24 ms·
CCPA Will Hit Dev Teams Harder Than GDPR
- lxe 8y ago> if a data breach occurs, the law permits consumers to recover up to $750 per incident This is great!
- llukas 8y ago"up to" Are there any guidelines for determining actual compensation?
- chmod775 8y agoPresumably it's a scale from "Leaked (e-mail) adresses" to "Leaked nude photographs".
- llukas 8y agoI don't mind my nude photographs. I mind if somebody takes loan in my name and dumb bank would send it to collections.
- jusssi 8y agoSomeone else might mind your nudes. E.g. your employer, the school your kids go to, the parents of your kids' friends, etc. At least in the US, rest of the world isn't that shocked of our natural form.
- flakss 8y agoPresumambly the upper end of the scale would be closer to identity theft with total asset loss and fraudulent lines of debt, which is likely would occur if eg google got hacked.
- icoe 8y agoIt would be decided in a civil court, most likely.
- Groxx 8y agoThe full sentence is this fwiw: >Additionally, if a data breach occurs, the law permits consumers to recover up to $750 per incident (or actual damages, if greater). So that might just be $750 as part of a punitive fee.
- tzs 8y agoIt sounds more like a statutory damages thing, although note I have not read the law. The idea with statutory damages is that determining the actual damages can be difficult and uncertain, so some laws allow plaintiffs to elect to ask for damages from a standard range, and the court will decide where damages should fall in that range based. It's basically saying "just give me about what is typical for cases like this one".
- kevin_b_er 8y agoSimple, you just add this to clickwrap agreement: The Parties mutually agree that any and all disputes arising from or relating to this Agreement, including the interpretation or application of this Agreement will be submitted exclusively to final and binding arbitration pursuant to the Federal Arbitration Act. The arbitration will be conducted the state of Delaware or such other location as the Parties may agree, by a single arbitrator in accordance with the substantive laws of the State of Delaware. Boom. No more pesky California law.
- wilg 8y agoOh are you a lawyer?
- dbdjfjrjvebd 8y agoOP needs to be not just a lawyer, but your lawyer. I.e. someone who is accountable to you if their advice is wrong.
- deleted 8y ago[deleted]
- carbocation 8y agoI dislike how the minute someone mentions a legal hack, the responses are "oh, are you a lawyer?" Why not consider this reply on its merits?
- deleted 8y ago[deleted]
- ChrisSD 8y ago"Legal hacks" are rarely, if ever, as clever as their proponents think. Scepticism is natural and warranted. Judges aren't complete morons and will take a dim view of "hacks". There could be loopholes somewhere but you'd need a lawyer to spot them.
- 8y ago
- b_tterc_p 8y agogood time to make a bot that signs up for things
- jhanschoo 8y agoOnly if you don't value your PII. If you don't use PII in your bot then you can't claim.
- heavyset_go 8y agoThere shouldn't be a cap to liability, this reeks of tort reform-esque legislation. If my identity gets stolen, there is much more than $750 at stake on my end.
- tzs 8y agoIt's up to $750 or actual damages if greater.
- gwbas1c 8y agoGreat article, until the end. Who uses PII in test data derived from real customers? That's just an absurd practice to begin with, and no one who takes security seriously would even consider doing this.
- munk-a 8y agoSmall companies that are just starting out may use real data in test environments since it's a bit easier than using mocked data... Honestly this really only holds for companies that also avoid unit/integration tests (which will generally require that data to support the tests be explicitly mocked in some manner) Since this involves computers nothing above is a hard rule, but it goes along with my experience.
- jboy55 8y agoThe $25 million revenue limit would be a pretty good guide from 'small'. Typically there are a lot of changes around that mark, one of which should be to stop using Customer data insecurely.
- coldacid 8y agoExcept that revenue limit is just one term of an OR clause. If you hit any of those three listed points, CCPA comes down on you. No revenue at all but 50k unique visitors, and it applies.
- munk-a 8y agoYea but the $25mil portion of the clause is the only one I see an excuse for, if you're saying that -all- businesses generating X revenue or higher need to comply with a regulation then it's good to make sure X is high enough that businesses in unrelated fields will be able to afford the cost of compliance without going bankrupt. The other two categories specifically target companies that really should comply with this law - I assume the $25mil clause is there to make sure large companies can't loop hole themselves out of this somehow (offload PII responsibility onto a subsidiary or a "third party" that is incorporated in Bermuda by the owner of the company)
- nixpulvis 8y ago"It defines de-identified as “information that cannot reasonably identify, relate to, describe, be capable of being associated with, or be linked, directly or indirectly, to a particular consumer.”" I'd love to know what they mean by reasonable... I've seen some demos of tech that can do some pretty amazing things at de-de-identifying.
