discriminations are generally lawful"
See https://www.ftc.gov/tips-advice/competition-guidance/guide-a...
They have no clue about the Robinson-Patman Act amendments to the Clayton Act.
Maybe you can show me generic ads based on your content instead of targeting them based on where I've been on vacation last month, etc.
Or simply stop building businesses based on people data. Sell something people want to pay for. Humankind has been able to do that for thousands of years, did we forget how to do it?
Couldn't a financial incentive be charging more?
> including by charging the consumer who opts out a different price or providing the consumer a different quality of goods or services, except if the difference is reasonably related to value provided by the consumer’s dat
Doesnt that second part cancel the first part? Businesses can also pay money for data ... so facebook can switch to subsciption only, but pay its users with virtual coins for viewing ads
I think it means that if you opt out of data collection, then things like personalized recommendations will no longer work, which makes the services worse. That is a part of the service directly related to the data.
sure, if it wanted to fall out of the fortune 500.
If people don't find your product valuable enough to pay for, then your company should go out of business.
Companies have been exploiting people's privacy behind their back, and now that they've been called on it they're throwing a tantrum.
"Something" doesn't mean "anything". You can't offer your services in exchange for e.g. my body parts. Why are we willing to ban that but not our data?
> The only reason those services are being provided at all is to get that data. That's effectively a requirement that people provide services for free.
Well, no — they could charge money for them. But even this is a false dilemma; surely we can come up with at least one business model other than "charge directly for our service" and "surveil our users".
Because if you were to run a survey over the general population the large majority is fine not having to pay for gmail, google search, maps and other "free" services while some data may be collected doing so while a much smaller percentage thinks it's OK to sell their organs for that?
No need to come up with something new, we had content based ads long before Google and Facebook took over.
Lots of us feel that the data thing should be allowed. That's all.
Is this a real question?
For many, many people, that is _fine_.
The real issue I see here is how this law is written and how we're interpreting it. If the law makes it so that people who want to opt out of free internet services because of privacy concerns are free to do so, then we're all good. If the law is written such that people who want to avail themselves of free services in exchange for their data are no longer able to do so because that business model is broken, then I see a lot of problems.
Please note that these are deliberately constructed as strawmen; I am not advocating for them or saying you do.
1/ Would you approve of a law which forbade companies (perhaps outside of eg healthcare or finance) from collecting or storing PII?
2/ Would you approve of a law which forbade a company which bought or sold PII (perhaps with the above exemptions) from doing any other kind of business?
3/ Would you approve of a law which required companies to explicitly price and purchase PII from consumers?
4/ Would you approve of a law holding employees or executives criminally responsible for data breaches?
5/ Would you approve of a law standardizing the requirements for anonymizing data?
6/ Would you approve of a law banning online advertising?
7/ Would you approve of a law which placed the same requirements on any company which stored PII as are currently imposed on credit agencies?
This is intuitive because regulation + law can really put a competitive barrier for established incumbents who (and arguably, they would be the target for lawsuits here) have resources to implement and comply with these regulations.
The law does sound great as a consumer, but I think the question is still up in the air about how will it be enforced and what will be the unexpected side effects?
Definitely something to watch for.
P.S. We've been working on a developer-friendly SaaS that helps companies automatically comply with jurisdictional controls + data security / privacy controls. Feel free to email me: mahmoud - @ - https://verygoodsecurity.com and I can dive deeper to answer any questions.
We don’t scrap seatbelt and airbag regulations just because they’ve had some unintended side effects.
Regulations aren’t set in stone forever, either, and a functional legislative body can always modify and update them as their effects become more well known.
Or, well, maybe I sound too idealistic. But...I think most of us can all agree that consumer data protections are highly lacking.
Often the downsides do outweigh their utility.
My only point is to support your case that it's not always idealistic to believe that some regulations, even ones that have been in place for decades, even with today's questionably functional government, can go away.
Yup. Especially here in the U.S.
Often times, they do. Often regulations don't even achieve their own goals. Sometimes they even result in the opposite.
So does a lack of regulation. That's how we ended up here.
- People who believe that privacy means being able to anonymously use services.
- People who believe that privacy means being able to control what other people do with data about you.
These are not compatible views, and they often conflict with each other -- both philosophically and practically.
If you believe you should be able to compel a business to delete data you gave them, then necessarily there needs to be a way for that business to confirm your identity and link you to that data. You become more concerned with this idea of "owning" information about yourself.
If you believe you should be able to do everything anonymously, then it becomes much harder to control information after it's been leaked. You can't implement things like geo-locking users because what you do with the information doesn't matter -- just collecting it is a problem.
If you're in the "everything should be anonymous" crowd, you're also less likely to agree with efforts like Right to Be Forgotten; you may even reject the idea of data ownership entirely. For someone in the "I control my own data" crowd, the Right to Be Forgotten is absolutely critical -- it's one of the most important safeguards we have against a future where everything is permanently indexed forever.
I'm oversimplifying, but at the moment, the majority of pure-tech solutions for privacy are on the "everything should be anonymous" side, and (at least for the moment) most legislative solutions are falling into the "you should control your own data" side. That leads to conflict. Not always, but sometimes.
It's important to keep in mind that even though the privacy movement is aligned on many issues, there is no binary "pro" or "anti" privacy, because there's disagreement from privacy advocates on both where we're going and how to get there. In this case, California's law is very much a "control my data" law. Points like, "Businesses would be required to comply with official consumer requests to delete that data" conflict with the way that "be anonymous" privacy advocates see the world.
necessarily there needs to be a way for that business to confirm your identity and link you to that data
Why would linking you to that data require confirming your identity? My password links my HN account to me and me alone, while revealing nothing about my identity.
