Statement on California State Senate Advancing Dangerous Surveillance Bill
eff.org
eff.org
Of course, the EFF doesn't actually tell you what the bill SAYS here, it instead breathlessly, dramatically, announces "SB 690 gives the green-light to dystopian big tech surveillance practices which will endanger the privacy and safety of all Californians".
The fact that EFF has to obfuscate the content of the bill this much says a lot.
Maybe "legitimate business purpose" is doing the heavy lifting here. Let's find out! Let's take another look at the bill:
> The bill would define a commercial business purpose to mean the processing of personal information either performed to further a business purpose or subject to a consumer’s opt-out rights
Let's keep reading, this is fun!
> (e) “Commercial business purpose” means the processing of personal information that satisfies either of the following criteria:
> (1) Is performed to further a business purpose as defined in subdivision (e) of Section 1798.140 of the Civil Code.
Okay, let's look up subdivision (e) of Section 1798.140 of the Civil Code of California... (this is kind of like pointers in C... very cool)
> (e) “Business purpose” means the use of personal information for the business’ operational purposes, or other notified purposes, or for the service provider or contractor’s operational purposes, as defined by regulations adopted pursuant to paragraph (10) of subdivision (a) of Section 1798.185, provided that the use of personal information shall be reasonably necessary and proportionate to achieve the purpose for which the personal information was collected or processed or for another purpose that is compatible with the context in which the personal information was collected. Business purposes are:
> (1) Auditing related to counting ad impressions to unique visitors, verifying positioning and quality of ad impressions, and auditing compliance with this specification and other standards.
> (2) Helping to ensure security and integrity to the extent the use of the consumer’s personal information is reasonably necessary and proportionate for these purposes.
> (3) Debugging to identify and repair errors that impair existing intended functionality.
> (4) Short-term, transient use, including, but not limited to, nonpersonalized advertising shown as part of a consumer’s current interaction with the business, provided that the consumer’s personal information is not disclosed to another third party and is not used to build a profile about the consumer or otherwise alter the consumer’s experience outside the current interaction with the business.
> (5) Performing services on behalf of the business, including maintaining or servicing accounts, providing customer service, processing or fulfilling orders and transactions, verifying customer information, processing payments, providing financing, providing analytic services, providing storage, or providing similar services on behalf of the business.
> (6) Providing advertising and marketing services, except for cross-context behavioral advertising, to the consumer provided that, for the purpose of advertising and marketing, a service provider or contractor shall not combine the personal information of opted-out consumers that the service provider or contractor receives from, or on behalf of, the business with personal information that the service provider or contractor receives from, or on behalf of, another person or persons or collects from its own interaction with consumers.
> (7) Undertaking internal research for technological development and demonstration.
> (8) Undertaking activities to verify or maintain the quality or safety of a service or device that is owned, manufactured, manufactured for, or controlled by the business, and to improve, upgrade, or enhance the service or device that is owned, manufactured, manufactured for, or controlled by the business.
Far from a freewheeling "they can wiretap anything!!!1111" screech I keep seeing here, it seems to me that the definitions are all nicely pinned-down and there isn't a lot of leeway.
Oh and an important note: I'm not a lawyer. It's possible that I've completely bungled this analysis, so don't take it as legal advice. This is just my opinion.
I see item 8 as giving permission. The AI Agent is the service controlled by business. The collected data would be provided as training to improve, upgrade or enhance the service.
Item six allows advertising, mainly limiting aggregating personal information taken from other entities that aren't the business. I can see Amazon designing an advertising platform compliant with item 6 and using existing Alexa devices to eavesdrop on all communications.
Reading the argument for section SB690 [https://calmatters.digitaldemocracy.org/bills/ca_202520260sb...] list the main argument as CCPA governs online business. The opposition points out that the CCPA specifically specifies that conflicting laws providing greater protections should apply.
The rest of the arguments cite CIPA as enabling frivolous lawsuits. There are already remedies for frivolous lawsuits. Attorneys can be disbarred and vexatious litigant laws would apply.
In multiple places you state there are 'probably' other laws that apply. That law is 'probably' the federal wiretap law. I'm not sure if you are aware, but California is an all party consent state. The federal wiretap law is single party consent. SB690 would effectively turn California into a single party consent state for anyone with an appropriate business purpose.
The majority of the business purposes listed as acceptable are not what I would call nicely pinned down. I would only be ok with item 2.
I can almost guarantee allowing business to collect this data will lead to use that doesn't fall under the legitimate business purposes. Uncollected data can't be mishandled.
