California passes bill to make it easier to delete data from data brokers
latimes.com
latimes.com
My position on this type of data is that I am simply a temporary custodian over it. The identifiable person owns this information. I recognize it as pure liability for us. All downside in our business models.
We go out of our way to keep this stuff out of our systems. We spent the better part of a month talking about various architectures that would "keep the mess over there" (aka inside the bank's 'secure' environment).
The closest we get to liability is storing salted & hashed PII so that we can correlate business keys within sessions. If we find a piece of PII actually makes it through our layers of redaction, it is treated similar to production going down. Our entire team is trained to respond to a PII incident as if it were a radiation leak at a nuclear power plant.
Better for compliance and better for customer security. And get to avoid whole sections of scrutiny and review when infosec comes knocking.
Absolutely, been trying to preach this for ~10 years now at various companies.
Another argument to make is that I can guarantee 100% certainty against leaks with a budget of $0, for all the data columns that I never had. Such a deal!
Any other choice is going to cost a lot more and have reduced chance of success.
Sure, we need to handle some sensitive data to run the business but choose selectively, since every one just adds both cost and risk.
Of course, it's all still a manual process. Requiring that the deletion of PII be a "single button click" would be great. And making all data collection opt-in, instead of forcing me to fill out Do Not Sell My Data forms on every single website. But the Act mentioned in this article will be the third "Change Logs" we've gotten to the CCPA since its passing seven years ago. So, again, color me less jaded; it seems California is slowly and steadily clawing back our rights. Good on us!
So expensive for so little real gain. We're spending more on making companies who don't use your data for anything nefarious (basically all companies outside of the advertising industry, if you even consider advertising nefarious) than we're spending on fixing climate change. Or preventing war. What a joke.
Edit: looks like this law applies specifically to self defined 'data brokers' (no one can find these entities IME and no one admits they are one) so at least it's somewhat targeted. Comment stands for CCPA and CPRA, which apply to all "businesses."
In general I think some privacy concerns are valid and others are not. Specifically I believe government surveillance is problematic and I wish there were more visibility and restrictions on it.
I do believe many companies are collecting data for reasons other than advertising. For example CRM tools (eg Salesforce) have heaps of personal information their customers store with them for a bunch of different reasons. It's really complex for them to comply with these laws - even though they aren't doing any advertising.
What costs money is companies trying to figure out how to work around legal requirements, obfuscate this option from users, or forcing them to go through support-intensive processes to delete their data rather than just building this like any other core automated business function.
Having PII littered about in ways that aren’t easily deletable is quite a canary. Companies with these issues are the same companies that end up with data breaches due to their cavalier treatment of user data. Perhaps these companies should be grateful they have a regulatory body ensuring they don’t fall too far behind the basic data stewardship practices the rest of the industry has in place.
I can’t believe people consider the argument that because companies have poorly managed systems and PII centered databases with no abstraction (and therefore are working right on actual customer record data in their data lakes), that this is somehow a viable argument for why we shouldn’t make deleting data possible.
Companies like this are the next Equifax. Why would you condone their stupidity?
My pov: maybe, but the cost isn't worth the benefit of doing it this way.
But I’m inarticulate and do understand your reasoned point.
"We can't figure out how to delete PII" and "Our schema is flexible" are the same canary in my view.
Everything goes back to founders & business owner giving enough of a shit to force a good architecture from the beginning.
You can't build an effective schema to store complex information if your mission isn't clear yet. If concerns over PII storage are "we'll worry about that later", then whatever schema is invented from that point will mirror that vision.
If the vision is "PII == high-level radioactive waste", then the resulting schema may not even offer places to store it, outside of specially-controlled tables.
It only applies to businesses that make over $25 mil, or that are in the business of selling user data.
(https://en.wikipedia.org/wiki/California_Consumer_Privacy_Ac...)
A remarkably high percentage of our legal framework is designed to protect a very small number of people from being exploited by another small number of people. Yes, the costs of implementing these laws are high, but the societal benefits are, in aggregate, huge.
My personal information is my own, just like my house, my car, my investments, my copyrights, and bank accounts. And I expect there to be laws that protect it, allow me to control it, and restrict how others can use it just as there are for my other assets.
If applying these laws is inconvenient, then that speaks volumes as to how overdue these laws were.
I like laws that say we can opt out of and must consent to email marketing. It leaves companies freedom to implement however they want.
CCPA requires complete deletion, which isn't easy to achieve these days, of data that no one is using in an out of the way data store that otherwise wouldn't need to be touched.
It's just a lot of effort for no benefit. I think you should be allowed to tell a company not to use your information. You shouldn't be able to tell them how not to use it.