There's no conflicting views. They're two, completely compatible aspects of the same view.
One is how much or how little data each service gets about you. The other is how much control you have over what those services do with the data they do get.
That's why technical and legislative solutions work in tandem, reducing the former (amount of data) and increasing the latter (control over data). That's also why technical solutions are preferable: there's no need to legislate control over data that services are unable to collect about you in the first place.
Let's say someone else uploads a photo of my face to an image sharing site. Is there a way for me to prove to that site that the face belongs to me without sharing additional information?
This principle also applies in the opposite direction. Let's say a third-party noncommercial site uploads a photo of my face and makes it publicly fixing. In order to demand they remove the photo, I need to be able to link that website to an owner.
It's not that the systems can never be combined. It's that following either system in the absolute results in conflicts with the other.
As for the use of photos of me that are owned by other people, I'm pretty certain that neither CCPA nor GDPR cover those. The EU might have some relevant privacy laws, but they're not relevant to the "dichotomy" you brought up, because no one expects to be unidentifiable in a photo in which their face is identifiably visible.
It today's world, data about a person is an asset. A person should own their assets, and have control over them. If there were only one option, this would have to be it - it's the only one that aligns with business interests. If you instead go purely the route of anonymous data collection, because data is such an asset it just gives businesses the strong incentive to find ways to de-anonymize your data. That is an unstable situation, and a societal counter-productive incentive.
Since data on me has value (clearly since businesses are run off it), make it a true product. Give it value, allow me as a consumer to trade it, allow businesses to quantify it's value in the market place, and explicitly bid on. That aligns incentives. As data becomes more (or less) valuable, businesses will adjust their prices for it. This aligns incentives, the more data is worth to a business, the more they'll be willing to pay for it. IMHO this is clearly the right approach.
That said, there is still a world where both methods exist. Users choose when they interact if they want to perform anonymous interaction (or pseudoanonymous), and people provide services to ensure it is anonymous. HN, reddit those are forms people would likely choose pseudoanon for, but there would be a firewall between someones pseudoanon identity and their true identity. And people would be pseudoanon knowing the risks and taking care to not divulge linking identityy info, and businesses would ensure there are limits on data preservation / recording of pseudoanon interactions. The same way people post on HN and use care in what they choose to disclose, HN would also ensur data expiry is short enough and would not share/sell pseudoanon data to 3rd parties.
Again, if you can only pick one, it has to be consumer ownership of their data, but I think they both can work together.
The first issue is that many privacy advocates who believe in anonymity do not believe in data ownership (or believe it should be much weaker). To them, the jump from "data is an asset" to "I own my data" to "because I own it, I should be able to control what people do with it" is begging the question.
The second issue is that in practice, most anonymous systems also make it hard to verify data ownership. In order for regional restrictions to work, you need a way to tell what regions your users are in. The "anonymous" side's solution here is, "anybody should be able to convincingly and legally lie about their physical location to (virtually) any business." If that solution is implemented, GDPR and Right to Be Forgotten don't work because it's impossible to verify jurisdiction.
This is part of why efforts around GDPR and Right to Be Forgotten are focused on businesses. Businesses have a physical address, they're easy to track, it's easy to prove that they're advertising to a specific region, and you can force them to share internal data with a judge. It's a compromise, because applying GDPR to non-commercial entities or individuals would require tracking them on a mass scale.
It's not impossible to compromise -- I mean, privacy advocates do compromise all the time. We work together even though we're different, because we have lots of shared goals. But the differences aren't trivial in the real world. When someone sits down to build a system, they're either thinking about managing data, or eliminating data. That approach is a big indicator into whether you'll end with GDPR or Tor.
How is that? GDPR protects EU residents when they are outside the EU, so you already can't just look at someone's location and decide not to give them GPDR protections. If the GDPR applies to you, your GDPR related features need to accessible to all your users.
> - Consumers can opt out of their data being sold, and businesses can’t retaliate by changing the price or level of service.
> - Businesses can, however, offer “financial incentives” for being allowed to collect data.
Seems to me that it’s a distinction without a difference. Is there something I’m missing?
Basically this puts Facebook in a real tight situation, I honestly wonder how they will survive it.
However, a mass movement to opt-out would absolutely affect them. This lays the groundwork for that, and thats what they should be afraid of.
Correct.
On top of that, many people on HN, aware of the privacy implications, continue to have a Google Home / Alexa in their homes. Myself included.
Sadly, I (and many people) simply don't care about privacy. The probability/expected negatives of surveillance abuse is far less than the benefit of being able to turn my lights on and off with my voice.
The US will for sure become like China in 10-20 years, with regards to surveillance.
For example, I think it would be legal for Verizon to get around this law by increasing their prices by $5 across the board, and offering a $5 rebate for customers who want to opt-in to their data being sold.
But it would not be legal for Verizon to allow customers to opt-out of data collection by paying an extra $5 a month.
In the first approach, Verizon will not track by default and customers have to opt-in.
In the second approach, Verizon will track by default and customers have to opt-out.
A user isn't "paying" for privacy. Privacy comes by default (for a price) and a company can pay a user to harvest their data.
Financially, they both work out the same, but based on opt-in, opt-out behaviors and perception I presume they have a different impact. The wording specified by the law says that users should have a default expectation of privacy. They can actively choose to give that up for a fee.