- icoe 8y agoSo, huge caveat (I'm NOT a lawyer), but right now most interpretations seem to suggest that masking and synthesizing would constitute appropriate deidentification even if a motivated adversary could reverse engineer given appropriate time and resources. Again, this is something that will likely be clarified over time.
- fuzzy2 8y agoot: What's wrong with this website? It loads super slow and behaves very weirdly on my iPhone.
- icoe 8y agoApologies. We're using wix right now. We'll be moving off shortly.
- Novashi 8y ago>Process personal information of >50k consumers, households or devices >Derive >50% of revenue from selling PII So if I forward all of the data to another company outside of CA, does my company count as processing data? What if the code that forwards that data is written by another company and I'm just hosting it on my site? Everything goes through their code and I'm paid to just setup a website to host their code. Maybe I do collect info in CA but I sell the data for $1, but the company also buys some consulting services for the actual price of that data that I'm selling them?
- figgis 8y ago> So if I forward all of the data to another company outside of CA, does my company count as processing data? You are still processing that data. Part of processing that data involves you shipping it off... > What if the code that forwards that data is written by another company and I'm just hosting it on my site? Everything goes through their code and I'm paid to just setup a website to host their code. You are as responsible, if not more, in making sure that compliance is met. You are the one hosting the code. The data is moving through your servers. > Maybe I do collect info in CA but I sell the data for $1, but the company also buys some consulting services for the actual price of that data that I'm selling them? That's just being a jerk. But better hope you don't pass the 50k mark...
- Novashi 8y ago>You are still processing that data. Part of processing that data involves you shipping it off... >The data is moving through your servers. So if a random company gets breached, everyone involved from cloud providers to ISPs are also responsible because they facilitated moving and storing the data and they are just hosting code? This is problematic. Cloud providers give you permission to publish code. I could position myself to allow another company to publish code on my popular website to collect data and my role is basically no different than a cloud provider. We don't have to agree that is what it's specifically for, I just need to give them access to upload their own code for whatever expensive fee.
- 8y ago
- mark_l_watson 8y agoI like the general idea and I like that it specifically applies only to organizations with more than $25 million in revenue. Give small startups a break. Does the GDPR also have a lower limit like this? It should.
- fooey 8y agoThe criteria is a "one or more of the following" not a combination of them all So if you make more than $25 million, OR your have more than 50k users or devices, OR you make more than 50% of your money selling data
- AnthonyMouse 8y agoSeems like the second one is the real problem. "50K users or devices" is less than 0.02% market share, even if you have only US customers, and for businesses with margins in the $1/user/year range it doesn't even cover one full time employee. You can end up with that many users on a side project all of a sudden if it gets posted to the front page of a site like this one.
- coldacid 8y agoAnd it doesn't even have to be users in the signed-up sense if you simply have access logging turned on for your web server; 50k unique IPs would be enough.
- pkaye 8y ago50K California customers.
- AnthonyMouse 8y agoSo less than 0.13% market share then. Assuming you have any way to reliably identify which state your users are in -- which means we're back to "privacy regulations" encouraging companies to collect more data on their users.
- bcheung 8y agoDoes this mean another swarm of privacy popups everywhere again?
- coldacid 8y agoIf we're lucky.
- jarvuschris 8y agoCounting an IP address as PII is kind of crappy, you need a court order to turn an IP alone into PII. Operators should be free to log traffic at the network level, PII should only come into play once you're asking someone to provide personal information.
- thaumaturgy 8y agoThere's been a lot of FUD surrounding the logging of IP addresses for network diagnostic and abuse purposes as a violation of GDPR (and now CCPA), but I'm not aware of any cases where that alone was sufficient to cripple a business. Until I hear otherwise, I'm going to gamble that for now that's not the kind of reckless mishandling of personal information that regulators are trying to crack down on.
