3 ms·
"Data brokers would have to undergo an independent third-party audit every three years to ensure compliance with the DELETE Act provisions and submit audit repo
by SnowProblem 3y ago
"Data brokers would have to undergo an independent third-party audit every three years to ensure compliance with the DELETE Act provisions and submit audit reports to the California Privacy Protection Agency."
Source: https://privacyrights.org/resources/california-delete-act-bill-give-californians-more-control-over-their-personal-data https://privacyrights.org/resources/california-delete-act-bi...
- jerf 3y agoWell, I can see how that means well, but this doesn't scale to dozens of other jurisdictions doing the same thing. The audits would have to either be cheap and toothless or impossibly expensive, or, given the dozens of jurisdictions eventually doing these, probably both and other combinations besides. One can only imagine the nightmare of this jurisdiction deciding this bit of data is private, some other jurisdiction deciding it's mandatory to keep (e.g., "you must record this user's legal identity in order to ensure that future data you may receive is also deleted"), and yet a third jurisdiction deciding that it must be deleted but if and only if the user explicitly asks for it in the request. It won't take much for (real) compliance to exceed what even the big tech companies could afford. At least something like the EU legislating this covers a significant fraction of the world economy in one go.
- minsc_and_boo 3y agoMost jurisdictions copy the main tenets* from each other, to make it easier for actors to enforce in their region - i.e. GDPR -> CCPA.
- chrisweekly 3y agotenets, not tenants
- throwaway-blaze 3y agoYou've obviously never dealt with the EU privacy machinery. There is a separate privacy directorate in every single EU country. There is also a privacy group at the EU level. These groups _fight_with_each_other_...the EU level authority recently forced Ireland's DPA to fine Facebook despite the Irish authorities initially finding no enforceable infringement. I get that everyone dislikes Facebook, but this is not a stable regulatory regime to do business in, nor is it covering all EU member countries "in one go".
- jerf 3y agoFair enough. It is true that I was being a bit idealistic for sure. The sad reality is probably that there is no solution to this. If one imagines that the regulatory apparatus for some operation requires some percentage of the complexity and velocity of the underlying thing being regulated, well, government can manage the requisite complexity probably (though getting the correct complexity is another matter), but the velocity is just never going to happen, and the attempts are just going to look like this. By the time this is pushed through California, the actual regulations written to comply with the law as passed by the legislature, and enforcement actions begin, it will already not know what to do with things like AIs using personal information or complicated cross-company AI-based data washing schemes ("we use AIs to transfer summary data about the individuals in a complicated manner that makes it look like all the data is anonymized but in practice the data is so rich in its own complicated manner that the receiving company is de facto operating on private information but good luck proving that in a court of law, have fun with this one regulators!", etc.).