The business profit loss side of it says, you can't build a business that assumes it gets to profit off harvesting user's data for free. User data has value, place a value on it, and make it an explicit part of the transaction.
Ah! I was always saying I'm surprised by the brazenness of gas stations to offer cash discounts in violation of their credit processing agreements. Today I learned that as of 2010 the law protects them. Thanks!
Which makes sense, most other countries actually roll sales tax and others into the advertised prices, and what you see is what you'll pay out the door.
I agree that there is no practical difference between the two, but given how deceptive companies can be when disclosing various pricing and hidden fees, this might be an attempt to curb that behavior?
1) allowing customers to opt-in to data collection by giving a them reward. In this case, the default behavior does not involve data collection
2) allowing customers to opt out of data collection by paying a penalty. In this case, the default behavior involves data collection.
People usually don't bother to opt out.
The second line would allow companies to pay people to permit them to collect information. I imagine that because of the first statement, a company that is charging for the service cannot take advantage of this statement.
Way too hard to enforce, the definition of 'customer data' is going to be a constantly moving target. Does every click count? How about aggregated clicks important for general product optimization?
What constitutes 'selling' user data? Very few companies actually sell your data, instead they place ads based on your data. Will that be banned as well? Many companies, including Google would have to significantly change their pricing model if so.. yet that is apparently illegal.
Yes a click counts as personal data if you can reference it back to a real person. Aggregated clicks probably wouldn't.
Selling ads based on personal data is selling your personal data. The personal data provides the value to the transaction.
Yes lots of companies may need new business models, but for the most part what I've seen is dark patterns, non compliance or wriggling to avoid any real change.
In Europe at least, it's back to the regulators to make a move.
> Selling ads based on personal data is selling your personal data. The personal data provides the value to the transaction.
What about selling ads based on aggregated data? e.g. put users into buckets, then sell ads for those buckets.
HIPPA manages with "Patient data". The standard techniques include non-reversible addressing of users. Patient N has an internal number and an external number. Without having Patient N's internal record in hand, you can't correlate it back to that user, which is particularly useful in a legal defense.
I sure hope so.
> Many companies, including Google would have to significantly change their pricing model if so
Good. It would be even better if they have to change their business model.
Jeff Hammerbacher: ‘The best minds of my generation are thinking about how to make people click ads… That sucks.’
Those best minds are now having to change the way they generate revenue..
Of course, they’d hate the idea of having a fixed revenue per user. They want to keep sucking out more revenue per user until the well runs dry.
There is an incessant amount of whining about GDPR for example, and how "confusing" the regulations supposedly are. What it comes down to is many HN denizens are doing things that are explicitly prohibited by these data collection laws and want to continue doing the things that have been outlawed.
As they say, it is difficult to get a man understand something when his salary depends on his not understanding it.
And for some companies doing shit like selling customer data is the only reason they’re in business. Good riddance to them though.
Many of the people here who work for these companies truly and honestly believe the online services they are offering are/will change the world for the better.
As such, they view hindrances to this as threatening to the progress they are trying to help bring about.
Personally, I support this privacy initiative and think SV companies are many times viewed through rose tinted glasses by their employees, but that's just my perspective.
I can totally see how viewed through the lens of a hindrance to progress, some people would feel very strongly that I'm wrong in supporting such legislation.
- How do you identify what is customer data? There may be information stored in logs somewhere. Do you now have to write log parsers to extract personal data for everything that previously you just stored for general debugging and security purposes? How do you even know all the permutations of personal data that came be stored in the logs. There are possibly infinite possible ways personal information can manifest in logs. How do you ensure compliance with something when you don't fully understand what can come out of it? Any engineers now must fully understand the consequences of anything they log and design delete mechanisms for it. This extends to any 3rd party software you use that generates logs. You must now fully and deterministically understand your entire system just to comply with this law. Such a request is essentially NP-complete.
- How do you prune said data from logs?
- How do you delete data that are archived in write only media formats and/or that are in cold storage somewhere? You'd have to physically destroy the media and make a copy of everything minus the part you want to exclude. This dramatically increases archive storage complexity and cost.
YES YES YES YES YES.
Are you not already doing this for passwords, credit card numbers, and social security numbers?
Such a request is essentially NP-complete.
I think you mean undecidable, or equivalent to the halting problem, or subject to Rice's theorem. NP-completeness is irrelevant. I think you'll find that HN is the last place you'll win arguments by inaccurately using technical terms in the hopes that it will go over other people's heads, Legally Blonde-style (https://www.youtube.com/watch?v=8rNVaY7Stt4).
To anyone who knows what they're talking about, this an obviously nonsensical argument. It's similarly undecidable to verify whether the data that you expose publicly contains customer data, or customer passwords, or your own passwords, but you do it anyway, by restricting your engineers to only write and deploy code that they understand.
Nonsense. You write the log statements. You know what data structures you are logging.
If you're using some server's built in logging, or some logging library or middleware you don't understand, turn that off until you understand what it's logging.
I don't think this is quite the dichotomy you make it out to be.
So we can create optimizing compilers, but we can't figure out what to log?
This seems like a problem of never having motivation to solve the problem before.
"We can't do that, it's too hard" is often a mea culpa I'm industry when they oppose regulation. Then they will come up with a solution from having actually spent some effort to actually think of potential solutions.
Don't bring complexity theory into it.
The Backups question is a bit more complex. One source I've seen: "According to France’s GDPR supervisory authority, CNIL, organisations don’t have to delete backups when complying with the right to erasure. Nonetheless, they must clearly explain to the data subject that backups will be kept for a specified length of time (outlined in your retention policy)."
