Just a reminder any email you have online that is over six months old can be read without a warrant.
Hm, I have 10 years worth of emails in my dovecot, on my metal, in my basement, online. Can you please describe how can it be read without a warrant by people who don't have my imap password or wheel ssh key to my server?
American Data Privacy and Protection Act
111–120 of 313 posts
Re: American Data Privacy and Protection Act
#112> (B) any time beyond the initial 2 times described in subparagraph (A), may allow the individual to exercise such right for a reasonable fee for each request. Paying any sum of money to receive a copy of or request to delete my private data is unreasonable in nature.
This is normal: https://www.techrepublic.com/article/how-to-request-your-per... >Although, the ICO also notes that a firm may charge a “reasonable fee” when “a request is manifestly unfounded or excessive, particularly if it is repetitive.” Privacy request shouldn't enable mechanisms of denial of service type attacks against companies.
These companies are happy to harvest up all your data, run all this crazy automation, spend millions analyzing algorithms, setting up machine learning, NFTs, run datacenters, networks, etc etc, but they can't figure out how to automate GDPR requests? FUCKING BULLSHIT.
There is literally zero reason why a data request should add any burden to a tech company.
Re: American Data Privacy and Protection Act
#113Earlier quoted context omitted.
That is incredibly shortsighted considering one of the prime ways the US Government skirts protections against domestic data collection is by simply buying it from private entities.
There's a large difference though between what governments could presumably buy from ad trackers or data warehouses and what they can get by intercepting unencrypted web traffic at the ISP level.
In this setting the gov can hint at what data it wants, and private parties will manage to get it for resale.
Re: American Data Privacy and Protection Act
#114Re: American Data Privacy and Protection Act
#115Earlier quoted context omitted.
> Privacy request shouldn't enable mechanisms of denial of service type attacks against companies. How would this even happen? I genuinely don't understand what you mean.
Users don't like a company, they automatically spam the company with large numbers of requests for personal information which they would legally be required to provide.
I mean, what year is this? We've been hearing "automate it, automate it, etc" for years and years now. But to get your personal data, these companies just throw up their hands and say that it's too hard?
Re: American Data Privacy and Protection Act
#116Earlier quoted context omitted.
Regulatory capture.
It's almost like blindly calling for regulation without accounting for the political/monetary influence of those being regulated is a bad idea or something
What do you expect people to do instead?
Re: American Data Privacy and Protection Act
#117I see they are also annoyed at cookie banners: > SEC. 210. UNIFIED OPT-OUT MECHANISMS. For the rights established under sections 204(b) and (c), and section 206(c)(3)(D) not later than 18 months after the date of enactment of this Act, the Commission shall establish one or more acceptable privacy protective, centralized mechanisms, including global privacy signals such as browser or device privacy settings, for indiv…
They need to specify that this has to work in an anonymous, per device way (like DNT). Otherwise, google could claim its current policies are compliant. ("Just log in if you want to be 'anonymous'...")
Re: American Data Privacy and Protection Act
#118You can also see which companies sent lobbyists to work on this bill. https://www.opensecrets.org/federal-lobbying/bills/summary?c...
The first thing to know about US Laws/Bills is that whatever they name it, it typically achieves the opposite
Re: American Data Privacy and Protection Act
#119Earlier quoted context omitted.
The problem is, "reasonable" is subjective. Things like this need to be tethered to something. "The fee may not exceed 50% of the hourly federal minimum wage."
That’s just not true. “Reasonable” is a binding term used in contracts all of the time. The court system is extremely experienced in determining what is and is not reasonable.
Re: American Data Privacy and Protection Act
#120Ten years or so ago, I was participating in a small business roundtable discussion with one of our state senators. At the time, I ran a consumer research agency and would often have multinational projects involving consumer data collection in both the US and EU; this is before GDPR had become ratified, but Safe Harbor was failing and there was ambiguity about what the future state would look like. Of the 15 or 20 bus…
I think this is a bit naive. As someone who has had to dwell a lot on the specific nuances of German privacy laws vs GDPR or South Korea's, I have come to the conclusion that conflicting privacy laws are a designed feature.
I think lawmakers certainly have consumer protection as one of their goals, most privacy legislation has many features intended to benefit domestic industries at the expense of foreign ones. Or to benefit national security in some way (such as requirements for certain types of data to be stored on servers inside the country).
Even if the US was to homogenize with GDPR in some way, I wouldn't doubt that the EU would fast follow with a slightly different spin on it just to give US tech companies an extra set of hoops to jump through.
In a way, this is already how safety regulations work in the automobile industry.