Stress aside, part of the problem is the very real possibility of a subject wasting money on hiring a lawyer.
Stress aside, part of the problem is the very real possibility of a subject wasting money on hiring a lawyer.
Or even if there is a legal threat, do you take it seriously unless you know the source? People regularly get calls saying they are in violation of tax law and must pay.
I've received legit legal threats over email from very serious people. I'm certain they would have escalated to more "official" channels if the situation wasn't resolved to their satisfaction (if you're curious, it was a contractor billing issue that was being ignored by my HOA. I was caught in the crossfire).
The fact that random scammers are calling folks claiming they're violating tax law isn't a justification for researchers to engage in similar acts. Do you agree?
This is an interesting point you bring up, which merits diving into a bit further.
I think it's precisely because CCPA is so new that this experiment is more unethical than if they were just calling up people saying "you owe money to the IRS, send me gift cards". The IRS spends a ton of money every year telling people that these calls are scams; but Christine or the operator of freeradical.zone likely had no such public service announcements from the State of California. On the other hand, they probably did hear news items about this new data privacy law that California passed, and thought the emails were from actual individuals.
An email purportedly from an individual is not the same as a contract or terms of service issued by a corporation from which I am getting a service. If I, as an individual, were to send you an email asking, for example, if you are paying all the taxes you legally owe, am I just giving you "a reminder of existing laws"? Or are you going to start wondering who I am and why I am asking and wonder if something is going on behind the scenes?
> People regularly get calls saying they are in violation of tax law and must pay.
Yes, that's true. And people who make such calls are regularly considered unethical scammers who do not deserve any consideration. So why should we treat researchers who send similar emails any differently?
However I’m dubious that there was even a threat of a lawyer. The request simply asked for a prompt response as required by law. That’s quite a stones throw from “I’ll sue you and take you for everything you own if you don’t reply”.
BTW, if you are actually being threatened by a lawyer then they send certified mail or show up at your door. And in terms of the webmaster almost contacting one, no lawyer is going to take your money before talking for 5-15 min to even figure out what the issue is. And even if you paid for 30 min of a lawyer's time, then they would promptly inform you that you can ignore such requests since you’re not a business.
Again, what’s the ethical problem here?
The usual legal standard is whether a reasonable person could interpret the email as potentially threatening legal action.
> The request simply asked for a prompt response as required by law.
And such a request reads exactly like something written by a lawyer. Lawyers don't usually explicitly threaten a lawsuit in their first communication. They write something very similar to the email the researchers sent. I can easily see how a reasonable person could interpret those emails as potentially threatening a lawsuit if the request were not complied with, or if the sender did not think the response was sufficient.
I think you are expected random people operating websites to share your knowledge of the legal system. I know you're right, but most people who operate a website likely don't, and these emails make them spend unnecessary time, money figuring that out; not to mention mental distress.
I find this not dissimilar from a standard "I'm in prison, but know where a million dollars are buried, send me money" email scam; and if researchers were sending those around as tests to see who was gullible, they would be promptly end up on several blocklists. I don't see how this is different; and therein lies the ethical problem. Quite a few people seem to agree.
But if you're hosting a website, you should have that knowledge. I can't run a business and expect not to be asked about taxes, either. Honestly, as an EU citizen, if I wasn't aware of the GDPR in regards to my websites, I'd have bigger problems than some research study.
That being said, I fully agree that this mail wasn't nice and I can absolutely understand why people became nervous. But things like this are expected and the issue seems exaggerated in that light. Quite a few people seem to agree to this, too ;-)
Sure, but if you haven't lawyered up by that point you're going to have a bad time. Doubly so if you aren't familiar with the amount of info-gathering and record-keeping involved in winning a suit--if you don't know what needs to be written down for when you do have to call a lawyer, waiting until the last second can easily shoot your entire case in the foot.
And if you do lawyer up, you're spending massive amounts of money--money that some people just don't have.
Search C&D samples on google and see for yourself.
“Your failure to abide by your Agreements will result in [redacted] pursuing any and all available remedies, including but not limited to injunctive relief and monetary damages.”
So, I don’t consider this very specific (you may, and that’s fine but then our disagreement is about something different).
Contrast that to the subject email. There’s no if you don’t respond then I will sue you. It’s not a threat, it’s a request and the requestor’s reference to a statute that they think might apply.
Yes, frequently. And throwaway.
About once a week, I pick an account in my LastPass collection, and initiate the following process:
1. Initiate a CCPA data request using a form or email, and I always include language about the timeline. I am not a lawyer, I'm just a person.
2. Then, once I have the data, I delete the account. I'm trying to purge my web presence before I move out of California. I have about 200 accounts left, and have done this with 50.
Admittedly, these are all large businesses, so far. Think Google, where I've worked myself, so I know they are equipped to handle it. But, I will be working my way down to small businesses eventually, and I am surprised to find out that simply quoting the statute (which is what I do) is considered anything but vaguely legally threatening. If the website doesn't fall under CCPA, or hell, if it does, I just expect it to be ignored. I mean no ill will.