Paired with that is that if you're keeping data (or backups) for any length of time beyond the immediate needs of the customer then you need to be able to justify it.
Think this law is going to allow me to require 7-11 to delete me from their DVR records? Not part of the business model, it's a matter of security. Nice straw man though.
Their terrible system design can't handle "FROM PornPrefs DELETE SSN,Name,Address WHERE SSN LIKE "999-11-2222"". They brought this on themselves.
It’s like lines of code in a program — each one makes the application worse, so each one should have a purpose that it achieves.
None of the big names in tech will have any trouble at all complying with this; I'd be very surprised if any at all are not already compliant today.
At the same time, the percentage of tech startups that are already compliant with this law is likely around zero, and few will ever become so. Unless this is precisely what your startup is about, small firms, especially with venture funding, can't afford to invest anything at all into privacy beyond the surface. If your startup fails because it gets sued into oblivion, that's no worse (and way less likely) than it failing because nobody actually wanted a chat app for dogs.
Just like I don't want startups making unsafe medicine, or losing my medical secrets.
Why? There are plenty of tech companies that collect very little data, and don't sell any of it. I fondly remember one of my customers telling me how much effort it took to come up with a wordy enough privacy policy page for one of their products so that it wouldn't look suspicious. The first draft was barely two paragraphs long and contained just a couple of items, most of them ephemeral (e.g. IP addresses, which were collected only for logging purposes and were only stored for 30 days).
If a company is unable to even articulate what data it collects and cannot do basic operations on it (e.g. remove a piece of it), then it shouldn't be in the business of handling personal information. The same way a clinic that can't even keep track of blood samples shouldn't be in business.
And if a company's earnings depend strictly on being able to collect and sell personal data, what they need is a better business plan, not having everyone turn a blind eye.
I’ve always been told that it’s good practice to take periodic backups. In the absolute worst cases, you can simply restore directly from these.
If a customer requests that their data are deleted, in addition to my production instance, does that mean that I have to remove their data from my backups? If so, I’m uncertain of the best way to do this. I’m uncertain if many managed services will allow me to mutate backups. And even if I were managing my database and backups directly, it seems painful to load each backed up database, remove the data, and rewrite the backup.
Note: I’m not saying that any of this is impossible. However, it does require a lot of ancillary engineering work difficult for a small company that’s just trying to get to product market fit.
But if that is really a problem, just apply the requirements to companies with a minimum amount of users. Venture capital funded companies don't need to cut corners and shouldn't be allowed to when it comes to privacy.
This is complete nonsense. The biotech industry is very large and vibrant and are most certainly not Big Pharma.
If you're ad dependent, would this basically mean you have to give your service to this user for free after this?
Basically Hillary's private email server getting bleachbitted, but for everyone now. Makes running an organized crime gang, political corruption graft ring or chinese espionage ring much easier. Same with banning facial recognition. Makes getting away with crime a lot easier than it would otherwise be. If you are a corrupt politician, this is really important stuff.
Are these the right laws to regulate SaaS companies that build business software? Should a consumer be allowed to request that data about them be deleted if that data are records of legitimate business transactions? If you buy a car from a dealership, do you "own" the data in their systems about your transaction and should you be able to request its deletion?
Yes, it is also subsidizing what would normally be paid services. Before online advertising, people would pay for services like email. Sure, $5 / month is cheap for us, but what about the developing world and the lower class?
If the price of the service is based on the ability to sell data, how is it reasonable to disallow the business from changing the price of the service for those who opt out?
Also, how can you reconcile this with being allowed to offer financial incentives for being allowed to collect it?
Remember last year when there was a big hoopla about that Massachusetts court case that hinted that any online vendor would now be responsible for collecting and reporting on sales tax for purchases coming from any US state (even if you as the business owner didn't have a business location there). Basically changing the requirement of the buyer to report sales tax for out of state purchases onto the business. The only problem is there's 9,998 different tax jurisdictions (as of 5 years ago)[1] spread across 50 states.
[1]: https://taxfoundation.org/state-sales-tax-jurisdictions-appr...
“It is difficult to get a man to understand something, when his salary depends on his not understanding it.”
[1] https://leginfo.legislature.ca.gov/faces/billTextClient.xhtm...
source: CCPA and its potential compliance has been a big PITA
The only other place households are referred to is in the section defining which companies the rules apply to, which is also pretty straightforward in a plain reading. If a company's number of consumers, households, or devices exceeds 50k, they qualify.
> (B) Alone or in combination, annually buys, receives for the business’ commercial purposes, sells, or shares for commercial purposes, alone or in combination, the personal information of 50,000 or more consumers, households, or devices.
Well, thanks for the link. For example, informing people that a user is located in a dormitory in The Netherlands sounds like free speech to me. So is location tracking information exempt from deletion?
> (e) Many businesses collect personal information from California consumers. They may know where a consumer lives and how many children a consumer has, how fast a consumer drives, a consumer’s personality, sleep habits, biometric and health information, financial information, precise geolocation information, and social networks, to name a few categories.
As to how this will interact with free speech - in this case, speech of the company - is a bit of an open question. One of the assumptions of the bill though is that selling telemetry data about a consumer is not a form of protected speech, and that adding some restrictions to this practice is reasonable.
The example I gave, by the way, is a real one: https://news.ycombinator.com/item?id=8418885
The physical establishment rule was the only sound approach. The fact that some countries started to lose shouldn't have allowed them to rewrite the rules (especially in such a hacky manner).
