CCPA goes into effect January 1, but nobody’s sure how the new rules work
latimes.com
latimes.com
For example, IP addresses are not really personal, but including them as such creates layers of ambiguity that undermines other positive aspects of the law. It's the typical outcome of politicians not really knowing the domain they're affecting.
Also what's especially interesting is that CCPA was effectively bankrolled by a single person, which should raise some alarms about political power used by the people.
Arguably, this is one of the reasons why the GDPR was necessary.
Is that even true? If I never consent do I get no cookies left on my browser?
> When assessing whether consent is freely given, utmost account shall be taken of whether, inter alia, the performance of a contract, including the provision of a service, is conditional on consent to the processing of personal data that is not necessary for the performance of that contract.
This would suggest consent may not be freely given if it was obtained by conditionally providing a service based on consent bring obtained for processing of extraneous data.
Recital 42 adds:
> Consent should not be regarded as freely given if the data subject has no genuine or free choice or is unable to refuse or withdraw consent without detriment.
I don't think many users have a genuine free choice on many websites, although admittedly it's now mostly the worst offenders to blame here - the average site probably does have an opt-out now that actually works (!)
Recital 32 also appears to deal with the annoying, interrupting, semi modal nature of prompts we see on ad-laden sites:
> If the data subject’s consent is to be given following a request by electronic means, the request must be clear, concise and not unnecessarily disruptive to the use of the service for which it is provided.
Browsers can be changed, but instead of picking a reasonable well thought through solution the governments crammed a quite horrible solution through. I honestly don't see how that protects the people who are most vulnerable nor anyone else really.
At least for Firefox this is not the case. Anyway, extensions like uMatrix exist.
> the DNT header
The DNT header is yet another way for sites to track you. I am glad it failed.
And clicking decline on cookie banners or your unique combination on the multiple choice cookie disclaimers wont allow sites to track you?
GDPR rectified some of it but added much more granularity which is why cookie popups have now turned into giant selection windows.
Companies built on surveillance capitalism should be shut down. Full stop.
I think whatever problems the cookie laws that got us all the popups are trying to solve would be better solved in conjunction with some technical changes. Like I could say in my browser what sort of cookies I allow - or set up some rules. Sure sites can just break the law and disregard this - but they can do it now anyway by just saving cookies even if I click "don't allow" or "decline" on the dumb popups.
I suppose that, to draw a better analogy with Prop 65, the requirements of Prop 65 did supposedly cause some manufacturing materials, certain dyes, rubbers, foams, and plastics, to be drastically removed from the marketplace. The story of lead alone is worth considering; as usual, lead was in the pipes. [0] We are not expecting a wave of cookie warnings, and indeed CCPA's language doesn't allow for it. Some businesses will have to alter their practices; some products may have to be withdrawn from the market entirely. The worry that children might get used to clicking through EULAs and giving away their data has already been shown true by the previous generation of Internet users; at this point, we are merely trying to curb the damage continuing to be dealt and done.
And remember: For every ingredient that needs a warning label, that ingredient also can't be dumped into streams or rivers. It's not just about a prettier warning label on the product, but about real improvements to the manufacturing process.
[0] https://digitalcommons.law.ggu.edu/cgi/viewcontent.cgi?artic...
Most people I know would be.
My point is that there's no chance it will happen. Any fallout will be just a new burden to users.
To me, this indicates that the drafters of the law probably didn’t really think it through.
(AB5 is the anti-freelancing bill whose intended targets, Uber & Lyft, may escape its application, while many other California freelancers have their traditional contract work patterns made illegal.)
https://www.globalprivacywatch.com/tag/ccpa/
Note since these were originally published, the big thing that changed is that employees and employees of clients and vendors are now generally exempt from the CCPA. There is still a general notice obligation (think short privacy policy) for your employees, but that is about it. They also tightened up the FCRA and GLB exceptions, but those are not generally relied on by the majority of businesses out there.
