Live data from Hacker News

American Data Privacy and Protection Act

congress.gov

111–120 of 313 posts

Re: American Data Privacy and Protection Act

#111
post #90
post #37

Just a reminder any email you have online that is over six months old can be read without a warrant.

Hm, I have 10 years worth of emails in my dovecot, on my metal, in my basement, online. Can you please describe how can it be read without a warrant by people who don't have my imap password or wheel ssh key to my server?

Can you describe how it could be read with a warrant, or how it's relevant at all to people who have email accounts with online services?

Re: American Data Privacy and Protection Act

#112
post #7

> (B) any time beyond the initial 2 times described in subparagraph (A), may allow the individual to exercise such right for a reasonable fee for each request. Paying any sum of money to receive a copy of or request to delete my private data is unreasonable in nature.

This is normal: https://www.techrepublic.com/article/how-to-request-your-per... >Although, the ICO also notes that a firm may charge a “reasonable fee” when “a request is manifestly unfounded or excessive, particularly if it is repetitive.” Privacy request shouldn't enable mechanisms of denial of service type attacks against companies.

Maybe they should automate the requests then. There's zero reason why they couldn't just write something where you log into your account and click "download my data."

These companies are happy to harvest up all your data, run all this crazy automation, spend millions analyzing algorithms, setting up machine learning, NFTs, run datacenters, networks, etc etc, but they can't figure out how to automate GDPR requests? FUCKING BULLSHIT.

There is literally zero reason why a data request should add any burden to a tech company.

Re: American Data Privacy and Protection Act

#113

Earlier quoted context omitted.

That is incredibly shortsighted considering one of the prime ways the US Government skirts protections against domestic data collection is by simply buying it from private entities.

There's a large difference though between what governments could presumably buy from ad trackers or data warehouses and what they can get by intercepting unencrypted web traffic at the ISP level.

Wouldn't it be the same if the ISP sold the gov. the extracted info they want ?

In this setting the gov can hint at what data it wants, and private parties will manage to get it for resale.

Re: American Data Privacy and Protection Act

#114
post #27

You can also see which companies sent lobbyists to work on this bill. https://www.opensecrets.org/federal-lobbying/bills/summary?c...

The first thing to know about US Laws/Bills is that whatever they name it, it typically achieves the opposite

Sadly true.

Re: American Data Privacy and Protection Act

#115

Earlier quoted context omitted.

> Privacy request shouldn't enable mechanisms of denial of service type attacks against companies. How would this even happen? I genuinely don't understand what you mean.

Users don't like a company, they automatically spam the company with large numbers of requests for personal information which they would legally be required to provide.

Guess they'd better figure out how to get people their data in a more rapid manner. I guess they could use a computer or something to automate it so that users can just click a button to download their data.

I mean, what year is this? We've been hearing "automate it, automate it, etc" for years and years now. But to get your personal data, these companies just throw up their hands and say that it's too hard?

Re: American Data Privacy and Protection Act

#116
post #62

Earlier quoted context omitted.

Regulatory capture.

It's almost like blindly calling for regulation without accounting for the political/monetary influence of those being regulated is a bad idea or something

> blindly calling for regulation [...] is a bad idea

What do you expect people to do instead?

Re: American Data Privacy and Protection Act

#117
post #78
post #3

I see they are also annoyed at cookie banners: > SEC. 210. UNIFIED OPT-OUT MECHANISMS. For the rights established under sections 204(b) and (c), and section 206(c)(3)(D) not later than 18 months after the date of enactment of this Act, the Commission shall establish one or more acceptable privacy protective, centralized mechanisms, including global privacy signals such as browser or device privacy settings, for indiv…

They need to specify that this has to work in an anonymous, per device way (like DNT). Otherwise, google could claim its current policies are compliant. ("Just log in if you want to be 'anonymous'...")

Google does not rely on a user being logged in. Go to adsettings.google.com in a logged out state, for example. I'm not sure what you're referring to.

Re: American Data Privacy and Protection Act

#118
post #27

You can also see which companies sent lobbyists to work on this bill. https://www.opensecrets.org/federal-lobbying/bills/summary?c...

The first thing to know about US Laws/Bills is that whatever they name it, it typically achieves the opposite

I assume "Data Privacy" means privacy for the company that collected the data and "Protection" means protection from the people they collected it from.

Re: American Data Privacy and Protection Act

#119

Earlier quoted context omitted.

The problem is, "reasonable" is subjective. Things like this need to be tethered to something. "The fee may not exceed 50% of the hourly federal minimum wage."

That’s just not true. “Reasonable” is a binding term used in contracts all of the time. The court system is extremely experienced in determining what is and is not reasonable.

Much like passing a bill to find out what's in it, going to court to discover the rules is not a healthy way for society to run.

Re: American Data Privacy and Protection Act

#120

Ten years or so ago, I was participating in a small business roundtable discussion with one of our state senators. At the time, I ran a consumer research agency and would often have multinational projects involving consumer data collection in both the US and EU; this is before GDPR had become ratified, but Safe Harbor was failing and there was ambiguity about what the future state would look like. Of the 15 or 20 bus…

> I maintain that it would be less complicated, less expensive, and more human-friendly to use data privacy rules as globally universal as can be achieved.

I think this is a bit naive. As someone who has had to dwell a lot on the specific nuances of German privacy laws vs GDPR or South Korea's, I have come to the conclusion that conflicting privacy laws are a designed feature.

I think lawmakers certainly have consumer protection as one of their goals, most privacy legislation has many features intended to benefit domestic industries at the expense of foreign ones. Or to benefit national security in some way (such as requirements for certain types of data to be stored on servers inside the country).

Even if the US was to homogenize with GDPR in some way, I wouldn't doubt that the EU would fast follow with a slightly different spin on it just to give US tech companies an extra set of hoops to jump through.

In a way, this is already how safety regulations work in the automobile industry.

Post reply on HN