Can you imagine owning a grocery store and having to ask every customer their nationality to check which law you must follow to do business with them? Then multiply this hell by 10 and soon 1000 considering new laws created left and right and you have the environment these dishonest politicians have created.
You know if you turn that around and say "How come we have to respect the laws of every country we do business in?" it sounds a lot more self serving.
Nobody said your website had to serve Californians. Nobody said your iPhone game has to be accessible in North Korea. Nobody said your movie has to be viewable in China.
If you're intending to serve any product to an entire planet composed of nations, states, societies all pulling from different experiences, different cultural attitudes, I think expecting a completely friction-free experience in doing so is more than a little unreasonable.
And more to the point that this particular discussion is about, these are principles that pretty much every society could reasonably get behind. Sorry that means mining data isn't a solid business model anymore, but I'm also not even remotely sorry. Adtech should die. It's a blight on our society.
You will of course forgive me if I do not find economic favoritism that benefits politically connected industrialists, the restriction of freedom of thought by oppressive governments, and the general Balkanization of the Internet, to be things that we ought to celebrate.
Once upon a time the memes of Internet culture would suggest that "information wants to be free!" Oh, sweet halcyon days of yore!
Turns out it’s not free — it’s actually very valuable, and the cost is borne by society writ large.
Information is not gratis.
Agreed. But martech pretty much killed that dead.
Same with the laws, especially those that remove agency from the users.
If I am from South Africa and I buy a US product from a smaller website I don't pay South Africa sales taxes. If I buy from Amazon I would because they have offices or a physical presence.
When you buy a product from a website hosted/incorporated in a different country you are literally going into another country and buying a product under their laws. Your local taxes (national/stat wide/city wide) shouldn't matter and don't.
The same should apply for eu privacy law.
I would assume importing milk might trigger 50% duty but receiving a dnakit from 23andme wouldn't.
Take for instance the issue with tariffs and China: if you were right, someone might say "Ha, I'll buy it on Amazon/AliBaba and I'll go around your unfair tariffs". If only!
Isn't there kind of an opt-out? Whenever I use a US VPN to read some non GDPR compliant website blocking EU users, I can hardly expect that law to protect me.
Thing is whatever is necessary to "literally going into another country" cannot be easy & automatically done to everyone and thus effectively allow companies to circumvent the law.
If the origin country is not willing to track it back to the source and do enforcement for you and you don't want to categorically block or have invasive monitoring everything from that country then it's a fool's errand. The same goes for websites.
Lying on manifests also lets people import quasi-legal things such as cell phone jammers. The manifest will usually say something like "laser pointer" or "wifi repeater".
As a user, I want to be able to pay or donate to a company or individual without providing them my identity or location data. This is already an extremely hard thing to do because of tax laws like VAT. Please don't make it harder for me.
As an activist, I want everyone to use technology that by-default masks their physical location from websites they access. I want them to feel free not to provide their physical location to anyone online, including businesses like Facebook.
As an activist, I want the majority of popular online payment systems to avoid revealing a buyer's physical location by default, and I want users to feel free to not provide their physical location when paying for a digital product or giving money to another individual. This is already a (nearly) impossible goal because of the sheer amount of tax and money-laundering laws that need to be addressed first. Please don't make it harder.
Laws that force websites to geo-lock based on consumer location are going to be (in the long run) bad for privacy and bad for the open Internet. I don't care about what businesses do or don't want, but the strategies we use to take down advertisers and data-hungry corporations matter.
My less-charitable reading of this situation is that people are generally fine with using user-location as an indicator of jurisdiction because the laws working on that principle are primarily pro-privacy right now. If these laws were being passed in other areas, I wonder if people would be more nervous about the precedent they set.
A completely friction free experience is exactly what you should expect.
Every political obstacle we create for data traveling through wires undermines the entire point of having an internet, and cedes more power to legislating bodies who are clueless about technology.
An individual should be empowered to serve data to another individual anywhere in the globe without barriers, period. If people can’t get behind that idea, then just get the fuck out of the way.
I am actually in favor of privacy regulations. But there are two major issues that most people don’t understand
- Compliance is not easy if you do anything much more complicated than serve a static website. Basically anything business related will have PII. And you can introduce PII accidentally with things like logging, putting it in places it shouldn’t be
- Because the internet is open by default you need to comply with basically every single regulation on the planet, and the burden is fully on you to know how and why you comply with those regulations. (Some places will just firewall you, which in many ways is better, but others just want to make money off you)
This is very often not true. A generic website will be visible everywhere, but new online stores will typically sell domestically only by default and may expand later. Even tech giants like google will roll out services to US customers first, like when they launched the play store. Amazon in Australia is nearly unheard of, not ubiquitous like they seem to be in the US. It took netflix a decade to start here.
The internet is not as universal as you think.
Is it so unreasonable? Given that the Internet essentially solves the problem of technically doing this, perhaps it is in fact the laws which are unreasonable.
Your statement isn't so different from saying "it's unreasonable to expect to be able to have a nearly-instant audio conversation with virtually anyone on the planet for very little cost." I would give the same response: that no, that's really not that unreasonable given that the technical problems are essentially solved, and if there are laws preventing that, perhaps the laws are unreasonable.
I suppose the regulation could be on the subsequent sharing/sale of user data upon capturing it, rather than the initial data collection?
If I have interesting ideas, I could write a book and sell it in every country of the world. Then this product would be taxed and would need to respect the publication-related laws of that country. On the other hand, if someone reads my book and then travels across the country to hold free seminaries to teach my ideas to the masses, it is not reasonable to try to tax this value transfer, but this is exactly what governments have decided to do.