- msla 8y ago> Until I hear otherwise, I'm going to gamble that for now that's not the kind of reckless mishandling of personal information that regulators are trying to crack down on. And you're probably right until they do otherwise. The problem with badly-drafted laws is that they can be used to attack people who are annoying but who haven't done anything wrong... except for technically violating a law which is "supposed to" mean something else but which can be read to penalize some harmless activity the gadfly happened to engage in. So, maybe you'll be patient when I'm not comforted by people telling me to not worry about it.
- sroussey 8y agoGDPR gives regulators a lot of leeway on how to crack down on things.
- mattnewton 8y agoAnd that’s problematic for someone trying to understand if their business operations are legal.
- kodablah 8y agoGoing into effect in a year? Seems like a business opportunity. Someone let me pay them $X and review my systems every so often and give me a seal saying I'm compliant with all these laws, and include some insurance up to $Y. Especially given the selective enforcement, there's money to be made from the chill alone. Compliance audit companies can probably just roll this into their package. Also, I'm a bit annoyed at laws only affecting companies of a certain size. At some point right at crossing the line, there's a negative effect to having 50,001 users. (really I'm annoyed at how these data protection laws are implemented in general and I wish the discussion would be about that instead of being idealistic and only looking at the supposed intent)
- M2Ys4U 8y ago>Going into effect in a year? Seems like a business opportunity. GDPR was law two years before it came in to effect and everyone left it until the last ~month.
- dmitriid 8y ago> how these data protection laws are implemented in general and I wish the discussion would be about that instead Let’s do that, shall we? Before GDPR there were laws in each European country protecting private data (GDPR is basically Sweden’s data protection law in that regard). Not a single “poor company that will need comply” gave a damn. Then GDPR was introduced, discussed, amended. Quite publicly. Not one of the “poor devs that would be hit by it” gave a damn. GDPR was passed and companies were given two years to adjust their software/systems/business practices to comply. Hardly any of the “let’s have a discussion shall we” devs gave a damn until the last few months of the transition period. And only when they realized that they had to actually do something, something they should have done literally years ago, we had (and still have) this fake outcry of “boohoo these laws make us work hard and do right things and we don’t wanna”. Cry me a river.
- SomeHacker44 8y agoAs a top engineer of a EU headquartered company, I can be one instance of saying this was not true of us. We started our preparations almost a year and a half in advance of the March 2018 deadline. Once we engineers and our GC were done interpreting the extent of what we believed we needed to do and the resources to do it, we were basically ordered by the CEO to do as little as possible as late as possible, automate as little as possible, and just wait to see if anything came of it. I left the company a few months after GDPR-day so cannot say how it worked out, but it was the CEO’s company and his choice to do it in a way that it then became my responsibility to implement. Compliance/legal is a company risk and as I indicated in the challenger article here a few days ago, as an engineer I can advise on hat the risks are and the potential consequences of bad outcomes, as well as the costs to reduce them. The business decides what level of risk to take. I personally would have preferred a robust response to GDPR and thorough internal procedures, but it was not my call to make. Of course, I personally believe that we humans should own our data and digital footprints, so I agree with a lot of the concepts behind GDPR and CCPA even if I do not agree with all and as an engineer may think some are ... silly/overzealous/misguided or what have you. Case in point: the IP tracking discussion above. If I hit your network, thats on me (barring externalities or bad actors, etc.). Retention periods and use definitions are fine, but a requirement to treat it as PII or other super sensitive data seems a bit much to the engineer in me.
- IfOnlyYouKnew 8y ago“He started worrying about data privacy after talking with a Google engineer and spent nearly $3.5 million in 2017/2018 to place an initiative on California's November ballot.” That Google employee must be somewhat nervous these days...
- truesy 8y agoIMO the biggest difference between CCPA and GDPR is that GDPR does not distinguish between large and small companies. Everyone needs to comply. At least with CCPA you can bootstrap a company and not have this be another thing you need to worry about, on day 0
- coldacid 8y agoNo, just once you reach 50k visitors to your site.
- rco8786 8y agoAlready starting to deal with this where I work. It’s gonna be interesting...
- DiabloD3 8y agoSo, devil's advocate here: why not just require your ToS to state that if the user is from the state of California, that they are to not use the service and find a local alternative? It is a state law, they can't hassle you if you're not Californian and do not service their target market. Most of America doesn't live there, and California seemingly doesn't want you to do business there.
- gleenn 8y agoBecause there are a huge number of users in California, and it’s also the fifth largest economy in the world. Ignoring California is probably throwing away a big market. You could say that about Europe to wrt GDPR but you should note that almost everyone is becoming GDPR compliant too because it’s a big market.
