U.S. retailers rush to comply with CCPA
reuters.com
reuters.com
It's embarrassing that the law isn't more explicit that this also covers "sharing" where money doesn't change hands, but I wouldn't expect any more from California's legislators where my default assumption is that they'll be captured by the industry in their backyard.
I guess it will be up to courts to decide if sharing data counts as payment-in-kind.
Our lawyers tell me that it does cover any in-kind exchange. For example, if we offered a customer summit in partnership with one of our product manufacturers (as we often do), and if that manufacturer helps underwrite the cost of the event, then us providing to them a list of attendees would count as a sale.
https://leginfo.legislature.ca.gov/faces/codes_displaySectio....
(t) (1) “Sell,” “selling,” “sale,” or “sold,” means selling, renting, releasing, disclosing, disseminating, making available, transferring, or otherwise communicating orally, in writing, or by electronic or other means, a consumer’s personal information by the business to another business or a third party for monetary or other valuable consideration.
https://leginfo.legislature.ca.gov/faces/codes_displaySectio....
Even if Google doesn't pay you for your data, you still have the right (as a resident of California) to prevent Google from selling on your data directly, or in using your data as part of a sale (e.g. targeted advertising).
My experience is the "confusion" is in what constitutes "other valuable consideration:" Can a company offer a personal data marketplace using credits that can only be used to obtain other personal data, and can only be obtained by sharing personal data? (e.g. the old data.com connect model). The code suggests maybe, but I suspect the Attorney General will take as broad a view as possible, so I'd steer clear from any startups that think this is a good idea.
He was one of two AGs to not join other state AGs in their antitrust investigation of Facebook [1], so I'm not holding my breath. Private right of action is what's going to hold businesses accountable, even though it's also been crippled [2].
[1] https://www.nytimes.com/2019/10/31/technology/tech-investiga...
[2] https://www.jdsupra.com/legalnews/a-closer-look-at-the-ccpa-...
Except the definition you quoted doesn't say anything about "using" the information to provide a product (ie targeted advertising), it only talks about actually transferring that information to "another business or third party for monetary or other valuable consideration". So if the information doesn't leave Google's servers then it seems like it doesn't apply to Google.
1. The ad tag Google delivers to publishers captures personal data like IP addresses and cookies, non-personal but potentially privacy-leaking data such as the URL the user is visiting, and somewhere in-between marketing segments that the user may belong to, and delivers that information (usually in JSON) to hundreds or even thousands of different advertisers using a protocol called OpenRTB.
2. The ad tag being served can also include an impression tracker. This is usually a pixel (literally an <img tag!) that refers to the advertisers' server where they record counts, sometimes media spend, and because it's a third-party server, that advertiser will receive (automatically) the IP addresses and cookies, the URL the user is visiting, and so on.
3. One of Google's products includes custom segments which contain IP addresses and cookies for one or more ad exchange. This is actually delivered in a flat file to buyers, and while Google themselves do not offer this service publicly (so conceivably the contracts could be updated to be CCPA-compliant), other exchanges that are like Google in other ways certainly do not.
It is entirely possible your point is accurate for someone who doesn't provide ad exchange services or impression trackers or custom segments (such as Facebook), but it is also likely that some party selling a product that is derived from the use of this data will be considered in-scope. I would steer clear of companies that favor an alternate interpretation until the Attorney General has had a say.
It feels a bit pedantic to say that about a post from a week ago, but the whole point of the article was that they had until January 1st to comply, which has now passed. When I first saw the article title, I assumed it would be an article about how companies were out of compliance already since the date had passed, but it's not.
As far as I'm aware, the actual text of the regulation is still not finalized. The most recent update to the text was in October, but the AG office was gathering public feedback in early December. They still haven't released their findings from the feedback. The October version was more a Release Candidate, if you will.
(I realize the fact it's not being enforced makes this moot, but...)
You want to sell my purchase/demographics data? No problem. Just let me know how much or what i'll get for it and i'll decide if it worth to opt-in.
By default - no one should be able to share my data with anyone.
There's no reason a government like California couldn't require honoring DNT (within their jurisdiction, of course, as with the CCPA) and provide penalties for violations.
It should be allowed to be the cost of admission to the site. If you don't like that the advertising and your own metadata allows you to view the site for free, you could just not visit (or when you click no to consent, they would block you).
Websites shouldn't be required to provide you content for free.
You may say that credit and debit cards do this already (and they do), but you can still pay cash in public stores. Of course they can track you with your phone's bluetooth identifiers, facial recognition, etc., but why as a society should we allow public businesses to require this? Once we permit one place to do it, others will follow.