You see: values vs principles. We can have values but we need to articulate sound principles to give life to these values. What you describe are values.
And what I contend is that we already had sound principles, principles developed across decades and even centuries. The physican establishment rule is the only sound and workable principle.
What we have now is a mess encouraging anti-democratic dynamics (centralization, fingerprinting, and ironically data collection since you need to know more about consumers to know how to apply the laws), in addition preventing innovation and making business difficult.
All of this while for every non-taxed value under traditional principles, a taxable value is actually created... but for some reason nobody is interested in investigating this correlation... for example, the person holding seminaries pays a tax on the room he rents for the seminary. But government prefer to go hard on their propaganda.
If a country wants to tax the books royalty, it should focus on upping its game to attract intellectuals instead of hacking together unsustainable notions to tax "learning".
Similar things could be said for advertising company. When an advertiser advertises in a country, it is by definition to sell a product that most of the time will be taxed into the country (and even if it doesn't, this value transfer will at the 2nd or 3rd degree lead to an activity that can be taxed).
This is why principles based on physical presence and not abstract fictions are not only sufficient and sound but they are also fair. The same is true for privacy, which are after all transactions of their own kind. If you want to regulate data, make sure people use services based in your country by creating the proper environment instead of hacking together extraterritorial laws based on wacky principles.
Just compare these new frameworks, with the readability of the physical establishment principles, that been able to accomodate even the most complex business models for centuries.
Principles should be a foundation, not something you throw out of the window as soon as you start losing to avoid confronting your difficult challenges at the cost of creating an international mess. Digital is not complex, and does not require complex regulations. Trying not to adapt to the world and not to confront your true problems is the only that is complex.
I don't think you can state this as fact without some justification. I think it's very debatable, and, frankly, I disagree. The physical establishment rule was borne out of practical enforcement considerations, not out of any principled approach.
Now, there are ways around it. Either agree on a supernational legal frame , for example a car which is certified in one EU-Country is deemed certified everywhere (something Tesla used to great effect) or have one reliable entity for certification (like the FAA was in Aerospace, which is most likely bound to change).
But putting the onus on the customer to find the legalities in the origin country of the software/website provider is not the solution. Especially for large providers. Just an example question: Where is the website "legally" located? The company's HQ? The local office? The office of the developers? The main database? The CDN-Server for your location?
edit:formatting/typos
In the case of visiting a website, the customer is the one visiting you, there is no good rational to put the burden on the business. It is much more sound and natural to either put it on the consumer, a business may be visited by nationals from hundreds of juridisction, while a consumer will only visit 1 or 2 businesses.
You can also decide that the laws of the country in which the business is based apply.
You make it sound more difficult than it actually is, every website selling software products already mentions the address of the owner, at the very least to define a party for the contract / terms of service.
Here, we're talking data and privacy, and it's commonly accepted fact that the disclosure of personal data can be harmful. Countries want to protect their citizen from such harms. Hence regulation.
> , there is no good rational to put the burden on the business. It is much more sound and natural to either put it on the consumer, a business may be visited by nationals from hundreds of juridisction, while a consumer will only visit 1 or 2 businesses
This seems completely, and obviously, be the opposite of reality as I experience it, as both a consumer and startup founder. Businesses have repeated transactions of similar types and products. Since there are fewer businesses than consumers, they also have more resources, and locating any burdens of transactions that occur once per country is vastly more efficient.
A company like Facebook has a theoretical upper limit of a little less than 200 jurisdictions to consider, using billions in revenue. Their customers would have to the same, only they number in the billions, and have few resources nor structures for sharing this burden (except, of course, their governments).
> while a consumer will only visit 1 or 2 businesses.
I'm pretty sure I interact with dozens of businesses every day.
If the EU made a law that made the NYC bookstore liable in the EU for selling "obscene" books to europeans, and then arrested the unaware bookstore owner in a vacation to france, is that really right?
That is a big issue with the GDPR in general.
Can you imagine a grocery chain who wants to profit from potential customers all over the world but doesn't want to obey local laws in the jurisdictions it operates in?
If people don't want to serve people outside their jurisdiction, do an IP lookup as some US outlets chose to do.
Hacky US start-ups don't get to dictate the rules of the game to the world.
Are you sure your comment you've just made comply with the law of all the 200 countries in the world?
If a purchaser calls a suppler from state Y from state X and ask to buy something. Which laws do I follow?
* The purchaser follow laws from state X
* The supplier from state follows laws from state Y
* We then pay any duties to ship from state Y to state X
This is the way things have been done, since, well... forever. No one thinks it's weird if this kind of business is conducted in person or over the phone.
Now, with the internet - it's believed that the supplier must now take on the burden of knowing the laws for purchaser - that's kind of strange.
The supplier is not operating in country X, so it probably wont be punished by country X.
Anyway, as a developer and maintainer of making a fair amount of cross boarder trade. I host my servers in one location, the state in which I operate. Good luck punishing me.
The reality is that my only burden is the state in which I operate, otherwise we're interfering with the sovereignty of the state in which I reside... don't think they'll like that. Good luck challenging that one.
In B2B transactions, there are often international standards. Even where the supplier's location is set to be the relevant jurisdiction, this only follows from the assumption that a purchaser of industrial goods tends to have the experience to navigate foreign law. This cannot be assumed for consumers.