- Novashi 8y ago>So, devil's advocate here: why not just require your ToS to state that if the user is from the state of California, that they are to not use the service and find a local alternative? Silently redirect them to a similar-enough site run by a partner company that's based in another state/country.
- anticensor 8y agoThat would be considered an anticompetitive behaviour.
- afpx 8y agoWhen using personal data is outlawed, only the outlaws will use personal data. What about all of the state actors (and 'hackers') who are cracking corporations for data and building a massive database on everyone?
- chias 8y ago> When using personal data is outlawed, only the outlaws will use personal data. This argument only works if you feel the thing being outlawed is good (it is most commonly used in the context of privacy). To your statement I would respond the same way as I would respond to "When shooting people is outlawed, only the outlaws will shoot people": sounds good to me!
- afpx 8y agoI meant, in jest, that if laws get tougher on the private sector, I hope that the government also throws a lot more money at data crime, too.
- zestyping 8y agoIf a company distributes a program or app that processes your address, personal data, geolocation, etc. _on your device only_ and the sensitive data never leaves your device, are they subject to the CCPA?
- newman8r 8y agoThe way this came into existence is what scares me.
- ahartmetz 8y agoThe "if they knew what we know" part or the you can (kind of) buy policy part? If the latter is shocking to you, I have some very bad news for you. (The process would have been more difficult and more expensive if the law wasn't genuinely benefiting the people, but still possible.) Also, Mr. Mactaggart, what a guy!
- newman8r 8y agoThe part that bothers me is how hastily the "compromise" was drafted, without any public debate. I don't like the idea of an individual holding the legislative process hostage. There are limits on campaign contributions, perhaps there should be limits on individual contributions for these signature drives, which are essentially just large marketing efforts. And just because this guy got x number of signatures, I don't see why he should now have the power to make compromise deals with the government. This isn't my area of expertise so I may be missing something here.
- briffle 8y agoThis seems like a good discussion to ask.. Have any of you used a tool like pg_Anonymizer [0] to mask your data when building test/dev databases? I see several tools on there, but have no idea where to be begin on them.. [0] https://pgxn.org/dist/postgresql_anonymizer/0.0.3/ https://pgxn.org/dist/postgresql_anonymizer/0.0.3/
- dmitriid 8y agoCan we stop talking about how privacy laws are hitting devs, and start talking how they will benefit people? Boohoo, poor devs need to finally pay attention to people’s private data.
- ThrustVectoring 8y agoYou need to talk about both costs and benefits when discussing public policy. Otherwise, you end up with a ton of terrible policy that looks good due to an obvious tangible benefit, but nets out to more harm than good. For example, minimum bedroom sizes for rental units. Seems nice to have enough space to live comfortably, right? End result though is the $20M apartment complex has 35 units instead of 40, and is only built later when rents have gone up to make the project make sense financially, exacerbating a housing shortage.
- dmitriid 8y agoLet’s look at the cost, shall we? Invasive and pervasive surveillance. Private and sensitive data sold wholesale not even to the highest bidder, but to anyone. Hell, when news about NSA surveillance broke, it was a huge scandal that was the focus of attention of all media for more than a year. Now Facebook alone is reported to have the same level of maliciousness and willfull ignorance on a monthly basis, and it’s business as usual. So yes, I don’t give a rat’s ass about the “poor developers” who couldn’t get their shit together and provide privacy and security to the common people. And who now pretend they are being unfairly punished by governments. And yes, I’m a developer myself.
- ThrustVectoring 8y ago"these costs fall on people who I feel deserve it" isn't a good reason to completely ignore the size of the costs being imposed. Especially since these costs are sublinear with respect to organization size, causing the tech behemoths you complain about to get a free competitive advantage against upstarts threatening their business model.
- raverbashing 8y agoSo are we going to have websites blacklisting CA IPs and answering back with some vague "this content is not available in your region?"
- Isinlor 8y agoHopefully not, unless we speak about some hyper-local businesses. It's now GDPR + CCPA, so you are cutting off EU and California. Probably, more to come. For example, seems like LA Times does not block EU anymore.
- bernardrubble 8y ago> Derive >50% of revenue from selling PII Would this even apply to most of the companies who are the worst data hoarders? Does google derive 50% of revenue from selling PII, or just derive 90% of revenue from the utilization of PII without actually selling it?