California DMV Is Selling Drivers' Data to Private Investigators
vice.com
vice.com
This comment seems like a lie, or at the least sly misdirection. According to this article the DMV is making 50M a year and openly admits that they redirect profits to other initiatives, they're not just "recovering the cost".
It's like saying, "I'm a software engineer, I sit at home and recoup the cost of sitting at my computer all day."
Also known as doublespeak.
That was $50M in revenue, not profit. I blame the Vice headline; it said "makes," but in the article clarified that it's revenue.
They are required by law to provide information. That's not selling... that's just complying with their obligation to provide certain data.
And they charge a fee for it.
In other words, if you want to prevent them from providing information, you need to change the laws requiring they share information.
EDIT: I think I got it - I am hearing the fee is equal to the amount it costs them to provide it.
Is Amazon not "selling" retail products because they aren't really making a profit on it? In fact, they aren't always even recouping their full cost of selling products, those losses are offset by other revenue streams like aws.
Stalkers, murders, debt collectors, etc., lives made easier / possible?
A sad state of affairs.
This data doesn't seem that sensitive or difficult to obtain via other methods depending on the exact situation. You should check out the system that the repo industry uses to track vehicle location via license plate scanning.
A government should not be in the business of betraying its citizens to private parties, even if those parties have other means to accomplish their goals. Should I expect them to start selling school records and police interactions next?
The school data is "anonymized" but like most anonymized data, it is possible in some cases to trace it back to individuals. They also publish some types of information.
The police interaction records can be public record depending on the type of interaction/document. Departments using unencrypted comms broadcast your information when they call in your stop, which could be heard by anyone with a scanner.
Also, how do you see this as a betrayal? It doesn't violate any laws nor any agreement with the individual.
I would like to see better privacy laws. What they did is not shocking, not a betrayal, and not illegal. It would be nice if it was.
Also, using the 'one is too many' argument is not valid. We could apply that to outlaw cars, electricity, or any other thing that is accepted as useful but also kills people. The DPPA law allows debt collectors, repo men, and other neccessary societal systems to function while providing protection for the data. If there have been only a handful of incidents over the years, then I think it would still be a net gain for society. If there is a better way to regulate the data and still allow the systems in society to function, that would be great to explore, but I don't see any obvious improvements.
You're wrong. They can function just fine without data from the DVM. Therefore, anybody being harmed by the sale of this data is one too many because there is nothing to offset this harm. Some harm is acceptable when it's offset by something else, like the utility of cars. That is not the case here.
Also, where is your evidence that someone has be hurt?
Work a little bit harder doing some old fashioned detective work instead of just paying the DMV for their records? It's a bit more work for them but I don't give a damn. Your suggestion that they'd be up shit creek without the DMV is just flat wrong.
I’m not excited about license plate tracking either, but I have different expectations of the data I leak by going about town, compared with the complete personal information that I must give to a state agency (on top of paying them, on top of them receiving state funding) to have the privilege of going (driving, I guess) about town.
They use machine learning with your license plate data so that they can predict where your home address, where you work, home of people you associate with, etc.
What expectations do you have with the DMV? They didn't break any laws or privacy policies. Was it just an assumption you made?
Selling private data is bad, no matter how legal it is, in most of the world. See GDPR as an example.
Edit: in the context of the CA DMV releasing data under the DPPA law.
Many states also use this information to register, or solicit the individual to register, to vote. Law enforcement also uses this data for enforcing all manners of law when they look up a person to question or cite, not just immigration. Since drivers' licenses are used for identification, you can see that they are used on many government forms such as tax returns or background checks. Along these lines, the only way to ensure the government will not use your data would be to prevent the government from collecting and storing it (rough paraphrase from Snowden). But if you prevent the collection of the basic data referenced in the article, then how do you provide the same benefits to society that the systems do today?
The issues you have seem not to be about the state releasing records but rather with how the government uses the data. The basic information referenced in the article is also available in other country's systems to many of the same organizations authorized under the DPPA. Given the system is also about titling and registration, the access by debt collectors would be warranted, especially if it is dealing with a vehicle. How exactly is this system enabling stalking given the protections of the DPPA?