I mean, that's exactly what's going on. You can choose to follow State Y's laws when serving customers in State Y, or you can choose to not serve customers in State Y. But if you choose to not follow State Y's laws while serving customers in State Y, then State Y can use whatever leverage they can get their hands on to keep you out of State Y. That's State Y flexing their own sovereignty when it comes to protecting their citizens, which is the flipside of your argument about your state protecting you.
Surely the purchaser has some rights to sovereignity?
Thats a bad metaphor. If you open a grocery store in one country you follow the relevant law of said country. If you extend you business to another country the new store has to follow the law of the other country.
The problem with physical establishment is that it could create a 'race to the bottom', similar to tax laws. With non-tangible elements like privacy, what stops big players like the USA to implement weak privacy protections to get a competitive edge?
While I understand your point about the impediments to unfettered interaction, this seems to me to be a fundamental problem with "globalized" interactions where the different parties to a transaction expect to be governed by different laws.
> Can you imagine owning a grocery store and having to ask every customer their nationality to check which law you must follow to do business with them?
It is, unfortunately, a little too easy, to implement filters based on whitelists/blacklists at the DNS level, since those are largely organized geographically (proximity by packet travel time, and what not)
The problem with the physical establishment rule is that it leaves the end user with no leverage to actually protect themselves or their data.
The EU and California taking a stance that you must obey their data handling rules in order to do business there is a direct result of the lack of a robust system between states and nations to give users the ability to control their own data when the company's physical establishment is in a different legal system. This approach is the most immediately practical one: I vote for the politician who is willing to enact laws that actually have teeth to regulate the use of my data.
The industry has certainly shown a lack of desire to put teeth into any sort of self-regulation. I worked in ad tech - that industry standard body (the IAB) pretended to care at best, and actively lobbied to erode privacy rights most of the time. Real privacy enforcement mechanisms that actually respected users only started to show up once the GDPR boogeyman showed up.
At the time when we were generally happy with the physical establishment rule, the set of problems we were dealing with was very different. We were more worried about individual freedom in terms of access to services and communications, not individual freedom in terms of safety from bad actors.
> The physical establishment rule was the only sound approach.
The only reason that rule exists is because enforcement was much more difficult when your target doesn't have a physical establishment within your own borders. If you can enforce it for foreign entities (via some kind of side leverage, like a trade treaty, threat of sanctions, etc.), then, at face value, you should: why should the law behave differently based on physical presence? You yourself point out that things are different in the Internet age; that includes the acknowledgement that commerce can now trivially cross borders without having to have satellite offices everywhere.
For privacy matters it's easy though. The UN has declared that privacy is a human right for all humans in all countries.
A lot of sites are doing that for GDPR.
Unlike the target/sell case, this doesn't seem to require intent to specifically deal with Europeans.
If you aren't sure that what you do doesn't count as monitoring behavior, then blocking can make sense.
It'd be nice if this was unified but it ain't because:
1. Tech companies lobby like hell at a national level
2. The national government is sort of broken right now
so that's how the cookie crumbles. The fact that a number of companies have skirted local regulations and abused data usage so much is why this is happening, so don't blame the victims of this activity that want sane privacy laws - blame the bad actors that have forced this issue to need to be dealt with.
As for every country making their own laws - well, yeah? That's what sovereignty is all about?
If your business operates well above board and is not doing anything close to what might be the danger zone, then you should have nothing to worry about.
It's always the folks walking right next to the cliff complaining about how complicated their path needs to be.
The startups end up either (1) ignoring the laws or (2) giving up.
Good job EU, if making the FAANGs the only companies with the clout to hold customer data or break into new markets was your primary goal.
Collect no information. Share no information. You are good - everywhere. And that really ought to be the default behaviour..
Just give me the facts and let me decide on my own after reading the facts. I don't need your opinion up front.
It should be fairly easy to add a contact us address for delete and info requests to the bottom of websites. A lot harder and would take development time to automate a UI for a person to see all data associated automatically (e.g. lots of separate analytics; would have to build api to lookup ip/device/user data match across tables/dbs, and then how do I verify a user is requesting their data and not someone else's). Also harder to 'block' new data collection of device/consumer post delete request.
What I'm less sure about is 'inform consumers before the point of collection.'
Does a privacy policy link in footer count? If not what is required for compliance? What about advertising?
Another big concern for me is that this is going to be weaponized in my industry (politics). I think a political campaign wont fit the bill's definition of 'business' (profit seeking for shareholders) but I think it will still be weaponized by opposition campaigns and service providers.
All of these are based on many companies contributing information about users to create profiles which curb abuse. And Sift/Google/etc. get commercial benefit from this data sharing, which might trigger the CCPA. But you can't give bad actors the ability to opt out of this kind of data sharing without crippling them.
I think these kind of companies are really important to a functioning internet. I hope there are carve outs of some sort, but seems like they're living on the edge right now.
As a citizen don't I have the right to create a business and privately take notes on whatever I'd like to about my customers? If i run a dry cleaners and take notes about my customers, should I be obligated to disclose these notes or even the existence of these notes to my customers? I don't see why extending the dry cleaning business to a mobile app or website effects anything. What about journalists, are they required to disclose what data they're collecting about people as they do their job?
I feel like the state constitution granted right to privacy does not supersede the federally mandated right to freedom of speech both the right to take internal notes and documentation and the violation of one's speech rights by forcing this disclosure.
however IANAL and I don't live in California. Could someone share some insights onto the first amendment side of this?
