I've gotten 4 of these mails to 4 of my domains (including my personal domain used just for email, and a one-page documentation site for an open source library)... 2 about CCPA and 2 about GDPR. They also gave me a lot of anxiety for no reason. Looking at the responses on Twitter, a lot of websites spent real money consulting lawyers before responding to these mails due to the thinly veiled threat of legal repercussi…
Sounds like a good place for a class action! Those legal fees ought to come out of Princeton.
CCPA Scam – Human subject research study conducted by Princeton University
331–340 of 353 posts
Re: CCPA Scam – Human subject research study conducted by Princeton University
#332Earlier quoted context omitted.
You did not lawyer up, but some other recipient might have had. Is there a ground for a lawsuit here for... well.. fraud? After all, resources were spent; surely, there was some stress.. Yeah, I agree with you.
I'm not a lawyer, clearly, but I'd say so. Some people are replying to him on Twitter saying that they've spent money here and asking who to send the invoice to.
Re: CCPA Scam – Human subject research study conducted by Princeton University
#333Earlier quoted context omitted.
If I had to guess, the wording is in the study's FAQ is carefully chosen: "an application detailing our research methods" doesn't necessarily mean "an application with the verbatim text of the emails we planned to send, including our thinly veiled legal threat at the end." Not trying to turn this thread into a generic flameware against "academic" research methods, but this whole things seems oddly reminiscent of the…
> Not trying to turn this thread into a generic flameware against "academic" research methods, but this whole things seems oddly reminiscent of the "let's try to insert malicious code into Linux" fiasco [1]. I'm conceptually fine with generic passive tools like web crawlers to conduct research, but since when did the internet become a place where nonconsensual interactive research became fine? In a very real sense, e…
I think the difference here is that the user requests a page with a web browser (which could be argued as giving consent to view the contents) while the person that received this email didn't request the experimental email (and therefore didn't consent to the experiment).
Re: CCPA Scam – Human subject research study conducted by Princeton University
#334Earlier quoted context omitted.
Sure, of course not, but a near panic attack still seems a bit... out of proportion.
If you have run a business small enough that you don't have a lawyer on standby then you might understand a little better. I have, and received a real legal threat. A bit of panic as you contemplate the financial devastation & wreckage it might leave your life in... well, a little bit of panic is actually a pretty reasonable response there. If you've been in that situation and been totally calm about it then that's a…
Re: CCPA Scam – Human subject research study conducted by Princeton University
#335Earlier quoted context omitted.
> Ethical questions arise when you ask people to take specific actions in order to measure their reactions "Answer my questions within 45 days or I will sue you." That seems to read like a demand for a specific action.
That's not what the message said. The message asked specific questions about data processing in regards to privacy regulations. Anyone could have sent this message. Hell, i have been on both ends of this message (with CNIL not CCPA) and as an honest person taking part in non-profits i can assure you there's nothing to feel threatened about. Maybe in your Silicon Valley culture where lawsuits are more easily triggered…
The message said:
> I look forward to your reply without undue delay and at most within 45 days of this email, as required by Section 1798.130 of the California Civil Code.
This is clearly a threat of legal action. Your experiences with CNIL might be misleading. There are few risks of getting bankrupt because of a frivolous lawsuit in Europe, but this is a very real risk in the US. Even if you are in the right and did nothing wrong.
Re: CCPA Scam – Human subject research study conducted by Princeton University
#336It is interesting in the study web page ( https://privacystudy.cs.princeton.edu/ ) that they consistently mention contacting "websites" instead of "people." As if a website is some autonomous thing that can communicate with a researcher. I wouldn't be sleeping well if I were involved in this study. There is no way an IRB could determine that this is not human subjects research if you're emailing people and asking the…
In my understanding (from a french cultural context), asking people questions as part of a field study is not human subjects research. Ethical questions arise when you ask people to take specific actions in order to measure their reactions, not when you're asking about the status quo.
The underlying ethos is that researchers should respect the people who are participating in their studies. People should know that you are conducting a study, the aims of the study, and choose whether or not they want to participate.
Re: CCPA Scam – Human subject research study conducted by Princeton University
#337Earlier quoted context omitted.
If you have run a business small enough that you don't have a lawyer on standby then you might understand a little better. I have, and received a real legal threat. A bit of panic as you contemplate the financial devastation & wreckage it might leave your life in... well, a little bit of panic is actually a pretty reasonable response there. If you've been in that situation and been totally calm about it then that's a…
These businesses should have been aware of this already. It is their own fault for not being aware of their status and preparing for it. In no way anyone but they are to blame in this case.
Re: CCPA Scam – Human subject research study conducted by Princeton University
#338Without getting into the question of whether this study involved human subject research, I find a lot of the anxiety and paranoia unwarranted. Companies to which these laws apply should already have a process in place to deal with subject access requests. Complying with relevant laws is just part of doing business. All the other site owners could have figured out with a bit of googling that the laws don't apply to th…
The US legal system is quite different; litigants are responsible for their own legal fees[0] and frivolous lawsuits[1] are common.
[0] https://en.wikipedia.org/wiki/American_rule_(attorney's_fees)
[1] https://www.azag.gov/press-release/serial-litigant-permanent...
Re: CCPA Scam – Human subject research study conducted by Princeton University
#339Earlier quoted context omitted.
Sounds like a good place for a class action! Those legal fees ought to come out of Princeton.
On what basis? Why can't we reasonably expect these sites to follow the laws? Just that they have in past survived being unethical and not following them does mean they have some sort of claim when they scramble to fix their failures.
A huge amount of the people that got this were ethical, individual, not corporate, not profit.