8 ms·
Californians' data deletion requests, DROP, become enforceable Aug. 1
- igor47 2mo agoI've been thinking of making a service which automatically sends deletion requests for all my service companies every month. Like, I currently keep a bunch of spyware features in my car turned of, but I have to keep location turned on to use the built in navigation which keeps track of range for me. Would be nice to have a ceiling on that data's retention. Long term, if compliance with data deletion requests becomes a pain, maybe companies will finally give us an opt out of surveillance capitalism? Or maybe they'll just lock me out of my own car (I guess it's their car since I don't have root on it, lol)
- rustcleaner 2mo agoIf it's a VW, pick up a Ross-Tech VAG-COM + VCDS, locate your Telematics unit (OCU, online communications unit) and remove it; mine was behind the instrument cluster. Then use VCDS on a laptop plugged into your car with VAG-COM, and code out the OCU from every module giving fault codes for its absence. You will probably lose the microphone, as in my Mk7 the microphone line goes through the OCU. Finally, optionally, you can code out your infotainment module's bluetooth features thus taking away another avenue for passive surveillance.
- hackernud3s 2mo agoWhat about unregistered data-brokers? I would he happy to sign up to webhooks for when someone wants to delete data. Problem is though, you'd be revealing more data about them than I probably have by sending it.
- jboggan 2mo agoDo you think you could be an unregistered data broker? You should probably reach out to me directly so I can give you more targeted advice. All of the requests are SHA-256 hashvalues, they aren't transmitting any usable information in the process of sending the deletion requests.
- hackernud3s 2mo ago[dead]
- echelon 2mo agoDoes this mean people can delete comments from HN?
- aw1621107 2mo agoOnly if HN counts as a "data broker" under the corresponding law [0]. It states: > “Data broker” means a business that knowingly collects and sells to third parties the personal information of a consumer with whom the business does not have a direct relationship. “Data broker” does not include any of the following: > An entity to the extent that it is covered by the federal Fair Credit Reporting Act (15 U.S.C. Sec. 1681 et seq.). > An entity to the extent that it is covered by the Gramm-Leach-Bliley Act (Public Law 106-102) and implementing regulations. > An entity to the extent that it is covered by the Insurance Information and Privacy Protection Act (Article 6.6 (commencing with Section 791) of Chapter 1 of Part 2 of Division 1 of the Insurance Code). > An entity, or a business associate of a covered entity, to the extent their processing of personal information is exempt under Section 1798.146. For purposes of this paragraph, “business associate” and “covered entity” have the same meanings as defined in Section 1798.146 [1]. I don't think HN counts as a "data broker" under this definition since they state that they "do not collect any Personal Information unless you choose to provide your email address and/or information in the "about" field" for HN accounts and "do not sell or share your Personal Information (as those terms are defined under the CCPA)." [0]: https://cppa.ca.gov/regulations/pdf/data_broker_reg_delete_act_statute_eff_20260101.pdf https://cppa.ca.gov/regulations/pdf/data_broker_reg_delete_a... [1]: https://leginfo.legislature.ca.gov/faces/codes_displaySection.xhtml?lawCode=CIV§ionNum=1798.146 https://leginfo.legislature.ca.gov/faces/codes_displaySectio....
- testing22321 2mo ago[flagged]
- adzm 2mo agoConversely, they did help me out.
- 2mo ago
- unstatusthequo 2mo agoThe Advertising ID field/ Nice of them to think of this, but it doesn't seem that I could actually get this from any of my Samsung TVs, Apple devices, apps?, etc? So while that field is nice and all, without transparency on getting the ad ID, those fields kind of do nothing.
- dwattttt 2mo agoGoogle TV surfaces this under settings (along with the ability to regenerate it, or remove it) EDIT: Android also surfaces this information more generally, I just found it under More Privacy Settings -> Ads
- amazingamazing 2mo agoWhy is there a time limit on deletion on this site?
- millerm 2mo agoBecause someone commenting leads to others spending time and effort responding. Deleting the comment breaks the chain. Don't comment if you feel that it's something you might want to delete. Think of commenting as like sending an email, but you get a short window to delete in this place.
- amazingamazing 2mo agoDo you believe the same about search results not being able to be deleted? I also assume this means you disagree with gdpr?
- EA-3167 2mo agoDo you not see the difference between a person volunteering to broadcast a post, vs a bird party scraping the web to index it for searching?
- amazingamazing 2mo agoYou believe volunteered information must stay on internet forever?
- EA-3167 2mo agoIf you knew those were the conditions when you joined? Yes.
- amazingamazing 2mo agoOk. Luckily people who make the rules don’t have such ideas.
- MrZander 2mo agoOut of curiosity, does anyone know how this is enforceable for a company not based in California? Can CA fine a data broker that is based in another state but that is selling CA residents' information?
- hackernud3s 2mo ago[dead]
- Xorakios 2mo agoYes; the nexus for legal purposes is generally the location of the user, not the broker
- connicpu 2mo agoThe company would have to not have any interstate presence at all. If you are a business based in the united states that has customers in California, you are easily reachable under California law.