Lastly to me the greatest reason to oppose is that the laws pretty much all cover intentional unauthorized access. CIPA as it is exempts pretty much the only businesses I would want granted the access to intentionally access unauthorized communications. Everyone else can ask me for permission, if I refuse they don't have to do business with me.
Yes, they are, but I think your real point is that:
> I would only be ok with item 2
Yep, this is what it all comes down to. But it seems like everyone else is arguing without even knowing that the scope of this is. It's of course your right to your own opinion about if these business purposes are acceptable. I was even aware that training LLMs and showing ads are legitimate business purposes. You act like that's a revelation, but it's important to realize that is purely your reaction, not the reaction of the average person. Is the average person okay with their emails being used to train LLMs, or show them ads? I mean, what percentage of the population uses Gmail for mail? I think the question is nicely answered there.
> I can almost guarantee allowing business to collect this data will lead to use that doesn't fall under the legitimate business purposes. Uncollected data can't be mishandled
Sure, but we can't just lock ourselves in iron boxes and survive on privacy alone. People have to engage with the world. Maybe credit card numbers should be 100,000 digits long, so someone can't look over my shoulder and steal mine?
>Lastly to me the greatest reason to oppose is that the laws pretty much all cover intentional unauthorized access. CIPA as it is exempts pretty much the only businesses I would want granted the access to intentionally access unauthorized communications. Everyone else can ask me for permission, if I refuse they don't have to do business with me.
That's what I have been saying pretty much the whole time. I'm not sure, but do you know that the section they are modifying is Chapter 1.5 Invasion of Privacy. It literally talks about placing a wiretap on a communication device. This change removes criminal charges for businesses when they have a business purpose which includes a lot of things I don't want businesses to be able to do to me.
Your argument is that the might be other laws that make it illegal. You are right there is another law that 'probably' applies. The federal wiretap laws would apply. I see some problems with that. First someone for some reason thinks it's a good idea to change this law in California. You say 'Doesn't matter, it's probably still illegal' That makes it sound pretty dumb to bother changing the law. Still illegal, so why bother. I don't know if it were me, I would only bother to change it if I planned on getting the other laws changed also. And if they managed to get the other laws changed, it's 'probably' legal.
Next, even if the federal law doesn't change, now only the feds can prosecute it. I see lots of problems there. Maybe the feds don't want to prosecute it. Maybe the feds do want to prosecute, but someone grants a pardon for the federal crime. Do you know that the President's pardon powers can't pardon state crimes?
I just don't see any reason to make it so California can't prosecute businesses for invading my privacy. I find it profoundly unwise to give businesses rights that I don't want them to have based on probably and maybe. The only logical reason to try to make the exemption in California is if you plan on making the exemption on every law.
TLDR: It would be insane to allow this exemption. It currently as is works just how I want it to. Business never ever needs intentional unauthorized access to my communications.
> No that isn't the real point
Regardless of if you think it is, it is.
Far from merely shielding tracking pixel abusers from "frivolous" lawsuits, this bill legalizes wiretapping all your calls and browsing sessions and selling the recordings to the cops. It even had a retroactive immunity clause, which at least seems to have been stripped out.
Yes, it really is that crazy. Read it yourself here: https://legiscan.com/CA/text/SB690/2025
PS: Your strident defense of the surveillance industry and caustic dismissal of warnings from a well-known and credible civil rights organization makes me wonder where your interests lie. What is your involvement in the industry and what role, if any, did you play in the passage of this bill in the CA Senate?
Secondly, if "someone disagrees with me an organization I like in a strident and caustic way" is enough to make you reach for an ad hominem, then that just shows an unfortunate delusionality on your part. Not really helpful to your cause me-thinks.
> Far from merely shielding tracking pixel abusers from "frivolous" lawsuits <blah blah blah>
It appears that we agree on the substance of my argument. Which is enough for me.
EDIT: After reading a comment below, it seems that you might actually be using the "popular" definition of wiretapping, in which case, please provide an example of a scenario where this law allows something nefarious, taking into account other laws such as the CCPA. I doubt one exists.
CCPA appears to limitations based on the size of the enterprise, so that doesn't guarantee protection.
So, which state laws prevent someone from wiretapping my communications and then selling it?
They may act like silly old men but they aren't stupid, they know reason and they know the implications - all of them. That's the true intent.
Why should a company's "right" to seek profit through advertising infringe upon my right to privacy on the web?