Forcing companies to track and manage the data in their stewardship is necessary because clearly the economic incentive is not high enough - by your own admission. It's easier (and cheaper) to just leave around. But - when, not if - it's hacked, /I/ bear the cost of their negligence, not them.
This is exactly why consumer protection laws are needed.
I'd actually love a law that says if my data gets stolen from a company and a hacker uses that stolen data to harm me, the company must pay for (some portion of) those harms.
But today it's setup so even if I don't get harmed they pay some lawyers to make the case go away.
The DMV, PG&E, and voter registration have all leaked my PII to third parties. F all of them.
I don't intend to register to vote again unless they can prove themselves worthy of keeping my personal information confidential.
I never use USPS forwarding. If you ever register for USPS forwarding, they will GLADLY tell stalkers your new address if they ask. This should have been made constitutionally illegal 100+ years ago if I were in charge of this country.
Governments need to protect PII before waving these laws around at companies. I don't enjoy companies leaking my info either, but as of now governments have done it way more.
On another note, US and California law need to stop requiring residential addresses for everything. Banks, voter registration, DMV, etc. don't need to know where I sleep to a 20-meter radius, they only need to know what state and MAYBE county I file my taxes in.
It can be reasonable for a particular website I visit to save some data (not fingerprinting though) on who visits it. It can be reasonable for Google Analytics or Facebook or a similar system to process the data so they can target ads which make so many good small businesses possible nowadays. Sharing the data with other parties makes no sense I would ever want.
I would love to tell these big tech companies I want all traces of myself removed from their search engines. I understand it gets a bit nuanced with first amendment n such (what about a news article of me committing "x crime"), but give citizens SOME protection. At least Europe tries and pushes back.
I also use this which seems to work, but it's hard to know how effective it is really: https://joindeleteme.com/
Take a look at https://www.kanary.com too - yc grant awardee in 2018.
I want to own my data and allow companies to collect and lease it in exchange for money, goods, or services. I want to be able to sue anyone who uses this data without explicit permission with option for punitive damages.
I want mechanisms to control my data and I don't see that happening without signed contracts.
I want to control what data is collected and how it can be used. I want this in writing in clear language in terms that cannot be changed until the contract termination date, some other specified period (with option to terminate), or with my signed consent. I also want the option to object to the sale of data to particular buyers. And I want the option to have the data deleted when my contract is terminated or when the company is sold.
I think the current hodge-podge of laws surrounding this don't come close to this kind of control and to the degree that they do, they're mostly a lot of work for the consumer; more opt-out than opt-in. Companies rely on people mostly not really knowing what they're doing with data and changing their privacy policies on a whim because how many people really read all these changes or leave? I'm not sure I've really seen any mass migration on privacy policies (although I have seen that on 'we own all your stuff forever' type TOS changes).
That would require sharing private data about employees with Equifax so that they're able to handle paying them.
Or if I want to ship a package to somebody; can I not give a 3rd party (DHL) the recipients address?
I like your idea but I think it needs some refinement. Perhaps just a time restriction; although I'm sure DHL would love to keep a photo proving that the package was delivered for a year.
https://hallboothsmith.com/california-dmv-sells-personal-inf...
Facebook knowing my name isn't that bad, facebook knowing that some individual bought "Hunky Firefighters Pt 7" isn't that bad. Facebook knowing that I'm the individual that bought "Hunky Firefighters Pt 7" is exactly what I would want to prevent.
That would be a net negative for privacy, because it would mean more parties having access to your data (without your consent or even knowledge). And given the state of security in ad-tech aside from Google, that means the chances of your data getting breached and leaked would increase exponentially.
Gmail with ads seems way preferable to Gmail who sells your data to others.
In particular, it is banning horizontally integrated surveillance capitalism (which requires the sale of data between the data gathering companies and the people using it), but not vertically integrated surveillance capitalism.
In all likelihood, some companies in this ecosystem will be forced to sell at fire sales to conglomerates (like Google) simply to avoid having to comply with this law. Of course, this benefits organizations that are large enough to acquire the companies, and no one else.
So, people with financial conflicts of interest are picking winners and losers, which is pretty much standard practice in US politics these days.
I personally think this whole consumer tracking industry should be shut down. It should be illegal to gather the types of information that this bill regulates.
Maybe you hate both, but there is a meaningful difference.
For ad placement, they only get it after you click on the ad, and it's only linked to you personally by your IP address and browser fingerprinting, or more directly if you log in or buy something.
Who knows what they'd sell if their business declined for a while and there was a hostile takeover or they otherwise got desperate for new revenue streams.
