Earlier quoted context omitted.
The false legal threat is particularly galling, but this absolutely should have gone through IRB even without it. Someone should have had to at least consider the impact on recipients of the messages before they were sent. IRB review is typically required even for just simple research surveys.
How is a reminder of the law a legal threat? More specifically when you feel like you're not impacted by this law, it's as far from a legal threat as could be.
CCPA Scam – Human subject research study conducted by Princeton University
251–260 of 353 posts
Re: CCPA Scam – Human subject research study conducted by Princeton University
#252As a counterpoint here I don't consider this study or the Linux kernel study human subject research unless we define human subject research so broadly that the definition essentially becomes meaningless. As a side note I find the "outrage" about these small academic studies quite hipocritical. This is a community where a significant proportion of people work in related to ads/clicks who constantly experiment on human…
Re: CCPA Scam – Human subject research study conducted by Princeton University
#253The study FAQ claims: > What happens if a website ignores an email that is part of this study? > We are not aware of any adverse consequences for a website declining to respond to an email that is part of this study. But the email sent out states: > I look forward to your reply without undue delay and at most within 45 days of this email, as required by Section 1798.130 of the California Civil Code. So the email very…
>So the email very clearly states that there is an adverse consequence for a failure to respond, namely a violation of the California Civil Code.
I've read and re-read (and read many comments) but where is the adverse consequence stated?
Re: CCPA Scam – Human subject research study conducted by Princeton University
#254Earlier quoted context omitted.
* When you do something to people to see how they act, it's a human experiment. The purpose of this study was officially "to understand how websites would respond to real users" * The participants / subjects of the study are people, not "websites" as the study claims. Websites don't read and respond to emails, people do. * The participants of this study were selected without their consent * The participants were not…
> When you do something to people to see how they act, it's a human experiment. All AB testing is a human experiment?
Re: CCPA Scam – Human subject research study conducted by Princeton University
#255Serious question: why should academic institutions be held to a higher standard than commercial ones? Google and Facebook, to just name two, routinely perform human subject research without informed consent as a matter of course. That's what A/B testing is. Ethically speaking the fine print in the ToS obviously isn't actually informed consent, even if the law says it is. I don't see why being a for-profit company sho…
I thought similar - it's such a routine and basic task to set up and run A/B testing to measure and optimize websites and apps for preferred conscious or subconscious response to visual stimuli. If this is a human subject research and human subject research without consent is a crime against humanity, most if not any proper web developer and the whole Web industry collectively are technically guilty of such a mouthfu…
Re: CCPA Scam – Human subject research study conducted by Princeton University
#256Earlier quoted context omitted.
This is incorrect. It's only human subjects research if the researcher is obtaining data about a human. This is the "about whom" requirement. A classic example is calling a business and asking someone about the products and prices they offer. That's not human subjects research.
You realize that the internal regulation is wrong, right? Like the semantic distinction doesnt matter because nobody gives a fuck about Princeton’s organizational policy.
Re: CCPA Scam – Human subject research study conducted by Princeton University
#257It is interesting in the study web page ( https://privacystudy.cs.princeton.edu/ ) that they consistently mention contacting "websites" instead of "people." As if a website is some autonomous thing that can communicate with a researcher. I wouldn't be sleeping well if I were involved in this study. There is no way an IRB could determine that this is not human subjects research if you're emailing people and asking the…
> I wouldn't be sleeping well if I were involved in this study. There is no way an IRB could determine that this is not human subjects research if you're emailing people and asking them anything. Do you have a citation for this? What I'm seeing from random Googling is that you have to be obtaining information about the person for it to count. If I were researching, say, price trends in some commodity and I called up…
The word "you" appears in every question.
To quote my IRB training (citiprogram.org):
"Most research in the social and behavioral sciences involves gathering information about individuals. However, some research that involves interactions with people does not meet the regulatory definition of research with human subjects because the focus of the investigation is not the opinions, characteristics, or behavior of the individual. In other words, the information being elicited is not about the individual ("whom"), but rather is about "what." For example, if a researcher calls the director of a shelter for battered women and asks her for the average length of stay of the women who use the shelter, that inquiry would not meet the definition of research with human subjects because the information requested is not "about" the director. If the researcher interviewed the director about her training, experience, and how she defines the problem of battering, then the inquiry becomes about her - and therefore "about whom."
The current example is similar, in my opinion, to "how she defines the problem of battering" which the IRB training identifies as human subjects research. The people receiving the researchers' email in the current study are being ask to define the way they interpret and comply with a legal statute.
I can accept that some people don't see the information requested as being "about whom" and therefore is not human subjects research. But the fact that people who have received this email have panicked indicates that the recipients, at least, felt that the questions were more than merely recording impersonal data about their websites.
Re: CCPA Scam – Human subject research study conducted by Princeton University
#258It is interesting in the study web page ( https://privacystudy.cs.princeton.edu/ ) that they consistently mention contacting "websites" instead of "people." As if a website is some autonomous thing that can communicate with a researcher. I wouldn't be sleeping well if I were involved in this study. There is no way an IRB could determine that this is not human subjects research if you're emailing people and asking the…
> I wouldn't be sleeping well if I were involved in this study. There is no way an IRB could determine that this is not human subjects research if you're emailing people and asking them anything. Do you have a citation for this? What I'm seeing from random Googling is that you have to be obtaining information about the person for it to count. If I were researching, say, price trends in some commodity and I called up…
If you called up companies' sales lines to ask for prices, that's just gathering facts.
If you called up companies' sales lines to see what happens when you ask them for prices for things they don't sell, or to see if they're willing to accept a bribe, or to see if they respond with different prices when you lie to them about who you are, you're researching human behavior.
In this case, they are testing what procedures, if any, companies have in place for handling CCPA and GDPR law, by posing as nonexistent customers and making potentially bogus and misleading requests under the terms of those laws.
This is like performing research on retail refund practices by going into a bunch of shops and seeing how they handle being asked for a refund for an item you didn't buy from there in the first place.
There's a more ethical way to do that study, though, which is to actually buy something from the store first, then go back and try to refund it.
Similarly, there's a more ethical way to discover how websites handle CCPA/GDPR requests, which is to use the website first, and determine in the course of that what possible information about you the website should have; then, within the terms of your rights under CCPA/GDPR, to contact them and make reasonable and legitimate requests to see if/how they are able to handle them.
Re: CCPA Scam – Human subject research study conducted by Princeton University
#259I am surprised by the reactions here. I did not receive that e-mail but I receive all sort of weird inquiries for my websites, (at least 2 or 3 per day). I don't understand why people are so mad about it or even panicking.
With regard to GDPR, the "respond within x" is simply not applicable. The one month period is strictly for any requests concerning Article 15 through 22 and none of the questions are talking about any of that.
Now, if one of the questions was something along the lines of "do you process any information related to me?" then it would potentially fall under Article 15.1 and would require a timely response. IANAL, however, I think in such cases you could simply point to a privacy policy, which you are already required to have.
Re: CCPA Scam – Human subject research study conducted by Princeton University
#260So it'd be perfectly reasonable to conduct an experiment to see how certain Princeton researches react to emails telling them bad things are going to happen to them and their families and pets, right? "If thrown from a tall building how high do you think you'd bounce?"
No, it wouldn't. One is a polite but firm email reminding a website administrator of their obligations under the law, and the other is a thinly-veiled threat of bodily harm.
It is not, because OP does not have the obligations that the email claimed they have.