- metalcrow 2mo agoCurious, how so?
- newsomix9xl 2mo agoComity iirc is the legal principle of mutually recognizing other states laws (giving them jurisdiction) as in recognizing a marriage contract in other states (and they recognize yours). That's my guess
- teraflop 2mo agoLook up "long arm statutes". State courts can have jurisdiction over out-of-state entities, subject to limitations established by federal precedent. Doing business with customers who reside in a state generally puts you under that state's jurisdiction, at least for purposes related to that business.
- petilon 2mo agoI hope other states adopt this. One of the biggest mistakes I have made is giving my real phone number to Dun & Bradstreet. Now the spam calls and messages (from people they sold my info to) won't stop. I don't want to change my phone number.
- hackernud3s 2mo ago[dead]
- cute_boi 2mo agoMy number used to belong to an elderly woman, so I keep getting spam texts intended for her. I block the numbers, but they somehow keep sending me spam messages from different ones. I don't think there is any solution other than changing my phone number at this point. The issue is fucking sites keep using phone number as 2fa.
- _dark_matter_ 2mo agoKeep the old number and get a new one. You'll have to gradually switch all 2fa if you want to lose the old number, otherwise keep it forever on a separate device.
- cyanregiment 2mo agoOut of curiosity, did you do this as part of Android's awful app submission process
- xeromal 2mo agoI think Apple requires it too or did when I made an app for my mom a few years ago
- cyanregiment 2mo agoNot for most people. You definitely did not need it for making an app for your mom. I've released games under my own name and never did that. A random person releasing an app or game on the App Store - you won't need it. But on Android you still might, even for something small, since they changed the rules for new developers. As of November 2023, any new developer account releasing an app basically has to have an Organization account to publish. Otherwise, the only way to do it as a solo dev is to go through some arduous testing phase with Google, where you have to find 12 or more people to help test at certain times for 14 consecutive days. If even 1 tester doesn't show up or deletes the app, it resets. Comical, but it's how they lowkey force you to create an Organization. And people should form companies (and operate as Organizations on platforms). It will protect you in the long run, and you can pay lower taxes on revenues. The main problem I have with it - and this also goes for certain payment processors - sometimes I just want to try an idea. Or like your example, build an app for a friend or relative without a ton of hoops to jump through. Involving a 3rd party credit bureau that operates as a private company - that apparently sells people's data to shit ball marketers, doing whatever else they want with basically no oversight - seems in almost all cases overkill and whack as a process as big as Apple or Google app submission that is borderline a public service if you're willing to not pretend we don't have 2 main choices in this market. The app store platform should just forward on to the downloading user that it's a corporation in Delaware, or whatever. They kinda do - with the "copyright" field, but that field and value has no legal bearing on anything and can be changed without a review - where even being an individual or "sole" proprietor is a legal designation. You could still form a company under your own name later. Adding a business license should be some optional thing IMO that links through to a local registry if possible and if not, then the end user can deduce that it is not "verified" to be that entity.
- bdcravens 2mo agoI wonder if there will be any funny data issues that happen because companies keep track of such requests in a table named "drop"
- m463 2mo agomom should look up little bobby tables
- tjwebbnorfolk 2mo ago> Companies that fail to comply can face fines of $200 per day for each affected Californian. Does this cover things like credit reports/scores? If someone submits a request to this DROP thing, is it possible data gets deleted that they don't intend?
- rustcleaner 2mo agoI hope this is true! Consumer credit is a serious problem. How much better would it be if only corporate entities could take on debt? That goes for school, home, and car loans too. Imagine the return to sanity in pricing when Big Finance can no longer scam time-preferenced and desperate buyers! Society might have a real savings rate again!
- dredmorbius 2mo agoProbably not. Under TITLE 1.81.48: “Data broker” does not include any of the following: (1) An entity to the extent that it is covered by the federal Fair Credit Reporting Act (15 U.S.C. Sec. 1681 et seq.). (2) An entity to the extent that it is covered by the Gramm-Leach-Bliley Act (Public Law 106-102) and implementing regulations. (3) An entity to the extent that it is covered by the Insurance Information and Privacy Protection Act (Article 6.6 (commencing with Section 791) of Chapter 1 of Part 2 of Division 1 of the Insurance Code). (4) An entity, or a business associate of a covered entity, to the extent their processing of personal information is exempt under Section 1798.146. For purposes of this paragraph, “business associate” and “covered entity” have the same meanings as defined in Section 1798.146. <https://leginfo.legislature.ca.gov/faces/codes_displayText.xhtml?lawCode=CIV&division=3.&title=1.81.48.&part=4.&chapter=&article https://leginfo.legislature.ca.gov/faces/codes_displayText.x...> Credit bureaus are, I think, covered as item (1).