What about Costco, BJ's, etc who require a membership to enter the store and (probably) are selling the data they get from your membership?
If I make an unauthenticated HTTP GET request to a server, and it responds with a 200, it can't claim after the fact that receiving that request means I agreed to something.
[1] https://developer.mozilla.org/en-US/docs/Web/HTTP/Status/402
But none of the websites should be allowed to pull the fast one on their visitors by stealing and sharing visitor data to other entities.
If you going to give me a free kiss, please ask my concent to be infected by personal-data-stealing disease. Of course if you like kissing and don't give a shit about others - government should step in to protect their citizens.
[yes] [leave]
Hi! The E.U. makes us put up warnings for cookies. These are silly things that every service on the WWW uses: don't worry, little user, we're just doing what everyone else does! [accept] [go away]
By Visiting This Website, You Agree to Have Cookies Placed on Your Device. [MORE INFORMATION]It's very easy to extend to whatever you'd like. Consent on the internet is a farce.
EU added a hell of an inefficiency to the WWW by making user education the responsibility of every site with no way for a user to pre-emptively signal "Yeah, I get it, and I don't care."
The EU didn't add any inefficiencies, rather, it's forcing the data abuse by websites to come to light.
If you use cookies only for login/session tracking then guess what, no popup is needed.
Also if the user expressed their consent (or lack of) once, then the popup is not needed anymore (google/fb/etc do exactly that).
Because if the answer is "per-site signaling," that's soft encouragement to keep using the same sites so I don't need to see that tedious notification and it rewards big players over small players (and defeats some of the benefit of the WWW as a hyperlinked network of data that's fairly location-agnostic).
That's on the website unfortunately
> that's soft encouragement to keep using the same sites so I don't need to see that tedious notification and it rewards big players over small players
I agree, I would want the same option (since I use privacy browser extensions I don't care), it's not the users fault the small sites are playing it dumb and using some generic annoying "we value your privacy" popup BS.
The GDPR does not require continuous confirmation of consent, only that they're allowed to withdraw consent at any time
> The GDPR does not indicate a shelf life for consent. Theoretically, a person’s consent is indefinite,
https://gdpr.eu/gdpr-consent-requirements/
> since the penalties are significant if small sites
This is FUD, proportionality is used when calculating penalties
Can you point to where in the law that guarantee is given? Furthermore, given the previous penalty was "none," any penalty can probably be considered significant for website operators who were previously assuming nearly zero risk in running their sites.
Paragraph 1. > Each supervisory authority shall ensure... in each individual case be effective, proportionate and dissuasive.
Paragraph 2. a) > the nature, gravity and duration of the infringement... as well as the number of data subjects affected and the level of damage suffered by them
Also, as we are discussing this, a lot of this will now apply to CCPA and (in some cases) COPPA
Yes, and COPPA has terrified YouTube content creators.
Wiggle language like "proportionate" (especially when paired with "dissuasive") doesn't assuage the fears of website admins, because it isn't a dollars-and-cents (or, in this case, euros) amount. It's at the behest of a judge, which is not a risk space an admin (particularly one running a site as a secondary function, not as core to their business model) wants to take on. So the law, as structured, encourages those popups everywhere forever. Annoying, to say the least.
I don't think I'm spreading the FUD; I think the FUD comes from the ambiguity in the penalties described in the law itself.
By Clicking Here you Agree to give us your personal information and we may share and monetise it with without compensating you in any way.
[yes, i'm sucker(or VPN user)] [no, GTFO]
Fortunately he's back at it again with a new ballot initiative, which he's funding himself, to improve on CCPA [1]:
>Mr. Mactaggart said his 2020 state ballot initiative, among other things, would create a state enforcement agency, limit targeted advertisements based on geolocation and add items covered by the “negligent data breach” section, which would allow consumers to pursue legal action in more instances of a hack.
>Most significantly, Mr. Mactaggart said, his new effort would make it harder to adjust the current law any further. The initiative includes a “purpose and intent” section that requires any amendment to the law to be in the service of protecting consumers’ rights to privacy, a legally binding clause that Mr. Mactaggart said would prevent industry from chipping away at the measure.
...
>The lobbying against Mr. Mactaggart’s earlier initiative kept it from the ballot in 2018, and legislators instead passed the privacy law. “It was the right thing to do because there was no guarantee at the ballot box,” Mr. Mactaggart said of his agreement to drop his measure. “Now, it’s different because we have the law.”