And then if you were paying attention you could make a new one of these requests... but maybe you'd miss it for a bit, and then it would be too late.
The law should be based on what you collect instead of what you sell to better protect against this sort of thing.
Companies selling your data are your bank(credit card purchases), mobile carriers(location), your DMV(photos, driving record, misc PII including address, dob etc), state/county government(public records like marriage licenses). Its weird everyone bashes on google and FB for something they don't even do.
... except when they sell their domain registration business.
And yes, I realize that there's a (technical) difference between selling data and selling a business including its data assets.
But then again, maybe a really big chunk of the value of that business is its customer data.
For some business acquisitions special terminology like "aqui-hiring"[0] has evolved so it's understood that not every sale of a business is of the same nature.
And since the value of data has arguably become much higher than ever before, the distinction of selling data by itself and selling the entire business is becoming smaller as time goes on.
I want the means to tell companies "Do not collect information on me." And I want that to be enforceable by law.
The same applies to any non-small business that you have a direct relationship with and provide your information to; CCPA requires that business to delete the info if you request it.
Data brokers are a special case because they don't get their information directly from you, instead they slurp up whatever public and private data they can scrape or buy, and then resell that to other companies. Given you don't have a direct relationship with the data brokers, it's hard to even figure out who has your information.
Note, CCPA seems to have excluded the credit bureaus from designation as data brokers, even though those guys are responsible for leaking SSN and full personal information on the majority of US citizens.
The US system of credit surveillance is pretty unusual (EU countries don't do anywhere near that much stalking and they have functioning debt markets) so I'd love to learn what would actually break if people were allowed to opt out of that tracking. Presumably there are some government records you can't opt out of like UCC filings and bankruptcy, and any potential creditor could just look up the primary sources themselves.
Anyone who thought that California's "Do Not Sell My Data" requirements would cause websites to tamp down on the data collection nationwide were sorely disappointed when sites simply implemented an IP Address check to only display the option if they were in California. Other states followed suit, and sites amended their logic to show the banner in California, Virginia, etc.
They are going to cling to data vacuuming for as wide and as long as they can.
Yet another use case for VPNs...
I have no doubt California businesses will immediately ship data outside California and play dumb.
Furthermore, if someone trains an AI on your data, does the AI have to be "untrained?" If not, I doubt this will have too much effect for some applications.
https://leginfo.legislature.ca.gov/faces/codes_displaySectio....
Can’t really comment on how effective or ineffective it is for the consumer though.
Here is one in particular that includes some people sharing reviews, plus Optery's CEO going into detail on the different data removal companies: https://news.ycombinator.com/item?id=30605010
If you're interested in these services, a good approach is to sign up for each company’s free scan and compare the results.
Full disclosure: I am on the team at Optery
1. They seem to largely rely on automated or semi-automated workflows, and that sometimes breaks down. For me, they removed ~95% of the stuff, but I could still find some breadcrumbs in web searches, and need to file a couple more opt-outs manually. It might be less of a problem if your online footprint is small.
2. They target "frontend" sites, rather than the actual data brokers. This cleans up search results, but doesn't necessarily remove from the commercial databases that are available to commercial and institutional users. Because the frontends come and go, it also means that if you cancel your subscription, you will probably go back to square one in 2-5 years.
Take a look at https://www.kanary.com too - yc grant awardee in 2018.
It's worked well for me. Outside of info on my own site, there's only one broker that's exposing an old address. That one was newly found or resurfaced within the past month, so it should be gone soon. I moved in December and my new address is not at all findable in correlation with my name, which is awesome.
That said, I think the sibling comment by hunson_abadeer about "95%" sets the right expectation for most. It's a constant whack-a-mole: we're always improving our strategies while data brokers multiply and find new datasets, which they use to resurface previously-removed profiles. Happy to answer any questions.
In 100 years they'll be investigating the real history of 2023, and most records were deleted, only aggregates survived by CNN and FoxNews, and other billion dollar institucions preserving their point of view
Today you can go 100 back and that John Panini traveled by boat from UK to US on what day and paid 1 cent
There's plenty of unerase-able public data on all of us, especially data that's going to be interesting in 100+ years from now. For example, things like owning property are recorded in the county registrar and will be there as long as the county registrar is.
Everything else, like travel logs and diaries will continue to exist for everyone who wants them to exist. Just as people did 100 years ago, who intentionally kept diaries, these things will remain indefinitely.
Regardless, there's so much content being pooped out right now that a single year will keep future anthropologists busy for centuries.
