Analysis of the California Delete Act
tomkemp.ai
tomkemp.ai
This doesnt apply to any information which is public record as a matter-of-fact.
So if you voted, your address and name is public record and can be used and displayed by these sites. If you got a DUI, your mugshot and arrest record may be public record and can be displayed. If you got into a custody battle and your court case was public, that can be displayed. And I guess that all makes sense in the end. If you got into a DUI, how does the government get to tell random website X that they are not allowed to say that you got into a DUI, especially when the information was public record.
So to be clear, if the peoplefinder style websites want to keep whitepages.com/user/john-smith online with an address, phone number and mugshot- They can tell you to pound sand and do so. This bill cant stop that.
Honestly, Theres alot of hype about this bill in general which is going to be... interesting... when people fail to understand what it can and cant be used for.
Additionally, this bill comes with a caveat that the sites can request proof you are living in california currently, via a license scan or some other method you get to now hand over to the data broker.
That said, in our research for https://redact.dev supporting these features from a pure API only interaction, is that most of the sites just delete you if you use their form. They dont want the headache of insane users threatening them and doing crazy shit because they dont delete their profile. And honestly the people who go through these removal processes are less than 1% of the stored data, so its mostly just a cost of doing business.
The problem is you’re changing the social contract. 25 years ago a DUI wasn’t a life sentence; it wasn’t something someone could find a record for something you did when you were 19 on a website 40 years later.
Now, it’s a life sentence. It will impact your ability to get gainful employment for a lifetime. I’m sure people who have a hard-on for criminal justice love this, but I think it’s unfair and detrimental to a healthy society.
I have some sympathy for anyone discriminated against for something they did long ago but the solution here is to educate HR departments to only use relevant criteria when assessing candidates. Or, in other words, reset the social contract a little.
[0] Bonus rant: this fact is why I've always been consistently vocal that the people trying to put so much liability on self-driving vehicle operators that it'll slow down deployment need to take a long hard look at themselves. We need to get humans away from the wheel ASAP and if a couple of people die on the way there those are lives better spent than what we do now.
However, we should use the justice system to deliver the right punishment instead of condemning people to an extrajudicial, de facto life sentence in all cases. The US is too liberal with making information public, while in most countries it's almost impossible to know who had a DUI in the past.
Any cop can arrest you for DUI, with or without evidence. You get a mugshot, a public record, and a booking charge of "DUI".
Whether you get immediately released with charges dropped, or have to fight it in court and are later declared innocent or have the charges dropped, that initial public record and mugshot next to the words "DUI" now lives forever in various public archives.
This doesn't require your record being kept forever, though. You're already dead or guilty.
> the solution here is to educate HR departments to only use relevant criteria when assessing candidates
This won't work. You don't decide what's relevant.
IN ADDITION to removal attempts, we SHOULD ALSO influence (regulation, societal pressure, etc) how HR/etc departments use data they find online about a person.
I run a software shop, not a trucking company or airline. Whether you had a settled DUI in your past doesn’t change your ability to write code now, which is what I’m hiring you for.
Why would I care about an old DUI?
Beats me; I don’t.
Also any prior arrest record - DUI for example - can affect your permissions to work on projects with high security clearances and thus a factor that might not be relevant to small shop would at any rate be potentially relevant to large corporations who are the ones getting government contracts that require high security clearances.
A DUI is so serious it's impossible to expunge in most states. Yes, it is a life sentence in the sense. It will always come up again.
The record of the former is still public even if the charges get dropped or the arrest was unlawful. And will appear on web searches or be surfaced by all of the background checkers that HR uses.
I would find your argument more compelling with a different example like shoplifting or vandalism: still deeply anti social, but not killing innocent people who are just going about their business.
One of the most to-the-book buddies I know is also the worst driver I know. He once had a gnarly accident where he flipped his car a few times because he had to look at his GPS briefly. I hate sitting in his car. He insists on always being the driver too because you can tell he finds driving overwhelming but thinks he’s actually good at it. Lol.
I have another buddy who does have a past DUI. He’s extremely coordinated and I have never felt unsafe in his car.
