3 ms·
> The hardest part is that the majority of companies seem to have no idea how to comply with requests... It's generally incompetence, not malice. After many e
by sillystuff 3y ago
> The hardest part is that the majority of companies seem to have no idea how to comply with requests... It's generally incompetence, not malice.
After many experiences of broken CCPA compliance I'm beginning to wonder if there is not a strategic component to the widespread incompetence.
Last night, I tried a CCPA request against keenan.com that a former employer had, apparently, "shared" my information with several years ago. Keenan.com recently sent out data breach announcements to let us know that they failed to properly secure the personal data they collected/hoarded on us via our [past] employers, and I wanted them to tell me what they potentially disclosed and then delete my data. From the email bounce message, they use Microsoft o356 hosted email, and configured their ccpa contact email address they list on the keenan.com website, "ccpa@assuredpartners.com" to only accept mail from internal senders on their own domain(s). Maybe the IT for keenan.com/assuredpartners.com is a clown show (they did hoard data they no longer needed, and failed to secure the data they collected/hoarded), but it seems unlikely that every company, of the many I've encountered with broken CCPA processes, would be similarly incompetent.
Several phone requests to other companies, using the CCPA contact number on their websites were answered by folks who have no idea what the CCPA even is.
One of the largest data brokers in the US failed to remove my data following a CCPA request until I contacted the VP of their legal department directly.
Most of my requests have either encountered (possibly strategic) incompetence as the above, or malicious compliance, where they make the process as time consuming and annoying as they possibly can. E.g., a web form that requires filling out the entire form repeatedly for each right you wish to exercise under the CCPA.
TLDR, maybe evil companies are just being evil?