Live data from Hacker News

American Data Privacy and Protection Act

congress.gov

71–80 of 313 posts

Re: American Data Privacy and Protection Act

#71

Earlier quoted context omitted.

This is normal: https://www.techrepublic.com/article/how-to-request-your-per... >Although, the ICO also notes that a firm may charge a “reasonable fee” when “a request is manifestly unfounded or excessive, particularly if it is repetitive.” Privacy request shouldn't enable mechanisms of denial of service type attacks against companies.

> Privacy request shouldn't enable mechanisms of denial of service type attacks against companies. How would this even happen? I genuinely don't understand what you mean.

When GDPR was new, several people sent "nightmare letters", deliberately and publicly designed to cause as much cost and hassle as possible. To my knowledge, no one was punished or even inconvenienced for blatantly abusing the law in this way.

https://duckduckgo.com/?q=gdpr+nightmare+letters

Re: American Data Privacy and Protection Act

#72

SEC. 203. INDIVIDUAL DATA OWNERSHIP AND CONTROL. (e) Verification And Exceptions.— (1) REQUIRED EXCEPTIONS.—A covered entity shall not permit an individual to exercise a right described in subsection (a), in whole or in part, if the covered entity— (C) determines that the exercise of the right would require access to or correction of another individual’s sensitive covered data; or Simple: store all your user data in…

Doubtful any court would accept that practice.

Re: American Data Privacy and Protection Act

#73
post #62

Earlier quoted context omitted.

So basically, this is a mostly toothless law, that requires small companies to follow to the extreme detriment of the large companies... which already likely do the bare minimum. I'm not sure of the term. It's like a regulatory legal barrier that keeps new companies from entering the market.

Regulatory capture.

It's almost like blindly calling for regulation without accounting for the political/monetary influence of those being regulated is a bad idea or something

Re: American Data Privacy and Protection Act

#75

Earlier quoted context omitted.

The problem is, "reasonable" is subjective. Things like this need to be tethered to something. "The fee may not exceed 50% of the hourly federal minimum wage."

GDPR is filled with "reasonableness" expectations and unspecified guidelines that aren't tethered to anything. Why the concern over this one specifically?

Yes because a 99 section 11 chapter law is really easy for small companies to follow…

Re: American Data Privacy and Protection Act

#78
post #3

I see they are also annoyed at cookie banners: > SEC. 210. UNIFIED OPT-OUT MECHANISMS. For the rights established under sections 204(b) and (c), and section 206(c)(3)(D) not later than 18 months after the date of enactment of this Act, the Commission shall establish one or more acceptable privacy protective, centralized mechanisms, including global privacy signals such as browser or device privacy settings, for indiv…

They need to specify that this has to work in an anonymous, per device way (like DNT).

Otherwise, google could claim its current policies are compliant. ("Just log in if you want to be 'anonymous'...")

Re: American Data Privacy and Protection Act

#79
post #6

For those following along at home: So far five states have passed local Data Privacy laws (CA, VA, UT, CT, MA). They are all different. This situation makes it much more likely that federal data privacy legislation will happen: while companies wish they could have 0 laws, they would still much rather prefer 1 law rather than 5 (trending towards 50) different laws that contradict each other. There's a whole buncha spe…

Partial preemption leads to supreme court decisions that lead to near total preemption.

Only if it's not a highly contentious issue. Otherwise the bigger states just go "We control X amount of the American population/economy, and thus we are going to enforce our own law anyway"

Granted they would be in the wrong since this is clearly and unambiguously interstate commerce, but that hasn't stopped them before

Re: American Data Privacy and Protection Act

#80
post #58
post #27

You can also see which companies sent lobbyists to work on this bill. https://www.opensecrets.org/federal-lobbying/bills/summary?c...

Great, we have the usual anti-privacy companies there as well as ByteDance .. what can go wrong.

It's insane enough letting Big Corps lobby your legislature and even write language that eventually gets enshrined as law.

It's even more insane we allow the state-affiliated entities of our adversaries to do this.

Post reply on HN