Do you have any examples of countries that don't aggregate data for government use and don't allow PIs to search many kinds of official documents? What system do you see that would replace the current one and maintain all the societal benefits but somehow increase privacy?
It wasn't a slippery slope - the opposite in fact. The records were practically wide open and the DPPA set the limits on who can access it and for what reasons.
I'd appreciate a real response to my prior comment. Simply stating your opinion that an action is unacceptable does not make for productive discourse.
Two reasons; privacy is axiomatically a human right (since it's an axiom you can unilaterally disagree, just as with any other human right), and caused harm arguments that the information is available in a way that can cause your physical harm (when you cannot escape a stalker, or a general class of invasive people if you're a celebrity or piss off qanon).
That's a very generalized axiom that doesn't even define what would be accepted by a society as falling under the protection of privacy. so we could accept it as true and discuss it's limitations and scope, but the axiom itself does not address whether the 'selling' of data under the DPPA is wrong. For example, is everything protected under privacy? Can I claim that my salary should be private from the government so that I don't have to pay taxes?
I see what you mean about the credit data access. My suspicion is that the permission to do that is hidden in the fine print of many agreements. They do similar stuff with credit cards where they will periodically check your card to see if it is valid, like for EZ-Pass. Car insurance does the same sort of thing. When you sign up, you give them permission to access your driving records, ownership info etc. That's how they can do that spooky stuff like list what cars you own without even needing to put in the VIN yourself (the industry also aggregates the data that any insurance provider has on a driver, but that much more detailed and personal).
The only way to truly end the privacy concerns around the DMV data would be to eliminate the need for the data to be collected and distributed. The government wont stop collection because they use that data in all sorts of systems for stuff like collecting fees/taxes and validating identities addresses. Data distribution could be partially reduced by making insurance companies ignore that type of data in their models. Many states would not go for this because they work with the companies to verify insurance information around mamdatory insurance laws. Plus, as long as cars are financed the banks and debt collectors need some way to track who is registering their asset and where.
* Real-time location from your cell provider
* Real-time AirBnB booking
* Real-time purchases from credit card companies
* Real-time browsing records from your mobile ISP, home ISP, and behavioral advertising networks
* Your complete prescription history from your pharmacy
This is truly the stuff of nightmares. Part of the problem with government data sales is that it normalizes morally abhorrent practices that would not have been tolerated just a few years ago.
So it's ok because there's more than one there's more than one way to get the data?
I would like to see privacy laws overall change, but I don't see any issue with the DPPA law.
The purpose of a system is what it does.
I'm not saying that welfare for a subset of the people who can pay their own way and high sin taxes on essential services are good government policy (I personally think the combination is farcically regressive), just that the system makes sense if you take that viewpoint.
I'm not saying CA is there yet but if you look at asinine policies from all the various states and their level of compliance it seems pretty clear that huge swaths of "perfectly fine when done reasonably" normal and common behaviors are more or less impossible to do while being legally in the clear. At what point does an unenforceable at scale policy become a backhanded infringement upon people's property rights?
https://www.theguardian.com/society/2020/mar/18/cannabis-can...
Stupidly high fees and requirements for production or sale licences, no real legal way to acquire initial stock, countless hoops to jump through and continuous fees, over top the exorbitant tax rates have made it fairly difficult for anyone without a lot of initial capital to even begin.
Despite the fact there was already and still is a thriving underground grey market that gets mostly left alone until somebody needs to be made an example of.
I know post 75 cars have to be smogged with factory equipment if using the stock engine (though I don’t know how the hell your average smog tech knows the factory setup for an 1980 Lancia Beta).
I've never done one for CA but some states make it hell to go from "car with no paperwork last owned by a dead person and last registered years ago" to "car with proper paperwork to sell/register" so for someone repairing old cars to flip that can cause a significant headache.
This from my time living on the border of Mexico. Everyone always talked about how the roads on our side were as bad as on Mexico's side as a criticism of texan infrastructure. It's fair, by the way, American infrastructure is a mess. But then the life expectancy was like ten years lower just a couple miles away because of an invisible line (and a fence you could easily hop over with a ladder).
