Live data from Hacker News

Californians' data deletion requests, DROP, become enforceable Aug. 1

nbcsandiego.com

51–60 of 106 posts

Re: Californians' data deletion requests, DROP, become enforceable Aug. 1

#51
post #4

Does this mean people can delete comments from HN?

[flagged]

We are never rude or obstinate like this. We will always do whatever we can to protect people's privacy, which we do by redacting PII and moving posts to anonymized accounts.

Re: Californians' data deletion requests, DROP, become enforceable Aug. 1

#52

Earlier quoted context omitted.

This comment [0] from dang might be relevant: > In case it's of interest, here's the standard language from emails I send people: > We try not to delete posts that got replies, because doing so would be unfair to the other commenters in the thread. What I've done so far is reassign it to a random user ID, so it's as if you'd used a throwaway account to post it and there's no link to your main account. Does that work?…

And it’s utterly useless, because your username and all comments get THE SAME random user ID. So once someone identifies that ID as you, it does nothing. When I asked dang to do better after me and my family got death threats online, dang told me “tough luck” To this day thousands of my comments from my old username are on this site and trivially east to link to my real name. (Links to my website, etc)

> dang told me “tough luck”

He (nor I) would never write that or anything like it. What we always say is that we aim to find a compromise between a user's wish for their entire history to be erased and the rest of the community's expectation that when they participate in discussion threads, those threads will persist unadulterated into the future.

We are always willing to redact PII and do other things to prevent people's real identities from being recognized from their HN activity. We help people with requests like this all the time.

Edit:

Now I can see the email in question, I can confirm that dang did not write “tough luck”. We were, and still are, happy to work with this user to redact material that reveals their identity or location from their old comments.

Re: Californians' data deletion requests, DROP, become enforceable Aug. 1

#53
As good intentioned as it is, I don't like the wording used around this law. "Request" and "Ask" and "please delete my information." Notice that regular users have to "ask nicely" but when it's something like the DMCA, which benefits corporations, they use "takedown notices" and "demand letters."

I don't want to ask data brokers, pretty please with sugar on top. I want to be able to demand they do it, and require them to immediately do it and provide proof that they did, under penalty of perjury.

Re: Californians' data deletion requests, DROP, become enforceable Aug. 1

#54
post #39

Earlier quoted context omitted.

I think Apple requires it too or did when I made an app for my mom a few years ago

Not for most people. You definitely did not need it for making an app for your mom. I've released games under my own name and never did that. A random person releasing an app or game on the App Store - you won't need it. But on Android you still might, even for something small, since they changed the rules for new developers. As of November 2023, any new developer account releasing an app basically has to have an Org…

It's probably because I registered the account in her business' name.

Re: Californians' data deletion requests, DROP, become enforceable Aug. 1

#55
post #35

Earlier quoted context omitted.

Look up "long arm statutes". State courts can have jurisdiction over out-of-state entities, subject to limitations established by federal precedent. Doing business with customers who reside in a state generally puts you under that state's jurisdiction, at least for purposes related to that business.

Define “doing business”. If no money is exchanged, how are you “doing business” with them?

If you've collected data on a California resident with the intent to profit from its sale then you're doing some type of business with respect to California

Re: Californians' data deletion requests, DROP, become enforceable Aug. 1

#56
post #2

I've been thinking of making a service which automatically sends deletion requests for all my service companies every month. Like, I currently keep a bunch of spyware features in my car turned of, but I have to keep location turned on to use the built in navigation which keeps track of range for me. Would be nice to have a ceiling on that data's retention. Long term, if compliance with data deletion requests becomes…

If it's a VW, pick up a Ross-Tech VAG-COM + VCDS, locate your Telematics unit (OCU, online communications unit) and remove it; mine was behind the instrument cluster. Then use VCDS on a laptop plugged into your car with VAG-COM, and code out the OCU from every module giving fault codes for its absence. You will probably lose the microphone, as in my Mk7 the microphone line goes through the OCU. Finally, optionally, you can code out your infotainment module's bluetooth features thus taking away another avenue for passive surveillance.

Re: Californians' data deletion requests, DROP, become enforceable Aug. 1

#57

> Companies that fail to comply can face fines of $200 per day for each affected Californian. Does this cover things like credit reports/scores? If someone submits a request to this DROP thing, is it possible data gets deleted that they don't intend?

I hope this is true! Consumer credit is a serious problem. How much better would it be if only corporate entities could take on debt? That goes for school, home, and car loans too. Imagine the return to sanity in pricing when Big Finance can no longer scam time-preferenced and desperate buyers! Society might have a real savings rate again!

Re: Californians' data deletion requests, DROP, become enforceable Aug. 1

#58

Earlier quoted context omitted.

The company would have to not have any interstate presence at all. If you are a business based in the united states that has customers in California, you are easily reachable under California law.

Curious, how so?

Comity iirc is the legal principle of mutually recognizing other states laws (giving them jurisdiction) as in recognizing a marriage contract in other states (and they recognize yours).

That's my guess

Re: Californians' data deletion requests, DROP, become enforceable Aug. 1

#59
post #35

Earlier quoted context omitted.

Look up "long arm statutes". State courts can have jurisdiction over out-of-state entities, subject to limitations established by federal precedent. Doing business with customers who reside in a state generally puts you under that state's jurisdiction, at least for purposes related to that business.

Define “doing business”. If no money is exchanged, how are you “doing business” with them?

From another California regulation (requiring telemarketers to register and secure a bond):

A seller is deemed to be doing business in the state if the seller solicits prospective purchasers from locations in California or solicits prospective purchasers who are located in this state.'

https://oag.ca.gov/consumers/general/telreg>

The DROP act creates a right to California residents. To the extent I've read the statute, it doesn't define what entities are covered (see: https://leginfo.legislature.ca.gov/faces/codes_displayText.x...>), which seems to me to suggest that affected entities are defined by their data collection from California residents, not where or how they engage in activities otherwise in California.

Re: Californians' data deletion requests, DROP, become enforceable Aug. 1

#60
Does this apply to Google, car companies, etc, or did they bribe in exceptions for themselves (like California grocery stores did for the Do Not Sell My Personal Information law)?

Also, who gets the $200/day? If I issue a drop request, wait 145 days, then buy my data from brokers, do they have to pay me $20,000 per record they return?

Post reply on HN