I'm personally pretty conflicted, since I actually fully agree with this [1] about the study being unethical, but if I send an email as an individual to a website with my data, quoting a California law, that doesn't seem wrong to me, even if it causes $10k in legal costs, since my request is truly genuine and not intended to cause harm.
I would agree that there is a distinction at the study level, but I'm not exactly sure why.
If a business engages this type of activity, they need to have a scalable process for providing California residents with their data.
Describing a California law passed by a majority of voters as “idiotic hoops” is a miss.
(Same person, another throwaway, my bad.)
I imagine that for some companies it is difficult, and to the extent that I feel a 'sense of justice' about it, I would hope that my efforts help the organization (or single person, acknowledging that) set up a process to handle this.
I'm *genuinely* not trying to be abusive though. It's *extremely important* that consumers have the ability to exercise their data and privacy rights.
I'm not that old (mid 30s), but genuinely much of the data I have on the internet was put there when I was an actual child. And it's still there. This is actually one of the first times I've posted in *years* online. I really want to delete *almost everything*. Note in my OP, I said I worked at Google. I quit, because although I actually think ad targeting and the surveillance network are actually okay-ish, I wanted to opt-out myself, on both ends. So far, this decision has cost me 250k USD personally (if I calculate out the opportunity cost since I quit, just so far). And for the websites/apps I do still use, I donate some amount of money per year. OK, maybe I'm a freak, I really do think this stuff is important.
What would you suggest I do? Leave all my data online? As I said, in my cases, I was an actual child (those COPPA things did nothing to stop me), and this is, so far, a really effective way at getting places to delete my data. Maybe it's because they're "scared" of the law, but you know, then the law is working. Before, nobody responded to my deletion requests, and many websites had no option to delete. As a libertarian-ish person, this is a clear win for the consumer in terms of "coercive power of the state being used to create a framework that increases net freedom".
I am open to being wrong though! Let me delete all of my data first though so I don't have to do this again.
I'm soooo behind that (one reason I am disappointed in the ethical lapses here)—I've often considered publishing the steps I take for each website on a substack or whatever, to help other people. Sometimes, it can be hard to figure out (1) if your data can be requested-to-be-deleted, and (2) how to even do it.
Clearly, the deception was bad; I guess, just thinking out loud, how could this study have been done ethically? Perhaps, sign up real people to request the data, and transparently include a notice that this was part of a study?
The last bit is the tricky one; including that might skew the results in favor of websites being compliant.
I consider myself a normal citizen and I receive "legal" and "illegal" threats regularly, the very vast majority being scam attempts of course.
Recently e.g. scammers keep telling me that my website's imprint is not up to code[0], either threatening to sue or outright claiming they are in fact a law firm and want a cease-and-desist and compensation for their law work, of course.
I also noticed how the Indian and Pakistani "security researcher" scammers[1] telling me about "major vulnerabilities" in my website - aka missing DMARC/DKIM headers (which are not even missing) - also started telling me how one can be fined under the GDPR for "bad security".
As for the "illegal" threats... I, according to scammers at least, watch a lot of "bad" porn[2] and they know about it because they hacked me, and recorded me on my own webcam. But if I paid them some BTC/monero/whatevercoin ("Follow this link to learn how you can easily buy <coin>"), they wouldn't rat me out to my family/friends or the police. I guess I will just have to pay them, but then again I have a HUGE payday coming from that nice Nigerian prince and another from that fantastic Singaporean economic attaché... once I send them some bucks to cover processing fees, of course[3].
All joking aside tho, I get how some people may be scared by things like the CCPA emails, or the kind of emails I mentioned (if those didn't work enough times, scammers would have stopped by now). When I just read that particular email in the article, I didn't see a legal threat, but that's just me of course. Other people might read it differently, and I cannot fault them for that. I remember being concerned myself the first time one of those "imprint" scam emails made it through the spam filter.
[0] In Germany, commercial websites are legally required to have an imprint, and everybody can basically sue you if you mess that up, that much is true. It's also true that courts regularly rule that if you profit even from a private website, e.g. by displaying ads, then your website is in fact commercial and requires that imprint.
https://www.bmjv.de/DE/Verbraucherportal/DigitalesTelekommun...
[1] This isn't to denigrate all Indian or Pakistani people, of course. It's just that the "security researcher" scammers I encountered thus far all operated from these two nations.
[2] Ranging from "homosexual" to "child". I wouldn't consider adult gay porn "bad" myself at all (just not interesting to me), that's their definition. It's quite interesting to me to see how they try to phish for closeted gay people more often than for pedophiles, at least anecdotally from what makes it to my spam folder. My guess is that the number of people who actually watch gay porn and are ashamed of it largely exceeds the number of people watching child abuse porn.
[3] I received those "huge money - pay fee" scam emails more than 20 years ago, and I still receive them today. Cannot argue with success, I guess?