There may be some overcorrection going on, but there's no way this is a bad thing. We had no idea what Einstein had for breakfast on May 5, 1903, and we're doing just fine.
The Privacy, Security, & OSINT Show did a podcast on it.[0]
0. https://inteltechniques.com/blog/2022/04/15/the-privacy-secu...
When I refinanced, I explained the situation to the other bank's loan agent. They emailed their underwriting division, and the underwriters simply issued an override.
Not sure if that works these days or not, but my point is that credit scores are complete bullshit. Hopefully most people will push the button, inadvertently opting out of credit reporting, and that corner of the industry will simply stop existing.
Lenders already do more due diligence than the credit agencies do.
If you default on a loan, there could be a central record (say, at the court house) of this, and lenders could consult that. That would fill in the remaining missing functionality of the score (and do so in a way that is transparently free of institutional racism, etc).
Without precision in the risk model, cost to the consumer will go up to mitigate risk. Someone who has paid all their credit lines for 10 years but and has never defaulted has the same risk profile as a person who has frequently missed payments.
You can also juice it up or down by over a hundred points by accumulating and then rapidly paying down balances.
So what here determines if the score goes up instead of down? I’m planning on getting a mortgage soon but wife’s credit score is in high 600s. If we can make it past, 720, we are told we’ll get a better rate. So I’m curious as to how to bump up the score.
Then there's things like age of oldest account, average age of accounts, etc. You may be able to add her to your accounts to improve this factor, if your accounts are older than hers.
Then balances. You get dinged for having a balance on too many accounts. I think you also get dinged for having zero balance everywhere. I think 'ideal' is 3ish cards with balances (you can (and should) pay the whole balance every statement, reporting is usually done just after the statements). Highest ever balance should be less than credit available or you get dinged; ask for credit increases on cards where you ever went over the limit. Total balance shouldn't be more than some % of total credit, I think 35%? You also get dinged for high % current balance on any one card. Again, you can add her on high limit, low usage cards to help her score. She'll get more score points as a joint account holder than an authorizer card holder.
You get dinged for recent (6 month?) credit inquiries, but inquiries are grouped, so if you apply for new credit, try to get it all done in a few days; mortgage inquiries have longer to be grouped.
If you know when your creditors do reporting, you can adjust your payment dates to tweak things. You might make a payment to your credit card before the statement closes even in order to show a lower utilization % and that could move your score a lot depending on details.
Find a way to pay down revolving balances to zero.
If you have cash sitting around, great. Otherwise borrow from a 401(k), friends or family, send non-reporting payments in late et cetera. Running balances rapidly to zero tends to cause a 50 to 100 point bump. After you’ve got approval, rebuild the balance and use that credit to repay the loan. In summary: transfer the debt from reporting to non-reporting sources.
If you’re thinking longer term, find bullshit collateralised reporting loans and take them out. Securities-based loans, HELOCs. Low rate. Manufactured borrowing. But it’s a credit line paid back on time. The algorithm likes those.
For example, any ML models trained on user data must be retrained when specific users' data is deleted.
So does the EFF: https://www.eff.org/deeplinks/2023/08/californias-delete-act...
And the LA Times: https://www.latimes.com/politics/story/2023-09-14/california...
To what extent do companies extend these rights to all Americans because it's easier than building a California-specific version of a website or online product?
Right to Unsubscribe? Gmail and other email providers do this for you even if you are not a CA resident and even if the Marketer does not have a built-in Unsubscribe link. From a Marketer perspective, you cost money to send emails to, and if you are not going to open, they kind of don't want you on the list anyway.
CCPA == GDPR? Not even close. Majority of CA businesses do not reach the compliance threshold and therefore do not have to or will not comply with requests. Additionally, you have no way to validate if the request was actually carried out. The company's "best efforts" to remove data from their systems is all that's required at best - and a lot of data can be retained for valid business reasons.
Lastly - despite what CA residents believe (and similar to EU residents with GDPR) - CA laws do not apply to the rest of the country simply because they are unenforceable except in the most egregious cases - and even then it would have to be a very large business anyway.
> because it's easier than building a California-specific version of a website or online product
Nobody is doing this in practice. At best, they use some GeoIP thing or if you are logged into an account (which means they have your data anyway). The law does not require them to validate the user anyway, so it's all "best effort" again which usually means low effort.
But hey, if it makes you feel warm and fuzzy believing these things - more power to you.
I am very skeptical even this is as great as some think. Outside CA, most companies can simply ignore these "viral" style laws with no consequences.
It's not about claiming ignorance. It's about not caring about CA viral laws and CA's inability to effectively enforce them around the world.
