Data Brokers
oag.ca.gov
oag.ca.gov
I had to make a few clicks to find the definition, more details here (scroll down to section 1c):
http://leginfo.legislature.ca.gov/faces/billTextClient.xhtml...
* LinkedIn - Sell your data via Sales Navigator
* ZoomInfo - Scrape your email account and sell the data to other businesses - https://www.zoominfo.com/business/about-zoominfo/privacy-pol...
* DiscoverOrg
* Clearbit - Browser extension scrapes your emails for data and they sell it to others via their "free browser-based add-ons, extensions, or plug-ins" - https://clearbit.com/privacy
* Hunter.io - Scrape people data from your browsing activities to resell.
* Demandbase
It might be different if they were selling information from shadow profiles that they created from other people sharing their contact lists, but I don't think they are selling that.
-----------------------------
> How a consumer may opt out of sale or submit requests under the CCPA:
> Go to spydialer.com, then click the link "Do Not Sell My Info".
-----------------------------
Cool. Now compare that to another one listed [infocore]:
-----------------------------
> How a consumer may opt out of sale or submit requests under the CCPA:
> contact the company
> How a protected individual can demand deletion of information posted online under Gov. Code sections 6208.1(b) or 6254.21(c)(1):
> contact the company
> Additional information about data collecting practices:
> No information provided.
-----------------------------
Ugh. Their contact page is intended for submitting requests to do business with them: https://infocore.com/about/contact-us/
> Cool. Now compare that to another one listed [infocore]:
To opt-out of spydialer.com, you go to https://www.spydialer.com/Consumers/, then you have to provide all of the information you think it has on you to verify your identity and selectively remove it from their services.
I'm not really comfortable providing my full name, address (or addresses if you've lived in multiple places), and phone numbers to a Data Broker just to opt-out - that feels quite counter to the idea of them ideally not having my information in the first place.
I feel like I need a global opt-out where a system or agent on my behalf can then handle this for me at each place where data can be collected.
Any company found in procession of personal data without the appropriate (delivered) email notifications being sent should be fined at minimum $1000 per individual, and criminal charges if intentional.
This won't put anything like services you voluntarily sign up for out of business (as they send sign up confirmations anyway, or should).
Danny W[ilkins]
- Job Title
- Salary
- Job application records
- Social media post history
- Email 1: dannyw@gmail.com (correct)
- Email 2: dannywilkins@EmployerLLC.com (correct)
- Email 3: dannywinters@hotmail.com (not correct)
I'd assume they'd send the email containing your salary and post history to the two valid emails as well as the one invalid email.
That seems like a potential nightmare for you, for example records of job searches being sent to your employer email.
In my case, I always feel I'm fighting a losing battle against the horde of emails addressed to users of unknown services...
There are a growing number of services that validate the email and include a "I didn't register at this service".
This has me worried, because I can imagine so many scenarios where the metadata aggregators scrape and mis-classify by email:
A teenage boy using a Snapchat-like service had created an account with my email and I had to manually delete it; some guy used my email to register his account at a MacDonald's franchise's ERP; I once received a booking confirmation from some large airline (and Google nicely reminded me that I had an upcoming flight); also, I was once wrongfully tagged by email in an unlisted web album of a party that had taken place in a French village by an older lady.
I always try to reach out to notify the person... But sometimes it's hard to call a Peruvian bank to notify them that one of their account holders used my email to register his account, and they tell you they'll get around to notifying the user, but don't.
Now; I could imagine several scenarios where things might get bumpy for me in the near future...
Like in the event where someone tries to forecast criminal behavior; or what if a government thinks I should be paying taxes on some income that their metadata suggests I have (because, why else would you have emails in your inbox from that bank?).
Even the deletion requests could cause an identity theft nightmare. One hack and all of your Facebook, Apple, Google, Microsoft, Steam/Blizzard/Any game company, identify and digital assets are gone forever with no chance of return.
I won't because they don't tell you what the "fee" is until the Attorney General "reviews" the submission and then assigns a fee to you. Sounds like extortion to me. I am not going to give them all of the leverage and then accept whatever fee they want to levy on me. If they want me to register, have a fixed fee and be up front about it.
I am willing to accept the penalty fee for not registering. At least I know what it is and it's well within the financial capability of my business, so who really cares.
Selling people's data is fine as long as the state gets a cut I guess?
Acxiom, Experian, etc.
(1) A consumer reporting agency to the extent that it is covered by the federal Fair Credit Reporting Act (15 U.S.C. Sec. 1681 et seq.)."
http://leginfo.legislature.ca.gov/faces/billNavClient.xhtml?...
> a “data broker” is in the business of aggregating and selling data about consumers with whom the business does not have a direct relationship
The new law requires companies to tell us who are they sharing our personal information with. Applying common sense law -- this sounds like anyone who sells my personal information to a third party with whom I'm not having a direct relationship - that gets covered.
The Ad I see on the top of my search query seems based on personal information that was sold to a third party.
Certainly visiting the website of a business is a consented action, when you were searching, and then clicked a link, for relevant keywords to that business.
I'm all for it, just wish that tidbit was more clear I guess.