At the end of the day, if I had to choose someone to suspend their license forever, it would be my first buddy. I don’t care if he has a clean record. He simply was not gifted hand-eye coordination and is already a menace while sober.
But luckily criminal records are not public in Germany so its not a life sentence.
So basically, as long as you’re not so impaired you’re an obvious danger to others you’ll probably get away with it, which might explain why it’s such a popular alternative to getting home from the pub.
my thing is I'm all for justice but not justice that creates more of the same problem in others or the same people giving them even more reason to give up with, well, it's like branding people on the forehead. Why be surprised when the outcast keeps doing outcast stuff when they're never allowed to be anything but an outcast? it's like if society shot itself in the foot then is outraged demanding to know who shot it in the foot.
tryin to say it feels good but just feelin good don't fix nothin
No reason to continue punishing people forever, that is destructive for society. This ideology of as large punishment as possible is something I find off-putting.
A DUI conviction is something you could judge someone personally, but causes mayhem on a societal level.
Near as I can tell, approximately 1% of licensed drivers get arrested for DUI a year, and most have repeat offenses.
That doesn’t strike me as any more of a society wide ‘impossible’ issue than anything else?
One thing I have noticed though - problem drinkers are amazing at making it always someone else’s fault.
For the record, I don't drink.
One thing I have noticed though - problem drinkers are amazing at making it always someone else’s fault.
It is their fault and they also have an addiction problem. And it is also a societal wide problem.
There are many society wide problems, all with various trade offs and costs to ‘fix’. (I added quotes, because in most cases I suspect a real actual fix is impossible - merely moving things around into another category or changing how the underlying situation presents itself).
There are also many different individual choices one can make, with relative tradeoffs.
How would you rate illegal drug use/overdose deaths relative to DUIs for instance? What solutions (and related costs) do you think would be necessary to ‘solve’ the DUI problem? How about obesity? How about heart disease?
https://www.cdc.gov/nchs/products/databriefs/db457.htm
You’ll find comments in this post complaining about getting DUIs in the most walkable cities in the world, and on bicycles too.
We could ban all alcohol - would that solve it? Historically, the answer is a solid no.
If someone requests to remove data associated with an email or username, they probably will.
But if the law says you can demand to have any data associated with your real identity removed - that requires verifying your real identity.
Otherwise some troll will demand data be deleted for another person.
Would that be a bad thing, though? I don’t personally value what these sites do and can’t imagine a healthy person who does. It could be better for everyone to do away with them
In florida you can force their hand if you are a veteran or in one of a few specialized jobs. http://www.leg.state.fl.us/statutes/index.cfm?mode=View%20St...
In other states, usually you can do something if you show you are a victim of 'fraud' or abuse. Fraud might be easy to prove, if someone ever stole your password or something
For anyone who doesn't know what BlockShopper does, what does it do?
It is nigh impossible to remove data from them.
As someone not from the USA: what the actual F?!
edit labster's sibling comment points out that there are actually laws on how public voter data is. So it is not nearly as dire as the quoted sentence made it seem.
https://www.ncsl.org/elections-and-campaigns/access-to-and-u...
The list of names so is not public or anything special, it is just a list names and adresses pulled from the respective resident list maintained by your cities / towns / communities authorities anyway.
The USA goes unusually far with this, but it's a matter of degree and it doesn't surprise me.
Sounds like a gap in the market
Please stop with this FUD that is just another voter suppression tactic.
In California:
Candidates, parties, ballot measure committees, and to any person for election, scholarly, journalistic, or political purposes, or for governmental purposes, as determined by the Secretary of State. All voter information is confidential except for those listed above that may request lists.
https://www.ncsl.org/elections-and-campaigns/access-to-and-u...
It's really, really not.
Like every other countries in the world have?
> how does the government get to tell random website X that they are not allowed to say that you got into a DUI
By saying you can't publish the information and suing if people do? It's not perfect but its very easy for governments to not make it show up in google so employers won't know, like it's a right in almost every developed country.
Americans seem unable to imagine anything else than what is.