Nope. That's not an express Constitutional limit imposed on states and thus states general police powers extend to regulating that behavior. (To the extend the proposed business engages in, or impacts, interstate commerce there is also federal regulatory power under the commerce clause, but the immediate issue is the broader state regulatory power.)
Gonna have to stop you there.
The First Amendment doesn't mandate a right to free speech. It only prevents Congress from passing laws abridging that right.
There's nothing, Constitutionally speaking, preventing states from doing so.
Edit: nope, Apparently I'm wrong on this one.
https://en.wikipedia.org/wiki/Incorporation_of_the_Bill_of_R...
Yet.
Hah!
This just seems like poorly written legislation with the purpose of pandering to the populist public. I guess if it makes you all at least feel better.
But it will be celebrated as a heroic victory because “privacy good. Business bad. I want a banana.”
As you proceed to state absolutely nothing. Before GDPR my information was in a bunch of databases managed by other people. After GDPR my information is in the same databases managed by the same people. Except now they have legalese stating this totally fucking obvious fact.
Before GDPR if my information was hacked and used to hurt me, the business was not liable. After GDPR they still are not liable. Oh and if they violate the GDPR the state gets money, but the victims don’t. Such amazing protection of consumer data...
>In doing so, the companies would be able to control their messaging through their extensive lobbying efforts, allowing them to push for a weaker statute that would nullify some of the provisions in California’s new privacy law. In doing so, companies wouldn’t have to spend a ton on more resources to ensure their compliance with a variety of statutes in multiple states.
Is it really that much easier to control a federal vs. state legislator?
I wonder if the idea might actually be to prevent the likely future scenario in which 50+ different privacy regulations need compliance. Setting a national standard could prevent such an outcome.
Privacy advocates should favor the state-by-state solution, though. The more difficult it is to comply with regulations, the more expensive it becomes to collect the data in the first place.
As the cost of compliance increases, the alternative of simply not collecting the data in the first place becomes more attractive.
But that itself can lead to unintended consequences. It would mean that only the biggest companies could afford the regulatory burden of collecting the data. And these are the very companies that have received the most negative attention.
All of which makes me wonder whether at some point we could see a private data settlement along the lines of the tobacco settlement:
https://en.wikipedia.org/wiki/Tobacco_Master_Settlement_Agre...
> The bill would authorize businesses to offer financial incentives for collection of personal information.
Means it's nothing like the GDPR. This might actually be a sane law. And it doesnt implement punitive fines if you get hacked. Nor does it bring about a massive cookie alert insanity.
The right to delete may work in europe , but i think in the US it is going to clash with free speech laws. So it might not work at all.
The whole article seems to be about shutting down thinking and manipulation via playing with emotions.
I am probably an outlier but I view that as an active sign that is terrible because otherwise they would lead on better points. The article made me /less/ supportive of it. It is perhaps unduly harsh but I would call it an outright propaganda piece not because of the message but how it was delivered.
It is an old trick narrative for pushing terrible "tough on crime" laws for advancement. If you point out that it isn't a well thought out idea you support bad people!
The only reason it was even passed was because some guy was going to force the issue with a ballot initiative so lawmakers scrambled to do something. If not for that, California would be the last state to pass meaningful privacy regulation.
One can only hope they make sure it hits big actors more than any other ones, because they are what makes this kind of data collection dangerous for societies.
Does anyone know how companies are supposed to comply if “user data” literally cannot be deleted? I’m thinking in the case of blockchain type applications, where one users’ actions feed into another users’ actions, and you can’t deleted user A’s actions without deleting potentially tons of other stuff and destroying the application.
Like does this law basically ban GitHub and code collaboration too?
What if a bank put the gold of their customers in a concrete pillar instead of a vault? Fuck the back, I guess. I don't see why not.
I suppose the argument would have to be made that it’s not personal data; it’s an act of public publishing or something. So in this case it’s akin to me publishing a blog and other people quoting it years later. I can delete the original blog but not the reprints in newspapers or quotes.
Or that it stops becoming “your” data and becomes instead “the other user’s” once eg the Django project accepts the PR. So you can delete user A’s PR but not the Django project’s now-integrated copy. I think this rationale makes the most sense. After all, someone could still have the repository on their computer and push it back to GitHub again.
I realize this is an edge case that doesn’t apply to 99.9999% of companies, but as an engineer I find it interesting!
Edit: after thinking this through more, I suspect that e.g. GitHub could argue they comply as long as they delete User A’s repo. Subsequently integrated PRs, etc wouldn’t have to be deleted because they could argue they’re no longer User A’s.
I kinda feel like if language to allow this was added to the law explicitly it would be open to abuse, so I suppose this kind of thing has to remain vague and open to interpretation in e.g. the courts if someone is being nasty.
Startups and side projects are a non-issue. They can just comply from the get go. It's the too small to afford compliance but too big to easily change their business model that are going to be hurt by this. However, that brings up the question as to whether those business models should be able to exist profitably in the first place.
> “The time to act is now,”
While pushing a federal law geared towards undermining privacy rights?
Doublespeak anyone?
Is there room for a TechCrunch-like publication with a more Silicon Valley-influenced editorial bent? (There's already a massive surplus of sneering Brooklyn-based scolds in "tech media".)
are you actually asking for someone to purposefully preach to the quire? The function of journalism is to speak truth to power, you think facebook et al need any further help? I think they actually paid the telegraph for a series of agitprop articles, you might want to check those out.
He's both rightfully pointing out that TechCrunch is preaching to one minority choir and asking for another publication to preach to a different choir. Ironically the publication he's asking for was TechCrunch before it was bought by AOL and ruined.