Consumers cannot opt out of this collection.
Consumers do have the option to opt out of having their personal information resold to third parties. The CCPA then specifically restricts businesses from withholding services or providing you with reduced services as penalty for this opt-out.
CCPA may not be perfect or even well-explained, but it's a first step in a positive direction within the United States. I think it's unfair to call it "useless".
https://docs.microsoft.com/en-us/microsoft-365/compliance/cc...
https://www.adweek.com/programmatic/everything-you-need-to-k...
> 95% of users choose to be tracked in exchange for access to websites and services
The GDPR explicitly disallows the practice of conditioning access to a site or service on acceptance. Without that it would be rather useless. Once that bit is also enforced (current fines for violation sadly week focused on poor data safety measures and similar) I think the online ad landscape actually may start to change.
Sadly, some sites seem to interpret that (incorrectly) as “well out business is to show news paid for by ads so the ad network cookies are essential”. These are the players I wish would be fined out of business.
I personally read a lot of news online, most of it is such utter trash that I would not want to pay for it. I have paid for some specific sites intermittently - currently I pay about $20 USD a month to one specific content creator that produces news content - but that is mostly because it is rather niche news that nobody else (that I know of) is reporting on. For the rest of the news I consume I feel that it is of such a low quality that the ad revenue is all they deserve.
I read dozens of sites, but I’m not going to allow being tracked if I can help it. I also don’t much care whether these sites survive or not, and I absolutely wouldn’t care if they disappeared because people behaved like me (answering no to tracking and/or using ad blockers).
My thinking is that if everyone blocked tracking ads, then money would return to dumb ads (that now aren’t worth anything because of tracking/targeted ads). So I hope that’s the future. If it isn’t then I guess the less optimistic future is that half of all “free” content online disappears while the rest is concentrated in silos like Facebook and YouTube that can ensure eyes on ads. I think both futures are better than the status quo.
would switching to non-personalized advertisements without taking additional steps support the website enough? Maybe but its hard to say one way or the other without looking at the data.
Another way to get revenue, which doesn't itself transgress against these privacy-focused laws, is to charge directly for providing your service. That's totally legal! Well, but maybe some companies would find that they don't get enough subscribers to fund their business—then the solution, in a privacy-focused environment, is that those business don't exist, rather than that they get a shadow source of funding by accepting bribes for participating in scummy privacy violations. This would be a very different environment from the one in which we live—clearly better in some ways and clearly worse in others—but it's far from impossible.
Is that what the consumer wants? Also - is depriving services to those who aren't able to pay the fee to participate the right thing to do when they don't mind something like privacy focused advertisements?
Judging by all the people unwilling to purchase Youtube Premium I would say no.
Privacy laws that remove freedom and opportunity aren't very good laws.
All laws remove somebody's freedom and somebody's opportunity, so either this argument is flawed or it indicates that we shouldn't have any laws.
I'm not a maximalist in allowing people to choose everything—the very notion of inalienable rights indicates something that a person cannot give up, not even by choice—but, even if I were, the problem with the current model isn't that I don't like the particular trade-offs people are making (though I don't), but that people aren't aware of those trade-offs. That, and the unfortunate confluence of companies' lack of desire to educate customers and customers' lack of desire to be educated, means that we're not really in a situation of informed choice.
If you're talking about criminal laws then those are designed around harm and the greater good. There's no harm here because it's up to the individual, allows them to gain value from content, and their decision doesn't affect anyone else.
Informed choice is something else entirely, but people go throughout the day making choices out of complete ignorance and that alone isn't a valid reason for preventing their freedom. Considering the relatively trivial risk, this falls well under personal responsibility. I encourage more education around privacy but am absolutely against making the choice for them, because that's how we got into this mess in the first place.
I really do hope regulators will take a few high profile sites and make an example with a massive fine for blatant violations.
