4 ms·
> reply without undue delay and at most within 45 days of this email, as required by Section 1798.130 of the California Civil Code So I looked this up and it r
by reactspa 5y ago
> reply without undue delay and at most within 45 days of this email, as required by Section 1798.130 of the California Civil Code
So I looked this up and it really exists.
I wonder if an account holder of a Facebook or Google account can use this law to get actual customer service.
- kstrauser 5y agoAlmost certainly. The law seems pretty clear that they'd have to completely delete all information about if you ask them to.
- User23 5y agoI guarantee you that they don't even know what all the information about you they have is and even if they wanted to they couldn't actually delete all of it because their systems have so many levels of redundancy to prevent data loss that even intentional deletion is impracticable, at least if you want it to be comprehensive.
- gpm 5y agoGDPR and CCPA compliance has been a big thing in the enterprise space recently. I wouldn't be surprised if they missed a small amount, and would assume that they didn't properly 0 out the bytes on the actual hard disk (as opposed to deleting the metadata used to find them - ssds in particular can make actually 0ing data hard), but I bet they do a reasonably good job.
- GauntletWizard 5y agoHaving worked at these companies and those like it, there's a lot to unpack in this law. The short version is, they have to delete data "about you", not data that was generated by you. Business records, such as receipts, are allowed to can be kept. They just delete your name and phone number, your photos and videos, and documents that were visible to you, but all of the actually useful tracking information is encoded into "Anonymized rows". It's bullshit and everyone knows it except the legislators writing the laws. That said, there's also a clever but effective workaround to all that redundancy - They store all your documents and photos encrypted with a key that's unique per user. When you request all your data, they delete the key - It's much easier for them to completely and quickly purge all that as a singular key, and clean up the files later. It's not a cop-out, because there's no effective way to get at your data once the key has been deleted. Those systems still have backups, but with much shorter lifetimes and explicit audit logs.
- dboreham 5y ago> except the legislators writing the laws Quite likely they do (or their staffers who do the actual work do). This is an example of regulatory capture.
- wglb 5y agoCurious that they don’t know what data they have, no? Collectors of data should know what they have and who they have shared it with. Think of holding data as risky, as if the data is toxic. Think of the monetary and reputational risk of a data breach. Incidentally, the data collected must be done so for a specific business purpose. And can even be kept if there are other requirements such as AML or KYC. Just slapping a zero over the data is not a viable solution.
- ncallaway 5y agoThere are three things that you can demand of a company (that meets certain revenue thresholds) if you’re a California resident: - that they delete information about you that they have (with potential exceptions) - that they provide you with what information they have about you, and for what purposes they have that information (with exceptions) - that they opt you out of sharing data with other entities (with exceptions) You cannot, as implied by the email, demand a response to an arbitrary query. There are essentially three queries the companies are required to answer with 45 days (90, if they opt for the 45 day extension). So, it can certainly be helpful in some situations, but will not serve as a general purpose CS tool.
- pessimizer 5y ago> You cannot, as implied by the email, demand a response to an arbitrary query. I wouldn't say that the questions were arbitrary; they were exactly the things you would need to know in order to submit a request for information, but without the actual request. The only alternative that I can think of to get the same information is to register at all of these websites, use them for five minutes, then make an actual legal request, and if not provided with "information" and "purposes", to make an actual legal threat. I don't get the impression that site owners would feel a lot happier about that approach. I can see how sending the email that was actually sent would be seen by a researcher as a better approach. And can also see a self-serving aspect, in that it's a cheaper approach - saves the labor of registering a bunch of accounts. But I'm getting the impression that site owners went to defcon 1 after getting a single request for information that should be easily available on the site if it were subject to the law (which the blog author has stated clearly that they were not.) If anything was missing imo, it's that there should have been help in the email mentioning the for-profit/$25MM revenue/50K Californians requirement in the law - but that might make it sound more like a threat, not less. They could also have made better guesses about whether the sites they were emailing would be bound by the law, and targeted the emails better. But if the site does fall under the law, and they felt threatened and hired a lawyer to answer those questions, I'm not sympathetic. They're supposed to be able to answer those questions if any of the >50K Californians they work with ask, at any time. If they were, replying would be a simple matter of sending a link or a form email that they already had ready.