6 ms·
I've been quite pleased with California and the CCPA thus far. I've submitted a few deletion requests a now, and despite my jadedness all but one went through
by fpgaminer 3y ago
I've been quite pleased with California and the CCPA thus far. I've submitted a few deletion requests a now, and despite my jadedness all but one went through without a hitch. I reported the one to the California AG and within two weeks the AG had followed up on it and forced the company to delete my data and the company fixed their processes. Color me slightly less jaded.
Of course, it's all still a manual process. Requiring that the deletion of PII be a "single button click" would be great. And making all data collection opt-in, instead of forcing me to fill out Do Not Sell My Data forms on every single website. But the Act mentioned in this article will be the third "Change Logs" we've gotten to the CCPA since its passing seven years ago. So, again, color me less jaded; it seems California is slowly and steadily clawing back our rights. Good on us!
- johndhi 3y agoCouldn't disagree more as someone who works in tech and guides companies in complying with laws like this. So expensive for so little real gain. We're spending more on making companies who don't use your data for anything nefarious (basically all companies outside of the advertising industry, if you even consider advertising nefarious) than we're spending on fixing climate change. Or preventing war. What a joke. Edit: looks like this law applies specifically to self defined 'data brokers' (no one can find these entities IME and no one admits they are one) so at least it's somewhat targeted. Comment stands for CCPA and CPRA, which apply to all "businesses."
- whelp_24 3y agoDo you not feel privacy is worthwhile? Do you believe that these companies aren't collecting data for advertising reasons?
- johndhi 3y agoHi - good questions. In general I think some privacy concerns are valid and others are not. Specifically I believe government surveillance is problematic and I wish there were more visibility and restrictions on it. I do believe many companies are collecting data for reasons other than advertising. For example CRM tools (eg Salesforce) have heaps of personal information their customers store with them for a bunch of different reasons. It's really complex for them to comply with these laws - even though they aren't doing any advertising.
- whelp_24 3y agoCompany surveillance is government surveillance. The companies may be collecting information for profit but once the data exists, it can be collected by the Government. In the US, the government can take data and make it so you legally can't even say it happened. But many times they can just buy the data. Companies like Salesforce may not be advertising to individuals, but the companies that use the crm software may be. The existence of the data itself makes it vulnerable to breach. I'd argue that privacy can't be compromised because any data can be used for any purpose (perhaps not always legally, but it doesn't matter since it is irreversible)
- appplication 3y agoIt doesn’t cost much at all for companies to have infrastructure to delete user data. That’s just a cascading delete in any relational table. Poof, data gone in a single query. Sure, some systems are slightly more complex but deleting data is one of the easier challenges for any company to solve. What costs money is companies trying to figure out how to work around legal requirements, obfuscate this option from users, or forcing them to go through support-intensive processes to delete their data rather than just building this like any other core automated business function.
- johndhi 3y agoThis hasn't been my experience. Do you work in a large company? My experience has been that there are heaps and piles of data including (or potentially including, unstructured) personal information. And lots of reasons why complete deletion isn't possible - because certain other information nearby the personal information is necessary for business purposes (like submitting invoices), or because the person requesting deletion only wants part - not all - deleted, or because the database is structured such that deletion isn't feasible until next year when we roll onto a new technology, etc etc.
- appplication 3y agoI work at one of the largest, and have also worked at startups and in between. Having PII littered about in ways that aren’t easily deletable is quite a canary. Companies with these issues are the same companies that end up with data breaches due to their cavalier treatment of user data. Perhaps these companies should be grateful they have a regulatory body ensuring they don’t fall too far behind the basic data stewardship practices the rest of the industry has in place.
- happytiger 3y agoNot sure why this is being downvoted. It’s precisely these companies that haven’t architected their systems well or prioritized the safety and security of PII by littering it about in various systems and making it “undeletable” in their processes, that need a swift kick in the ass to get it together. I can’t believe people consider the argument that because companies have poorly managed systems and PII centered databases with no abstraction (and therefore are working right on actual customer record data in their data lakes), that this is somehow a viable argument for why we shouldn’t make deleting data possible. Companies like this are the next Equifax. Why would you condone their stupidity?
- fpgaminer 3y ago> which apply to all "businesses." It only applies to businesses that make over $25 mil, or that are in the business of selling user data. (https://en.wikipedia.org/wiki/California_Consumer_Privacy_Act#Compliance https://en.wikipedia.org/wiki/California_Consumer_Privacy_Ac...)
- happytiger 3y agoThe alternative is that they don’t collect the data. If companies can’t afford to shelter the data, delete it when asked, etc., there is an easy fix! Don’t collect and store it!
- agar 3y agoAs a California resident who regularly opts out of data collection (and also, incidentally, works in tech), as a consumer I don't really care what you or your clients think. I just want you to comply with the law. A remarkably high percentage of our legal framework is designed to protect a very small number of people from being exploited by another small number of people. Yes, the costs of implementing these laws are high, but the societal benefits are, in aggregate, huge. My personal information is my own, just like my house, my car, my investments, my copyrights, and bank accounts. And I expect there to be laws that protect it, allow me to control it, and restrict how others can use it just as there are for my other assets. If applying these laws is inconvenient, then that speaks volumes as to how overdue these laws were.
- johndhi 3y agoI completely disagree that the benefits are huge. I like laws that say we can opt out of and must consent to email marketing. It leaves companies freedom to implement however they want. CCPA requires complete deletion, which isn't easy to achieve these days, of data that no one is using in an out of the way data store that otherwise wouldn't need to be touched. It's just a lot of effort for no benefit. I think you should be allowed to tell a company not to use your information. You shouldn't be able to tell them how not to use it.
- agar 3y agoHard disagree. Many security "breaches" are really the discovery of customer data in an S3 bucket "that no one is using in an out of the way data store that otherwise wouldn't need to be touched." Forcing companies to track and manage the data in their stewardship is necessary because clearly the economic incentive is not high enough - by your own admission. It's easier (and cheaper) to just leave around. But - when, not if - it's hacked, /I/ bear the cost of their negligence, not them. This is exactly why consumer protection laws are needed.
- johndhi 3y agoI think we're forcing them to manage the data in their stewardship inefficiently. I'd actually love a law that says if my data gets stolen from a company and a hacker uses that stolen data to harm me, the company must pay for (some portion of) those harms. But today it's setup so even if I don't get harmed they pay some lawyers to make the case go away.
- dheera 3y agoOn the other hand I've been highly disgruntled with California after living here a few years. The DMV, PG&E, and voter registration have all leaked my PII to third parties. F all of them. I don't intend to register to vote again unless they can prove themselves worthy of keeping my personal information confidential. I never use USPS forwarding. If you ever register for USPS forwarding, they will GLADLY tell stalkers your new address if they ask. This should have been made constitutionally illegal 100+ years ago if I were in charge of this country. Governments need to protect PII before waving these laws around at companies. I don't enjoy companies leaking my info either, but as of now governments have done it way more. On another note, US and California law need to stop requiring residential addresses for everything. Banks, voter registration, DMV, etc. don't need to know where I sleep to a 20-meter radius, they only need to know what state and MAYBE county I file my taxes in.