Much like how most companies laugh when some EU citizens tries to flex GDPR in the US... hilarious unless you're Google...
People lock-in on the intent and names of these things and believe they've "won" the privacy war. Just like the "Inflation Reduction Act" these laws do very little if anything for their namesake.
Sometimes the government really does work for the people. It is actually possible.
You can read the laws yourself. There's not a lot of teeth for small businesses to comply.
Go look at the state AG website for P65 complaints (they are all by law published). 99% are privately settled without wrongdoing (you can see this on AG website too), and some fee is paid to the plaintiff's attorneys. Sometimes the math says it's cheaper to comply, but often not. Small (and even big) businesses around the country freely ignore P65 despite the law having citizen enforcement. If you search on the AG website you will find many repeat offenders. P65 laws have been around for decades...
There's a difference between what people believe should happen and what actually happens. If you believe these laws have "won" the privacy war - you are mistaken.
Given the decades of P65 enforcement - and given the prevalence of "harmful" chemicals imported into this state every day, we have no reason to believe this unsubscribe law will be any different.
Having this law makes people feel like something was accomplished, despite reality.
I expect nothing less for this law. Show me an example for a relevant law not the P65 BS.
I also gladly unsubscribe easily without frustration - just not sure if this is common in other states.
Netflix? Nope. Comcast? Nope. Google? Nope. Verizon? Nope. AT&T? Nope. Apple? Nope. PG&E? Nope...
Where is this mythical renaissance of new online cancellations?
Turns out - most big businesses did this already... oh, but now it's the law but who's enforcing? Lawyers who gain private settlements? That's not enforcement, that's a racket.
Edit: and by “terminate service” I mean “stop fucking taking my money, I don’t even live at the address you are claiming”
Because if there's one thing I've almost never seen, it's data being deleted from a db.
> The bill would, beginning January 1, 2028, and every 3 years thereafter, require a data broker to undergo an audit by an independent third party to determine compliance with these provisions and would require the data broker to submit an audit report to the agency upon the agency’s written request, as specified.
https://leginfo.legislature.ca.gov/faces/billTextClient.xhtm...
> "This bill would require the agency to establish, by January 1, 2026, an accessible deletion mechanism that, among other things, allows a consumer, through a single verifiable consumer request, to request that every data broker that maintains any personal information delete any personal information related to that consumer held by the data broker or associated service provider or contractor. The bill would specify requirements for this accessible deletion mechanism, and would, beginning August 1, 2026, require a data broker to access the mechanism at least once every 45 days and, among other things, process all deletion requests, except as specified. Beginning July August 1, 2026, after a consumer has submitted a deletion request and a data broker has deleted the consumer’s data pursuant to the bill’s provisions, the bill would require the data broker to delete all personal information of the consumer at least once every 45 days, as specified, and would prohibit the data broker from selling or sharing new personal information of the consumer, as specified....
> "This bill would provide that a data broker that fails to comply with the requirements pertaining to the accessible deletion mechanism described above is liable for civil penalties, administrative fines, fees, and costs, as specified, and would raise the amount of the existing civil penalty provisions described above...."
I guess it all comes down to the implementation level how specific and "actually deleting" they will be. And whether the new agency (ugh) charged with enforcing this will actually have teeth in the details.
And I don't know why such a long 45 day period is required. For reasons we're all too familiar with, people are quite able to gather data within seconds, but somehow need 45 days to delete it?
I guess it has to have some method of what you mention then. If someone wants their data deleted, yes, what about the backups?
No way.
Seems like a deeply positive step towards allowing people sovereignty over their own identities, albiet their identities in digital forms, which is deeply humanistic and a core of a less evil civil cyberpunk future.
The internet is a mess with the "It's free, but actually the costs are deeply hidden" architecture we have.
It probably keeps him pure that he represents a district that mainly feels the impact of the credit industry, and doesn't proportionately have that many tech jobs (as CA).
Flew under my radar
> This bill would provide that a data broker that fails to comply with the requirements pertaining to the accessible deletion mechanism described above is liable for civil penalties, administrative fines, fees, and costs, as specified, and would raise the amount of the existing civil penalty provisions described above. The bill would require that moneys collected or received by the agency and the Department of Justice under these provisions be deposited in the Data Brokers’ Registry Fund, which the bill would require to be administered by the agency, instead of the Consumer Privacy Fund and would expand the specified uses of moneys in the Data Brokers’ Registry Fund to include the costs incurred by the state courts and the agency in connection with enforcing these provisions and the costs of establishing, maintaining, and providing access to the accessible deletion mechanism described above.
https://leginfo.legislature.ca.gov/faces/billTextClient.xhtm...