Live data from Hacker News

CCPA goes into effect January 1, but nobody’s sure how the new rules work

latimes.com

21–30 of 129 posts

Re: CCPA goes into effect January 1, but nobody’s sure how the new rules work

#21

Good.

It's good that one state can force it's hand over the other 49?

This single state contains Silicon Valley and is 14% of the US economy. Jurisdictionally, it could be challenged - but again, a business could just decline to do business with all customers in CA.

btw - nothing new here (fta): "Big companies are signing deals with firms that specialize in compliance".

Big companies already hire compliance companies for a large number of other regulatory requirements. This is just yet another such requirement - and it's still being hammered out in a public comment period prior to going into law.

Re: CCPA goes into effect January 1, but nobody’s sure how the new rules work

#22
post #16

Earlier quoted context omitted.

It's good that each state can determine the laws applicable in its jurisdiction. If you don't want to comply, don't do business in California.

Of course the question when you want to block California or run different code for users in California is "how do you legally and reliably tell if a user is in California"; eg. if they're using a VPN to new york could they sue you/file a complaint and win? What if Maxmind's IP database is outdated and you miss a bunch of California users?

Could this be handled with a single checkbox stating that you are either in CA or a CA resident/etc?

Re: CCPA goes into effect January 1, but nobody’s sure how the new rules work

#23
post #16

Earlier quoted context omitted.

It's good that one state can force it's hand over the other 49?

It's good that each state can determine the laws applicable in its jurisdiction. If you don't want to comply, don't do business in California.

Within limits. There is stuff in the Constitution about interstate commerce. For instance, California had to refund me an "emissions fee" after I moved here with a car bought elsewhere that didn't have the same emissions standards. It was found to be unconstitutional. Other climate initiatives are facing similar objections.

https://www.mofo.com/resources/insights/the-commerce-clause-...

Re: CCPA goes into effect January 1, but nobody’s sure how the new rules work

#25

Earlier quoted context omitted.

You mean like all of the US news sites that just firewall off EU citizens at the moment?

I do not understand why they do that. If a US news outlet has no presence in the EU there is nothing which can be done if they do not follow EU rules.

It’s just a passive-aggressive hissy fit. The cost of writing the middleware to write out your angsty nonsense is higher than the cost of writing the middleware to just remove all cookies from every request. The EU detection logic is the same in both cases.

Re: CCPA goes into effect January 1, but nobody’s sure how the new rules work

#26
post #22

Earlier quoted context omitted.

Of course the question when you want to block California or run different code for users in California is "how do you legally and reliably tell if a user is in California"; eg. if they're using a VPN to new york could they sue you/file a complaint and win? What if Maxmind's IP database is outdated and you miss a bunch of California users?

Could this be handled with a single checkbox stating that you are either in CA or a CA resident/etc?

I suppose so, but it's a similar situation as GDPR/cookie consent when you need to perform 0-interaction data collection like running Ads for incognito users or creating a session that might also be used to track you on other websites. Maybe these use cases will just fall out of play as compliance when using them gets harder (which would not be a bad thing).

Re: CCPA goes into effect January 1, but nobody’s sure how the new rules work

#28

Earlier quoted context omitted.

It's good that one state can force it's hand over the other 49?

Personally I think it is appropriate. California has long been known to do such things, for instance having different requirements for cars regarding emissions. In general I think California is using their huge size and role (obviously, as home to most of the dominant internet companies like Google and Apple and Facebook) to push the rest of the country forward.

Or backward. Depending on one's view of any particular policy that California does that the other states choose not to.

Re: CCPA goes into effect January 1, but nobody’s sure how the new rules work

#29

How are these different from GDPR? Most global companies should already have most of this in place, so it will just hurt the small businesses which has yet to expand outside the states. Is there some limit to company size here to avoid that?

For starters, one thing that the big global companies did was carefully internally segment EU/non-EU users so that they make the technical implementation and business processes to comply with GDPR, but apply these things only when necesseary, and keep the data processing of their (very profitable) USA users the same. A small or medium website most likely went either with privacy-for-everyone or ignore-the-GDPR, but any large global company can afford separate flows and has large enough financial incentives in mining that data so that it makes sense to differentiate.

For example, Equifax has a bunch of subsidiaries in EU who have to follow GDPR - and mostly are following it, or at least make a decent show in attempting so; but the main USA Equifax business could not bother with it, to great benefit of Equifax itself and detriment of all the USA citizens whose data Equifax mismanaged.

Post reply on HN