Live data from Hacker News

American Data Privacy and Protection Act

congress.gov

231–240 of 313 posts

Re: American Data Privacy and Protection Act

#231
post #21

Can't read legalese much, and -judging by how these things tend to go- I bet it's butchered beyond recognition before it gets to a vote (if at all). Instead, we should consider a constitutional amendment that enshrines digital privacy as a fundamental human right.

Why would a constitutional amendment be less prone to getting butchered beyond all recognition? An amendment may not have its text butchered, but there's no guarantee at all that it will be interpreted the way you hope.

It probably will be interpreted in all the wrong ways you can't even anticipate. All you need for an example is 2A.

Re: American Data Privacy and Protection Act

#232

Ten years or so ago, I was participating in a small business roundtable discussion with one of our state senators. At the time, I ran a consumer research agency and would often have multinational projects involving consumer data collection in both the US and EU; this is before GDPR had become ratified, but Safe Harbor was failing and there was ambiguity about what the future state would look like. Of the 15 or 20 bus…

> Would never clear filibuster. A filibuster by who? Neither party would support any privacy rules that placed any undue importance on privacy.

I'm mostly just projecting based on the current 48+2+50 state of the Senate where virtually everything gets held up. If the Democrats brought it forward, I would expect the Republicans to filibuster just on principle.

Re: American Data Privacy and Protection Act

#233

Earlier quoted context omitted.

States move faster... so fast that a technology company would be constantly chasing 50 different state laws. The Internet is a global entity, and it doesn't strike me as being well served by the "laboratory of the states". Federal legislation is slow, but executive agencies can move faster if they are empowered by legislation to make rules. Congress sets broad principles, and it's not unreasonable that those principl…

After seeing how the ATF operates entirely autonomously to nearly eliminate the right to bear arms through increasingly more unnecessarily complex and ridiculous "rules" that make you felon for things that were previously (and should still be) totally legal, I have zero interest in giving executive agencies autonomy to make laws. And it doesn't matter that the rules can be ruled as ineffective by a high court, becaus…

> unnecessarily complex and ridiculous "rules" that make you felon for things that were previously (and should still be) totally legal

Not going into the US-centric gun debate and assuming that guns are simply tools, isn't it reasonable that gun owners need to monitor the regulations? If you operate heavy machinery or run a chemical lab, I'd expect you to keep a close eye on upcoming legislation and rules. I'd not be surprised if a food truck operator would need to keep track of more rules than gun owners.

Re: American Data Privacy and Protection Act

#234

Earlier quoted context omitted.

But we have to process every request even if we do not find any of their data . A majority of requests are actually this way - people use online services that submit blanket removal requests.

Yeah, that's definitely the case and I see where the hassle is, but to restate my point, those costs are simply a part of overhead and not the business of users. Unless the users are given an opt-out first and foremost, they're owed ownership over their personal data.

Again, the language of the proposed bill is requiring 2 free requests per person.

$100 for an occasional person? No biggie.

Potentially infinite? That's a bit more than normal overhead.

While we haven't seen this sort of DDoS attack through our GDPR process yet, the potential is already there if bad actors or competitors wanted to exploit it.

Re: American Data Privacy and Protection Act

#235

Earlier quoted context omitted.

>>Preemption would be an enormous mistake Preemption is always a mistake, i am not sure why everyone wants federal laws for everything, without even touching the fact that Data privacy is in no way even close to any of the enumerated power of the US Federal Government Federal Laws almost always favor large companies, the exact companies these laws are needed to protect the consumer from Facebook, Microsoft, etc would…

> Preemption is always a mistake, i am not sure why everyone wants federal laws for everything So that my marriage is recognized across state lines, for a start.

eh poor example imo; that's guaranteed by the Constitution, not legislation.

Re: American Data Privacy and Protection Act

#236

Earlier quoted context omitted.

>>Preemption would be an enormous mistake Preemption is always a mistake, i am not sure why everyone wants federal laws for everything, without even touching the fact that Data privacy is in no way even close to any of the enumerated power of the US Federal Government Federal Laws almost always favor large companies, the exact companies these laws are needed to protect the consumer from Facebook, Microsoft, etc would…

> Preemption is always a mistake, i am not sure why everyone wants federal laws for everything So that my marriage is recognized across state lines, for a start.

Why would you the government to be involved in your marriage?

Re: American Data Privacy and Protection Act

#237

Earlier quoted context omitted.

Users don't like a company, they automatically spam the company with large numbers of requests for personal information which they would legally be required to provide.

Guess they'd better figure out how to get people their data in a more rapid manner. I guess they could use a computer or something to automate it so that users can just click a button to download their data. I mean, what year is this? We've been hearing "automate it, automate it, etc" for years and years now. But to get your personal data, these companies just throw up their hands and say that it's too hard?

When we implemented CCPA lookups, one of the many necessary lookups was through a decade of glacier'd request logs (necessary to hold onto for compliance).

Even ignoring implementation cost, there was a significant computational cost that's pretty hard to avoid.

Re: American Data Privacy and Protection Act

#238

Ten years or so ago, I was participating in a small business roundtable discussion with one of our state senators. At the time, I ran a consumer research agency and would often have multinational projects involving consumer data collection in both the US and EU; this is before GDPR had become ratified, but Safe Harbor was failing and there was ambiguity about what the future state would look like. Of the 15 or 20 bus…

> I maintain that it would be less complicated, less expensive, and more human-friendly to use data privacy rules as globally universal as can be achieved. I think this is a bit naive. As someone who has had to dwell a lot on the specific nuances of German privacy laws vs GDPR or South Korea's, I have come to the conclusion that conflicting privacy laws are a designed feature. I think lawmakers certainly have consume…

I agree that we're not going to see a US privacy framework that's identical to GDPR and where all players have the same obligations and enforcement mechanisms. What is extremely problematic, IMHO, is the US having _no_ privacy framework to speak of while the rest of the world does. Beyond HIPPA and COPPA (and CCPA if you happen to live in Cali), there's really not much recourse for US citizens besides their collection of company-paid credit monitoring after each security breach.

If one outcome of GDPR is that 10-15 years later, the US adopts some sort of national privacy framework that motivates industry to reevaluate their data monetization business models, that's a good outcome.

Re: American Data Privacy and Protection Act

#239
post #3

I see they are also annoyed at cookie banners: > SEC. 210. UNIFIED OPT-OUT MECHANISMS. For the rights established under sections 204(b) and (c), and section 206(c)(3)(D) not later than 18 months after the date of enactment of this Act, the Commission shall establish one or more acceptable privacy protective, centralized mechanisms, including global privacy signals such as browser or device privacy settings, for indiv…

Sigh. I have my cookies enabled because I want to use them. If I didn't, I wouldn't enable them. I wish there were a "fuck GDPR, I agree to whatever terms" browser setting.

GDPR doesn't disallow cookies, it disallows tracking cookies, afaik. Tracking data is not yours too see, so how could you use them? Do you mean that you want personalized ads?

Re: American Data Privacy and Protection Act

#240
Why on earth would we want MORE restrictions and government interference / intrusion in our affairs? Especially in this era of worldwide creeping authoritarianism?

The only way implement these sorts of mandates is stomping all over a developer's right to freedom of expression. I'm a firm believer that code is speech and that limiting what a developer can do is infringing on his own right to free speech.

Post reply on HN