Live data from Hacker News

American Data Privacy and Protection Act

congress.gov

21–30 of 313 posts

Re: American Data Privacy and Protection Act

#21
Can't read legalese much, and -judging by how these things tend to go- I bet it's butchered beyond recognition before it gets to a vote (if at all). Instead, we should consider a constitutional amendment that enshrines digital privacy as a fundamental human right.

Re: American Data Privacy and Protection Act

#22
post #7

> (B) any time beyond the initial 2 times described in subparagraph (A), may allow the individual to exercise such right for a reasonable fee for each request. Paying any sum of money to receive a copy of or request to delete my private data is unreasonable in nature.

This is normal: https://www.techrepublic.com/article/how-to-request-your-per... >Although, the ICO also notes that a firm may charge a “reasonable fee” when “a request is manifestly unfounded or excessive, particularly if it is repetitive.” Privacy request shouldn't enable mechanisms of denial of service type attacks against companies.

DoS is an understandable concern, but charging for a service is probably one of the least sensible ways to prevent it. To me, it just looks like the most profitable and impeding hurdle that companies can set up to prevent users who want to access their own data. I would be frustrated if any application made me pay even a small fine because they suspect a DoS attack. For example, entering my credit card info because I've searched a phrase too much just isn't efficient.

Re: American Data Privacy and Protection Act

#24
post #7

> (B) any time beyond the initial 2 times described in subparagraph (A), may allow the individual to exercise such right for a reasonable fee for each request. Paying any sum of money to receive a copy of or request to delete my private data is unreasonable in nature.

This is normal: https://www.techrepublic.com/article/how-to-request-your-per... >Although, the ICO also notes that a firm may charge a “reasonable fee” when “a request is manifestly unfounded or excessive, particularly if it is repetitive.” Privacy request shouldn't enable mechanisms of denial of service type attacks against companies.

> Privacy request shouldn't enable mechanisms of denial of service type attacks against companies.

How would this even happen? I genuinely don't understand what you mean.

Re: American Data Privacy and Protection Act

#26
post #7

> (B) any time beyond the initial 2 times described in subparagraph (A), may allow the individual to exercise such right for a reasonable fee for each request. Paying any sum of money to receive a copy of or request to delete my private data is unreasonable in nature.

This is normal: https://www.techrepublic.com/article/how-to-request-your-per... >Although, the ICO also notes that a firm may charge a “reasonable fee” when “a request is manifestly unfounded or excessive, particularly if it is repetitive.” Privacy request shouldn't enable mechanisms of denial of service type attacks against companies.

Strong disagree. There are already other options for malicious actors, most notably Americans with Disability act.

Re: American Data Privacy and Protection Act

#28

Earlier quoted context omitted.

This is normal: https://www.techrepublic.com/article/how-to-request-your-per... >Although, the ICO also notes that a firm may charge a “reasonable fee” when “a request is manifestly unfounded or excessive, particularly if it is repetitive.” Privacy request shouldn't enable mechanisms of denial of service type attacks against companies.

> Privacy request shouldn't enable mechanisms of denial of service type attacks against companies. How would this even happen? I genuinely don't understand what you mean.

Users don't like a company, they automatically spam the company with large numbers of requests for personal information which they would legally be required to provide.

Re: American Data Privacy and Protection Act

#29
post #3

I see they are also annoyed at cookie banners: > SEC. 210. UNIFIED OPT-OUT MECHANISMS. For the rights established under sections 204(b) and (c), and section 206(c)(3)(D) not later than 18 months after the date of enactment of this Act, the Commission shall establish one or more acceptable privacy protective, centralized mechanisms, including global privacy signals such as browser or device privacy settings, for indiv…

Was scanning for this thanks for pointing it out. Some of these banners are infuriating, and if I use firefox containers sometimes I see them over and over, especially if I'm clearing my cookies. It is insane to me that this isn't already a standard.
Post reply on HN