Or maybe I'm just not reading it correctly, who knows.
The problem of course is that you may not know that you are dealing with a Californian’s data. For example, you may have scraped an email address and have no idea who it belongs to. I suspect that for this reason, I got a bunch of emails from affiliate programs recently saying that they had to close because of this law. Example:
“Unfortunately, the Yelp For Business Owners program is being paused immediately due to 2020 California Consumer Privacy Act (CCPA) concerns. As of the sending of this notification we have expired all affiliates, which will be effective 1/13/20.
As you may be aware, the newly enacted California Consumer Privacy Act has placed new requirements on Yelp. While we evaluate the implications of these requirements, we are taking the step of temporarily pausing our affiliate program. Thank you for all of your hard work in 2019 and we?re looking forward to working more closely with all of you in 2020 once we work past this issue.”
This is basically to prevent atrocities like Equifax, right?
[1] http://leginfo.legislature.ca.gov/faces/billNavClient.xhtml?...
To me it seemed outrageous that a company I had no dealings with, accumulated data on me without my consent, and above all - their data was breached.
I thought that's what this legislation was trying to address.
This is primarily about the companies that buy your phone number from your gym membership or supermarket loyalty card and sell it to telemarketers. They won’t be missed.
Many countries do fine without private third party entities managing people's credit history and score. Instead, you have to provide data on your credit worthiness each time you request credit from a particular bank. Such as bills, income proof, assets etc.
It's quite different and a lot less fine-grained than feeding all your credit-related and non-credit-related history into some ML model to estimate your credit worthiness.
It is still a third party collecting a fact about someone and repeating it to others, to the data subject's detriment and against his will.
Credit history companies like Equifax are very much an American thing; lending still works everywhere else.
They are such a non-topic in France that I only learned about them last year, and the French Wikipedia page on the subject is very short, and only documents the US, Canada, and China: https://fr.wikipedia.org/wiki/%C3%89valuation_des_risques-cl...
And IANAL, but it seems to me that credit history databases are made illegal by Article 5 of the 1978 "Computing and freedoms act" https://www.legifrance.gouv.fr/affichTexte.do?cidTexte=JORFT...
As I understand it, the American weirdness is that this is a private sector function rather than a service of the state. Not that it exists.
Source: https://www.service-public.fr/particuliers/vosdroits/F17608
That's nowhere near the amount of data Equifax collects.
If the process of selling data involves a daisy-chain of three middlemen companies, they're all data brokers.
Confused, so this means you won't know who is a data broker this year until next year?
I am looking to know -
- What the legal obligations of a data broker are.
- What are the legal obligations of sites/services that use them on their pages and enable them to get user data
The bill explicitly says the following entities are not considered data brokers: consumer reporting agencies, financial institutions, and insurance companies. (I'll note that this is a summary; the bill states more specifically those entities covered. However, the categories are generally correct.)
So, to the questions.
> What are the legal obligations of a data broker?
According to 1798.99.82(b), the obligations are two:
1) The data broker must register with the Attorney General and pay the annual registration fee.
2) The data broker must provide the state with the name of the data broker; its primary physical, email, and internet website addresses; and any additional information or explanation the data broker chooses to provide concerning its data collection practices.
> What are the legal obligations of sites/services that use them on their pages and enable them to get user data?
The bill does not directly state any obligations. In my read, the key part of the definition of a data broker lies in the lack of a direct relationship to a consumer. A business can still sell customer information to a data broker, but I believe this would then fall under the purview of CCPA (which appears to be corroborated by the final line of this bill.) This bill seems targeted toward those who solely acquire information through other, indirect collection means.
My read of this bill (I'm not a lawyer) tells me the state understands the present value of data brokers and doesn't want to eliminate the industry with crushing regulations. However, we know there's plenty of corruption, greed, and lack of ethics among data brokers. Requiring entities to publicly declare their brokering of data seems like a reasonable way for government to reduce these issues.
Consider a restaurant which operates without a license. A license is good because the city knows of the existence of the restaurant. If the city was not aware of the existence of the restaurant, they could not, say, reliably send in health inspectors. Restaurant cleanliness is clearly a good thing since it reduces the potential for food-borne illnesses. I can envision similar analogous benefits from licensing data brokers.
----
Sources:
http://leginfo.legislature.ca.gov/faces/billNavClient.xhtml?...
The deadline for registration looks like it's January 31st, hopefully after that date California will start going after those who do not comply.
Their lobbyists did their jobs, I suppose.
[1] https://leginfo.legislature.ca.gov/faces/codes_displaySectio....
Google Ads (formerly AdWords) now has an API so that customers can disable possibly-sales-like features on a per-use basis if someone clicks "Do not sell my information." So, while Google doesn't sell users information, they're only willing to go to bat and say "this is definitely not a Sale Of Information under CCPA" for a subset of the services they offer.
https://privacy.google.com/businesses/rdp/
Facebook I dunno. My sense is they have a larger appetite for testing the boundaries of the law.
Facebook builds shadow profiles. Those involve no direct relationship with the surveilled.
> they do not sell the data itself
Selling seems like an important part of brokering
Each person own their own data, and can sue to enforce those rights.