California Passes Regulation Banning "Dark Patterns" Under Landmark Privacy Law
gizmodo.com
gizmodo.com
The notice of right to opt-out shall be designed and presented in a way that is easy to read and understandable to consumers. The notice shall:
a. Use plain, straightforward language and avoid technical or legal jargon.
b. Use a format that draws the consumer’s attention to the notice and makes the notice readable, including on smaller screens, if applicable.
c. Be available in the languages in which the business in its ordinary course provides contracts, disclaimers, sale announcements, and other information to consumers in California.
d. Be reasonably accessible to consumers with disabilities. For notices provided online, the business shall follow generally recognized industry standards, such as the Web Content Accessibility Guidelines, version 2.1 of June 5, 2018, from the World Wide Web Consortium, incorporated herein by reference. In other contexts, the business shall provide information on how a consumer with a disability may access the notice in an alternative format.
source: https://oag.ca.gov/system/files/attachments/press-docs/CCPA%..."The newly-approved regulations ban so-called “dark patterns” that delay or obscure the process for opting out of the sale of personal information. Specifically, it prohibits companies from burdening consumers with confusing language or unnecessary steps such as forcing them to click through multiple screens or listen to reasons why they shouldn’t opt out."
https://oag.ca.gov/news/press-releases/attorney-general-bece...
You click to customize tracking cookies and get presented with a list of checkboxes, but primary button on the right is "Accept all cookies", whereas the left side (where you'd usually find a "Cancel") is a secondary-looking button that says "Accept changes".
If you don't take the time to actually read the buttons, you end up unchecking a bunch of boxes just to inadvertently accept them all. Real scumbag stuff. From the above, it sounds like tricks like that may not even be covered.
Everyone has now been trained to click accept / accept all / OK or whatever on all these pop-ups.
Now we are starting to get the even worse GPDR ones with like 6 different options.
If I don't want you to track me using cookies I will clear them, block them or isolate them on MY machine. This doesn't require tons of click throughs. I will chose software that helps me with this.
Can I actually sue some russian website owner hiding behind some dns registration privacy domain if they use a cookie they shouldn't have? Will I collect? Or is this just tail chasing when an actual technical solution to BLOCK cross domain or other forms of cookie use are available to me.
The amount of time wasted on these nightmares, the number of clicks, the horrible impact on user experience is crazy - govt really can't seem to get this stuff right - it's mind boggling.
Let's start with simpler things.
1) Ban regulated entities from selling my info or personalizing ads to me based on my browsing history (cable companies) electric usage (electric companies) phone usage (telecom companies). No opt in or out, these are regulated folks with monopoly or close power - banned.
2) Actually ramp up real investigations of folks committing crimes online. There are billions in harm here waiting for someone to give two sh*ts about someone with their life savings stolen.
3) I have a list that goes on and on.
And while you may be able to block cookies, are you able to block canvas fingerprinting? IRL tracking? the gdpr also applies to every bit of life, to the third parties a doctor can use to process your medical data, to the third parties having access to surveillance cameras in a parking lot, to the legal notifications required when your covid 19 test data or contact tracing data might be breached.
--
(h) A business’s methods for submitting requests to opt-out shall be easy for consumers to execute and shall require minimal steps to allow the consumer to opt-out. A business shall not use a method that is designed with the purpose or has the substantial effect of subverting or impairing a consumer’s choice to opt-out. Illustrative examples follow:
(1) The business’s process for submitting a request to opt-out shall not require more steps than that business’s process for a consumer to opt-in to the sale of personal information after having previously opted out. The number of steps for submitting a request to opt- out is measured from when the consumer clicks on the “Do Not Sell My Personal Information” link to completion of the request. The number of steps for submitting a request to opt-in to the sale of personal information is measured from the first indication by the consumer to the business of their interest to opt-in to completion of the request.
(2) A business shall not use confusing language, such as double-negatives (e.g., “Don’t Not Sell My Personal Information”), when providing consumers the choice to opt-out.
(3) Except as permitted by these regulations, a business shall not require consumers to click through or listen to reasons why they should not submit a request to opt-out before confirming their request.
(4) The business’s process for submitting a request to opt-out shall not require the consumer to provide personal information that is not necessary to implement the request.
(5) Upon clicking the “Do Not Sell My Personal Information” link, the business shall not require the consumer to search or scroll through the text of a privacy policy or similar document or webpage to locate the mechanism for submitting a request to opt-out.
(6) The steps to discover and opt-out shall be no more difficult than the original steps to discover and opt-in.
It's the asymmetry of effort in granting consent and attempting to revoke it, or of signing up to a service and attempting to cancel it (hello Economist!) that is a pain.
This seems really oddly worded, like wanting to preserve a loophole. This sounds like it would be perfectly compliant to e.g. make you click through half a dozen "show advanced settings" links to opt-out - as long as you put the "re-opt-in" button (that no one outside a marketeer's fantasy would ever want to use) in the same place.
A site could still make opt-out unnecessarily difficult compared to the path they want their users to take: Just dismiss the popup and never opt-out at all.
edit: Then again, the parent paragraph (h) seems stricter. Is (h)(1) then just an "illustrative example" and not legally binding?
Then partway through the process, you are presented with other "adjustment" options, which in their default state show "none" in the dropdown selector. Only if you click on "none" do you learn that you can deduct various amounts (ranging up to $40) for each of the various dropdown menus. There is no way to adjust all of these menus with one selection — you have to do it separately for each of them. It took me a couple years of paying inflated dues before realizing that I was doing so. I think opt-outs are bad, but they are especially heinous when camouflaged amongst opt-ins.
If the state ever expands their regulation of dark patterns (which are very narrow, as other commenters have pointed out), they will have to make sure that organizations like the CA Bar Association, which is tasked with setting and enforcing ethical rules related to judges and lawyers, get their houses in order.
What does this actually mean? An extra overlay to click away when I visit a new website for the first time?
Hmm, had not heard the term "dark patterns" -- until now...
Anyway, it's going into my 2021 lexicon...
I knew that there were "attack sites" on the Internet -- that is, websites which openly attacked the browser of any visitor... Maybe "dark patterns" could be thought of as the "lesser version" of that -- instead of attacking your browser -- the website attacks your rights (!)
That is, by railroading you (the user) into "accepting" "agreements" -- that you normally would not have accepted!
Now, the $64,000 question:
Where have I seen that pattern before?
?
Some examples I have collected: non-response to requests, spamming the email address used for a request, failure to disclose specific pieces of personal information, etc. The best one I had was a letter from Experian where they had everything redacted even my address.
The CANSPAM act was implemented a decade ago and I still receive spam emails without unsubscribe links from salespeople at Fortune 500s. Reporting it does nothing. There is no real enforcement of any of this.
Maybe even automatically tweet a “hall of shame”.?
Their business model is to guess, and false negatives deprive Californians of their rights.
Likewise lately I’ve found myself wanting a better general news source and I think NYT is fairly reputable, until some quick research shows you can not unsubribe without calling someone, but sign up yeah absolutely, a few clicks and you’re done
If there was bill addressing the first one, that’s not “failing for the basic necessities of life”. I don’t think it’s unreasonable to demand business not try to F you cause they can. There’s been so much consolidation in the market that “voting with your money” has become nothing more than an untenable aphorism.
Of course, in reality, I know the government would botch it. Still, the system seems really bad.