Live data from Hacker News

American Data Privacy and Protection Act

congress.gov

131–140 of 313 posts

Re: American Data Privacy and Protection Act

#131
post #48

It's not clear that ADPPA will move forward. The current version preempts California's CCPA/CPRA legislation, and (big surprise) California doesn't like that. But, that's far from the only issue with it. Here's an update from a couple of weeks ago which discusses some of the problems, as well as potential next steps. https://thenexusofprivacy.net/adppa-new-compromise/ And, here's EFF's position: " Americans Deserve M…

Preemption would be an enormous mistake. Federal legislation moves at a glacial pace. In a field like privacy, you may only get to pass one substantial bill every 10 or 15 years. Technology moves too quickly for lawmakers at the Federal level to keep up. States can move much faster. Justice Brandeis popularized the phrase that "[the] states are the laboratories of democracy" and digital privacy law is a text book case of an emerging field that will benefit enormously from iterative experimentation at the state level.

Re: American Data Privacy and Protection Act

#132
post #66

Earlier quoted context omitted.

but not tens of billions of dollars between them.

You can help them if you want! :) https://supporters.eff.org/donate/

The ACLU also does a lot of great privacy work, so donating to them is also a good idea if you care about this stuff. National ACLU does a lot of great work, but I personally suggest giving to your local affiliate https://www.aclu.org/about/affiliates, as they are often the ones who work on local issues that are likely to directly impact you. We do privacy lobbying at the municipal and state level and our local ACLU affiliate has been a huge, huge ally.

There are also other great privacy orgs that are not quite as big but are also fantastic in their own ways, like Restore the Fourth (which also has local chapters like shameless plug) rt4mn) Fight for the Future, Demand Progress, Cato, and Privacy International

Also, If you want to do more then just donate, you can help the EFF with its lobbying efforts by joining the Electronic Frontier Alliance https://www.eff.org/fight We participate, its pretty great.

Re: American Data Privacy and Protection Act

#133
post #29

Earlier quoted context omitted.

Was scanning for this thanks for pointing it out. Some of these banners are infuriating, and if I use firefox containers sometimes I see them over and over, especially if I'm clearing my cookies. It is insane to me that this isn't already a standard.

Standardization was attempted. https://en.wikipedia.org/wiki/Do_Not_Track the tl;dr for that story is that it wasn't mandated to be honored, the industry didn't voluntarily adopt it widely, and when IE 10 tried to turn it on by default and the standard's lead supporter responded by submitting a patch to Apache web server to ignore the DNT signal coming from IE 10 because "does not protect anyone's privacy unless the…

I wonder if a browser plugin that utilizes AI would work as a sidestep to a standardized cookie dialog. Granted someone would have to build such a tool and standardization seems inevitable at some point. Shouldn't be too difficult to build something like that.

Re: American Data Privacy and Protection Act

#135
post #27

You can also see which companies sent lobbyists to work on this bill. https://www.opensecrets.org/federal-lobbying/bills/summary?c...

The first thing to know about US Laws/Bills is that whatever they name it, it typically achieves the opposite

Completely, especially if it has the words "Digital", "Online" or "Data". I haven't read the bill or read about the bill but I'd wager a coffee there's also some form of entertainment/copyright industry hostility in there.

I'm really trying not to be cynical here, but I started so I might as well finish. Step #2 is if it does happen to pass, the parts of the bill that are actually consumer protections will be unenforceable, be ruled unconstitutional or have unintended negative consequences. The bad parts of the law will have no issues in the courts or with enforcement. They, too, will have unintended added negative consequences.

Re: American Data Privacy and Protection Act

#136

Earlier quoted context omitted.

The first thing to know about US Laws/Bills is that whatever they name it, it typically achieves the opposite

I assume "Data Privacy" means privacy for the company that collected the data and "Protection" means protection from the people they collected it from.

The U.S. government makes often use of the data that many companies keep about us. Android geofencing is my clasic example for non tech.

Re: American Data Privacy and Protection Act

#137

Earlier quoted context omitted.

Only if it's not a highly contentious issue. Otherwise the bigger states just go "We control X amount of the American population/economy, and thus we are going to enforce our own law anyway " Granted they would be in the wrong since this is clearly and unambiguously interstate commerce, but that hasn't stopped them before

Its not unambiguous. Google is based in CA, I am based in CA. Packets may go across state lines, but the commercial transaction (a search query) has occurred between two CA entities and should fall under state law.

It doesn't work like that. Once Congress enacts something then it can be preempted by federal law. Just because the activity took place in a single state doesn't mean that the Federal courts don't have jurisdiction. Erisa is a good example.

Re: American Data Privacy and Protection Act

#138
post #116

Earlier quoted context omitted.

It's almost like blindly calling for regulation without accounting for the political/monetary influence of those being regulated is a bad idea or something

> blindly calling for regulation [...] is a bad idea What do you expect people to do instead?

Call for individual protections, possibly with a solvent soaked rag in a bottle, typically.

Re: American Data Privacy and Protection Act

#139
post #7

> (B) any time beyond the initial 2 times described in subparagraph (A), may allow the individual to exercise such right for a reasonable fee for each request. Paying any sum of money to receive a copy of or request to delete my private data is unreasonable in nature.

I mean, at our company, GDPR requests have to cost at least $50 a pop. It goes to a human team to review and process with a dedicated legal representative.

Sounds like an appropriate cost of doing business with data. If you don’t want to pay for it, collect less data.
Post reply on HN