5 ms·
They should have narrowed the exemption. As it is the current exemptions are for pretty much the operation of a telephone company and jails. Your local police d
by zdp7 1y ago
They should have narrowed the exemption. As it is the current exemptions are for pretty much the operation of a telephone company and jails. Your local police department is not exempt, they need a warrant. This law specifically is about intentional access to communications you aren't authorized to access. I'm not good with letting that being ok for commercial business purposes.
- phendrenad2 1y ago> They should have narrowed the exemption Maybe "legitimate business purpose" is doing the heavy lifting here. Let's find out! Let's take another look at the bill: > The bill would define a commercial business purpose to mean the processing of personal information either performed to further a business purpose or subject to a consumer’s opt-out rights Let's keep reading, this is fun! > (e) “Commercial business purpose” means the processing of personal information that satisfies either of the following criteria: > (1) Is performed to further a business purpose as defined in subdivision (e) of Section 1798.140 of the Civil Code. Okay, let's look up subdivision (e) of Section 1798.140 of the Civil Code of California... (this is kind of like pointers in C... very cool) > (e) “Business purpose” means the use of personal information for the business’ operational purposes, or other notified purposes, or for the service provider or contractor’s operational purposes, as defined by regulations adopted pursuant to paragraph (10) of subdivision (a) of Section 1798.185, provided that the use of personal information shall be reasonably necessary and proportionate to achieve the purpose for which the personal information was collected or processed or for another purpose that is compatible with the context in which the personal information was collected. Business purposes are: > (1) Auditing related to counting ad impressions to unique visitors, verifying positioning and quality of ad impressions, and auditing compliance with this specification and other standards. > (2) Helping to ensure security and integrity to the extent the use of the consumer’s personal information is reasonably necessary and proportionate for these purposes. > (3) Debugging to identify and repair errors that impair existing intended functionality. > (4) Short-term, transient use, including, but not limited to, nonpersonalized advertising shown as part of a consumer’s current interaction with the business, provided that the consumer’s personal information is not disclosed to another third party and is not used to build a profile about the consumer or otherwise alter the consumer’s experience outside the current interaction with the business. > (5) Performing services on behalf of the business, including maintaining or servicing accounts, providing customer service, processing or fulfilling orders and transactions, verifying customer information, processing payments, providing financing, providing analytic services, providing storage, or providing similar services on behalf of the business. > (6) Providing advertising and marketing services, except for cross-context behavioral advertising, to the consumer provided that, for the purpose of advertising and marketing, a service provider or contractor shall not combine the personal information of opted-out consumers that the service provider or contractor receives from, or on behalf of, the business with personal information that the service provider or contractor receives from, or on behalf of, another person or persons or collects from its own interaction with consumers. > (7) Undertaking internal research for technological development and demonstration. > (8) Undertaking activities to verify or maintain the quality or safety of a service or device that is owned, manufactured, manufactured for, or controlled by the business, and to improve, upgrade, or enhance the service or device that is owned, manufactured, manufactured for, or controlled by the business. Far from a freewheeling "they can wiretap anything!!!1111" screech I keep seeing here, it seems to me that the definitions are all nicely pinned-down and there isn't a lot of leeway. Oh and an important note: I'm not a lawyer. It's possible that I've completely bungled this analysis, so don't take it as legal advice. This is just my opinion.
- zdp7 1y agoIt's my opinion you don't understand the business purposes listed. As I read it this would allow collection of communications for training an AI Agent. I see item 8 as giving permission. The AI Agent is the service controlled by business. The collected data would be provided as training to improve, upgrade or enhance the service. Item six allows advertising, mainly limiting aggregating personal information taken from other entities that aren't the business. I can see Amazon designing an advertising platform compliant with item 6 and using existing Alexa devices to eavesdrop on all communications. Reading the argument for section SB690 [https://calmatters.digitaldemocracy.org/bills/ca_202520260sb690 https://calmatters.digitaldemocracy.org/bills/ca_202520260sb...] list the main argument as CCPA governs online business. The opposition points out that the CCPA specifically specifies that conflicting laws providing greater protections should apply. The rest of the arguments cite CIPA as enabling frivolous lawsuits. There are already remedies for frivolous lawsuits. Attorneys can be disbarred and vexatious litigant laws would apply. In multiple places you state there are 'probably' other laws that apply. That law is 'probably' the federal wiretap law. I'm not sure if you are aware, but California is an all party consent state. The federal wiretap law is single party consent. SB690 would effectively turn California into a single party consent state for anyone with an appropriate business purpose. The majority of the business purposes listed as acceptable are not what I would call nicely pinned down. I would only be ok with item 2. I can almost guarantee allowing business to collect this data will lead to use that doesn't fall under the legitimate business purposes. Uncollected data can't be mishandled. Lastly to me the greatest reason to oppose is that the laws pretty much all cover intentional unauthorized access. CIPA as it is exempts pretty much the only businesses I would want granted the access to intentionally access unauthorized communications. Everyone else can ask me for permission, if I refuse they don't have to do business with me.
- phendrenad2 1y ago> not what I would call nicely pinned down Yes, they are, but I think your real point is that: > I would only be ok with item 2 Yep, this is what it all comes down to. But it seems like everyone else is arguing without even knowing that the scope of this is. It's of course your right to your own opinion about if these business purposes are acceptable. I was even aware that training LLMs and showing ads are legitimate business purposes. You act like that's a revelation, but it's important to realize that is purely your reaction, not the reaction of the average person. Is the average person okay with their emails being used to train LLMs, or show them ads? I mean, what percentage of the population uses Gmail for mail? I think the question is nicely answered there. > I can almost guarantee allowing business to collect this data will lead to use that doesn't fall under the legitimate business purposes. Uncollected data can't be mishandled Sure, but we can't just lock ourselves in iron boxes and survive on privacy alone. People have to engage with the world. Maybe credit card numbers should be 100,000 digits long, so someone can't look over my shoulder and steal mine?