So, yes. We cant imagine it because basically the government has extremely, extremely limited ability to control the speech of corporations or people- Essentially limited to yelling 'fire' in a crowded theatre. Aside from that, People and corporations are able to say whatever they want. They can still be held liable for defamation, breaking contracts, etc.. but you cant legislate the right away for people to say things.
Wait...the final Senate vote was:
D R
Yes 31 0
No 1 8
and the final Assembly vote was: D R
Yes 52 1
No 14 14
and it is considered bipartisan because a single R voted yes?!> It received a Republican vote on the Assembly floor, making it bipartisan.
By nearly every definition I've seen of "bipartisan" that would not be be bipartisan. There's no precise definition, but generally the usage I've seen is for these kinds of situations:
1. A majority of each party support it.
2. The majority party does not have enough votes within the party to pass it, so have to get cooperation from members of the minority party. This generally requires the majority party to make concessions to get those votes, which generally requires making some concessions that help advance the minority party's agenda.
Politicians sometimes do call bills bipartisan with few (or even zero!) votes from the other party, but they get called out on that by fact checkers [1].
[1] https://www.factcheck.org/2019/12/pelosis-bipartisanship-boa...
e.g. I suspect Skittles won't have a "California recipe" to avoid Red No 3 which will effectively make it national law.
Has the rate with which they're driving consumer protection gone up as a legitimate broader strategy or is it just part of the Newsome might run activity?
I'd say that CA regulations are not quite on the EU's level though. For instance, the GDPR requires that you render all the data you have on a user in response to DSARs while the CCPA, as I understand, only requires you to say what the data is that you have but not actually show the values.
Some companies do not comply with the law, however-- the penalties are a slap on the wrist. Enforcement is only from the California Attorney General's office and the California Privacy Protection Agency (no individual action is possible unless your data was released in a breach where you can demonstrate negligence). Enforcement and penalties is the main place where the CCPA / CPRA is _much_ weaker than the GDPR.
It seems so obviously the best way to use government funds in a way only government can. What is preventing them from passing changes that make more aggressive enforcement possible?
What we really need to do is outlaw data collection and "sharing". If the service being provided does not require the company to know e.g., your location data (and has not received an explicit opt-in [for that single specific data type to be collected] that auto expires in n months), there should be massive GDPR style fines if the company is found to have collected location data. Unlikely to happen (in the US) as authoritarians in law enforcement and their supporters love to use private companies to do an end-run around 4th amendment protections that would make the data they are buying illegal, if they had collected it themselves.
I'd love to hear someone with expertise in the law opine on whether a pro-privacy DA could use existing laws like anti-stalking laws to prosecute these companies and their execs-- I'm thinking of the way RICO laws have been used so creatively over the last few decades.
A lot of companies that do comply, do so obviously begrudgingly. E.g., they will make you repeatedly fill out a long web form for each right you wish to exercise under the CCPA, instead of allowing you to just enter e.g., your identifying information once, and just check off each right you wish to exercise. It is malicious compliance.
Serius XM's CCPA web form, in addition to malicious design, was broken-- it simply did not work, and the number they listed to call _for CCPA requests_ turned out to be a general support number where none of the Indian call center folks even knew what a CCPA request was*.
*SeriusXM account was created by the dealer when purchasing a new car against my explicit request for them to not register me for any of the introductory "free" accounts listed as perks for the vehicle. SeriusXM (among other things) collects and sells your GPS location data-- a streaming service has no legitimate reason to collect your GPS location. I suspect they also pay dealerships a commission for signups, as the dealer had to go to extra effort to ignore my request.
2. Newsom's stealth-campaign for President in 2024 needs him to stay in the national news cycle without directly competing with team Biden's messaging.
So I tend to believe that Newsom is picking and choosing bills to sign/veto with a focus on running for President in 2024.
Cali has some decent laws when it comes to consumer protection. I’d love to see more of them on federal level.
> We are in receipt of your request dated September 12, 2023. You are submitting a request from a jurisdiction that does not currently provide data rights.
You've agreed to their terms that don't violate the law, why would they forfeit their hard earned cash, even if it's the right thing to do?
