Live data from Hacker News

CCPA Will Hit Dev Teams Harder Than GDPR

tonic.ai

31–40 of 179 posts

Re: CCPA Will Hit Dev Teams Harder Than GDPR

#31
post #28
post #23

Earlier quoted context omitted.

> So if I forward all of the data to another company outside of CA, does my company count as processing data? You are still processing that data. Part of processing that data involves you shipping it off... > What if the code that forwards that data is written by another company and I'm just hosting it on my site? Everything goes through their code and I'm paid to just setup a website to host their code. You are as r…

>You are still processing that data. Part of processing that data involves you shipping it off... >The data is moving through your servers. So if a random company gets breached, everyone involved from cloud providers to ISPs are also responsible because they facilitated moving and storing the data and they are just hosting code? This is problematic. Cloud providers give you permission to publish code. I could positio…

>So if a random company gets breached, everyone involved from cloud providers to ISPs are also responsible because they facilitated moving and storing the data and they are just hosting code?

ISP's aren't (supposed to be) "storing" that data. They are transferring bits between computers. You on the other hand are hosting a website with some sort of form that people input PII into. You are accepting that PII, whether or not it gets forwarded or not is irrelevant. You are processing it. So do your due diligence, contact your users and let them know what is going on, and speak with a lawyer for more information.

Re: CCPA Will Hit Dev Teams Harder Than GDPR

#32
post #29

I like the general idea and I like that it specifically applies only to organizations with more than $25 million in revenue. Give small startups a break. Does the GDPR also have a lower limit like this? It should.

The criteria is a "one or more of the following" not a combination of them all So if you make more than $25 million, OR your have more than 50k users or devices, OR you make more than 50% of your money selling data

Seems like the second one is the real problem. "50K users or devices" is less than 0.02% market share, even if you have only US customers, and for businesses with margins in the $1/user/year range it doesn't even cover one full time employee.

You can end up with that many users on a side project all of a sudden if it gets posted to the front page of a site like this one.

Re: CCPA Will Hit Dev Teams Harder Than GDPR

#34
post #2

> if a data breach occurs, the law permits consumers to recover up to $750 per incident This is great!

There shouldn't be a cap to liability, this reeks of tort reform-esque legislation.

If my identity gets stolen, there is much more than $750 at stake on my end.

Re: CCPA Will Hit Dev Teams Harder Than GDPR

#35
post #2

> if a data breach occurs, the law permits consumers to recover up to $750 per incident This is great!

Simple, you just add this to clickwrap agreement: The Parties mutually agree that any and all disputes arising from or relating to this Agreement, including the interpretation or application of this Agreement will be submitted exclusively to final and binding arbitration pursuant to the Federal Arbitration Act. The arbitration will be conducted the state of Delaware or such other location as the Parties may agree, by…

Oh are you a lawyer?

Re: CCPA Will Hit Dev Teams Harder Than GDPR

#36
post #2

> if a data breach occurs, the law permits consumers to recover up to $750 per incident This is great!

Simple, you just add this to clickwrap agreement: The Parties mutually agree that any and all disputes arising from or relating to this Agreement, including the interpretation or application of this Agreement will be submitted exclusively to final and binding arbitration pursuant to the Federal Arbitration Act. The arbitration will be conducted the state of Delaware or such other location as the Parties may agree, by…

[deleted]

Re: CCPA Will Hit Dev Teams Harder Than GDPR

#38
post #2

> if a data breach occurs, the law permits consumers to recover up to $750 per incident This is great!

There shouldn't be a cap to liability, this reeks of tort reform-esque legislation. If my identity gets stolen, there is much more than $750 at stake on my end.

It's up to $750 or actual damages if greater.

Re: CCPA Will Hit Dev Teams Harder Than GDPR

#39
post #4

Great article, until the end. Who uses PII in test data derived from real customers? That's just an absurd practice to begin with, and no one who takes security seriously would even consider doing this.

I have never seen a “dev” instance of a DB that wasn’t just a snapshot of the prod DB from earlier. I admit haven’t seen many - but I have seen zero of any other kind (e.g. anonymized or synthetic)

Re: CCPA Will Hit Dev Teams Harder Than GDPR

#40
post #2

> if a data breach occurs, the law permits consumers to recover up to $750 per incident This is great!

Simple, you just add this to clickwrap agreement: The Parties mutually agree that any and all disputes arising from or relating to this Agreement, including the interpretation or application of this Agreement will be submitted exclusively to final and binding arbitration pursuant to the Federal Arbitration Act. The arbitration will be conducted the state of Delaware or such other location as the Parties may agree, by…

I dislike how the minute someone mentions a legal hack, the responses are "oh, are you a lawyer?"

Why not consider this reply on its merits?

Post reply on HN