>Mr. Mactaggart said he would do whatever it takes to pass his initiative next year, including spending millions of his own money. He bankrolled his last campaign almost entirely himself, spending more than $3 million. Mr. Mactaggart will have to collect more than 623,000 signatures for his new initiative to qualify for the ballot. A survey in October by Goodwin Simon Strategic Research of 777 registered voters in California found that most supported Mr. Mactaggart’s initiative.
[1] https://www.wsj.com/articles/activist-behind-californias-new...
What's his motif for this?
https://www.nytimes.com/2018/08/14/magazine/facebook-google-...
>What's his motif for this?
Making a dent in the universe.
Instead, the rules weren’t tight enough to stop the current shitshow we now have. Your explicit opt in is a nice single button click, on a modal that fills the entire screen. It tells you nothing about what happens, it’s just easy.
Meanwhile, the rest is hidden away. And you still don’t know if those changes have any effect, especially if the tracking is also done server side. You’ll still get opted into all the emails by default, the needy ones that have to remind you every day that you made an account, and make you log in to disable them (to update their active monthly user count I’m sure).
Of course, it’s working that way because companies share your data with so many random third parties that opting in for each one would scare you away. And most of them do similar things, it’s probably different teams or departments insisting on using their own tools.
I don’t blame advertising for this per-se, I blame growth hacking too.
I wouldn't blame GDPR for any company's deficient consent process. That's just what they believe to be in compliance with GDPR, it may not actually be. Many of these questions are being litigated by privacy activists like Max Schrems.
"""
If loyalty programs run afoul of the law, it'll be interesting to see if this creates a plane of competition between companies that kick out or forego loyalty programs in states outside of CA as well as inside CA and companies that continue to offer loyalty programs in states outside CA.
Loyalty programs seem a mixed bag for consumers; some are actually into them, some hate them (seeing them as inefficiency that pushes labor onto the consumer).
Also, I don't hate them (the ones that collect data, that is) because they push inefficiency onto the customer, but because I have to pay more so other people get paid for helping corporations manipulate me more effectively.
I don't anticipate most stores going back to them (or staying that way as they grow; small stores will always do whatever).
Given how much fraud is happening with customer data (that is: it being acquired under a pretense and then used for a different purpose), I very much doubt it.
> require more physical product be printed, and are less convenient for users than online solutions.
Except that's kinda orthogonal. The paper solution is easier to demonstrate to be free of back doors, but there is no reason why you couldn't build an "online solution" that doesn't do any tracking. You could just hand out random tokens without ever associating them with a transaction, and then accept sets of ten of those to redeem for a rebate, say.
Sorry; I was unclear. More prone to fraud against the loyalty program, i.e. customers buying the appropriate stamp and photocopying a dozen instances of the card to make "every 10th visit" into "every visit."
Like, it would be perfectly possible for a merchant to encrypt the transaction description with a public key of the customer, and their bank only submitting the encrypted record with the amount and the account to debit to the card issuer, who would debit the account and pass on the encrypted record to their customer.
That's just a random idea, but the point is that you could achieve much the same result with a lot less data collection if you actually cared to.
It's been done.
Cash. Checks. Travelers checks. Money orders. Cashiers checks. Gift cards. Pre-paid debt cards.
The truth is "profiling" / ad targeting is actually a benefit to the consumer.
No, pervasive surveillance is not a benefit to me because it facilitates smoother attempts at psychological manipulation. It's generally a good thing when spam stands out as much as possible, making it easier to ignore.
It's been done for hundreds of years with billboards, newspapers, magazines, radio, and television. Heck, even web sites can do it, and did for many years before Google even existed.
"Targeted advertising" has been around longer than you think.
I don't remember exactly what Tim Cook said in the announcement, but I believe it was something to the effect that Goldman Sachs can't use the information for marketing. Whether that means internal marketing, or if they're selling it or not wasn't specified.
It's not ideal, but it's a start; and other than cash, the only way to vote with my dollars.
If they do business in CA, why wouldn't CCPA apply to them? Even for HIPAA-covered entities, the CCPA still applies, just not all the parts (specifically there are exceptions for health data).
Edit: Curious the effectiveness of browser extensions like Ad-Nauseum. I've used it on & off and became amused with how much I 'cost' the ad-companies but for all I know it just proves another data point that my machine clicks every add that comes across it.
california didn't outlaw the internet guys, you're just being hysterical because you're going to have to ease back on your data collection a bit
This is how my company's counsel (and other attorneys with whom our counsel consults with) has read the CCPA. If you don't sell data you don't need to include language to opt out of data sales since you don't do it. If that changes you have to message customers of change and provide the button.