Live data from Hacker News

American Data Privacy and Protection Act

congress.gov

11–20 of 313 posts

Re: American Data Privacy and Protection Act

#11
Always good to see links to direct text of bills.

Reading the tea leaves a bit, Speaker Pelosi seems dead set against it and I dont think will allow it to be moved as is. she has publicly stated that "states must be allowed to address rapid changes in technology", IE, the bill preempts to many state privacy regulations, esp in California. But as a rule my default assumption for the "real reason" why Pelosi is against something is because she thinks it will harm chance of caucus holding majority in house.

https://pelosi.house.gov/news/press-releases/pelosi-statemen...

Skeptical as I am of her motives / methods, I'm inclined to agree with her in this case. Act should be a floor not a ceiling.

Re: American Data Privacy and Protection Act

#12
post #7

> (B) any time beyond the initial 2 times described in subparagraph (A), may allow the individual to exercise such right for a reasonable fee for each request. Paying any sum of money to receive a copy of or request to delete my private data is unreasonable in nature.

This is normal:

https://www.techrepublic.com/article/how-to-request-your-per...

>Although, the ICO also notes that a firm may charge a “reasonable fee” when “a request is manifestly unfounded or excessive, particularly if it is repetitive.”

Privacy request shouldn't enable mechanisms of denial of service type attacks against companies.

Re: American Data Privacy and Protection Act

#13

Ten years or so ago, I was participating in a small business roundtable discussion with one of our state senators. At the time, I ran a consumer research agency and would often have multinational projects involving consumer data collection in both the US and EU; this is before GDPR had become ratified, but Safe Harbor was failing and there was ambiguity about what the future state would look like. Of the 15 or 20 bus…

I would be interested to hear why you think it has no chance in Senate.

Re: American Data Privacy and Protection Act

#16
post #7

> (B) any time beyond the initial 2 times described in subparagraph (A), may allow the individual to exercise such right for a reasonable fee for each request. Paying any sum of money to receive a copy of or request to delete my private data is unreasonable in nature.

This is normal: https://www.techrepublic.com/article/how-to-request-your-per... >Although, the ICO also notes that a firm may charge a “reasonable fee” when “a request is manifestly unfounded or excessive, particularly if it is repetitive.” Privacy request shouldn't enable mechanisms of denial of service type attacks against companies.

I wonder if a company can be DoS'd via privacy request maybe they are collecting more data than they can effectively handle and that should be re-examined.

Re: American Data Privacy and Protection Act

#17
post #3

I see they are also annoyed at cookie banners: > SEC. 210. UNIFIED OPT-OUT MECHANISMS. For the rights established under sections 204(b) and (c), and section 206(c)(3)(D) not later than 18 months after the date of enactment of this Act, the Commission shall establish one or more acceptable privacy protective, centralized mechanisms, including global privacy signals such as browser or device privacy settings, for indiv…

halle-fuckin-lujah please don't make it some bullshit centralized service where you have to have a specific cookie from a random website to actually use it. please just expand DNT.

Re: American Data Privacy and Protection Act

#18
post #7

> (B) any time beyond the initial 2 times described in subparagraph (A), may allow the individual to exercise such right for a reasonable fee for each request. Paying any sum of money to receive a copy of or request to delete my private data is unreasonable in nature.

This is normal: https://www.techrepublic.com/article/how-to-request-your-per... >Although, the ICO also notes that a firm may charge a “reasonable fee” when “a request is manifestly unfounded or excessive, particularly if it is repetitive.” Privacy request shouldn't enable mechanisms of denial of service type attacks against companies.

The problem is, "reasonable" is subjective. Things like this need to be tethered to something. "The fee may not exceed 50% of the hourly federal minimum wage."

Re: American Data Privacy and Protection Act

#19
post #7

> (B) any time beyond the initial 2 times described in subparagraph (A), may allow the individual to exercise such right for a reasonable fee for each request. Paying any sum of money to receive a copy of or request to delete my private data is unreasonable in nature.

This is normal: https://www.techrepublic.com/article/how-to-request-your-per... >Although, the ICO also notes that a firm may charge a “reasonable fee” when “a request is manifestly unfounded or excessive, particularly if it is repetitive.” Privacy request shouldn't enable mechanisms of denial of service type attacks against companies.

I agree privacy request shouldn't enable mechanisms of denial of service type attacks against companies. But I don't think that justifies allowing companies to put in place fees to access personal data.

If cloudflare required people to pay to bypass their denial of service protections... well, I guess I dont know what would happen, other then that I would hate them even more then I already do for all the terrible things they do for my experience as a default tor browser user.

Post reply on HN