It's also worth noting I would never try to compare the USA to other nations typically lumped under the now-vague definition of "first-world." The USA fails at many things.
https://www.econlib.org/about-that-cuban-life-expectancy/
Independent studies have shown giant anomalies in other metrics that suggest the favorable metrics are being fudged:
https://mobile.twitter.com/wwwojtekk/status/1233017228792082...
Also a lot of reports that women are pressured to get late term abortions if there are any potential issues observed with the fetus, as this will ensure it doesn’t count as a mortality and not hurt that clinic’s stats.
The USA is distinctly, profoundly third world. Just because your rich ass is enjoying a pretty good life in the USA doesn't make that not the case; the rich enjoy good lives in many third-world countries.
I personally know someone who was a victim of stalking back in the 90s. Her stalker managed to find out where she lived by getting it from the California DMV. The only way she found to block it was to move and have her car owned by someone else so that there would be no DMV record.
The result is that while this is not new, it really should be a story.
If your scenario happened in the 90s, it might have been before the DPPA law took effect.
The author has a clear bias and is using an event that took place before the protections were in place to further their agenda.
However social engineers have no problem getting information. And private investigators are easy for anyone to hire. I doubt that the DPPA will slow a dedicated stalker much.
Nobody should have access to this without a warrant, its a huge invasion of privacy.
A better alternative is to have strict recording and auditing of requests and legal accountability for abusing the access (such as renting it out on fiverr).
So the data is sold wholesale to private investigators/lawyers and retail to the public. This is just a supply chain. The data is sold to the public.
Having spent most of my professional career providing software support to Debt Collectors--I think you're greatly overestimating the level of professionalism by your average debt collection agency.
[1] https://www.cdph.ca.gov/Programs/CFH/DGDS/Pages/nbs/default....
[2] https://sanfrancisco.cbslocal.com/2015/11/09/dna-data-from-c...
The worst part isn't that they take it, it's that it's not disclosed to you, nor can you opt out[]. You can have the sample destroyed after-the-fact by writing a letter to the correct authority. We did so and a few months later got supposed confirmation of destruction and supposed confirmation that the sample was not used in any way for any purpose. Of course it's far better to be able to refuse collection than to trust that your destruction request was properly followed.
It would be acceptable (welcome, even) if the samples were properly anonymized. Clearly they are not, since you can request destruction of yours.
I mean, you can probably absolutely refuse while you are at the hospital. What are they gonna do, call in the sheriff?
The information is only supposed to be used for political, scholarly, or journalistic purposes. There doesn't seem to be a way to opt out.
> (3) Shall be provided with respect to any voter, subject to the provisions of Sections 2166 , 2166.5 , 2166.7 , and 2188 , to any candidate for federal, state, or local office, to any committee for or against any initiative or referendum measure for which legal publication is made, and to any person for election, scholarly, journalistic, or political purposes, or for governmental purposes, as determined by the Secretary of State.
IIRC we never dealt with the DMV directly. The parts of the government we worked with would send us the DMV and voting data. So even if you somehow get the DMV to stop selling your data, other parts of the government will probably keep giving it away to companies. We weren't using the data for anything nefarious, but I'm sure there are many other less-trustworthy companies with access to the same data.
This isn't news, and it isn't specific to CA. All 50 states sell DMV data. I don't know about other states, but for CA it is required by law.
Does anyone have another/earlier example?
The DMV is not being caught selling data; the DMV is legally required to sell this data.
We should just stop the illusion of privacy, your data isn't private. It may have never been private.
Private DMV run by Google: 'Your paperwork has been denied because our classifier says you're a scammer. We won't tell you why. You are forbidden from ever trying again.'
https://azdot.gov/motor-vehicles/mvd-hours-and-locations/aut...
What this does is punishes people who cannot pay convenience fees (how much or how little that is orthogonal) and rewards people who can.
This is an extremely sad state of affairs where privatization of something that government is supposed to provide with reasonable quality and timely manner.
This is why our country is compared to third world. Because of shit like this.