3 ms·
Thanks, that spurred me to read about it given the link above. > "This bill would require the agency to establish, by January 1, 2026, an accessible deletion m
by kepler1 3y ago
Thanks, that spurred me to read about it given the link above.
> "This bill would require the agency to establish, by January 1, 2026, an accessible deletion mechanism that, among other things, allows a consumer, through a single verifiable consumer request, to request that every data broker that maintains any personal information delete any personal information related to that consumer held by the data broker or associated service provider or contractor. The bill would specify requirements for this accessible deletion mechanism, and would, beginning August 1, 2026, require a data broker to access the mechanism at least once every 45 days and, among other things, process all deletion requests, except as specified. Beginning July August 1, 2026, after a consumer has submitted a deletion request and a data broker has deleted the consumer’s data pursuant to the bill’s provisions, the bill would require the data broker to delete all personal information of the consumer at least once every 45 days, as specified, and would prohibit the data broker from selling or sharing new personal information of the consumer, as specified....
> "This bill would provide that a data broker that fails to comply with the requirements pertaining to the accessible deletion mechanism described above is liable for civil penalties, administrative fines, fees, and costs, as specified, and would raise the amount of the existing civil penalty provisions described above...."
I guess it all comes down to the implementation level how specific and "actually deleting" they will be. And whether the new agency (ugh) charged with enforcing this will actually have teeth in the details.
And I don't know why such a long 45 day period is required. For reasons we're all too familiar with, people are quite able to gather data within seconds, but somehow need 45 days to delete it?
- addaon 3y agoDeleting data from backups (or, more often, aging out backups and deleting them wholesale) is usually a batch process. You really don't want to have to do online modification of backups... they're not really backups at that point. 45 days doesn't seem unreasonable.
- callalex 3y agoIf it’s so much work to handle the data responsibly, maybe it shouldn’t be collected in the first place.
- kepler1 3y agoWell... doesn't that circumvent the point of backups? Backups in my mind are supposed to be like read-only, can never be modified so that the system that was corrupted can't do anything harmful to the safe previous checkpoint. I guess it has to have some method of what you mention then. If someone wants their data deleted, yes, what about the backups?