Earlier quoted context omitted.
That's a very generous assumption. Especially in the context of an email sent under false pretenses and a false name and an anonymous domain. It's either a veiled threat or a serious error. Either way, this study needed more oversight.
Calls for more oversight are calls for more bureaucratic procedures and this whole situation is already bureaucracy gone mad.
CCPA Scam – Human subject research study conducted by Princeton University
231–240 of 353 posts
Re: CCPA Scam – Human subject research study conducted by Princeton University
#232Earlier quoted context omitted.
Sounds like a good place for a class action! Those legal fees ought to come out of Princeton.
Why? If that's indeed the law, then it's up to the website owner to comply. Whether it's Princeton or a private individual writing the email doesn't matter.
The emails were from fake people. So any work preparing any response regarding those fake peoples personal data is obviously not required by law. They don't exist.
And, as pointed out elsewhere in the thread, the researchers are probably not protected by either of CCPA or GDPR.
Re: CCPA Scam – Human subject research study conducted by Princeton University
#233It is interesting in the study web page ( https://privacystudy.cs.princeton.edu/ ) that they consistently mention contacting "websites" instead of "people." As if a website is some autonomous thing that can communicate with a researcher. I wouldn't be sleeping well if I were involved in this study. There is no way an IRB could determine that this is not human subjects research if you're emailing people and asking the…
Do you have a citation for this? What I'm seeing from random Googling is that you have to be obtaining information about the person for it to count.
If I were researching, say, price trends in some commodity and I called up several companies' sales lines and asked for their current price that looks like it would not be human subject research despite the fact that I'm talking to a human to get each company's price.
If I were researching pay trends at those companies and called up their sales lines and asked the people who answered how much they were paid it would be human subject research.
Re: CCPA Scam – Human subject research study conducted by Princeton University
#234https://news.ycombinator.com/item?id=29539266
I was concerned enough about this that I updated our project privacy policy with pre-emptive wording about CCPA (now reverted):
https://web.archive.org/web/20211218125309/https://textpatte...
I'm mildly annoyed about the time I wasted on this, but I guess that in itself is anecdata for this study.
Re: CCPA Scam – Human subject research study conducted by Princeton University
#235Re: CCPA Scam – Human subject research study conducted by Princeton University
#236Hm, they use https://tranco-list.eu/ for top website list and not alexa. Whatever happened to Alexa ratings?
Re: CCPA Scam – Human subject research study conducted by Princeton University
#237Re: CCPA Scam – Human subject research study conducted by Princeton University
#238Earlier quoted context omitted.
If I had to guess, the wording is in the study's FAQ is carefully chosen: "an application detailing our research methods" doesn't necessarily mean "an application with the verbatim text of the emails we planned to send, including our thinly veiled legal threat at the end." Not trying to turn this thread into a generic flameware against "academic" research methods, but this whole things seems oddly reminiscent of the…
The wording of the message is one hell of a detail to leave out when detailing your research methods.
The IRB review determination is going to be based on the typology of what you are doing not the internal contents for the most part. Once they decide the level of appropriate review then they will typically look at the ‘details’.
Re: CCPA Scam – Human subject research study conducted by Princeton University
#239Some jurisdictions consider IP addresses to be personal identifying information, and so if you run a web site that logs the IP addresses of visitors you should generally try to be aware of the privacy laws in any jurisdiction that might think its laws apply to you. These fall into three groups. First, there are those jurisdictions in which you and/or your site are actually located. You almost always have to care abou…
I wholly support the CCPA and GDPR. They have their issues, but they’re big steps in the right direction. In the case of the CCPA, nothing I do is subject to it as it applies only to business, and only to those 1) making at least $25M in revenue, 2) handling the information of at least 50,000 Californians, or 3) making at least half their annual revenue from selling Californian’s personal information. I’m running a f…
Thus to avoid unpleasant surprised like the one you had, people with websites should add "check to see if my site has any obligations under privacy laws" to the list of routine things they do to maintain the site, and then plan accordingly.
If that check reveals that they aren't doing anything that places any obligation upon them, they can write a canned response to send back to anyone who asks.
Re: CCPA Scam – Human subject research study conducted by Princeton University
#240Earlier quoted context omitted.
Not sure I follow your question. An example of something that's not human subjects research would be emailing people who have websites and asking about their privacy policy. An example of something that is human subjects research would be emailing people who have websites and asking what inspired them to start a website. I realize that may seem like a subtle difference, but it's an important distinction from an IRB p…
I think one problem is that with small websites run by a single person or small group, a person can feel the website is an extension of herself. So a question about the website in some way becomes a question about the person.