I don't think there's much agreement going on with data brokers beyond very broad "we reserve the right to share your data with third parties to improve services" or some such. In most cases people are not interfacing directly with a data broker.
> why would they forfeit their hard earned cash, even if it's the right thing to do?
Usually to stave off regulation.
This is why we should pay for services. If someone wants something deleted from my app... I'll delete it. No problem. They pay me a subscription, I don't even want their data. It's a liability if anything.
You know what business scoundrels like more than profiting off your data and attention? Getting direct revenue from you, especially recurring one via subscription, and profiting off your data and attention on top of that. More than that, your choice to pay for a good or service demonstrates you have disposable income and are willing to spend it - i.e. a high-value target for advertisers.
> They pay me a subscription, I don't even want their data. It's a liability if anything.
This is (a big part of) the solution - but personal data isn't enough of a liability yet to deter the scoundrels.
So likely their isn't like if (state = ___) { delete } { else fuck you } but more like "if state = X, do state X logic, if state = Y, do state Y logic, else nothing"
its a total absence of requirements
think of it like requesting water at a bar or club. in the states without regulation, all the businesses say "you can only buy this $8 bottled water", the same hospitality organization has companies in another state that are like "oh yeah the tap water's right over there"
sure, they both have.... fire code requirements or whatever analogy you find more applicable, but they also will say { else fuck you } to all other aspects without any thought aside from what's most convenient
Considering the government has in no way regulated phone solicitors or spam, how could anyone assume this law would have any effect? I mean, lawbreakers ignore laws, and spammers hoard personal data.
edit: the Los Angeles Times article's first sentence is less hyperbolic, more sober...
> Californians will be able to make a single request asking that data brokers delete their personal information, under a bill Gov. Gavin Newsom signed into law Tuesday.
Editorialized headline ("Californians now able") is false, not available for another two years.
California passes bill to make it easier to delete data from data brokers - https://news.ycombinator.com/item?id=37524158 - Sept 2023 (145 comments)
Also:
'Delete Act' seeks to give Californians more power to block data tracking - https://news.ycombinator.com/item?id=35691243 - April 2023 (131 comments)
Has anybody tried to actually buy data from a data broker? I haven't found it to be nearly as easy as this makes it seem. Looking for tips / suggestions on brokers who might sell me my own information for decently cheap :) for academic purposes of course...
I do like this law tho.
They told me where they got the lost and I bought it for my zip code for $50. So I found out which neighbors were pregnant, had diabetes, were buying a car, etc.
The medical information was sourced from “anonymized” insurance subrogation data and prescription data. They were able to correctly identify that my wife was pregnant and project the due date, but didn’t have the diagnosis or the reason for the hospital/OB admission.
This is also why pharmacies pester you for your phone number, and to participate in their loyalty programs (don't).
My understanding is that "anonymized" data leaks from subrogration and the PBM as well that can be un-anonymized later.
So, not only easy, but also cheap.
I don't know what to think about California seeming to set an upper limit on privacy policy for the country.
California's revenues seem partly tied to some of the worst invaders of privacy, and presumably Californian legislation gets industry input.
At one point, I naively wondered whether a wealthy and independent-minded state like Texas might lead this (a bit like they have with textbooks). I guess they're pretty tied now, too, and also have a lot of anti-regulation voters.
It's true that California's legislation gets a lot of industry input, and they're not going to pass something puts the big tech companies out of business. On the other hand, there's a very effective coalition of privacy organizers there -- who are quite familiar with tech's tactics, and can be very effective at cutting through tech's spin with legislators. Plus, the California Privacy Protection Agency (which got established by a referendum, not through the legislature) has a lot of clout -- there isn't anything comparable in any other US state.
Washington state has similar dynamics, although with the CPPA equivalent. Microsoft and Amazon are hugely influential here; but, grassroots organizers had repeatedly stopped them from getting the very weak Bad Washington Privacy Act through the legislature. And this year, we passed My Health My Data -- stronger in some ways than California's privacy law.
Texas ... has been a disappointment. The privacy law they passed this year is based on the Bad Washington Privacy Act but significantly weaker.