The rule is: if I visit a site then tracking is OFF until I switch it on. Seeing the content can’t be conditioned on accepting, and the default “ok close the popup and show me the article” should always result in the miminum cookies allowed - that is, typically no ad networks at all.
It can be costly to be in perfect compliance but nobody is really is afraid of GDPR risk anymore, especially since most internet companies are not in the EU anyway and are completely unaffected by regional legislation.
There are also dozens of workarounds from legitimate use of data to contract-in-effect (like email newsletters). This is an example of the poor legislation aspects of GDPR and other privacy laws that are not based in technical reality.
The problem is that no, they don't. Companies wrote infrastructure on premise that user would never ask/get/delete the info that is stored on him/her therefore now it's really difficult for companies to actually gather/delete data that is tied to a specific user in a safe matter.
This is refreshing, I wish GDPR had a revenue threshold like this.
I worry that regulations like GDPR benefit the existing monopolies, and make it too difficult/expensive for startups. The legal ambiguity of it, and the additional software requirements add a lot of roadblocks if you're a small company. I'd rather the burden be limited to established companies (but I guess that isn't quite fair either).
And for small/side projects, I just don't want to worry about this stuff.
In general I think California is using their huge size and role (obviously, as home to most of the dominant internet companies like Google and Apple and Facebook) to push the rest of the country forward.
Can you give an example of something California did that was a move backwards? As in, moving back to a way that we did things in the past but the rest of the country has moved on from?
San Francisco's homeless issue has a lot to do with the fact that tolerance is not equally spread across the nation. If every city was equally tolerant, there wouldn't necessarily be more homeless total, but they'd be more evenly spread out across the nation. As it is, they tend to migrate here from other places.
That said, I've lived in SF for nearly 20 years and seen human poop on the sidewalks maybe twice.
Regardless I looked at enough of your past postings to decide you aren't the kind I'd like to engage with further. Good bye.
https://www.mofo.com/resources/insights/the-commerce-clause-...
btw - nothing new here (fta): "Big companies are signing deals with firms that specialize in compliance".
Big companies already hire compliance companies for a large number of other regulatory requirements. This is just yet another such requirement - and it's still being hammered out in a public comment period prior to going into law.
california is the sixth largest economy in the world.
Data should never have been a gold rush and we should be more keen to kill it
I'm a US expat and honestly its extremely frustrating to try to use sites I formerly was able to access (with µblock) due to either absolutely obtrusive and confusing opt-in/out policies (e.g., Oath) or complete rejections/refusal of anyone with an IP outside the US (this is exceptionally frustrating as I don't even live in the EU, but because the lazy solution of applying the GDPR block to any non-US address is often used, I cannot read many US new sites)
Global companies have __not__ adapted to GDPR, and instead have just dragged their feet. I'm curious if the EU is going to do anything about it for sites that frequently do business in the EU, or if they will start enforcing actual GDPR policies on the big players (for example, Google is a beast to use in any EU member nation if you choose not to grant consent for data collection by just using element blocking)
The idea that companies have complied with GDPR does not mesh with my experience actually trying to use websites in the Schengen Area. And I don't blame GDPR, I blame companies for the insane amount of data and tracking they want for viewing even a minute amount of content.
If a US news outlet has no presence in the EU there is nothing which can be done if they do not follow EU rules.
Can you explain this a bit more?
You should clean up, no?
> How are these different from GDPR? Most global companies should already have most of this in place
There are tons of companies, global or not, that don't have it in place. They won't be able to deal with it by firewalling off their home market.
Now, it could simply be that everybody is waiting to see if the GDPR enforcement is going to become aggressive before doing so. There is no point in trying to compete with an entrenched US company until the EU actually neuters them.
For example, Equifax has a bunch of subsidiaries in EU who have to follow GDPR - and mostly are following it, or at least make a decent show in attempting so; but the main USA Equifax business could not bother with it, to great benefit of Equifax itself and detriment of all the USA citizens whose data Equifax mismanaged.