- garpoon 2mo ago[dead]
- faucetl 2mo ago[flagged]
- ChrisArchitect 2mo agoSome previous Delete / Drop Act discussion: The Delete Act https://news.ycombinator.com/item?id=46449694 https://news.ycombinator.com/item?id=46449694 California residents can now request all data brokers delete personal info https://news.ycombinator.com/item?id=46495220 https://news.ycombinator.com/item?id=46495220
- ryandrake 2mo agoAs good intentioned as it is, I don't like the wording used around this law. "Request" and "Ask" and "please delete my information." Notice that regular users have to "ask nicely" but when it's something like the DMCA, which benefits corporations, they use "takedown notices" and "demand letters." I don't want to ask data brokers, pretty please with sugar on top. I want to be able to demand they do it, and require them to immediately do it and provide proof that they did, under penalty of perjury.
- kooi 2mo agohere-here
- brookst 2mo agoYou’re free to label it as a demand, but unless you run a courtroom and swear them in, any failure to do so will not be perjury.
- Y-bar 2mo agohttps://www.law.cornell.edu/wex/request https://www.law.cornell.edu/wex/request https://munley.com/tag/request/ https://munley.com/tag/request/ I’m not a US lawyer, but the word ”request” seems like it has a solid legal basis and can be used to compel action.
- ooterness 2mo agoI always liked the archaic form, "You are hereby requested and required to [insert naval orders here]." It's asking very politely, for now, but also making it clear that declining will result in jail or worse. I don't know if it's apocryphal, but it shows up in the Hornblower novels and at least one episode of Star Trek.
- wilg 2mo agoWell, I don't think any of these things are legally required, so call it whatever you want.
- dragonwriter 2mo agoThe penalty for not honoring a DROP “request” is more severe than perjury (and, conversely, there is no penalty at all for not honoring a DMCA notice, the only effect is that you do not benefit from the DMCA safe harbor if you would have been liable for copyright violation without it.) You are being distracted from the substance by non-substantial surface features.
- hedora 2mo agoDoes this apply to Google, car companies, etc, or did they bribe in exceptions for themselves (like California grocery stores did for the Do Not Sell My Personal Information law)? Also, who gets the $200/day? If I issue a drop request, wait 145 days, then buy my data from brokers, do they have to pay me $20,000 per record they return?
- ransom1538 2mo agoFast workers make $20 an hour in Cali, except for panera bread workers OBVIOUSLY.
- jboggan 2mo agoWell the CPPA (state regulator) just hit General Motors with a $12.75M fine for selling data to two registered data brokers, and made the brokers who received the data delete it all: https://ccpa.world/enforcement/gm-onstar-smart-driver https://ccpa.world/enforcement/gm-onstar-smart-driver Does it apply to Google? Well that's an interesting question. I think the answer is yes but the practical matter is that the CPPA is going to get some legal precedent and some more lawyers on staff before they take on Google. At the current number of requests in the DROP platform they could determine Google is an unregistered data broker and fine them $25B+, but I don't think they are going to do that this year. I think within 36 months they will take the legal victories from prosecuting the first set of unregistered data brokers and apply it to the real players in the data ecosystem. At least, that's what I would do if I were Michael Macko.
- Razengan 2mo agoHow does this apply to shit like not being able to delete your past messages from a Discord server if you get banned from it?
- aw1621107 2mo agoI don't think Discord counts as a data broker under the act as it does not apply to entities with whom you have a "direct relationship"
- sourcecodeplz 2mo agogoing the way of the gdpr eu
- jboggan 2mo agoI've been building the infra for data brokers to connect to DROP (easy), actually effect deletions (hard), and make sure the data stays deleted (harder): forgetmenaut.com DROP is pretty significant considering that it's the first compliance system meant to have an immediate effect (delete the data), backward-looking effect (forward a legally-binding deletion request to everyone that data was sold to or shared with), and a forward-looking effect (never let that record re-enter your system, in perpetuity). This is significantly more tracking and auditing infrastructure than anyone in the industry has ever normally run, not to mention that the request volume is 100-10000x what most of these brokers would process in previous years. We'll see how well companies actually managed to comply when audits are performed for every registered broker in 24 months. I also think the impending prosecutions (and likely bankruptcies) of several unregistered data brokers will encourage the others to take it more seriously.
- Ferret7446 1mo agoHow are you supposed to ensure you never store that info without storing info about what info to never store
- m4xp 2mo agoLet me guess, to delete your data you need to give them your data so that they can keep track that you want your data to be deleted.
- kmfrk 2mo agoOne thing to flag from Europe and GDPR is all the malicious compliance of companies and governments using the law as an excuse to not meet some basic obligations to users like storing and retrieving useful information, or getting pretty basic customer support. It's very reminiscent of companies deliberately making cookie warnings annoying instead of protecting user privacy. Who knows, maybe this will be used to obstruct FOIA too. Because of this, be sure to pay attention to companies getting too clever in interpreting this law, even after it's passed. It ain't over 'til it's over, so be sure to keep fighting it until we actually get the desired outcome, and track the actual compliance with the law. The law itself sounds great, just remember that people often aren't.