(Technically not the first privacy law with private right of action because the Video Privacy Protection Act has one, but that law was originally passed to cover videotape rentals and the courts are still working out how it applies to video content on the Internet)
Of course MHMD doesn't take effect until after the next legislative session, so I'm sure there will be attempts to weaken it. So I'm not counting any chickens quite yet!
I remember emailing a site that apparently scraped LinkedIn, asking them to remove my information. They told me to fill out a form attesting I lived in California. When I told them I did not live in California, they told me to just sign it anyways and they'd proceed - and they did. So how many other companies are really checking each individual for truthiness? Doing so would seem impossible at such a scale.
Some of the data deletion requests would ask "Are you a California resident (yes/no)" while some would ask for a California address, and some wouldn't ask at all.
One of the companies had a support person respond back to my request when I had answered no to being a California resident strongly implying I should resubmit my request with it marked yes which I ended up doing and it resolved smoothly.
I imagine companies that mainly make their money from the data would be a lot more strict on it though.
But the devil as always is in the details and more often than not these 'sounds good' initiatives on this front have perverse effects, either intentional or unintended though judging from the past the former is far more likely than the latter.
A central registry for all personal profile data brokers makes it so very convenient for agencies that already can demand access to all the data on a peer basis, to now basically have a central shopping catalog in which you have to register by law.
Also, their seem to be very many exemptions to the right to have your data purged. Things that people imagine might happen after they submit such a request in many cases wont.
Admittedly I do not have the competence to the level of detail required to flesh out the exact consequences of each word in a bill , its interpretation or its implementation.
If more competent experts can. Here's the current text as a start https://leginfo.legislature.ca.gov/faces/billTextClient.xhtm...
Is it silly to suggest that laws like these could make cascade on delete a whole lot more commonplace?
If their user now brings up "deleted user 12345", you've done your job and deleted the data they cared about.
Instead of asking "how can rows in my posts table reference a deleted row in the users table?" ask "how can I show posts by deleted users?"
And that's a business requirement. Either you delete the post, or you delete the post's author link, or you delete the post's author link and content. Find out which one, and design and implement it.
"You've said you have access to your email address, password and recovery email but you lost your phone number in a fire.
Based on that, we currently don't have any other account recovery suggestions for you. We encourage you to try to recover your account at g.co/recover. There's no limit to the number of times you can attempt to recover your account. To increase your chances of successful recovery, you can:
Try different variations of your answers. Try recovery from a device you previously used to sign in.
If you still can’t recover your account, we recommend you set up a new account."
"Thanks for contacting us! A Google expert will respond to you soon. For your reference, your case ID is 2-9118000034846."
There was already a ton of discussion about this a month ago. Anything new here? Other than it passing across the Governor's desk?
> the Delete Act would empower the CPPA to develop a system by 2026 that allows residents to make a single data deletion request across the nearly 500 registered data brokers operating in the state. The CPPA would also be charged with enforcing provisions of the Delete Act, such as requiring data broker registration and ensuring brokers delete an individual's personal information every 45 days upon receipt of a verified request.
Source: https://iapp.org/news/a/california-legislature-passes-delete...
It would be very helpful, especially because they will keep collecting it. When we have it I'll automate something to trigger it every week or so.
One requirement that is less known is also that, if a company has PII about you and you never explicitly gave this data to them, you then have the right to be informed. What it means is that you can ask what data they hold on you and what is the source of the data.
So if you get a cold call from a random sales person, you can ask them where they got your number, they have the obligation to tell you the data broker they bought it from. You can then request the deletion of your data from the data broker. I did it a few times.
California has that.
But asking the people who they got the data from doesn't work. They just hang up as soon as you talk about it. Especially because I'm on the "do not call me" register and they are already in breach of the law by calling me in the first place.
Brokers aren't allowed to store your data in the first place without your consent in EU. This button is an opt out, EU is opt in.
I do agree with you that a centralised way to get your data to be deleted is great. It does feel like a band-aid to me though, I would just prefer that reselling PII would be made illegal. I don't see the point of allowing that.
California has that.
Credit agencies like Equifax and TransUnion satisfy that condition. They should be subject to the law, especially given Equifax's security history [0]